Privacy Policy
Last updated: 9 June 2026
This Privacy Policy explains how Engineer OS collects, uses, and protects personal data when you use the Engineer OS platform at engineeros.uk and its subdomains (the “Service”).
Engineer OS is operated by Trailhead Holdings Ltd (“Engineer OS”, “we”, “us”, “our”), a company registered in England and Wales (company number 16910286), with its registered office at 12 Lindsey Close, Brentwood, Essex, CM14 4PN, United Kingdom. We are registered with the UK Information Commissioner’s Office (ICO) under registration reference C1990040.
We take your privacy seriously and process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who this policy applies to
Engineer OS is a multi-tenant platform used by field service businesses (our “Customers”) and the people who work for them. This policy covers two distinct relationships:
- Where we are the controller. For account holders, administrators, and engineers who sign in to Engineer OS, and for visitors to our marketing site, we decide how and why personal data is processed. This policy governs that processing.
- Where we are the processor. When a Customer uploads or creates data about their own end customers, jobs, sites, and contacts, the Customer is the controller and Engineer OS is the processor acting on their instructions. Our handling of that data is governed by the agreement and Data Processing Agreement (DPA) between us and the Customer, not solely by this policy. If you are an end customer of a business that uses Engineer OS, please contact that business about their use of your data.
2. What personal data we collect
Account and identity data. Name, work email address, phone number, role (owner, admin, or engineer), organisation, and authentication data. For engineers, this may also include van registration, home address, and uploaded certificates and their expiry dates where the Customer chooses to record them.
Customer-uploaded content.Jobs, schedules, notes, messages, photos, documents, forms, certificates, and records about the Customer’s own customers, sites, and contacts. This content is controlled by the Customer.
Billing data. Billing contact email and subscription details. Card payments are processed by Stripe; we do not store full card numbers on our systems.
Usage and technical data. Log data, device and browser information, IP address, and actions taken in the Service, collected to operate, secure, and improve the platform.
Communications. Records of support requests and correspondence with us.
3. How we use personal data and our legal bases
We process personal data on the following legal bases under UK GDPR:
- To provide the Service (performance of a contract): creating and managing accounts, authenticating users, delivering job management, forms, photos, certificates, and notifications.
- To take payment (performance of a contract): managing subscriptions, trials, invoices, and renewals through Stripe.
- To operate and secure the platform (legitimate interests): monitoring, preventing abuse, debugging, maintaining service quality, and protecting tenant data isolation.
- To send service communications (performance of a contract or legitimate interests): transactional email such as invites, password resets, certificate expiry digests, and billing notices.
- To send marketing (consent or legitimate interests, where permitted): only where you have agreed or where lawful for business contacts, and always with an option to opt out.
- To meet legal obligations (legal obligation): tax, accounting, and responding to lawful requests.
4. AI features
Engineer OS offers optional AI-assisted features, including notes cleanup and certificate field extraction. Where these features are used, the relevant content is sent to our AI sub-processor (Anthropic) to generate the output. This content is processed only to provide the feature and is not used by us or the sub-processor to train models. See our sub-processor list in section 7.
5. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in, maintain your session, and remember your active organisation. These are essential to the Service. Where we use any analytics or non-essential cookies, we will request consent first. We do not sell personal data or use it for cross-site advertising.
6. How we share personal data
We share personal data only as needed to run the Service:
- With sub-processors who provide infrastructure and tooling on our behalf (section 7), under contracts that require appropriate security and confidentiality.
- With the Customer organisation you belong to, whose administrators can access data within their tenant.
- With professional advisers, auditors, or authorities where required by law.
- In connection with a business transfer, such as a merger or acquisition, subject to this policy.
We do not sell personal data.
7. Sub-processors
We rely on the following sub-processors to deliver the Service. Each is bound by contractual data protection obligations:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and file storage | EU (AWS eu-west, Ireland) |
| Vercel | Application hosting and content delivery | EU / global edge |
| Stripe | Payment processing and subscription billing | EU / UK / US |
| Resend | Transactional email delivery | EU / US |
| Anthropic | AI features (notes cleanup, certificate extraction) | US |
Where data is transferred outside the UK, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision. An up-to-date list of sub-processors is available on request.
8. International transfers
Some sub-processors may process personal data outside the United Kingdom. Where they do, we ensure an appropriate transfer mechanism is in place as described in section 7, so that your data continues to receive a level of protection consistent with UK GDPR.
9. How long we keep data
We retain personal data for as long as your account or the Customer’s account is active, and afterwards only as long as needed for legitimate business or legal purposes, such as billing records and tax obligations. When a Customer’s account is closed, we delete or anonymise tenant data within a reasonable period, except where retention is required by law. Customers may request export or deletion of their data in line with their agreement with us.
10. How we protect data
We apply technical and organisational measures appropriate to the risk, including encryption in transit, role-based access controls, per-tenant data isolation enforced at the database level, and least-privilege access for our systems. No method of transmission or storage is completely secure, but we work to protect your data and to notify the relevant parties and the ICO where required in the event of a personal data breach.
11. Your rights
Under UK GDPR, you have the right to access, correct, delete, or restrict processing of your personal data, to object to processing, to data portability, and to withdraw consent where processing is based on consent. Where Engineer OS is the controller, you can exercise these rights by contacting us using the details in section 13. Where we act as a processor for a Customer, we will refer your request to that Customer, who is the controller.
You also have the right to lodge a complaint with the ICO (ico.org.uk) if you are unhappy with how we have handled your personal data, though we would welcome the chance to address your concern first.
12. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
13. Contact us
For any privacy question or to exercise your rights, contact:
Engineer OS (Trailhead Holdings Ltd)
Email: info@trailheadholdings.uk
Post: 12 Lindsey Close, Brentwood, Essex, CM14 4PN, United Kingdom
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Where changes are material, we will take reasonable steps to notify you.