Privacy Policy
Last updated: 12 September 2026
Who We Are
ArchLens is operated by SY Design Studio Ltd ("we", "us"). For privacy queries, contact us via our contact page or email info@sydesignstudio.co.uk.
We are registered with the Information Commissioner's Office (ICO) as a data controller, registration reference ZC210424.
Information We Collect
- Account information: full name, email address, company name (optional), password (stored as a secure hash only).
- Project information: property addresses, proposal descriptions and related details you submit to generate assessments.
- Reports: AI-generated report content associated with your projects.
- Contact enquiries: name, email, telephone (optional) and message content when you contact us.
- Payment information: credit purchases are processed by our payment provider, Stripe. We do not store full card details ourselves.
- Security and usage logs: login timestamps, rate-limiting data, and audit logs of account actions, retained to protect the security of the Service.
How We Use AI to Generate Reports
When you request a Planning Assessment, Building Regulations Assessment or Planning Statement, the project and proposal information you have entered is sent to our AI provider, Anthropic (Claude API), solely to generate your report. We do not send your account password or payment details to the AI provider. You should avoid including information in free-text fields that you would not want processed by our AI provider for this purpose.
We do not claim that Anthropic retains or does not retain this data beyond what is stated in Anthropic's own API terms; you can review Anthropic's current data handling terms directly with Anthropic. [TO CONFIRM sub-processor data retention terms once verified against the live Anthropic API agreement].
Legal Basis for Processing
We process your data to perform our contract with you (providing the Service), for our legitimate interests (security, fraud prevention, service improvement), and to comply with legal obligations.
Data Retention
We retain account and project data for as long as your account remains active. Retention period following account deletion: [TO CONFIRM data retention period]. Security and audit logs are retained for a limited period to support fraud prevention and troubleshooting.
Your Rights
Under UK data protection law, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You can export or delete your account data from your account settings, or contact us directly.
Sharing of Information
We do not sell your personal data. We share data with sub-processors strictly necessary to operate the Service: our AI provider (Anthropic, for report generation), our hosting provider (Hostinger), our email delivery provider (Google), and our payment provider (Stripe, for credit purchases). Where you have agreed to analytics cookies, Google Analytics also receives usage data as described under Cookies below.
Cookies
ArchLens uses a strictly necessary session cookie to keep you logged in securely. It does not track you and cannot be switched off without breaking sign-in, so we do not ask permission for it.
We also use Google Analytics 4 to understand how people find and use the site — which pages they read, and which sources send them here. Google Analytics sets cookies and shares data with Google, including transfer outside the UK, so it does not run unless you agree to it. We ask on your first visit, nothing is set if you decline, and the site behaves identically either way. We have IP anonymisation enabled and do not use Google Analytics for advertising or remarketing.
You can change your mind at any time using the Cookie settings link, which also appears in the footer of every page. Declining removes nothing you have already agreed to on Google's side; to delete data already collected, contact us and we will action the request.
Your choice is remembered in your browser's local storage rather than in a cookie, so recording that you said no does not itself require consent.
Security
We apply industry-standard safeguards including password hashing, encrypted connections (HTTPS), CSRF protection, rate limiting, and role-based access control. No system can be guaranteed 100% secure.
International Transfers
Our AI provider and certain infrastructure providers may process data outside the UK. Where this occurs, appropriate safeguards required under UK data protection law are used.
Complaints
If you are unhappy with how we handle your personal data, you can contact us directly, or lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Changes to This Policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.