PlanUp scanner tester diagnostics
Notice version: 3 October 2026. Effective date: 3 October 2026.
Who this notice is for
This notice explains scanner diagnostics from PlanUp testing in the UK, including customer tests during normal surveys in occupied or empty properties. It also covers people whose home, workplace or information may appear in diagnostics. You do not need a PlanUp account to read this notice or contact us. Ordinary floor-plan and survey processing is separate; the organisation carrying out your survey should explain its own use of your information.
Who is responsible
Prototec Software Ltd, trading as PlanUp, is responsible for its use of tester diagnostics to investigate scanner faults. Our head office is Unit 214, Filwood Green Business Park, Filwood Park Lane, Bristol, BS4 1ET. Contact support@planup.co.uk. The organisation carrying out your survey remains responsible for its own survey processing.
Why we use diagnostics
We use tester diagnostics to investigate scanner problems, reproduce faults and verify fixes. They are not approved for marketing, public demonstrations, employee performance monitoring, identifying occupants or broader development unrelated to a specific fault.
Our legal basis
We rely on legitimate interests for this diagnostic use. Our interest is investigating specific scanner faults, reproducing problems and verifying fixes. We limit diagnostic information to what is necessary for that work and consider the rights and expectations of testers and affected people.
Your right to object
You can object to this use of your personal information because of your particular situation. Email support@planup.co.uk. If you are at a property being scanned, you can also raise your concern with the operator before or during the scan.
What diagnostics contain
Tester Mode saves scanner logs and technical scan information. Depending on the app path and fault, this can include room geometry and layout, timings, device and app information, tester notes, crash reports, and account, scan and plan identifiers. Diagnostics come from the tester's device and scan, information the tester enters, and associated account and plan records. If you are an occupant, the information may come from the tester or survey organisation rather than an account you hold.
Video is a separate, optional choice. In PlanUp's diagnostic-video feature, the camera view is blurred on the device before the video is saved, and no audio is recorded. Scanner labels and controls remain visible. Blur does not guarantee anonymity: room layouts, notes, overlay text and account or plan links can still identify people. This description does not cover separate manual photographs or recordings.
Avoid including occupant names, paperwork, health or medication details, screens and other unnecessary personal information in recordings or notes. If sensitive information is accidentally included, tell the operator or contact us so it can be handled appropriately.
Your choices before a scan
Choose “Scan without video” to continue in Tester Mode with logs. Choose Standard Mode to scan without tester logging. Ordinary scanning and plan processing still take place. Declining diagnostic video does not prevent ordinary scanning.
Explain diagnostic recording and sharing to everyone affected before starting. Permission to enter or survey a property, or permission from one homeowner, is not permission from every affected adult. The recording confirmation checks the operator's authority; it does not select a legal basis or give consent on behalf of everyone present.
Use the least intrusive evidence that can answer the specific scanner-fault question. Use no-video/minimal logs or a controlled reproduction where sufficient. Use optional occupied-property diagnostic video only where the specific need cannot reasonably be met by those alternatives, after explaining the recording and sharing to affected people. Avoid including children, vulnerable people or sensitive personal information. If this cannot be achieved, use another setting or pause for guidance.
If anyone objects or cannot be informed, choose no video or a controlled test space. If their concern includes logs, room information or notes, use Standard Mode, another test setting or pause the diagnostic test and seek guidance. Do not routinely collect occupant names or signatures.
Uploads and interrupted scans
Tester Mode is not a per-upload approval flow. Finishing a scan can queue diagnostics for automatic upload to PlanUp. Interrupted scans may be recovered and uploaded later. Some cancellation screens offer “Upload” or “Don't upload”; declining upload can still leave the latest diagnostic archive on the device until it is replaced or disposed of. Wi-Fi and mobile-data choices control network use, not permission to record or share.
Stopping recording, declining a later upload or uninstalling does not delete copies already sent elsewhere. Contact us about those copies.
Access and sharing
Our staff-access rule limits diagnostic access to engineering and support staff who need the evidence for scanner diagnosis and are authorised by Julian or James. Broader sharing requires separate approval. Ticket evidence is limited to the minimum useful frames checked for identifying or sensitive details; whole diagnostic videos or ZIP archives should not be attached.
We use Microsoft's Azure hosting, storage and database services for diagnostics, and Azure DevOps for selected fault evidence. We use OpenAI's Codex on company computers, through PlanUp's company Business workspace, to help analyse scanner diagnostics, investigate specific faults and verify fixes. Necessary diagnostic context, such as logs, scan information, notes and information from significantly blurred diagnostic video, can be supplied to OpenAI for model analysis. Company-computer execution does not mean all model processing stays on that computer. Our fault-diagnosis purpose and information-minimisation rules also apply to AI analysis. ChatGPT is not used for this diagnostic analysis.
