1. Who is responsible for what
Two different things happen in Incursus, and different rules apply to each.
Your account. Your email address, your name, your practice name and your login history. We decide what happens to these, so we are the controller and this policy tells you what we do with them.
What you upload. Client emails, decision notices, drawings and survey schedules, and the names, addresses and postcodes in them. You decide what to upload and why; we only handle it to produce your reports. You are the controller and we are your processor.
If you are a client of a practice that uses Incursus and you want to know what is held about you, ask the practice — it is their information, not ours. We will help them answer you.
2. What we collect
| What | Which |
|---|---|
| Account | Email address, name, practice name |
| Logging in | Session cookie, and a one-way fingerprint of your email used to limit failed attempts — we do not store a list of addresses for this |
| Support | Anything you send us, and what you type into the “report an error” button |
| Server logs | Requests to the site, kept briefly by our hosting provider |
| Your uploads | The documents themselves, the text extracted from them, and the fields read out of them |
| Anonymous statistics | Counts and patterns with nothing identifying in them |
We do not track you. There is no analytics, no advertising, no third-party scripts, and the fonts are served from our own site rather than someone else’s.
3. Why, and on what basis
- To provide Incursus — because we have an agreement with you.
- To keep it working and secure, and to fix what breaks — because we have a legitimate interest in running a service that works and is not abused.
- To handle your uploads — on your instructions, as your processor.
- To meet legal obligations, where one applies.
4. Documents sent to an AI model
To read fields out of your documents, Incursus sends them to Anthropic, in the United States, and gets back the values it found. The whole document goes — we cannot know in advance which page holds the reference.
Anthropic is contractually prohibited from training its models on what we send. Its commercial terms state that it “may not train models on Customer Content”, and that you keep all rights to what is sent and own what comes back.
Anthropic holds what we send for a limited period to check for misuse, and then deletes it. Nothing we send is used to improve anyone’s model.
Every value the model returns is shown to a person and can be edited before it reaches a report. There is more detail on how we use AI.
5. Who else is involved
These are every company that handles information on our behalf.
| Who | What for | What they see | Where |
|---|---|---|---|
| Supabase | Database, logins, file storage | Everything held in Incursus | London (eu-west-2) |
| Vercel | Running the site | Requests and server logs | London (lhr1) |
| Anthropic | Reading fields out of documents | The documents you upload | United States |
| Working out mileage for an invoice | A site postcode and a starting address | United States |
If we add another, we will tell you before it starts handling anything.
6. Information leaving the UK
Your database, your files and the site itself are in the UK. Two things leave it: documents sent to Anthropic, and a postcode sent to Google for a mileage figure.
Both are covered by the UK’s approved safeguards for transfers abroad — the International Data Transfer Agreement or the UK Addendum to the standard contractual clauses, as applicable to each provider — which bind them to protect the information to a UK standard.
7. How it is kept safe
These are measures actually in place, not intentions:
- Every practice’s data is isolated at the database level, so one account cannot read another’s
- Uploaded files are in private storage, reachable only through links that expire after one minute
- Everything travels encrypted, and is encrypted at rest by our hosting providers
- Repeated failed logins are rate-limited
- The site sends strict security headers, including a content security policy
We can see your data when we need to help you with a problem. We only look when there is a reason to.
8. How long we keep it
- Your jobs and uploads — until you delete them, or until you close your account. Both remove the files as well as the records.
- Your account — until you close it.
- Server logs — a short period set by our hosting providers.
- Backups — deleted data stays in backups for a short period and then rolls off on its own cycle.
- Anonymous statistics — kept indefinitely. They contain nothing identifying and cannot be traced back to you.
9. Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict or object to what we do with it, or to have it sent somewhere else. You can withdraw consent where we relied on it.
Email fin@incursus.co.uk and we will respond within one month. There is also a Delete everything button in Settings that removes your account and all of its data immediately.
10. Complaints
If you are unhappy with how we have handled your information, tell us first — by any means you like, to fin@incursus.co.uk or by phone. We will acknowledge it within 30 days and tell you what we are doing about it.
You can also complain to the Information Commissioner’s Office at any time: ico.org.uk, or 0303 123 1113.
12. Children
Incursus is for professional use and is not intended for anyone under 18.
13. Changes
If we change this policy we will update the version and date at the top, and tell you if the change matters.