Version 3.0 — June 2026

Privacy Policy

National Building Intelligence Platform · nbip.uk

Compliant with UK GDPR and the Data Protection Act 2018. Supersedes Version 2.1 (May 2026).

1

Who We Are

The National Building Intelligence Platform ("NBIP", "we", "us", "our") is operated as a trading name of a sole trader based in the United Kingdom. NBIP is not a registered limited company.

NBIP is the data controller for personal data collected through the Platform at nbip.uk.

For any privacy-related queries, contact us at: contact@nbip.uk

2

What Personal Data We Collect

Account and Access Request Data

When you submit a request for platform access or are activated as a subscriber, we collect:

  • Full name
  • Email address
  • Company or organisation name
  • Phone number (if provided)
  • Engagement scope and access level
  • Invoice details (invoice number, date, amount) — held for accounting purposes

Authentication and Session Data

NBIP uses email magic links (one-time login links) for authentication. We do not store passwords. Each login generates a secure, time-limited link sent to your registered email address. Sessions persist for up to 7 days.

Our authentication provider (Supabase) automatically records your last sign-in timestamp and account creation date as part of its standard auth infrastructure. We do not actively query or display this data in our application.

Export Audit Log

Each time you download a data export from the Platform, we record: the date and time of the export, the number of records downloaded, and the filters applied. This audit log is stored against your subscriber record and is accessible to NBIP administrators.

Communications Data

  • Emails you send to contact@nbip.uk
  • Support enquiries or feedback you submit
3

Building Intelligence Data and Public Sources

NBIP is a building intelligence platform. The property intelligence records made available through the Platform ("Building Intelligence Data") are derived exclusively from publicly available UK government and authoritative public datasets — including the Energy Performance of Buildings Register (MHCLG), the Valuation Office Agency, Historic England, the Environment Agency, and other national data sources.

Building Intelligence Data relates to non-domestic properties, not directly to individuals. However, where outputs include addresses that may be associated with identifiable individuals, NBIP acts as a data controller under UK GDPR and processes that data under the lawful basis of legitimate interests — specifically, supporting evidence-led asset management, decarbonisation planning, and regulatory compliance across the built environment.

Subscribers who use Building Intelligence Data in communications with third parties act as independent data controllers in their own right and are responsible for their own compliance with UK GDPR, the Data Protection Act 2018, and all applicable law. NBIP's Terms and Conditions (clause 9.3) set out this responsibility explicitly.

NBIP does not collect building data submitted by users. The Platform is read-only for Subscribers — it surfaces and fuses publicly available data; it does not ingest user-provided building records.

4

How We Collect Your Data

We collect data:

  • Directly from you when you submit an access request, use the Platform, or contact us
  • Automatically when you authenticate — your sign-in triggers a session cookie and is recorded by our auth provider
  • Automatically when you download a data export — we log the event as described in Section 2
  • From third-party public data sources (EPC Register, national energy datasets, ONS, OS) — this is building and property data, not personal data about you as a user
5

Why We Process Your Data

PurposeLegal Basis
Managing access requests and subscriber activationPerformance of a contract
Providing platform access and Building Intelligence Data to SubscribersPerformance of a contract
Sending magic link authentication emailsPerformance of a contract
Managing invoicing and subscription recordsLegal obligation / Performance of a contract
Maintaining export audit logs for security and complianceLegitimate interests (platform integrity and data protection enforcement)
Revoking sessions and managing subscriber lifecycleLegitimate interests (platform security)
Sending service-related communicationsPerformance of a contract
Complying with legal obligationsLegal obligation
Notifying the administrator of new access requestsLegitimate interests (platform management)
Processing Building Intelligence Data derived from public sourcesLegitimate interests (supporting evidence-led asset management and decarbonisation across the built environment)
6

How Long We Keep Your Data

Data TypeRetention Period
Account and access request dataDuration of account, plus 2 years after closure
Export audit log entriesDuration of account, plus 2 years after closure
Auth provider records (last sign-in, account creation)Retained by Supabase per their data retention policy; deleted on account removal
Invoice and payment records7 years (tax and accounting requirements)
Support and communications data3 years from last contact
Building Intelligence Data (property records)Updated periodically — prior-period data retained for cohort access

When retention periods expire, data is securely deleted or anonymised.

