Last updated: 12 August 2026
This policy is issued by [legal entity name — to be confirmed], trading as easyCP12 (“easyCP12”, “we”, “us”). easyCP12 is a subscription service that lets gas and heating engineers log gas safety checks and issue CP12 (Landlord/Homeowner Gas Safety Record) certificates. This policy explains what personal data we collect, why, and what rights you have — whether you are an engineer with an easyCP12 account, or a landlord, tenant, or occupier whose details appear on a certificate an engineer has issued through easyCP12.
Under UK GDPR, easyCP12 acts in two different capacities depending on whose data is involved. This matters because it determines who you should contact with a request, and what we are able to do with the data.
If you are a landlord, tenant, or occupier and your details appear on a CP12 certificate, your primary point of contact for data requests is the engineer or business that issued the certificate, not easyCP12 directly — they are the controller of that data. We will still help resolve valid requests we receive, and pass them on to the relevant engineer.
When an engineer signs up for easyCP12, we collect and control:
We collect this because it is necessary to provide the service (performance of a contract with you). An engineer's Gas Safe registration and ID card number specifically are also what must legally print on every certificate they issue, so collecting them is core to the product working at all.
Lawful basis: performance of a contract (Art. 6(1)(b) UK GDPR).
When an engineer logs a gas safety check and issues a certificate through easyCP12, the certificate contains:
We store this data, generate the certificate PDF from it, and send it by email, all on the engineer's instruction — we do not decide to collect it, and we do not determine its onward use ourselves. The engineer is the data controller for this data; easyCP12 is the processor. Every engineer agrees to data processing terms as part of signing up to our Terms & Conditions — these stand in for a separately negotiated Data Processing Agreement (DPA), which is the standard approach for self-serve SaaS. See Terms & Conditions.
Lawful basis (set by the engineer, as controller of this data, not by us): typically legal obligation — Regulation 36(3) of the Gas Safety (Installation and Use) Regulations 1998 requires this record to be produced — and legitimate interest in providing the certificate to the landlord or tenant.
We use the following sub-processors to run easyCP12. Each only processes the data necessary to perform its function, and none are permitted to use the data for their own purposes:
We do not sell personal data, and we do not share it with third parties beyond these sub-processors except where required by law.
Turso, Resend, Vercel, and Clerk are all US-headquartered companies. Depending on where a given sub-processor's infrastructure runs, data may be processed outside the UK/EEA. Where that happens, we rely on Standard Contractual Clauses (SCCs) and/or the sub-processor's own UK/EU GDPR compliance measures to protect the transfer. We are in the process of confirming each sub-processor's specific data-processing terms and data residency options, and will update this section as that work completes.
Account data — kept for as long as your account is active, plus a limited period afterwards to meet accounting and legal obligations.
Certificate data — CP12 certificates are legal records. Regulation 36(3) of the Gas Safety (Installation and Use) Regulations 1998 requires the engineer to retain a copy of each certificate for a statutory period. Because of this legal retention obligation, we retain issued certificate data for as long as that statutory period requires, even against a request to delete it sooner (see “Erasure requests”, below) — and no longer than that purpose requires.
Where easyCP12 is the controller of your data (engineer account data), you have the right to:
To exercise any of these, contact us at hello@easycp12.com.
Erasure requests and certificate data: if you ask us to delete certificate data — as an engineer, or as a landlord, tenant, or occupier named on a certificate — we may not be able to fully comply while the statutory retention period under Regulation 36(3) applies. This is not us declining the request: the same law that makes the certificate a valid legal record also requires it to be kept. We will tell you plainly if this applies, and delete what we lawfully can.
easyCP12 does not currently use analytics, tracking, or advertising cookies. Once sign-in is live, Clerk will set strictly-necessary cookies to keep you signed in — these are not tracking cookies and do not require separate consent under UK PECR. If that changes — for example, if we add analytics — we will update this policy and this section first.
We rely on our sub-processors' own security measures (encryption in transit, access controls, and infrastructure security) alongside our own access controls on the easyCP12 application. No method of storage or transmission is completely secure, but we take reasonable steps appropriate to the sensitivity of the data involved.
easyCP12 is in the process of registering with the Information Commissioner's Office (ICO), the UK's data protection regulator. Registration reference: [ICO registration number to be added on completion].
If you are unhappy with how we have handled your data, you can complain to the ICO at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it directly first — contact us at hello@easycp12.com.
We may update this policy as the service changes — for example, when sign-in (Wave 4) goes live, or when sub-processor arrangements are confirmed. We will update the “last updated” date above when we do, and post material changes prominently.
Data protection queries: hello@easycp12.com. We do not currently have a separately named Data Protection Officer — queries are handled by the easyCP12 team directly.
Registered address: [registered company address].