Where information is processed
The production Azure storage arrangement reviewed for these diagnostics uses UK South and UK West. Staging storage uses West and North Europe. Supplier processing, remote access and OpenAI model analysis can involve countries outside the UK, including the United States; UK testing does not mean UK-only processing. Applicable supplier data-processing agreements and contractual transfer safeguards, including UK transfer terms, cover those transfers. Contact support@planup.co.uk for information about the safeguards or how to obtain a copy. Our company-workspace use is not a claim that all supplier processing or recovery copies remain in the UK.
How long diagnostics are kept
Our agreed diagnostic policy uses the original capture time. Uploading, retrying, recovering, downloading or extracting information does not restart the clock.
- Uploaded source diagnostics: 30 days from capture.
- Tester-device copies and pending uploads: 7 days from capture; the retained latest copy may be replaced sooner. Replacing it does not cancel every independent pending scan. Source holds do not extend the device or upload deadline.
- Staff downloads, extracted frames and personal analysis outputs, including saved diagnostic AI outputs: by the earlier of analysis completion plus 7 days and source expiry.
- Personal ticket evidence: the source expiry date. Synthetic examples may remain with the ticket; blur alone does not make an example anonymous or synthetic.
A specific unresolved fault can justify a documented source hold approved or explicitly renewed by Julian or James. Each decision lasts no more than 30 days. A current source hold can also suspend the staff-derived and personal ticket-evidence deadlines. On release, fault resolution or missed renewal, the original deadlines apply again; already overdue material becomes due immediately. A hold cannot recreate disposed evidence.
Expiry and recovery limits
Access cut-off, deletion of normal copies and final disappearance from recovery systems are different events. An app cannot run cleanup while powered off or suspended; managed expired files are disposed of at the next execution opportunity. Compatible server controls must refuse uploads completing at or after the seven-day deadline. Apple-controlled transfer and recovery copies, unmanaged exports and historical copies need separate handling.
Cloud versions, soft-deleted copies, database backups and exported, historical or recipient copies can remain after active deletion. The diagnostic deadlines above are not a guarantee that every provider or physical copy disappears at capture plus 30 days. Provider recovery checks remain open, including the scheduled 9 October 2026 storage observation; that future check has not passed.
The reviewed production recovery arrangements include seven-day Azure storage soft deletion, a seven-day database point-in-time recovery window, and long-term weekly/monthly database backups configured for eight weeks/twelve calendar months. These periods do not all start at scan capture, and backup chains can outlast a configured restore window. They are recovery arrangements, not extra ordinary diagnostic-use periods.
Codex analysis can create local conversation records, submitted model context and analysis outputs with separate copy lifecycles. Removing a local file or archiving a chat does not prove those copies have been erased. OpenAI service records and security, safety or legally required copies can remain under the supplier's applicable deletion and retention rules after PlanUp's working copies are removed. We do not claim a universal capture-based provider-erasure deadline. Recovery and supplier-held residuals must be handled separately from normal diagnostic access and working-copy disposal. Ask support@planup.co.uk about the relevant retained copies and safeguards.
The production retention rollout includes a temporary access exception for the existing legacy diagnostic cohort during reconciliation. That exception ends on 9 October 2026 at 18:21:40.519 UTC (19:21:40.519 BST). It does not give new uploads a fresh deadline or establish a validated capture time for old records. Deployment does not by itself prove every installed app, copy or cleanup path meets the policy.
Questions and requests
Email support@planup.co.uk with questions, a concern about recording or logs, or a request about your information. Requests go to James or Steven, including for legal questions. You can ask about access, correction, deletion, restriction or objection, according to the applicable law and legal basis. These are not unconditional promises of immediate erasure of every copy. You can make an objection verbally or in writing. We will assess it and explain our response; continued processing requires applicable lawful grounds. We normally respond to rights requests within one calendar month, subject to applicable legal exceptions or extensions.
You do not need a tester account. Give only enough detail to help locate the test, such as an approximate date and the operator or organisation, or a scan reference if you know it. Do not routinely send more private footage, occupant lists or identity documents; we will ask for proportionate information if needed to locate the data and protect other people's information.
You can complain to the Information Commissioner's Office at ICO complaints.
Readable information and changes
Ask for a readable or spoken explanation if needed. Before testing, the operator must provide affected people with information they understand. Reading this notice or continuing to use PlanUp is not blanket agreement to new diagnostic purposes. Material changes will be explained before new use where required.