Skip to content
Onesheet · Privacy PolicyVersion 1.0 · Effective 20 August 2026

Privacy Policy

Onesheet is a service of IHS LOTHIAN LIMITED. This policy explains what personal data and business information we hold when you use ihslothianprojects.com, why we hold it, how long we keep it, and how you get it back or get rid of it. It is written to be read once, in full, by the person it concerns.

01Who we are

Onesheet is operated by IHS LOTHIAN LIMITED, 13 Queen's Road, Aberdeen, United Kingdom, AB15 4YL. We are the controller of the personal data described here. You can reach us at support@ihslothianprojects.com or +44 7861674405.

02Your company information, and what we will never do with it

This service exists to lay out unpublished information about a business: what it does, who it sells to, how it earns, how many of a thing it has completed, how much of its revenue is committed, and what it is asking for. That is commercially sensitive material, and in most cases it is not public anywhere else. We treat it accordingly.

Your company information and trading data are not used to train models. Not ours, and not any third party’s. Nothing you write, upload or export from a page is placed in a training set, sold, licensed, or shared with a model provider for improvement purposes.

What we send to a model provider, when you ask for a structural breakdown or a layout base, is limited to the text of that request, and it is sent under contract terms that prohibit its use for training. We do not send your figures to be rendered into a picture, because on this service figures are never rendered by a model at all — the browser draws them.

We may count things that carry no content: how often a request failed, how long a layout took, how many pages an account holds. Those counts contain no words from your page and cannot be traced back to what your business does.

To delete a page and everything in it, open the file and choose Delete. To have the whole account erased, write to support@ihslothianprojects.com from the address on the account. Erasure removes the account record, every page, every uploaded photograph and every export within 30 days, and we will confirm when it is done.

03What we collect

CategoryWhat it isWhy we have it
Account dataEmail address, a hashed password, the display name you choose.To let you sign in and to reach you about the account.
Billing dataPlan, billing period, renewal date, invoice history, and a token identifying your payment method.To run the subscription and to answer billing questions. We never see or store your full card number.
Page contentEverything you type into a page, every figure, the cut list, and any photograph you upload.To produce the page you asked for. Held while the file exists.
ExportsThe PDF files you generate.So you can download a page again without rebuilding it.
Technical dataIP address, browser and device type, timestamps, error logs.Security, fraud prevention, and finding out why something broke.
Support messagesWhat you write to us and what we write back.To handle the request and to keep a record of what was agreed.

We do not ask for, and you should not enter, special category data — health, ethnicity, political opinion, biometric identifiers or anything similar. A company one-pager has no reason to contain it.

04Why we are allowed to hold it

  • Performance of a contract — account data, page content and billing data, because without them there is no service to give you.
  • Legitimate interests — technical data and abuse prevention, because a service that cannot detect misuse cannot stay available to anyone. We have balanced this against your interests and it is limited to what security needs.
  • Consent — optional analytics cookies only, and only after you say yes. You can withdraw it at any time from the cookie control.
  • Legal obligation — billing records, which tax law requires us to keep for a fixed period.

05Payments and card security

Subscriptions are processed by our payment provider, a regulated payment institution that is certified to the Payment Card Industry Data Security Standard. Card details are entered on their hosted page, over an encrypted connection, and are never transmitted to or stored on our servers. We receive a token, the last four digits, the card brand and the expiry month, which is what we need to show you which card is on file and to take the renewal.

Prices are shown and charged in USD. Your bank may apply its own conversion and may charge for it; that is between you and your bank.

06Who else sees it

We do not sell personal data, and we do not share it for cross-context behavioural advertising. Data reaches a third party only where the service cannot run otherwise:

  • Our hosting and database providers, who store the data on our instruction.
  • Our payment provider, for taking payment and handling refunds and disputes.
  • Our model provider, for the text of a structural request only, under terms that forbid training on it.
  • Our email provider, for account and service messages.
  • Professional advisers, or a public authority, where the law requires it and only to the extent it requires.

Every one of these is bound by a written contract covering security, confidentiality and deletion.

07How long we keep it

WhatKept for
Account dataUntil you close the account, then 30 days.
Page content and uploadsUntil you delete the page, then 30 days in backup.
Exports12 months, or until you delete them.
Billing recordsSeven years, because tax law requires it.
Technical logs90 days.
Support messages24 months.

The 30-day tail is a backup cycle, not a second copy we work from. Nothing in it is readable by the product, and it is overwritten in the ordinary course.

08Your rights

Under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR where it applies to you, you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to another provider in a portable format, or object to processing we carry out on the basis of legitimate interests. You can also withdraw consent to analytics at any time without it affecting anything that happened before.

Write to support@ihslothianprojects.com. We answer within one month. There is no charge unless a request is repetitive or excessive, and we will say so before doing anything.

If you are in California, you may request the categories and specific pieces of personal information we have collected, ask for deletion or correction, and opt out of any sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we honour Global Privacy Control signals as an opt-out. Exercising a right will never get you a worse service or a worse price.

If you think we have handled your data badly, tell us first — it is usually quicker. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or to the supervisory authority in the country where you live.

09Where the data goes

We are based in the United Kingdom, and some of our providers process data in the United States and elsewhere. Where data leaves the UK or the EEA we rely on adequacy regulations where they exist, and otherwise on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment. A copy of the safeguards used for a particular provider is available on request.

10Security

Traffic is encrypted in transit with TLS. Data is encrypted at rest. Passwords are stored as salted hashes and are not recoverable by us or by anyone else. Access to production data is limited to the people who need it, requires multi-factor authentication, and is logged. We review these arrangements at least annually.

No system is beyond reach. If a breach is likely to result in a risk to your rights we will notify the ICO within 72 hours of becoming aware of it, and we will tell you directly where the risk is high.

11Children

This service is for adults running or representing a business. You must be at least 18 to open an account. We do not knowingly collect data from children, and if we learn that we have, we delete it. If you believe a child has given us data, write to support@ihslothianprojects.com.

12Cookies

One strictly necessary cookie keeps you signed in and protects the forms against cross-site request forgery. Everything else is optional, off until you turn it on, and as easy to refuse as to accept. The detail is in the Cookie Policy at ihslothianprojects.com/cookie-policy.

13Changes to this policy

If we change this policy in a way that matters, registered users get at least 14 days’ notice by email before it takes effect, and the version and date at the head of this document change with it. Continuing to use the service after that means you accept the new version.

14Contact

IHS LOTHIAN LIMITED, 13 Queen's Road, Aberdeen, United Kingdom, AB15 4YL. Email support@ihslothianprojects.com. Telephone +44 7861674405. Monday to Friday, 09:00–17:00 UTC. We reply to every message within one working day.