Legal

Privacy Policy

Last updated: 12 March 2026  ·  Effective: 12 March 2026

Your privacy matters to us. This Privacy Policy explains how WhealBit, operating as Quick Waste Note (QWTN), collects, uses, stores, and shares your personal data when you use our Service. It also explains your rights under applicable data protection law.

Contents

  1. 01Who We Are
  2. 02Data We Collect
  3. 03Special Category Data
  4. 04How We Collect Data
  5. 05Legal Bases for Processing
  6. 06How We Use Your Data
  7. 07Data Generated Through the Service
  8. 08Sharing Your Data
  9. 09Our Sub-Processors
  10. 10International Transfers
  11. 11Data Retention
  12. 12Security
  13. 13Your Rights Under UK GDPR
  14. 14Children's Privacy
  15. 15Cookies & Tracking
  16. 16Third-Party Links & Services
  17. 17Changes to This Policy
  18. 18Contact & Complaints
01

Who We Are

WhealBit, trading as QWTN ("we", "us", "our") is the data controller responsible for your personal data collected through the Quick Waste Note (QWTN) platform ("Service"). ICO registration pending.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the controller of personal data we process in connection with the Service. Where you enter personal data about your own employees, clients, contractors, or other third parties into the Service, we act as a data processor on your behalf in relation to that data.

Data Controller: WhealBit
Privacy enquiries: privacy@qwtn.co.uk
Jurisdiction: England and Wales

If you have questions, concerns, or requests regarding this Policy or the processing of your personal data, please contact us at privacy@qwtn.co.uk.


02

Data We Collect

We collect the following categories of personal data, depending on how you interact with the Service:

Account & Profile Data

When you create an account, we collect:

  • Full name;
  • Email address;
  • Password (stored in hashed form — we never store plaintext passwords);
  • Business name, address, and postcode (if provided);
  • Electronic signature image (if uploaded);
  • Preferred theme and language settings.

EA Carrier Registration Data

If you verify your EA waste carrier registration through the Service:

  • EA registration number (CBDU/CBDL);
  • Registration type (Upper Tier / Lower Tier);
  • Registration expiry date;
  • Companies House number (if applicable);
  • Verified timestamp.

Billing & Invoice Data

For paid subscriptions, our payment processor collects and processes payment details. We receive and store:

  • Subscription status and plan details;
  • Transaction reference IDs.

We do not store your card number, CVV, or expiry date. These are handled exclusively by our payment processor.

If you choose to store BACS payment details for invoice purposes, we also collect and store:

  • Bank account name;
  • Sort code;
  • Account number.

See Section 3 for important information about this data as special-care financial data.

Waste Transfer Note Data

Data you enter when generating Waste Transfer Notes, including:

  • Waste description, EWC codes, container types, and estimated quantities;
  • Names, companies, addresses, and postcodes of waste producers, carriers, brokers, and recipients;
  • Transfer locations, dates, and times;
  • Carrier registration numbers and permit details;
  • Electronic signature data of transferors, transferees, and other signatories;
  • Transfer chain data (parent notes, chain IDs, deferred party status).

Client & Customer Data

  • Client name, company, address, postcode, and contact email;
  • Client role classification (producer, carrier, disposal facility, broker, etc.);
  • SIC code.

Invoice Data

  • Invoice numbers, statuses, and dates;
  • Line items, quantities, unit prices, VAT amounts, and totals;
  • Invoice notes and payment terms;
  • Recipient email addresses;
  • Sent and paid timestamps;
  • Invoice logo and branding preferences.

Team, Driver & Staff Data

  • Invited team member email addresses;
  • Team member roles (owner, driver, staff) and permissions;
  • Invitation status and timestamps;
  • Driver assignment data (collections assigned, job status updates, driver notes).

Health & Safety Data

When you use the Health & Safety Module, we collect:

  • RAMS: Title, project, location, assessor name, assessment and review dates, hazard descriptions, risk ratings, control measures, methodology, status, and signatory name and signature;
  • Near-Miss Reports: Reporter name (or anonymised flag), category, description, severity, GPS coordinates (latitude and longitude) if location capture is enabled, photo URLs, assignment data, and resolution notes;
  • Accident Records: Injured person's name, date of birth, and role; accident date, time, location, and description; witness names; injury details (body region, type, severity); treatment records (date, type, provider, follow-up required); RIDDOR status, reported timestamp, and reference number. See Section 3 for important information about this data as special category health data.

