Compliance

Built to be compliant.
Not patched to be compliant.

CONNETIC processes publicly available planning data under a documented UK GDPR legitimate interests framework. Every technical control, every process, and every contractual obligation is designed around one principle: the correct party holds the correct responsibility.

ICO Registered
Data Controller Model
90-Day Auto-Deletion

How it works

You receive a WhatsApp notification.
We handle everything else.

When a homeowner receives a CONNETIC brochure, the data controller for that communication is CONNETIC — not you. You never receive, store, or process homeowner personal data. Your GDPR exposure in connection with our outreach is zero. This is not a contractual workaround. It is the structural model.

The correct party holds the correct responsibility.

Overview

Data protection at a glance.

Data Controller
Nexxtrade Ltd t/a CONNETIC
ICO Registration
Registered · Advertising, marketing and PR
Lawful basis
Legitimate Interests · Art. 6(1)(f) UK GDPR
LIA
On file · Full 3-part assessment
ROPA
Maintained · Record of Processing
Privacy Policy
connetic.uk/privacy

Data we process

What data we process — and what we never store.

  • Property street address and postcode
    Source
    PlanWire API (council portal — public register)
    What we never store
    Buyer name — never stored
  • Planning work description
    Source
    PlanWire API (council portal — public register)
    What we never store
    Applicant name — never stored
  • Approved architectural drawings
    Source
    Local authority portal (public — LGA 1972)
    What we never store
    Personal identity from drawings

Data minimisation is technical, not procedural. Names are excluded at the point of ingestion by the pipeline — they are never in our system.

Channels

Physical mail only. By design.

  • Physical post to 'The Homeowner'
    CONNETIC position
    Used — most compliant channel
  • Email to homeowner
    CONNETIC position
    Not used
  • SMS to homeowner
    CONNETIC position
    Not used
  • Cold calling homeowner
    CONNETIC position
    Not used

Every brochure is addressed to 'The Homeowner' — not by personal name. Every brochure includes our contact details and a clear opt-out instruction referencing the Mailing Preference Service.

Suppression

Three layers of suppression on every batch.

Layer 01

MPS Screening

Every address list screened against the Mailing Preference Service before upload to our print provider. Opted-out addresses removed automatically. Over 5.4 million UK consumers are registered — we screen them all on every send.

Layer 02

CONNETIC Direct Suppression List

Any homeowner who contacts us directly to opt out is added to our suppression list within 5 working days. That address is permanently excluded from all future mailings across all clients and all councils.

Layer 03

Print Partner Blocklist

Our fulfilment partner maintains a platform-level blocklist. Opted-out addresses are suppressed at the print provider level, independently of our own list.

Note

Royal Mail Door to Door opt-out

This opt-out covers unaddressed mail only — leaflets with no postal address. It does not apply to CONNETIC's addressed brochures. Royal Mail is legally obliged to deliver addressed mail regardless of this opt-out.

Retention

90 days. Automated. No exceptions.

Homeowner data is automatically purged from all CONNETIC systems after 90 days. This is a technical control in the pipeline code — not a manual process.

  • Homeowner addresses
    Retention
    90 days
    Basis
    Automated deletion
  • Planning descriptions
    Retention
    90 days
    Basis
    Automated deletion
  • Blueprint images
    Retention
    90 days
    Basis
    Automated deletion
  • Client business records
    Retention
    Contract + 6 years
    Basis
    HMRC / Companies Act
  • Suppression list
    Retention
    Indefinitely
    Basis
    Legal obligation

Infrastructure

Infrastructure and subprocessors.

One unified directory: how we host and secure the pipeline, and every third-party processor that touches data on our behalf.

A · Infrastructure controls

EU-Region Hosting
Railway.app · EU data centre
TLS 1.2+ Encryption
In transit and at rest
Secrets Management
Environment variables · never hardcoded
Access Control
Private repo · authorised personnel only

B · Subprocessors

5 vendors · all DPAs on file
Fulfilment supplier — TBC
Role
Print and post
Under confirmation — DPA to be signed prior to launch
Data Soap
Role
MPS screening
UK · Suppression-only DPA
Supabase
Role
Database / lead inbox
EU Region (eu-west-2) · SOC 2
Anthropic
Role
Letter generation
No personal names processed
Railway.app
Role
Pipeline hosting
EU Region · ISO 27001 (GCP)

Your obligations

Your obligations as a client.
You have almost none.

Because CONNETIC is the Data Controller for all homeowner data, your obligations in connection with our outreach are minimal:

Low-effort by design
  • Obligation 01
    Notify us within 48 hours if you receive an opt-out request or data subject rights request relating to a CONNETIC brochure.
  • Obligation 02
    Do not use any address or signal from our service to conduct independent direct marketing without establishing your own lawful basis.
  • Obligation 03
    Keep your contact details and QR destination current so opt-out instructions on brochures reach you.
That's it. Everything else is on us.

Security

Incident response.

In the event of a suspected data breach:

01Step

Internal assessment within 24 hours

02Step

ICO notified within 72 hours where required under UK GDPR Article 33

03Step

Affected individuals notified where required under Article 34

04Step

Full incident log maintained

05Step

Root cause documented and remediation applied

Documents

Compliance documents available on request.

Legitimate Interests Assessment
LIA · PDF · 12 pages
Record of Processing Activities
ROPA · PDF · 8 pages
Data Processing Agreements
Data Soap, Airtable, Anthropic, Railway
Privacy Policy
connetic.uk/privacy
ICO Registration
Confirmation certificate · PDF

Get in touch

Questions about how we handle data?

We're happy to share our full LIA, ROPA, or any DPA before you commit. Most clients find the compliance model is one of the reasons they chose us — not a concern they needed to resolve.

Nexxtrade Ltd t/a CONNETIC · Leeds, UK · ICO Registered · connetic.uk