7

Who We Share Your Data With

We do not sell your personal data. We share data only in the following circumstances:

Service providers. We use trusted third-party providers to operate the Platform, including: Supabase (database and authentication infrastructure, EU region) and Vercel (hosting and deployment infrastructure). All providers are contractually bound to process your data only on our instructions and in accordance with UK GDPR.

Legal requirements. We may disclose your data where required by law, court order, or regulatory authority.

Business transfers. In the event of a merger, acquisition, or sale of NBIP, your data may be transferred to the acquiring entity. We will notify you in advance.

Aggregated data. We may share anonymised, aggregated data that does not identify any individual user.

8

Cookies and Session Management

Cookie / Storage TypePurpose
Authentication session cookieMaintains your logged-in session for up to 7 days (essential — required for the Platform to function)
Supabase auth tokensSecure session tokens used to verify your identity on each request (essential)

We do not use analytics cookies, advertising cookies, or any third-party tracking technologies. We do not use cookies to store your filter preferences — these are held in temporary browser memory for the duration of your session only.

Essential cookies are required for the Platform to function and do not require consent under UK PECR. We will update this section if any non-essential cookies are introduced in future.

NBIP administrators may revoke your active session at any time, for example upon account suspension. This immediately invalidates your session cookie.

9

Your Rights Under UK GDPR

RightWhat It Means
AccessRequest a copy of the personal data we hold about you
RectificationAsk us to correct inaccurate or incomplete data
ErasureAsk us to delete your data, subject to legal obligations
RestrictionAsk us to pause processing your data in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests
Withdraw consentWithdraw consent for any consent-based processing at any time

To exercise any of these rights, contact us at contact@nbip.uk. We will respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk | 0303 123 1113.

10

Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encrypted data storage and transmission (HTTPS/TLS) via Supabase (EU region) and Vercel
  • Role-based access controls — only authorised NBIP administrators can access subscriber account data
  • Session management with 7-day persistence and administrator revocation capability
  • Export audit logging — every data export is recorded with subscriber identity, date, record count, and filters applied
  • Invite-only access — no self-registration; all accounts are manually activated by an NBIP administrator

No system is entirely immune from risk. In the event of a data breach likely to result in risk to your rights and freedoms, we will notify you and the ICO in accordance with our legal obligations.

11

International Transfers

We aim to store and process all personal data within the UK or the EEA. Our authentication and database infrastructure is provided by Supabase, hosted in the EU region. Our hosting infrastructure is provided by Vercel, using EU edge nodes where possible.

Where any data is transferred outside these regions by a third-party provider, we ensure appropriate safeguards are in place in accordance with UK GDPR, including Standard Contractual Clauses or equivalent transfer mechanisms.

12

Third-Party Links

The Platform may contain links to third-party websites or services. We are not responsible for the privacy practices of those sites and recommend you review their privacy policies before submitting any personal data to them.

13

Children

The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted data to us, please contact us at contact@nbip.uk and we will delete it promptly.

14

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a notice on the Platform. The version date shown in the header will always reflect the most recent version.

15

Contact

For questions about this Privacy Policy or how we handle your data: contact@nbip.uk — subject line "Privacy".

For a formal data subject access request: contact@nbip.uk — subject line "Data Request". We will respond within 30 days.

To report a security concern: contact@nbip.uk — subject line "Security".

NBIP — National Building Intelligence Platform · nbip.uk · contact@nbip.uk

Version 3.0 · June 2026 · Compliant with UK GDPR and the Data Protection Act 2018