Fleet Management Data

  • Vehicle registration numbers, VINs, make, model, year, weight class, fuel type, and status;
  • MOT expiry dates, insurance renewal dates, purchase date, and acquisition cost;
  • Walkaround check records (checklist responses, defects, pass/fail results, driver confirmation);
  • Maintenance records (type, cost, labour hours, parts used, technician name);
  • Fuel logs (date, fuel type, quantity, cost, odometer reading);
  • Expense records (category, date, amount, description, supporting documents).

Collections & Scheduling Data

  • Scheduled dates and times, collection type, and status;
  • Driver and customer assignment data;
  • Site address and postcode;
  • Waste description, EWC codes, and estimated quantities;
  • Driver notes entered during or after collection.

Permit Data

  • Permit type, permit number, expiry date, and status;
  • Supporting permit documents (uploaded files).

Usage Data

  • IP address and approximate geolocation;
  • Browser type, version, and operating system;
  • Pages and features accessed, including timestamps;
  • Referral URLs;
  • Session duration and interaction data;
  • Error logs and diagnostic information.

Communication Data

  • Content of any emails, support requests, or contact form submissions you send us;
  • Newsletter subscription email addresses;
  • Email tracking events (opens, clicks, bounces) via our email delivery provider.

Cookie & Tracking Data

See Section 15 for full details of cookies and tracking technologies we use.


03

Special Category Data

The accident book feature processes special category personal data. Health and injury information collected through the accident book constitutes special category data under Article 9 of the UK GDPR and requires a specific legal basis for processing.

When you use the accident book feature within the Health & Safety Module, you record personal data including the injured person's name, date of birth, injury details, and treatment records. This data constitutes special category health data under Article 9 UK GDPR.

Your legal basis. As the data controller for your employees' and workers' personal data, you must have an appropriate Article 9(2) lawful basis to process this data. Relevant bases may include:

  • Article 9(2)(b) — Processing necessary for carrying out obligations in the field of employment and social security and social protection law (e.g. the Health and Safety at Work etc. Act 1974 and RIDDOR);
  • Article 9(2)(h) — Processing necessary for the purposes of preventive or occupational medicine and the assessment of the working capacity of employees.

You are solely responsible for identifying and documenting your lawful basis for processing special category data through the Service.

Our role. We process accident record data only as your data processor, strictly to provide the Service. We do not use accident record data for our own purposes.

Access controls. The Service restricts access to accident records to users with the "Senior Safety Officer" or "Admin" health and safety role. These controls are a technical aid only. You are responsible for implementing appropriate organisational access controls independently.

BACS financial data. While not special category data under UK GDPR, bank account details (sort code and account number) stored in the Service require heightened care. We implement enhanced security measures for this data and recommend that you do not store BACS details in the Service unless strictly necessary for invoice generation purposes.

Location data. GPS coordinates captured in near-miss reports may constitute sensitive data depending on context. We process this data only as your data processor. You are responsible for ensuring that location capture is lawful and that affected individuals are informed of this processing.


04

How We Collect Data

We collect personal data through the following means:

  • Directly from you — when you register an account, enter data into the Service (including waste notes, H&S records, fleet records, permit records), contact us, or subscribe to our newsletter;
  • Automatically — through cookies, server logs, and analytics tools when you access or use the Service;
  • From third parties — including payment processors, authentication providers, and analytics platforms (see Sections 8 and 9);
  • From external APIs — when you perform a Companies House search or EA carrier register lookup through the Service, we query those external APIs and store the results in your account (see Section 9).

05

Legal Bases for Processing

We process your personal data only where we have a valid legal basis under UK GDPR. The legal bases we rely on are:

Contract Performance

Processing necessary to provide the Service, manage your account, process subscriptions, and fulfil our contractual obligations to you — including delivering all modules of the Service (waste notes, H&S, fleet, permits, invoicing, scheduling).

Legitimate Interests

Processing for our legitimate business interests, including improving the Service, preventing fraud, ensuring security, delivering email communications about the Service, and monitoring usage patterns — where these interests are not overridden by your rights and freedoms.

Legal Obligation

Processing required to comply with our legal obligations, including tax records, anti-money laundering requirements, data protection law compliance, and responses to lawful regulatory requests.

