Privacy Notice

Privacy Notice for the Experior website, software, and services.

Last updated: 11 April 2026. Effective date: 11 April 2026.

This Privacy Notice explains how Experior Engineering Software (“Experior”, “we”, “us” or “our”) collects, uses, stores, shares and otherwise processes personal data through our public website, our mobile and desktop applications, our downloads, product pages and licence purchase routes, our support, enquiry and customer communications, and any related services we provide.

This notice is intended to help individuals understand how their personal data is handled when they interact with Experior directly, and how certain types of data may be handled when our software is used by organisations in live operational workflows.

Contact Experior

1. Who we are

Experior Engineering Software provides specialist software and workflow tools for pavement investigation and related reporting, including tools for:

  • DCP field capture.
  • DCP calculation and reporting.
  • Road core logging.
  • Road core reporting.
  • Associated technical workflows, downloads and support.

For the purposes described in this Privacy Notice, Experior may act as a controller, a processor, or in some cases both, depending on the type of data and the purpose of the processing.

Contact details:
Experior Engineering Software
9 Stonebyres Drive
Winchburgh
West Lothian
EH52 6DQ
Email: info@experior.co.uk
Website: www.experior.co.uk

If you have questions about this Privacy Notice or about how your personal data is handled, please contact us using the details above.

2. When this Privacy Notice applies

This Privacy Notice applies where:

  • You visit our website.
  • You contact us by email, form or other route.
  • You download or use our software.
  • You create or use an account with us.
  • You request sample outputs, support or product information.
  • You receive support, billing or account communications from us.
  • Your personal data is included in app, support or account records we handle.
  • Our software is used in a way that involves personal data.

This Privacy Notice does not replace any privacy notice that your employer, client, contracting authority or other organisation may need to provide to you in its own role as controller of project, workforce or operational data.

3. Important controller and processor position

This is the key split.

3.1 When Experior acts as controller

Experior generally acts as controller for personal data we use for our own purposes, including website analytics and site operation where applicable, handling enquiries and product-fit requests, managing customer and prospect relationships, account administration, billing and payment records, support handling, security, abuse prevention and fraud prevention, technical diagnostics and service reliability, product and service improvement where we decide the purpose of that use, and properly anonymised and aggregated analytics and benchmarking activity.

Where we act as controller, we decide why and how that personal data is processed.

3.2 When Experior acts as processor

Where an organisation uses our software to enter, store, process or report on its own project, site, core, DCP, reporting or operational records, that organisation will usually act as the controller for that project data, and Experior will usually act as processor to the extent we process that data on the organisation’s behalf and on its instructions.

This will commonly apply to customer-entered operational records such as project names and references, site details, DCP records, core logs, coordinates or mapped points, photographs, report content, and job or workflow metadata.

3.3 When both positions may exist

Experior may act as processor for customer project data and at the same time act as controller for separate data it uses for its own purposes, such as user account data, support tickets, billing records, security logs, licence usage records, service diagnostics, and internal product improvement processing.

The ICO’s guidance is clear that controllers determine the purposes and means of processing, while processors process personal data on behalf of controllers.

4. The personal data we collect

The personal data we collect depends on how you interact with us and how our software is used.

4.1 Website and enquiry data

If you visit our website or contact us, we may collect your name, your email address, your organisation name, your job title, your phone number if provided, the contents of your enquiry or message, the product or workflow you are interested in, correspondence history, and website usage and cookie-related data where applicable.

4.2 Account, customer and commercial data

If you create an account, download software, request access or purchase a licence, we may collect account login details, licence details, organisation details, billing name and billing contact details, invoice and payment records, support entitlements, transaction history, renewal history, and records of product version, environment or activation status.

4.3 App and software usage data

When our mobile or desktop software is used, we may collect or receive user-entered job details, project references, site references, DCP records, road core records, observations and notes, reports and outputs, photographs or attachments, timestamps, device and application version information, operating system information, basic technical logs, sync, export or transfer events, error reports and crash diagnostics where enabled, and usage information necessary to operate, support, secure or improve the software.

4.4 Core, site and location-linked record data

The software may be used to capture structured site records, including site names and references, chainages, positions or mapped points, DCP test positions, road core locations, layer descriptions, photographs, notes, and associated location-linked metadata.

Where location features are used, the app may capture the location of a record such as a core or DCP point at the time the record is created, confirmed or updated.

This feature is intended to help identify the position of the record on site for mapping, revisits, technical checking, reporting and operational reference. It is not intended to track a user’s movements, monitor staff activity, or create continuous background location history, unless a specific feature expressly states otherwise and is lawfully enabled.

That said, location-linked information can still be personal data where it can be linked, directly or indirectly, to an identifiable individual, account or device. The ICO’s guidance on personal data expressly includes location data and online identifiers as examples of information that may identify a natural person.

4.5 Support and communications data

If you request help, we may collect your contact details, the content of your support request, screenshots, attachments or sample files you send us, product version and environment information, troubleshooting notes, support history, and our responses and resolutions.

