Privacy Policy

Last updated · 18 August 2026

This policy explains how Pointnode Limited, trading as Pointnode ("Pointnode", "we", "us"), handles personal data when you visit our website, contact us or use the Pointnode platform. The platform supports industrial assets of any type. The separate craneIQ iOS app is a mobile client for lifting-equipment workflows.

It is written in plain English. If anything is unclear, email privacy@pointnode.io.

1. Who is responsible for your data

Pointnode is a B2B platform used by asset owners, operators, service providers and inspection organisations. Our role depends on why the data is being used:

If your employer, customer or service provider added your data, contacting that organisation is usually the quickest route. You can also use our privacy request form; we will handle the request where Pointnode is Controller or route it to the appropriate Controller where we act as Processor.

Pointnode contact details

2. What personal data we process

For Customer accounts (Pointnode as Processor)

Telemetry from assets (not personal data, with caveats)

The bulk of data on the platform is operational telemetry from the monitored assets (load, cycle counts, temperatures, levels, fault codes, etc.). This is machine data, not personal data. It only becomes personal data when correlated with operator activity through the audit log (e.g. "operator X started a session on asset Y at time Z"). Telemetry reaches us from more than one kind of source, but lands in the same place and is treated the same way:

Command / actuation data (optional interlock feature)

Where a Customer opts in to the optional wireless start-inhibit interlock, the platform can send an outbound command to a wireless relay fitted to an asset — enabling or inhibiting the asset's start command based on whether a pre-use safety check has been passed. We record the command issued (enable / inhibit), the time, the identity of the person or automated rule that triggered it, the relay's reported contact state, and any use of the operator override. This record is kept as part of the audit trail (and can be correlated with the operator who filed the underlying pre-use check, so it may be personal data on that basis). The interlock is an administrative / procedural control that is always physically operator-overridable; it is not a functional-safety device (see the Terms of Service).

Profile contact details

Support tickets and help-centre feedback

Integration credentials (where you choose to use them)

Multi-factor authentication state

Technical data

Website, demo and business-contact data

Where the data comes from

We receive personal data directly from you; from your employer or an organisation administrator; from a customer or service provider that has invited or assigned you; from records, photographs and documents users upload; from connected assets and devices; and from the hosting, security, email, payment and authentication services used to operate Pointnode.

3. Why we process it (lawful basis)

For Customer content, Pointnode acts on the Controller's documented instructions. The Controller decides and records its lawful basis. Depending on the workflow, that may include a legal obligation, performance of a contract, or legitimate interests in operating, maintaining and evidencing the safety of its assets.

Where Pointnode acts as Controller for its own business activities, we use the following bases. "Contract" applies only where the individual is a party to that contract; for corporate customer contacts we normally rely on legitimate interests instead.

PurposeLawful basis (UK GDPR Art. 6)
Answer demo enquiries and manage customer relationshipsLegitimate interests; steps requested before a contract where applicable
Administer accounts, support and service communicationsLegitimate interests; performance of contract where applicable
Billing, tax and company recordsPerformance of contract; legal obligation; legitimate interests
Audit logging, fraud prevention and platform securityLegitimate interests in protecting Pointnode, Customers and users
Handle privacy requests and complaintsLegal obligation; legitimate interests in resolving concerns
Comply with valid law-enforcement requestsLegal obligation

4. Who we share it with (sub-processors)

We do not sell personal data and we do not share it with anyone other than authorised users and connected organisations within the access scope set by the Controller, the sub-processors listed at /legal/sub-processors and their authorised sub-processors, professional advisers, or a regulator or law-enforcement body where disclosure is legally required. Each platform sub-processor is engaged under written terms that include the data-protection obligations required for the service it provides.

Customers are notified at least 30 days before any new sub-processor is added and may object before the change takes effect.

5. International transfers

Core database storage is configured in the EEA. Some providers process limited data in the United States or through global infrastructure. For a restricted transfer, we use an available adequacy route or appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, together with the required data-protection test or transfer risk assessment and supplementary measures. Transfers from the EEA to Pointnode in the UK can currently rely on the EU's UK adequacy decision. See the sub-processor list for provider details.