Consent

Where you have given your explicit consent, such as for marketing communications or non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Where we rely on legitimate interests, you have the right to object. See Section 13 for details of your rights.

For special category health data processed through the accident book, we rely on Article 9(2)(b) (employment and social security obligations) in our capacity as your data processor. You, as controller, must have your own Article 9(2) basis — see Section 3.


06

How We Use Your Data

We use your personal data for the following purposes:

  • To create, maintain, and manage your account and team;
  • To provide all modules of the Service, including generating, storing, and managing Waste Transfer Notes, H&S records, fleet records, permits, invoices, and collection schedules;
  • To process payments and manage subscriptions;
  • To send transactional emails, including waste note sharing emails, signature request emails, invoice emails, invoice reminders, driver schedule notifications, team invitation emails, and RIDDOR/incident alert emails;
  • To communicate with you about your account, subscriptions, and the Service;
  • To send updates about the Service, including new features and pricing changes (where you have not opted out);
  • To send marketing and promotional communications, where you have consented;
  • To respond to your support requests and enquiries;
  • To maintain the security and integrity of the Service, including rate limiting requests via our infrastructure providers;
  • To detect, prevent, and investigate fraud, abuse, or other unlawful activity;
  • To improve and develop the Service through analysis of aggregated usage patterns;
  • To comply with our legal and regulatory obligations;
  • To enforce our Terms of Service and protect our legal rights;
  • To send regulatory compliance updates relevant to UK waste management, health and safety, or fleet compliance.

We will not use your personal data for purposes incompatible with those listed above without providing you with prior notice.


07

Data Generated Through the Service

Important — Third-Party Personal Data. When you use the Service, you may enter personal data relating to third parties, including clients, waste carriers, employees, drivers, witnesses, injured persons, and their representatives. You are the data controller of that third-party personal data. We process it only as your data processor, strictly for the purpose of delivering the Service.

You are solely responsible for:

  • Ensuring you have a lawful basis for providing third-party personal data to the Service;
  • Providing appropriate privacy notices to individuals whose data you enter into the Service (including employees whose data appears in accident records, near-miss reports, or driver assignment data);
  • Complying with all applicable data protection law in relation to that data;
  • Responding to any data subject requests made by third parties whose data you have entered;
  • Ensuring that special category health data entered into the accident book is processed under an appropriate Article 9(2) legal basis.

Where required by law, we will assist you in responding to data subject requests made in connection with data you have submitted to the Service, subject to any applicable data processing agreement.

Data you store in the Service — including Waste Transfer Notes, H&S records, fleet records, permits, and invoices — is retained in accordance with Section 11. You acknowledge that we may delete this data upon account termination or service discontinuation without independent obligation to export or migrate it to you.


08

Sharing Your Data

We do not sell your personal data. We share your data only in the following circumstances:

Service Providers & Sub-Processors

We engage carefully selected third-party service providers who process personal data on our behalf. See Section 9 for a full list of our current sub-processors.

All service providers are bound by data processing agreements and are required to process data only on our instructions and in accordance with applicable law.

When You Initiate Sharing

When you use features that send data to third parties — such as sharing a Waste Transfer Note via email, sending a signature request, sending an invoice, or inviting a team member — you direct us to transmit your data to the specified recipient. You are responsible for ensuring you are authorised to share that data with the recipient.

External API Lookups

When you perform a Companies House search or EA carrier register lookup through the Service, we query those external APIs on your behalf. The data returned is stored in your account. These queries are subject to the terms and privacy policies of Companies House and the Environment Agency respectively.

Legal Obligations

We may disclose your data where required to do so by law, court order, or regulatory authority (including the Environment Agency, HSE, ICO, DVSA, or HMRC), or where disclosure is necessary to protect our legal rights, investigate fraud, or protect the safety of any person.

Business Transfers

In the event of a merger, acquisition, sale of assets, or other corporate transaction involving the Company, your personal data may be transferred to the successor entity. We will notify you of any such transfer as required by law.

With Your Consent

We may share your data with third parties in other circumstances where you have given your explicit consent.

We do not share your personal data with third parties for their own marketing purposes without your explicit consent.


09

Our Sub-Processors

The following third-party sub-processors currently process personal data on our behalf in connection with the Service. We maintain data processing agreements with each.

