What we do with the people named in your pack
Your pack names people: who is on the roster, who decides on a lockdown, sometimes who would need help getting out. They did not sign up to us, you entered them, and that makes you responsible for what your procedures say and us responsible for handling it properly. This page is the written version of that, and you can rely on it.
What is being processed, and for how long
| Subject matter | Producing and maintaining public protection procedures for your premises under the Terrorism (Protection of Premises) Act 2025, and keeping the record that your people have read them. |
|---|---|
| Duration | For as long as your subscription runs, and for twelve months after you close your account. An account that has never paid is deleted six months after it was last used, with a warning email thirty days beforehand. The three exceptions are set out below. |
| Nature and purpose | Storing what you enter, generating documents from it, letting you and your staff read those documents, and holding the dated record of who confirmed what. We do nothing else with it. |
| Type of personal data | Names and roles of the people on your staff roster. Names, job titles and contact details of the people you name as running the premises. Free-text answers about your building, which are yours to write and may name a person if you put one in them. No special category data is asked for anywhere, and the one question that comes close, who might need help getting out, asks for groups rather than individuals and says so on the form. |
| Categories of data subject | Your employees and volunteers, and whoever you name as the responsible person or the day-to-day contact for the premises. |
| Your instructions | This page, together with our terms, is the documented instruction we process on. We will not process your data for any other purpose, and if we are ever required by law to do something outside it we will tell you first unless the law forbids that. |
Who is responsible for what
You are the controller of the details you enter about your staff and your building. You decide what goes into your procedures, and you decide when a name comes out of them. We are the processor: we hold that information, turn it into your documents, and do nothing else with it. We do not sell it, we do not use it to train anything, and we do not use it for our own purposes.
For your own account details, the email you sign in with and what you pay, we are the controller. That half is covered by our privacy notice.
What we do on your instruction
We process this data only to provide the service: to build your pack, to let your staff confirm they have read it, to keep the record of who confirmed what, and to support you when you ask. If you tell us to delete something we delete it, subject to three exceptions, all three set out in our privacy notice:
- Records of what you paid. UK tax law requires six years of them. That is a legal obligation rather than a choice.
- Backups. Deleted data goes from the live service at once and cannot be restored into it, then ages out of our encrypted backups within seven months.
- Records that prove something happened. Where a name is attached to evidence, we remove the name and keep the evidence. "Somebody confirmed version 3 on 4 March" survives; the name is replaced with a marker recording that it was redacted, when, and on whose request. Deleting the row itself would destroy your own proof that your staff were briefed. Anyone who never confirmed anything is deleted outright.
If one of your staff asks us to remove their details, we will tell them to ask you, and we will tell you they have asked. That is not us passing the parcel: your procedures are your document, and we cannot decide that a name should come out of your lockdown plan.
When you give us that instruction we act on it without undue delay, and in practice the same working day. Removing somebody is one operation for us; it is your deadline for answering them that the clock is running against, not ours, so we will not be the reason you miss it. If anything about a request means we cannot act at once, we tell you why on the day rather than at the end of a period.
Who else sees it
Four companies in five roles, and only these. Google appears twice because the mailbox and the backup store are separate services that see completely different things. Each sees the least it can.
| Hostinger | Runs the server and the database, so it holds everything the service holds. United Kingdom (Manchester). |
|---|---|
| Google (Workspace) | Sends and receives our email. Sees the address we are writing to and what the message says, which is your venue name and a link. |
| Google (Drive) | Holds our offsite backups, encrypted before they leave our server. Google stores the encrypted files and does not have the key, so it cannot read your data, your staff names or anything else in them. This is worth saying plainly because it is unusual. |
| Stripe | Takes the payment. Sees the buyer's email, billing address and card details, and issues the VAT invoice. Sees nothing about your building or your staff. |
| Anthropic |
Runs the check on your answers before your documents are made, and
the assistant in the corner of every page. Sees your answers about
the building, and whatever you type into the assistant.
It is not sent the names of anyone on your roster:
it gets how many people there are and what roles they hold, and is
told that we withheld the names. It is sent no email addresses, no
contact details and nothing about billing.
What we cannot control is what you type. An answer sent for checking goes as you wrote it, so a person's name typed into a box asking for a job title travels with it. United States. |
Where it goes, and what covers it
The application, its database and its nightly backups are held in the United Kingdom. The offsite copies are encrypted on that server before they go anywhere, so what reaches Google Drive is ciphertext without a key.
Two things leave the UK. The check on your answers runs on a model in the United States, and our mailbox is Google Ireland, which may process email elsewhere. Both are made under the provider's data processing terms, which incorporate the Standard Contractual Clauses with the UK International Data Transfer Addendum issued by the Information Commissioner. That is the mechanism, named, so you can check it against your own policy rather than take our word for it.
Your staff roster is in neither of them. The one place you name other people is the roster, and it is the one thing we deliberately do not pass on: the reviewer works from counts and roles. The names of your staff are in your pack, in our UK database, and in the encrypted backups nobody else can read.