6. How long we keep it

DataRetention
Active user accountFor the life of the account. Identifiers are removed or tombstoned within 30 days of a valid deletion instruction, subject to the exceptions below.
Audit log of user actions7 years rolling while the Customer account remains active, as the platform's standard integrity and accountability period; shorter or longer periods may be agreed where appropriate.
Notification log (sends, failures)12 months rolling
Inspections, services, work orders, pre-use checks, defects and lockout recordsFor the Customer's configured or instructed retention period and any period required for the relevant asset and record type. There is no single UK statutory period for every asset record: for example, LOLER periods vary by report type, PUWER inspection results should generally be kept at least until the next inspection, and RIDDOR records have their own rules.
Asset telemetry (machine data)Full-resolution telemetry is retained for at least 30 days. Aggregated or summary history is retained for longer, with extended retention available by agreement.
Demo enquiries that do not become a customer relationshipUp to 24 months after the last substantive contact, unless you ask us to delete them sooner.
Privacy requests and complaintsNormally 6 years after closure so we can demonstrate how the request was handled and manage legal claims.
Server logs (hosting and infrastructure providers)Per provider defaults — typically 7–30 days

At the end of the contract with a Customer, we return or delete the Customer's personal data within 30 days as set out in the DPA, unless the Customer instructs us to retain or return it differently, or law requires Pointnode to keep a limited record. Provider backups may take a short additional period to age out and remain protected while they do.

7. Your rights

Under UK GDPR you have the right to:

Rights are not absolute and the applicable response period can depend on the request and our role. We normally respond to a rights request within one month after receiving it and any information reasonably needed to verify identity. We will explain any extension, refusal or exemption.

8. Security

Technical and organisational measures we apply:

Technical detail for your security team: see our public security overview page and the Annex 3 (Security Measures) of our DPA.

9. Automated processing and AI features

Pointnode offers an optional set of AI features, marketed as the Asset Intelligence add-on. These are:

What data is sent, and to whom

To generate this analysis we send a bounded amount of context to two AI sub-processors, both in the United States and both engaged under the EU Standard Contractual Clauses / UK International Data Transfer Agreement (see the sub-processor list):

We do not send payment data or account credentials. Asset context is minimised before transmission, but defect text, questions and uploaded documents can contain personal data if a user includes it. Customers should avoid placing special-category data or credentials in AI questions or documents. This processing is separate from Pointnode's own engineering use of AI tooling, which does not touch production Customer data.

When these features run

The per-asset AI features (an asset's briefing, and the AI Engineer scoped to a single asset) require the paid Asset Intelligence add-on to be enabled for that asset. No asset context is sent to Anthropic or Voyage for an asset that does not have the add-on switched on. Certain fleet-level features — for example a fleet-wide briefing or a fleet-scoped AI Engineer available to an organisation's administrators — run only where the organisation-level Asset Intelligence entitlement is enabled, whether or not every individual asset carries a legacy per-asset add-on.

Automated decision-making

These features are advisory and human-in-the-loop. They produce analysis and suggestions about equipment for a person to review and act on; they do not make automated decisions, and they do not produce legal or similarly significant effects concerning an individual. Accordingly, they do not constitute solely automated decision-making under UK GDPR Article 22. AI-generated output can be incomplete or wrong and must not be relied on as a substitute for a competent person's judgement or a statutory inspection.

10. Cookies

We use essential, strictly-necessary cookies only — no advertising, analytics, or tracking cookies — so no consent banner is required under the Privacy and Electronic Communications Regulations (PECR). Every cookie we set is first-party and needed for the service to function or to keep it secure. They fall into these categories:

You can clear cookies in your browser settings; you will need to sign in again afterwards.

11. Children

Pointnode is a workplace tool intended for adults using or managing industrial equipment. We do not knowingly collect personal data from anyone under 18.

12. Personal data breaches

If a personal data breach occurs that is likely to result in a risk to rights and freedoms, we will:

Where Pointnode is acting as Processor, the affected Customer (Controller) is responsible for any onward notification to the ICO and to data subjects.

13. Changes to this policy

The current version is always at this URL with a "Last updated" date at the top. We will highlight material changes through the service or by direct notice where reasonably possible and where our contract or the law requires it. Sub-processor changes follow the notice process in the DPA.

14. Contact

Submit a request or complaint through our privacy request form, or email privacy@pointnode.io. Pointnode has not formally appointed a Data Protection Officer because we do not currently consider the Article 37 thresholds to be met. The privacy contact is responsible for escalating data-protection matters to senior management.
Pointnode Limited, registered in England and Wales (Company No. 13338758). Registered office: Kingsland House, 39 Abbey Foregate, Shrewsbury, Shropshire, SY2 6BL.