Sub-ProcessorPurposeLocation
Supabase, Inc.Database, authentication, and file storage (all account data, document data, H&S records, fleet records)EU / US (AWS)
Twilio SendGridTransactional email delivery (waste note sharing, signature requests, invoices, team invitations, incident alerts, reminders)US
Cloudflare, Inc.CAPTCHA verification (Turnstile), network security, and CDNUS
Upstash, Inc.Redis-based rate limiting and request throttlingEU / US
Vercel, Inc.Application hosting, edge functions, and analyticsUS
Companies House (HM Government)Company name and registration lookup (queried only when you initiate a search)UK
Environment Agency (HM Government)Waste carrier register lookup (queried only when you initiate a verification)UK

We may update this list from time to time as our sub-processors change. Material changes will be reflected in this Policy. You may request the current sub-processor list at any time by contacting us at privacy@qwtn.co.uk.


10

International Transfers

The Service is operated from England and Wales. However, some of our sub-processors (including Supabase, SendGrid, Cloudflare, Upstash, and Vercel) may process your data in the United States or other countries outside the UK or EEA.

Where we transfer personal data outside the UK, we ensure that appropriate safeguards are in place in accordance with UK GDPR, including:

  • Transfers to countries with an adequacy decision from the UK Secretary of State;
  • Use of UK International Data Transfer Agreements (IDTAs) or equivalent standard contractual clauses;
  • Reliance on sub-processors' participation in approved transfer frameworks.

You may request further information about international transfers and the safeguards in place by contacting us at privacy@qwtn.co.uk.


11

Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes or enforce our agreements.

Data TypeRetention PeriodReason
Account dataDuration of account + 6 yearsLegal, contractual, and tax obligations
Billing & payment records7 years from transactionHMRC and legal requirements
Waste Transfer Notes (Pro/Business)2 years from creation (minimum)Statutory Duty of Care retention
Waste Transfer Notes (Free)90 days from creationService delivery
Hazardous waste consignment notes3 years from creationHazardous Waste Regulations 2005
H&S records (RAMS, near-miss)3 years from creationRIDDOR and HSE record-keeping guidance
Accident records3 years from date of last entrySocial Security (Claims and Payments) Regulations 1979 / RIDDOR
Fleet walkaround records15 months from creationO-licence operator compliance guidance
Fleet maintenance recordsDuration of vehicle ownership + 2 yearsOperator compliance and contractual
Permit documentsDuration of permit + 3 yearsRegulatory compliance
BACS payment detailsDuration of account (deleted on request)Invoice generation; deleted upon account closure
GPS/location data (near-miss)Same as associated H&S recordH&S record-keeping
Photo uploads (H&S/fleet)Same as associated recordH&S and fleet record-keeping
Usage & analytics data26 months from collectionService improvement
Support communications3 years from last contactDispute resolution
Marketing consent recordsDuration of consent + 3 yearsConsent management
Security & fraud logs12 months from creationSecurity and compliance

After the applicable retention period expires, we will securely delete or anonymise your personal data. Anonymised data (which cannot be used to identify you) may be retained indefinitely for analytical purposes.

If your account is closed — whether by you or by us — we may retain certain data for the periods set out above, even after account closure, to comply with our legal obligations.


12

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

  • Encryption of data in transit (TLS/HTTPS);
  • Encryption of sensitive data at rest;
  • Secure password hashing (passwords are never stored in plaintext);
  • Row-level security database policies restricting access to data by organisation;
  • Role-based access controls within the application;
  • Rate limiting on all API endpoints to prevent brute-force and abuse;
  • CAPTCHA verification on public-facing forms;
  • Access controls limiting staff access to personal data on a need-to-know basis;
  • Regular security assessments and monitoring;
  • Secure development practices.
No method of data transmission or storage is 100% secure. While we take data security seriously and implement industry-standard measures, we cannot guarantee the absolute security of your personal data. You use the Service at your own risk. We are not liable for any unauthorised access, breach, or loss of data that occurs despite our reasonable security measures, except to the extent required by law.

If you believe your account has been compromised, please contact us immediately at privacy@qwtn.co.uk.

Data Breach Notification. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you without undue delay, as required by UK GDPR, and will notify the Information Commissioner's Office (ICO) within 72 hours where required.


