Security and data

What we can prove, what we promise, and what we have not checked yet.

Most software security pages read like a list of badges. This one is split into three honest groups, so you can see exactly which sentences are backed by the running software, which are legal commitments, and which we are still verifying before we will put them in writing.

Group A

Confirmed in the software

These are checked against the live configuration of this website and its admin area.

Everything is served over HTTPS

Every page of this website, and every sign-in link from it, is served over an encrypted connection.

No tracking on this website

This site sets no analytics or advertising cookies and loads no tracking scripts. Only cookies strictly needed to make the site work are used.

Card details never reach us

Subscriptions are paid through Stripe's own hosted checkout. Card numbers are entered on Stripe's page, not ours, and we never see or store them.

Locked-down admin data

The enquiry and waiting-list records this website collects are protected by per-row database rules, and the admin views behind them require a signed-in account with an explicit admin role.

Group B

Committed in our legal documents

These are promises already published in our Privacy Policy and Terms of Service. They are contractual commitments rather than technical descriptions.

Who is responsible for your data

PLANIT Innovations UK Ltd is the data controller for your account data and the processor for the client data you put into the product, under UK GDPR.

ICO registration

We are registered with the Information Commissioner's Office under reference ZC111604.

Your rights over your data

You can ask for a copy of your data, correct it, delete it, restrict how it is used, move it elsewhere or withdraw consent. We respond within 30 days, and you can complain to the ICO at any point.

What happens when you cancel

Our Privacy Policy and Terms both state a 30-day window to export your data after cancellation, after which it is deleted.

Who we work with

Our Privacy Policy lists the companies that handle data on our behalf, covering the database, AI drafting, payments and hosting.

Telling you about a problem

If there were a breach affecting your data, our Privacy Policy commits us to telling you promptly.

Drafts are drafts

Anything Grout writes is a first draft for a qualified person to review and sign. Nothing is submitted to a council automatically.

Group C

Not yet verified, so not claimed

We would rather leave a gap here than publish something we cannot evidence. Ask us and we will tell you where each one stands.

Where data is physically stored

We will publish the exact hosting region once it has been confirmed in writing.

Encryption at rest and backup schedule

We will publish the specifics once they have been confirmed against the live configuration.

Separation between customer accounts

Account separation inside the products is being documented properly before we describe it here.

How AI providers handle your text

Retention and training terms with our AI provider will be published once the signed agreement can be pointed to.

Activity history

A record of who changed what, and when, is not something we describe yet.

Calendar and other connections

We do not connect to Google Calendar today, and we would never ask you to make a calendar public to get it working. Any future calendar connection will use a proper per-user sign-in that you can revoke whenever you like.

PLANIT Innovations UK Ltd, company number 17071896, 3rd Floor, 86–90 Paul Street, London, England, EC2A 4NE. Questions about any of this go to hello@gettile.co.uk.

Privacy PolicyTerms of ServiceCookie Policy