Legal

    Privacy Policy

    Last updated: March 2026

    1. Who We Are

    Wastrio Ltd ("Wastrio", "we", "us", "our") is a company registered in England and Wales. Our registered office is at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. We operate the website at wastrio.co.uk and the compliance application at app.wastrio.co.uk.

    For any privacy-related queries, contact us at steve@wastrio.com.

    2. What Data We Collect

    We may collect and process the following personal data:

    • Account data: name, email address, company name, job title
    • Usage data: pages visited, features used, login timestamps
    • Compliance data: waste transfer records, carrier licence numbers, consignment details you enter into the app
    • Communication data: messages sent via our contact form or email
    • Technical data: IP address, browser type, device identifiers

    3. How We Use Your Data

    We use your personal data to:

    • Provide and operate the Wastrio compliance platform
    • Maintain your digital waste tracking records as required under the Environment Act 2021
    • Respond to your enquiries and provide customer support
    • Send service notifications, product updates, and compliance reminders
    • Improve and develop our software
    • Comply with legal obligations

    4. Legal Basis for Processing

    We process your data on the following legal bases under UK GDPR:

    • Contract: processing necessary to perform our agreement with you
    • Legal obligation: where we must retain records to comply with waste regulation
    • Legitimate interests: improving our service and communicating relevant updates
    • Consent: for any marketing communications (you may withdraw at any time)

    5. Data Retention

    Waste transfer records are retained for a minimum of two years in line with Environment Act 2021 requirements. Account data is retained for the duration of your subscription plus 12 months. You may request deletion of non-regulatory data at any time.

    6. Data Storage & Security

    Your data is stored on servers located in the European Union. The application is hosted on Netlify, also running on AWS infrastructure. We implement industry-standard security measures including encryption in transit (TLS 1.2 and above) and at rest (AES-256), role-based access controls, multi-factor authentication, and regular security reviews.

    7. Sharing Your Data

    We do not sell your personal data. We may share it with:

    • Cloud infrastructure providers operating within the European Union under data processing agreements
    • Regulatory authorities (e.g. the Environment Agency) where legally required
    • Professional advisors bound by confidentiality obligations

    8. Your Rights

    Under UK GDPR you have the right to:

    • Access the personal data we hold about you
    • Correct inaccurate data
    • Request erasure (where not overridden by legal retention requirements)
    • Object to or restrict processing
    • Data portability
    • Withdraw consent at any time

    To exercise any of these rights, contact steve@wastrio.com.

    9. Cookies

    We use essential cookies to operate the platform (session management, authentication). We may use analytics cookies to understand usage patterns. You can control cookie preferences through your browser settings.

    10. Changes to This Policy

    We may update this policy from time to time. Significant changes will be notified by email or via the platform. Continued use of Wastrio after changes constitutes acceptance of the updated policy.

    11. Complaints

    If you have concerns about how we handle your data, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.