Skip to main content

Privacy Policy

Version 2026-05-05 · Last updated 5 May 2026

Introduction

ET Planning Ltd ("we", "our", "us") is the data controller for the personal data we process. This policy explains how we collect, use, store, and protect your personal data when you use our website or engage our services.

If you have any questions, you can contact us at:

ET Planning Ltd 200 Dukes Ride Crowthorne, RG45 6DS Email: privacy@etplanning.co.uk Phone: 01344 508048

We are registered with the Information Commissioner's Office (ICO) under reference ZA814553.

What we collect

We collect personal data in the following circumstances.

When you submit the contact form or a lead-capture form:

  • Name
  • Email address
  • Phone number (optional)
  • Site / property address relating to your enquiry
  • The message you send us
  • Service interest, project type, and planning stage (where provided)
  • Postcode and local planning authority (where provided)
  • Marketing-consent preference

When you subscribe to our newsletter or watchlist:

  • Email address and (optionally) name
  • Postcode and local planning authority (for the Local Plan Watchlist)
  • Interest categories you select
  • Confirmation timestamp from the double opt-in process

Automatically, when you use the site:

  • IP address and user-agent string (kept for 90 days only — see Retention below)
  • Referring URL
  • Aggregated, non-identifying analytics about page views and on-site behaviour

When you start a chat with our AI assistant:

  • Any details you choose to share in the chat
  • A conversation record linked to your session

How we use your data

We use your personal data to:

  • Respond to your enquiries and provide planning consultancy services.
  • Prepare and submit planning applications on your behalf.
  • Send you the documents, guides, or alerts you have requested.
  • Send marketing emails and watchlist updates only where you have given specific consent.
  • Operate, secure, and improve the website.
  • Comply with our legal and regulatory obligations.

Lawful basis

We rely on the following lawful bases under the UK GDPR:

  • Legitimate interests — to respond to enquiries you initiate via the contact form, and to operate and secure our website. You can object to processing based on legitimate interests at any time.
  • Contract — to deliver the services you have instructed us to provide.
  • Consent — for marketing emails, the newsletter, and the Local Plan Watchlist. You can withdraw consent at any time without affecting the lawfulness of processing already carried out.
  • Legal obligation — where retention or disclosure is required by law (e.g. tax records, planning regulations, court orders).

Consent record

When you submit a form or subscribe to a list, we record the date and time of your consent, the version of this privacy policy in force at that point, the page from which consent was given, and your IP address. This is so we can demonstrate, if asked, that your consent was freely given, specific, informed, and unambiguous.

Who we share data with

We share personal data only with the following categories of recipient:

  • Local planning authorities and statutory consultees — where necessary to progress an application you have instructed us on.
  • Professional collaborators — architects, surveyors, ecologists, or other consultants working with you on your project, with your knowledge.
  • Our sub-processors — third-party service providers who process data on our behalf under written agreements:
    • Convex (database and application platform)
    • Resend (transactional and marketing email delivery)
    • Clerk (authentication for staff accounts)
    • Our hosting provider (server infrastructure)
  • Legal and regulatory authorities — where required by law.

We do not sell your personal data. We do not share your data for advertising or profiling by third parties.

International transfers

Where our sub-processors process personal data outside the UK, the transfer is covered by an appropriate safeguard:

  • Resend processes email data in the European Economic Area (Ireland). This transfer is covered by the UK-EU adequacy decision, so no additional safeguards are required.
  • Convex and Clerk may process data in the United States. Transfers are protected by the UK International Data Transfer Agreement (IDTA) executed as part of our Data Processing Agreements with each provider.

We do not transfer your personal data to any other country without an equivalent safeguard in place.

Retention

We keep your personal data only for as long as we need it.

  • Contact form and lead-capture submissions — 7 years from the date of last contact, in line with our professional indemnity insurance requirements and the limitation period for contract claims.
  • Spam-flagged submissions — 30 days, then permanently deleted.
  • IP address and user-agent on submissions — 90 days, then cleared from the record.
  • Newsletter / watchlist subscribers — for as long as you remain subscribed; 30 days after you unsubscribe.
  • AI chat conversations without a contact submission — 90 days, then permanently deleted.
  • Audit log of administrative access to personal data — 24 months.

When the retention period expires, records are either permanently deleted or anonymised so they can no longer be linked to you.

Your rights

Under UK data protection law, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data, subject to our legal obligations to retain certain records.
  • Restriction — ask us to pause processing while a query is resolved.
  • Objection — object to processing based on legitimate interests.
  • Portability — receive a copy of the data you have provided in a structured, machine-readable format.
  • Withdraw consent — at any time, where processing is based on consent.

To exercise any of these rights, email privacy@etplanning.co.uk. We will respond within one calendar month.

Security

We protect personal data using:

  • TLS encryption for all data in transit.
  • AES-256 encryption at rest at the platform layer.
  • Role-based access controls — only staff who need to see your data can see it.
  • An internal audit log recording administrative access to personal data.
  • Annual review of access permissions and security practices.

Cookies

We use only essential cookies needed to operate the site (for example, authentication and security). We do not use advertising or third-party tracking cookies. Our analytics are aggregated and do not identify individual visitors.

Complaints

If you have concerns about how we handle your data, please contact us first at privacy@etplanning.co.uk. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Changes to this policy

We may update this policy from time to time. Material changes are published with a new version date and the previous version is retained in our internal history. The version in force when you submitted any data is recorded against your consent record.


Questions about this policy? Contact us.