How it is kept safe
Article 32 asks for measures appropriate to the risk. These are ours, and each one is a thing the software does rather than a thing we intend:
- There are no passwords, anywhere. Signing in is a six-digit code sent to your inbox, stored only as a hash with a server-side key, and it expires in ten minutes. There is no password database to leak and none can be added: it is forbidden by the repository's own build rules.
- Everything is encrypted in transit, over TLS, with HSTS set so a browser that has visited once will not use plain http again.
- The database refuses to rewrite history. The application connects as a restricted role that has no UPDATE or DELETE on the documents, attestations and download-log tables. An attacker with the application's own credentials cannot quietly alter your evidence, and neither can we.
- Offsite backups are encrypted before they leave the server, with a key held off it. Google Drive stores files it cannot read.
- Your staff roster is withheld from the answer checker. It receives a count and the roles, never the names, and that is enforced in code and tested rather than promised.
- Personal data is stripped before anything is logged, at the point of writing rather than afterwards.
- Cookies are first-party and unreadable by JavaScript, the content security policy allows no third-party origin at all, and every sensitive route is rate limited.
- Access is one person. Four Drills is run by its founder, so the list of people who can reach production is one name long. That is a real limit on exposure and it is also a real concentration, which is why the continuity clause below exists.
Confidentiality. Anyone we ever authorise to process your data will be under a written duty of confidence before they are given access. Today that list is the founder alone.
Sub-processors. The five roles listed above are the only ones, and you are giving general authorisation for them by accepting these terms. If we intend to add or replace one we will tell you at least thirty days beforehand, and you may object; if we cannot resolve an objection you may cancel and we will refund the unused part of your year. This is the one circumstance in which we refund part of a year.
Helping you answer your people. If one of your staff exercises a right, we will give you what you need to answer them, and act on your instruction without undue delay. We will not answer them ourselves: it is your document and your decision.
Showing you. We will give you the information you need to show that we are meeting this agreement, and we will answer a security questionnaire. If you need to audit us, write and we will arrange it at a reasonable time and no more than once a year unless something has gone wrong, in which case as often as it takes.
If we stop
Four Drills is a small company run by one person, and you are buying a record you may need years from now. So it is worth saying plainly what happens if we are not here.
- Your documents are ordinary PDFs and they are already yours. Download them today and they keep working with no account, no licence check and nothing to phone home to. Nothing we do later can take them back.
- If the service is going to close we will give you at least ninety days' notice by email to every account, and refund the unused part of any year you have paid for.
- Export everything before you go, at any time, including after you cancel. If you would rather have it in a machine-readable form, ask and we will send it.
- Keep a copy off our system. We would say this even if we were certain of being here in ten years: the procedures are meant to be on a wall and in a folder, and a venue whose only copy is in somebody else's database has a single point of failure regardless of who that somebody is.
How long we keep it
While your account is open, and then it depends on whether you have ever paid. If you have, twelve months after you close your account, so that your compliance evidence does not vanish the moment you stop paying. If you have never paid, six months after you last used it, with an email thirty days beforehand; signing in stops it and starts the six months again. The two numbers are one rule: we keep what somebody is relying on, and we do not sit on a building's exit routes and staff details for years because an account was opened once and never used. The exceptions, again, are payment records for six years and backups expiring within seven months.
At the end you choose: return or delete. When the agreement ends you can export everything first, and then we delete it on the timetable above. Tell us to delete it sooner and we will. This is what Article 28(3)(g) asks for, and the only reason it is not simply "we delete everything" is the three exceptions named above, which are the law, the backup schedule and your own evidence.
If something goes wrong
If we discover a breach affecting your data we will tell you without undue delay and within twenty-four hours of becoming aware of it, with what we know, what we are doing, and what you may need to do. Twenty-four rather than seventy-two, deliberately: seventy-two hours is YOUR deadline for telling the Information Commissioner, and a supplier who takes all of it leaves you none. We would rather tell you early with an incomplete picture than late with a tidy one.
We will also help you meet your own obligations under Articles 32 to 36: answering what you need for your breach report, and giving you what we hold if you have to carry out a data protection impact assessment.
Getting your data out
You can download your pack and your attestation records at any time, including after you cancel, without asking us. If you want everything we hold in a machine-readable form, write to hello@fourdrills.co.uk and we will send it within thirty days.
Staff attestation is not live yet: it launches before duties commence (expected spring 2027) and is included in the price you pay today.
This agreement forms part of our terms. If you need it signed as a separate document for your own records, or your insurer or funder needs a particular form of words, write to us and we will do it.
Last updated . We will change the date here whenever the substance of this page changes, and not for a wording tidy.
This page is not legal advice and not security advice. It describes what this service does and what we undertake to do. Decisions about your premises, and about how the Act applies to them, remain yours to take and are worth taking with someone qualified where the answer is not obvious.