Last updated: 2 August 2026
Outtrn™ is the hosted platform operated by Acumine Ltd for construction teams. This Privacy Policy explains what personal data the platform handles, why, where it is kept and for how long. It covers the platform at www.outtrn.com and the legal pages published on it.
This platform is not a marketing website — there is no public content, no enquiry form and no advertising. Information about Acumine and its products is published separately on acumine.com, which has its own privacy notice.
The platform is owned and operated by Acumine Ltd, a limited company registered in England under company number 12457548.
Registered address:
VAT number: 371216518.
Data Protection Officer: Daniel Maddocks.
Email: support@acumine.com.
We are registered with the Information Commissioner's Office (“ICO”).
Our responsibilities depend on which personal data is involved, and the distinction matters for how you exercise your rights.
We are the controller for data about the people who use the platform — account holders and the administrators who invite them. We decide how that data is handled, and this Policy governs it.
We are a processorfor everything your organisation puts into its workspace. That includes uploaded programme (schedule) files, the dashboards derived from them, and commercial reporting content. Your employer, client or main contractor — the organisation whose workspace holds the data — is the controller of that content. We act only on that organisation's instructions, under the terms of our Data Processing Addendum.
This matters if you are named inside an uploaded programme. Programme files produced by scheduling tools such as Asta Powerproject or Primavera P6 routinely record the name of the person who authored or last revised the programme, and the platform reads those fields as part of processing the file. If you want to know why your name appears, or ask for it to be corrected or removed, the organisation that uploaded the programme is the controller and is the right party to approach. If you contact us instead, we will tell you which organisation holds the data where we are permitted to, and we will pass your request to them.
| Category | What it includes | Why | Lawful basis |
|---|---|---|---|
| Account identity | Name and work email address, obtained from your Microsoft account when you sign in, plus the organisation, projects and permissions you have been granted | To authenticate you and apply the correct access rights | Art. 6(1)(b) — necessary to perform our contract with your organisation |
| Sign-in records | Date and time of each successful sign-in, the provider used, IP address, browser user-agent | Security monitoring, investigating unauthorised access, and telling customers how much the platform is being used | Art. 6(1)(f) — our legitimate interest in keeping the platform secure |
| Activity and audit records | A record of governed changes made in a workspace: who changed what, when, from which IP address and browser | Accountability. Reporting is governed, so a durable record of who changed a figure is a core function rather than an add-on | Art. 6(1)(b) and 6(1)(f) — contractual necessity, and our customers' legitimate interest in an auditable record |
| Notification emails | Your email address, and the name of the project the notice relates to | To tell you a reporting period has been submitted, frozen or reopened | Art. 6(1)(b) — necessary to provide the service |
| Error diagnostics | Technical details of software faults: the page, the error and a stack trace | To find and fix faults | Art. 6(1)(f) — our legitimate interest in a working, secure platform |
We have configured our error-monitoring service not to attach IP addresses, cookies or request contents to fault reports. We do not use your personal data for advertising, we do not sell it, and we do not carry out profiling or automated decision-making that has legal or similarly significant effects on you.
We use a small number of service providers to run the platform. Each acts on our instructions under a data processing agreement, and each is named — with its purpose, the data it handles, where it processes it and the safeguard relied on for any transfer outside the UK — on our sub-processor page. We keep that page current and notify customers before adding a new sub-processor.
One of those providers deserves a plain-English mention. When our staff investigate a support query or a fault, they may use AI tooling (provided by Anthropic, under commercial terms) to help them examine the data relevant to that query. The tooling works under our staff's direction, the data involved is not used to train AI models, and the platform itself contains no artificial intelligence features. Details are on the sub-processor page.
Beyond those providers, we share personal data only where we are legally required to (for example a court order or a regulator's instruction), or where our business or its assets are sold or merged, in which case any new owner may continue to handle the data as described here.
The database, sign-in system and file storage that hold your workspace are hosted in the United Kingdom (London). The application itself also runs in London. Personal data kept in the UK is fully protected by the UK GDPR and the Data Protection Act 2018.
Two parts of the service can involve processing outside the UK, and we would rather be specific than reassuring:
Where personal data leaves the UK we rely on the safeguards permitted by the Data Protection Legislation — an adequacy regulation where one applies, or otherwise the International Data Transfer Agreement, or the European Commission's Standard Contractual Clauses together with the ICO's International Data Transfer Addendum. The specific safeguard for each provider is set out on the sub-processor page.
The periods below are maximums, not commitments — we may delete sooner, and we will not keep personal data for longer than the period stated against it. Where a period is enforced by an automated job we have said how often that job runs, so that “up to 12 months” means what it says rather than implying deletion to the minute.
| Data | Kept for no longer than |
|---|---|
| Account identity and permissions | The life of your organisation's subscription, then 30 days. Removed within 30 days of the account being deleted or the subscription ending |
| Sign-in records | 12 months from the date of the sign-in. Deleted automatically on a weekly cycle |
| Activity and audit records | For the life of the subscription, then deleted with the workspace within 30 days of it ending. These records are deliberately append-only while the subscription runs, because an audit trail that can be edited is not an audit trail |
| Uploaded programme files and the dashboards derived from them | For the life of the subscription, then deleted within 30 days of it ending, unless the customer asks for them sooner |
| Notification email delivery records | 30 days |
| Error diagnostics | 90 days |
Where we act as processor, the customer's own retention instructions take precedence over the periods above, and our Data Processing Addendum governs deletion and return of data at the end of the contract.
Separately from the above, we keep the records that company and tax law require us to keep — contracts, invoices and accounting records — for six years from the end of the accounting period they relate to. Those records are held outside the platform.
Access to a workspace is limited to the people your organisation has invited, and to the permissions it has given them. Sessions are held in cookies that JavaScript cannot read. Data is encrypted in transit. Each organisation's data is isolated from every other organisation's, both in the database and in the application. Access by our own staff is restricted to those with a genuine need, who are bound by confidentiality. We maintain procedures for handling personal data breaches, including notifying the ICO and affected people where the law requires it.
Under the Data Protection Legislation you have the right to:
To exercise any of these, email support@acumine.com or write to the address in Part 1, for the attention of Daniel Maddocks. There is normally no charge. We will respond within one month, and will tell you if a complex request needs longer — up to a further two months.
Where the data in question sits inside a customer's workspace, we act as processor and cannot decide the outcome ourselves, so we will forward your request to that organisation and support them in answering it. See Part 2.
If you are unhappy with how we have handled your personal data you can complain to the ICO at ico.org.uk. We would appreciate the chance to put things right first.
The platform sets strictly-necessary cookies only — two session cookies and one that records that you have seen the cookie notice. There is no advertising or third-party analytics tracking. Full detail is in our Cookie Policy.
We may update this Policy — for example if the law changes, or if we change how the platform works. Changes are published on this page with a revised date at the top. Where a change materially affects how we handle personal data, we will tell affected customers directly rather than relying on you noticing.