Privacy policy
Last updated 8 September 2026
1. Who we are
Plan@Job ("we", "us") is a property maintenance operations platform operated by Net Access Market Ltd, 101 Elim Estate, Weston Street, London SE1 4DD, United Kingdom. We are the controller for our platform account, security and own administration purposes. For company operative onboarding records, the engaging company controls its recruitment, engagement and compliance purposes, and we process those records on its instructions to provide the service. For anything in this policy, contact us at contact@netaccessmarketing.com.
2. What we collect
Account and company details: name, work email, phone, company name, role and team information.
Content you add to the platform: properties, jobs, quotes, variations, invoices, messages, community posts, reviews, photos and videos, completion reports, and compliance documents (for example insurance certificates, DBS certificates and trade accreditations).
Identity verification through Stripe Identity: in this separate flow, your ID document and selfie are submitted to Stripe acting as our processor. We receive the outcome and verified name to match against your company's registered officers. This description does not apply to identity documents uploaded for company operative onboarding, which are stored privately on the platform.
Company operative onboarding: names, addresses, contact details and agreement particulars including day rates; identity, DBS, asbestos and other role-related evidence; upload and review records identifying the uploader and reviewer; and the agreed document and policy versions, acknowledgements and signatures. Signing records include signer identity, timestamps, IP address and browser information, together with email-verification delivery and proof metadata. Accepted agreement and policy text is preserved unchanged so the parties can evidence what was accepted.
Details of other people that members add so work can be done: residents' and landlords' names and contact details, access notes, and contacts imported by members into their own contact books.
Technical data needed to run and secure the service: device and browser information, IP address, and sign-in records (including when you accepted our terms).
3. People whose details are added by members
An engaging company or its authorised recruiter may add operative particulars and documents. Before any such upload, the company must provide the operative with its own applicable privacy notice explaining the purpose, checks, lawful basis, access, retention and rights. Contact that company about its onboarding records or decisions, or contact us and we will help route the request. The company's notice supplements this platform notice.
If you are a resident, landlord or other contact whose details were added to Plan@Job by a property manager or trade business, that business added your details so that repairs and related work can be arranged. We process them for that purpose on the instructions of that business, and everyone who receives them through the platform is required to use them only to deliver the job concerned. If you want your details corrected or removed, contact the business that manages your property, or email us and we will help.
4. How we use data and our lawful bases
We use data to run the platform: creating and routing jobs, quoting, scheduling, messaging, completion reports, invoicing and payment collection; to review compliance documents that trade businesses upload for vetting; to send service notifications; to prevent fraud and abuse and keep the platform secure; and to improve the platform.
For our own controller purposes, our lawful bases under UK GDPR are performance of our contract with you (running your account and the marketplace), our legitimate interests (running a safe, trusted marketplace, securing the service, improving it), and legal obligation (tax, accounting and similar records). The engaging company must identify and explain its own lawful bases for operative onboarding and satisfy any additional legal conditions and safeguards for criminal-record or other sensitive information. Signing an agreement or policy is not blanket consent to that processing.
For operative onboarding, we provide the company's invitation, private document upload and review, agreement generation, personal signing and policy-acknowledgement records. We also process verification and security information to confirm access to the signing email address, protect accounts and prevent misuse. An upload or signature does not replace the company's lawful checks or suitability decision.
We do not sell personal data, and we do not use it for third-party advertising.
5. Who sees what
Data is shared between members only as the platform needs. For example: contractors see a job's full details, including the resident's contact details and exact address, only once their quote is accepted; subcontractors see the scope their contractor shares with them and resident details only where the contractor enables it; clients see the quotes, reports and invoices sent to them. Business vetting documents are available to authorised vetting staff. Private operative onboarding records are restricted to the operative and authorised people within the engaging company who need access to prepare or review the onboarding, with platform access where necessary to operate and secure the service. They are not public profiles or documents shared with residents or unrelated companies.
Service providers who process data for us: Stripe (card payments - card details never touch our servers), Vercel (hosting) and Supabase (database and file storage). Where these providers process data outside the UK (for example in the United States), the transfer is protected by recognised safeguards such as the UK Extension to the EU-US Data Privacy Framework or standard contractual clauses.
Supabase stores private operative documents and onboarding records. Resend delivers operative verification emails and receives the recipient email address and verification-message content needed for delivery. Operative ID and DBS files are not included in those verification emails.
We may disclose data where the law requires it, for example to HMRC, a court or the police.
6. Retention
We keep account data while your account is active. Job, quote, invoice and payment records are kept for as long as needed for tax and legal purposes (normally six years after the tax year they relate to). Other records must be limited to what is necessary for their purpose and applicable law. For company operative onboarding, the company must set and apply its actual retention schedule and explain it in its privacy notice. Identity evidence and full DBS certificates require separate, normally shorter retention than contract and acceptance evidence; the six-year financial-record period and continued account membership are not default reasons to retain them. Retain only the evidence of a check that is still necessary. Signed agreement and policy versions are preserved unchanged while retained to evidence acceptance, with corrections recorded separately; this does not justify indefinite retention. Contact the company or us about a retention, correction or deletion request.
7. Your rights
You can ask us to access, correct, export, restrict or delete your personal data, or object to processing based on legitimate interests, at any time: email contact@netaccessmarketing.com. If you think we have handled your data badly you can complain to the Information Commissioner's Office (ico.org.uk); if you are in the EU you can also complain to your local supervisory authority.
8. Cookies
We use only the cookies needed to keep you signed in and keep the service secure. No advertising or cross-site tracking cookies.
9. Changes and contact
We will update this policy as the platform evolves; material changes will be announced in the app. Questions or requests: contact@netaccessmarketing.com, or write to Net Access Market Ltd, 101 Elim Estate, Weston Street, London SE1 4DD, United Kingdom.