13

Your Rights Under UK GDPR

Subject to applicable law and certain exceptions, you have the following rights in relation to your personal data:

Right of Access

You can request a copy of the personal data we hold about you (a "Subject Access Request" or SAR). We will respond within one month of receipt.

Right to Rectification

You can ask us to correct inaccurate or incomplete personal data we hold about you.

Right to Erasure ("Right to be Forgotten")

You can ask us to delete your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent. This right does not apply where we are required to retain data by law — for example, accident records subject to statutory retention requirements cannot be deleted until the retention period expires.

Right to Restriction of Processing

You can ask us to restrict the processing of your personal data in certain circumstances, for example while you contest its accuracy.

Right to Data Portability

Where processing is based on contract or consent, you can request a machine-readable copy of personal data you have provided to us.

Right to Object

You can object to processing based on our legitimate interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Rights in Relation to Automated Decision-Making

You have the right not to be subject to solely automated decisions that significantly affect you. We do not currently make such decisions.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us at privacy@qwtn.co.uk. We may ask you to verify your identity before processing your request. We will respond within one month, which may be extended by a further two months for complex or numerous requests (we will notify you of any extension).

We will not charge a fee for exercising your rights unless a request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act.

Right to Lodge a Complaint. If you are not satisfied with our handling of your personal data or your request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection:

Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113

We would welcome the opportunity to address any concerns directly before you contact the ICO, and encourage you to contact us first.


14

Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect or process personal data from children. If you believe that a child under 18 has provided personal data to us, please contact us immediately at privacy@qwtn.co.uk and we will take steps to delete that data.

This restriction does not affect accident or H&S records that may incidentally reference a minor (for example, a member of the public). Such data must be handled in accordance with UK GDPR and you, as the data controller, are responsible for appropriate safeguarding.


15

Cookies & Tracking

We use cookies and similar tracking technologies on the Service. A cookie is a small text file placed on your device when you visit a website.

Types of Cookies We Use

Strictly Necessary Cookies

Essential for the operation of the Service, including session management, security, authentication, and CAPTCHA verification (Cloudflare Turnstile). These cannot be disabled without significantly affecting the Service.

Functional Cookies

Enable personalised features such as remembering your preferences, theme settings, and UI state. These are not strictly necessary but enhance your experience.

Analytics Cookies

Help us understand how users interact with the Service, which features are most used, and where improvements can be made. We use aggregated and anonymised data wherever possible (via Vercel Analytics).

Marketing Cookies

Used to deliver relevant advertising or to track the effectiveness of marketing campaigns. We will only use these with your explicit consent.

Email Tracking. Emails sent through the Service via our email delivery provider (SendGrid) may include tracking pixels that allow us to record whether an email was opened and whether links were clicked. This data is used solely to monitor deliverability and improve our communications. You can opt out of email tracking by disabling image loading in your email client.

Cookie Consent. When you first visit the Service, you will be presented with a cookie banner. By accepting non-essential cookies, you consent to their use. You can withdraw or update your cookie preferences at any time via the cookie settings link in the footer.

Managing Cookies. You can also control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service. Most browsers allow you to:

  • See what cookies are set;
  • Accept or decline cookies individually or in groups;
  • Delete existing cookies;
  • Block third-party cookies.

For more information about managing cookies, visit allaboutcookies.org.


16

Third-Party Links & Services

The Service may contain links to third-party websites or services. These third-party services have their own privacy policies, and we accept no responsibility or liability for their content, privacy practices, or data handling.

Where we use third-party integrations (such as payment processors, Companies House, the EA carrier register, or analytics tools), those providers operate under their own privacy policies. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.


17

Changes to This Policy

We reserve the right to update this Privacy Policy at any time to reflect changes in our data practices, legal obligations, new Service features, or changes to our sub-processors. When we make material changes, we will update the "Last updated" date at the top of this page and, where required, notify you by email or through a notice within the Service.

We encourage you to review this Policy periodically. Your continued use of the Service after any update constitutes your acceptance of the updated Policy. If you do not agree with any changes, you must stop using the Service and may close your account.


18

Contact & Complaints

For any questions, requests, or concerns about this Privacy Policy or the way we handle your personal data, please contact our privacy team:

WhealBit — Privacy

Email: privacy@qwtn.co.uk

Response time: Within 30 days

Jurisdiction: England and Wales

If you are dissatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).

ICO Contact
ico.org.uk  ·  0303 123 1113
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF