Privacy Policy
Data controller:
Cement Industries Ltd.
14 Henley Place, London Road, Teynham,
Sittingbourne, England, ME9 9QB
Email: contact@cementindustries.co.uk
Company number: 15657644
This Privacy Policy explains how we collect, use, and protect personal data when you use Concrete Direct (the customer mobile application and website at concretedirect.uk), together the "Customer Platform".
Personal data we collect
We may collect and process the following categories of personal data:
- Account data: email address, password (stored in hashed form), user role, and email verification status.
- Social login (optional): if you sign in with Google, we receive identifiers and email address from Google as permitted by your Google account settings.
- Profile data: name, phone numbers, company details where applicable (company name, registration number, VAT number), business or home address, and Service Area subscription settings.
- Order and transaction data: order details, delivery addresses, location coordinates used for delivery validation, concrete specification and volume, schedules, invoices, proformas, subscription plan information, and payment status where applicable.
- Communications: messages sent through in-app chat and support channels.
- Device and technical data: push notification tokens, device and platform type, app version, IP address, and server logs for security and troubleshooting.
- Local app storage: the mobile app may store order drafts and preferences on your device.
Service notifications (email and push)
We send transactional service notifications by email and, where you enable notifications on your device and we hold a valid push token, by push notification. These messages keep you informed about your account and activity on the Customer Platform.
Depending on your orders and account, notifications may relate to: new quotes and quote updates; progress through each stage of an order request (including scheduling, acceptance, production, delivery, and completion or cancellation); payment status, proformas, and invoices; subscription and Service Area changes; in-app chat and support messages; and other account events (such as verification, security, or changes to your profile or account status).
These are service messages about your use of the platform, not third-party advertising. Optional marketing, if we offer it in future, would be subject to separate consent where required by law.
You can turn off push notifications in your device settings. Some emails (for example security, legal, or tax-related notices) may still be sent where necessary to operate the service or meet legal obligations.
How we use your data
We process personal data to create and manage your customer account, submit and fulfil order requests, issue invoices and proformas, manage subscriptions and Service Area settings, provide maps and address services, send service notifications as described above (email and push), maintain security, prevent abuse, keep audit logs, and comply with legal obligations.
Our legal bases under UK GDPR include performance of a contract, legitimate interests, and legal obligation. Where required, we will ask for your consent (for example for optional marketing, if offered).
We do not intentionally collect special category data (such as health data).
Closing your account
You can close your account in the mobile app or website under Account → Close account.
After closure you will not be able to log in. We will stop using your personal data for active account management and optional marketing where applicable.
Closing your account does not delete order, invoice, or tax records we are required or permitted to keep under UK law.
Retention
We retain personal data for as long as your account is active and as needed for orders, invoicing, legal and tax retention, and dispute resolution.
After account closure, we may retain order, invoice, and related records containing personal data for up to six years from the end of the relevant financial year or from the date of the document (as applicable under UK Corporation Tax and VAT rules), or longer if required by law, an HMRC enquiry, late filings, or legal claims.
Backup and log retention periods depend on operational and security requirements.
You may request erasure of personal data not subject to these obligations by contacting contact@cementindustries.co.uk. We will respond within one month where UK GDPR applies.
Security
We use technical and organisational measures including encryption in transit (HTTPS), access controls, and hashed passwords. No method of transmission or storage is completely secure.
Your rights (UK GDPR)
You may have the right to access, rectify, erase, restrict, object to processing, and data portability, and to withdraw consent where processing is based on consent.
You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
To exercise your rights, contact us at contact@cementindustries.co.uk.
Children
The Customer Platform is intended for users aged 18 or over and is not directed at children.
App-specific notes
The Concrete Direct mobile app may request notification permission so we can send push alerts described in Service notifications (email and push). Account closure is available under Account → Close account.
Map features use delivery address data you provide and Google mapping services. We do not continuously track your GPS in the background unless a future feature explicitly requests that permission and this policy is updated accordingly.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version at https://concretedirect.uk/privacy with a revised date. Material changes may be communicated in-app or by email where appropriate.
Contact
Cement Industries Ltd.
14 Henley Place, London Road, Teynham,
Sittingbourne, England, ME9 9QB
Email: contact@cementindustries.co.uk
Company number: 15657644