Privacy Notice
Version: 2026-09-17 · Effective: 17 September 2026
This notice explains how LBM Developments Ltd acts as controller for BrakerBase account, billing, website, security and support data. When a subscriber enters its own customer, staff, order or delivery data, that subscriber will normally be controller and we act as processor under the DPA.
Who we are
LBM Developments Ltd, company number 17077349. Address: Holly Hall Farm Trentside Scunthorpe DN17 3EF. Privacy contact: sy@lbmdevelopments.com.
Information we process
- Business, account, user identity and contact details.
- Login, session, device, IP, audit, fraud-prevention and security events.
- Subscription, payment status, invoices, order references and Stripe identifiers; we do not store full card details.
- Support correspondence and essential service communications.
- Customer-controlled vehicle, stock, photograph, order, invoice, delivery and connected-service data.
- Inputs and outputs for optional vehicle-data checks and Smart Part AI.
Purposes and lawful bases
| Purpose | Lawful basis |
|---|---|
| Accounts, trials, subscriptions and support | Contract and legitimate interests in operating the Service |
| Payment, invoices and accounting | Contract and legal obligation |
| Security, misuse prevention and incident investigation | Legitimate interests and legal obligation where applicable |
| Essential service, billing and security messages | Contract and legitimate interests |
| Limited reliability diagnostics | Legitimate interests balanced against user rights |
| Customer-controlled operational data | The subscriber’s documented instructions under the DPA |
We do not rely on consent for the core Service. Where consent supports an optional activity, it may be withdrawn without affecting earlier lawful processing.
Sources and required information
We receive information from users, subscribers, Stripe, selected integrations and security/hosting systems. Account and billing information is contractually required; without it we cannot provide an account. Optional integration and AI information is required only when that feature is chosen.
Sharing and subprocessors
We share information only as needed with contracted hosting, database, image, payment, AI and communications providers; connected marketplaces or carriers selected by the customer; professional advisers; or authorities where required by law. The Subprocessor Schedule identifies principal providers. We do not sell personal data.
International transfers
Where a restricted transfer occurs, we use a UK adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, with transfer-risk and security measures where required. Details are available from sy@lbmdevelopments.com.
Retention
- Trial data: at least 30 days after expiry, then deleted from active systems unless upgraded.
- Operational data after termination: exportable for 30 days and deleted from active systems within a further 30 days.
- Backups: overwritten or deleted within 90 days.
- Billing, invoice and accounting records: six years after the relevant financial year or longer where required.
- Security and audit logs: normally 12 months, longer for an active investigation or claim.
- Support correspondence: normally three years after closure.
- Deletion-request and legal-acceptance evidence: up to six years to establish or defend legal rights.
Limited records may be preserved for legal hold, regulation, fraud prevention or disputes and restricted from unrelated use.
Your rights
Depending on the circumstances, individuals may have rights of access, rectification, erasure, restriction, objection and portability, and withdrawal of consent where relied upon. Requests about subscriber-entered data should normally go to that subscriber; we will assist it. Contact sy@lbmdevelopments.com. Identity verification may be required.
Automated decisions and AI
BrakerBase may generate suggestions, risk indicators or vehicle/part information, but does not make solely automated decisions about individuals producing legal or similarly significant effects. Customers must review AI and provider outputs.
Cookies
The application uses strictly necessary session and security technologies. We do not currently set non-essential advertising or analytics cookies. See the Cookie Notice. If that changes, non-essential technologies will remain off until the required choice is obtained.
Security
Measures include tenant separation, authentication, role controls, secure same-site sessions, CSRF protection, encrypted integration credentials, audit logging and backup/export controls. No system guarantees absolute security.
Complaints and changes
Contact sy@lbmdevelopments.com first. Individuals may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We review this notice when processing changes and notify affected users of material changes before new uses begin.