4.6 Data from other sources

We may receive personal data from your employer or organisation, authorised colleagues or administrators, software distributors or resellers, payment service providers, app distribution platforms, hosting or support systems, and public or professional sources where relevant to a business enquiry.

If we obtain personal data from a source other than the individual, the ICO says privacy information should generally be provided within a reasonable period and at the latest within one month, unless an exception applies.

5. How we use personal data

We use personal data only where we have a valid reason to do so.

5.1 Website and enquiry handling

We use website and enquiry data to respond to messages and requests, provide product information, assess product fit, send requested sample outputs or materials, manage business relationships, and keep records of communications.

5.2 Accounts, licensing and commercial administration

We use account and commercial data to create and manage accounts, provide downloads and access, issue and manage licences, process orders and renewals, handle invoices and payments, administer customer relationships, and provide account-related communications.

5.3 Providing and operating the software

We use relevant data to enable product functions, store and synchronise records, generate outputs and reports, support exports and transfers, maintain continuity between field and office workflows, support troubleshooting, and operate and secure the service.

5.4 Support, diagnostics and service reliability

We use data to diagnose technical issues, investigate faults and support tickets, maintain service performance, resolve bugs, identify compatibility issues, and protect the integrity and security of the software and related services.

5.5 Product improvement and service analytics

We may use technical, usage and service data to understand how products are used, improve workflow design, prioritise product changes, improve reliability and performance, assess demand for features or pages, and develop future product improvements.

Where we use personal data for these purposes, we do so only where a lawful basis exists. Where we can use anonymised and aggregated information instead, we prefer to do so.

6. Our lawful bases

The ICO says privacy information must explain the lawful basis relied on for processing personal data.

Depending on the context, we may rely on one or more of the following lawful bases.

6.1 Contract

We may process personal data where this is necessary to provide requested downloads or software access, manage an account, provide support included with a product or arrangement, administer a licence, process billing and payment, fulfil an order, or take steps requested before entering into a contract.

The ICO’s guidance states that if processing is not necessary for the contract, another lawful basis such as legitimate interests or consent should be considered.

6.2 Legitimate interests

We may process personal data where this is necessary for our legitimate interests or those of a customer or user, provided those interests are not overridden by the rights and freedoms of the individual.

This may include responding to business enquiries, managing customer relationships, providing business support, securing the website and software, maintaining service reliability, preventing misuse or abuse, logging and investigating technical problems, and making proportionate improvements to our services.

The ICO describes legitimate interests as a flexible lawful basis that may be appropriate where people would reasonably expect the processing and the privacy impact is limited.

6.3 Consent

Where we rely on consent, we will ask for it clearly and give you a real choice.

This may apply, depending on the feature and context, to matters such as optional analytics or cookies, optional promotional communications where consent is required, optional app permissions not necessary to core service delivery, or other optional processing where consent is the appropriate basis.

The ICO says consent must offer real choice and control, and if consent is difficult to obtain properly, another lawful basis should be considered instead.

6.4 Legal obligation

We may process personal data where necessary to comply with legal or regulatory obligations, including obligations relating to accounting, taxation, legal claims, fraud prevention or regulatory enquiries.

7. Customer project data and controller / processor split

7.1 Customer-entered operational data

Where an organisation uses Experior software to capture or manage project, site, DCP, core, report or location-linked records for its own operational purposes, that organisation will usually decide what data is collected, why it is collected, how long it should be kept, who can access it, and how it is used in the project or business workflow.

In those circumstances, that organisation will usually be the controller of that personal data.

7.2 Experior as processor

Where we process such customer project data solely to provide the software or related services on the customer’s behalf, we will usually act as processor.

Where we act as processor, we generally process personal data only on the customer’s instructions, to provide the agreed service, to maintain security and integrity, to resolve support or technical issues, or as otherwise required by law.

7.3 Experior as separate controller for certain data

Even where a customer is controller for project data, Experior may still act as controller for separate categories of personal data processed for our own purposes, such as account contacts, billing records, direct support correspondence, internal service logs, security and fraud monitoring, service diagnostics, and internal improvement activities.

7.4 Customer responsibilities

Where a customer is controller for personal data entered into the software, that customer is responsible for identifying the appropriate lawful basis, providing any required workforce or project privacy notices, ensuring the data entered is lawful and proportionate, setting appropriate retention and access controls, and handling data subject rights requests relating to that controller data.

8. Core, site and location data

This is worth spelling out separately.

8.1 What location data is used for

If a location feature is used in the app, it is used to support the position of the record on site, such as geolocating a DCP test, pinning a road core location, linking a record to its site position, supporting mapping, report references and revisits, and improving operational clarity and checking.

8.2 What it is not used for

Unless a feature expressly states otherwise, we do not intend location-linked record capture to be used for continuous background user tracking, workforce surveillance, behavioural profiling, movement history reconstruction, or employee monitoring.

8.3 When location data may still be personal data

Even where the purpose is only to pin a core or DCP point on a site, location-linked data may still be personal data if it can be linked to a named user, an account, a device, a timestamped workflow trail, or another identifiable individual.

That is why we treat location-linked information carefully and explain its use here. The ICO states that privacy information should be given when personal data is collected, including by observation, and that location data can be personal data where it identifies or helps identify an individual.

9. Anonymised and aggregated information

We may create and use aggregated and anonymised information derived from website, app, service or record data for purposes such as analytics, benchmarking, product development, service improvement, research, technical trend analysis, operational insight, and business reporting.

We will only treat information as anonymised where the resulting information does not identify, and cannot reasonably be used to identify, any individual, customer, project or site.

We do not treat pseudonymised data as anonymous merely because obvious identifiers have been removed. The ICO’s anonymisation guidance says anonymised information falls outside data protection law only where people are not, or are no longer, identifiable, and that pseudonymisation is a distinct concept.

10. Who we share personal data with

We may share personal data, where necessary and lawful, with the following categories of recipient:

  • Hosting and infrastructure providers.
  • Software distribution platforms.
  • Analytics providers where enabled and lawful.
  • Payment processors.
  • Billing or accounting providers.
  • Email and communications providers.
  • Support and service-management providers.
  • Security providers.
  • Professional advisers such as lawyers, accountants and insurers.
  • Regulators, courts, law enforcement or public authorities where required.
  • Resellers or implementation partners where this is part of the customer relationship and lawful to do so.
  • The customer organisation itself, where relevant to software operation or support.

We do not share identifiable customer project data for unrelated third-party marketing.

The ICO says privacy information should tell people who their personal data will be shared with, or at least the categories of recipient.

11. International transfers

We may use suppliers or systems that process personal data outside the UK.

Where personal data is transferred outside the UK, we will take steps intended to ensure that an appropriate level of protection applies, such as adequacy regulations, standard contractual safeguards, supplementary measures where appropriate, or another lawful transfer mechanism.

If you want more detail about a particular transfer arrangement, you can contact us.

12. How long we keep personal data

We keep personal data only for as long as necessary for the relevant purpose, or for as long as required by law, contract, security need, support need or legitimate business recordkeeping.

Retention periods vary depending on the category of data. In broad terms, enquiry data is retained for as long as necessary to respond and follow up appropriately, account and licence records are retained for account administration, renewal history, legal and tax recordkeeping, and support continuity, support records are retained for troubleshooting history, product support and service quality purposes, technical logs are retained for security, diagnostics and service integrity for an appropriate period, customer project data retained on behalf of customers is retained according to the service arrangement, customer instructions, technical architecture and lawful obligations, and anonymised and aggregated information may be retained longer because it does not identify individuals.

The ICO says that if you do not have a fixed retention period, you should tell people the criteria you use to decide how long data will be kept.

13. Security

We use proportionate technical and organisational measures intended to protect personal data against unauthorised access, misuse, loss, disclosure, alteration or destruction.

These may include, depending on the service and environment, access controls, authentication measures, licence and environment controls, logging and monitoring, secure hosting arrangements, role-based access, encryption or protected transfer methods where appropriate, and incident response processes.

No system is completely secure, and no internet transmission can be guaranteed to be fully secure. Users and customers also have their own responsibilities for device, account and workflow security.

14. Your rights

Where UK data protection law applies to our processing of your personal data, you may have the right to access your personal data, ask us to correct inaccurate personal data, ask us to erase personal data in certain circumstances, ask us to restrict processing in certain circumstances, object to processing in certain circumstances, ask for portability of data in certain circumstances, and withdraw consent where we rely on consent.

These rights are not absolute and may depend on the lawful basis and context.

The ICO says privacy information should tell people which rights apply to the processing.

If you want to exercise a right, contact us using the details in this notice.

If we are acting only as processor for customer project data, we may need to refer your request to the relevant customer controller, because that organisation may be the party responsible for responding.

15. Complaints

If you have concerns about how we handle personal data, please contact us first.

You also have the right to complain to the Information Commissioner’s Office if you believe your personal data has been handled unlawfully or unfairly.

16. Cookies and similar technologies

Our website may use cookies or similar technologies for core site operation and, where enabled lawfully, analytics or other optional functions.

Where cookies or similar technologies are optional, we will seek consent where required and provide relevant controls.

More detail should be set out in the relevant cookie or privacy section of the website.

17. Changes to this Privacy Notice

We may update this Privacy Notice from time to time to reflect changes to our services, changes to law or guidance, changes to our suppliers or systems, or changes to how we use personal data.

The latest version published on our website will apply from the date shown at the top.

18. Contact us

If you have any questions about this Privacy Notice or about how your personal data is handled, please contact:

Experior Engineering Software
9 Stonebyres Drive
Winchburgh
West Lothian
EH52 6DQ
Email: info@experior.co.uk
Website: www.experior.co.uk