Who we are
Cooper & Codex Ltd is a chartered building surveying practice and AI-systems business, incorporated in England and Wales on 18 April 2026 (Companies House registered number 17165926). The firm is regulated by the Royal Institution of Chartered Surveyors (RICS), firm number 925582. For the purposes of UK data protection law, Cooper & Codex Ltd is the data controller for the personal data this notice covers.
We have registered as a data controller with the Information Commissioner's Office (ICO) under registration number ZC147390.
- Registered office: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ
- Trading address: St George's Works, 51 Colegate, Norwich NR3 1DD
- Email: enquiries@cooperandcodex.co.uk
- Principal: Hamish Cooper MRICS
If you have any questions about this notice or how we handle your personal data, please write to us by email at privacy@cooperandcodex.co.uk, addressed to the Director.
What this notice covers
This notice tells you what personal data we collect, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have. It applies to:
- Clients and prospective clients of the firm's surveying and AI-systems services.
- Professional contacts at firms we work with or may work with: instructing firms, sub-consultants, principals, design teams, contractors, lenders' representatives, and the like.
- Visitors to the firm's website at cooperandcodex.co.uk.
- Attendees at CPD sessions delivered by the firm.
- Anyone who corresponds with the firm.
If you are giving us personal data about someone other than yourself (for example, occupant details supplied as part of a survey instruction), please share this notice with them.
What personal data we collect
We collect the following categories of personal data:
- Contact and identification details: name, organisation, professional role, postal address, email address, telephone number(s), professional qualifications.
- Engagement and project records: correspondence about your instruction, site notes, photographs (which may incidentally show people or personal effects), drafts, deliverables, and any other working records produced or received in the course of your engagement.
- Third-party information referenced in your engagement: names and professional contact details of other parties named in your matter (other consultants, contractors, prior surveyors, occupants), where relevant to the work.
- Financial and billing records: invoices, payment references, banking details where supplied for payment, and records required for tax and anti-money-laundering purposes.
- Marketing and CPD records: for those who opt in to marketing communications or who attend CPD sessions, name, contact details, and CPD-attendance record.
- Website and email metadata: server logs, email delivery metadata, and information your browser sends in the ordinary course (IP address, browser type, referring page). We use this for security and operational diagnostics only, not to profile visitors. We do not use website analytics cookies that identify individuals.
We do not seek special-category personal data (such as data about health, racial or ethnic origin, religious beliefs, or sexual orientation) or criminal-offence data, and our work does not ordinarily involve it. Where such data is incidentally present in material we receive (for example, where an occupant's mobility is mentioned in correspondence about access), we keep it to a minimum, restrict access to what the engagement requires, and do not use it for any other purpose.
We do not knowingly collect or process personal data relating to children.
How we use your personal data: purposes and lawful bases
We use personal data for the following purposes, on the following lawful bases under Article 6 UK GDPR (and Article 9 where special-category data is involved):
| Purpose | Lawful basis |
|---|---|
| To deliver the surveying or AI-systems engagement you (or your firm) have instructed | Performance of a contract — Article 6(1)(b) |
| To respond to your enquiries and provide quotes | Legitimate interests — Article 6(1)(f); or pre-contractual steps — Article 6(1)(b) |
| To produce, issue, and stand behind professional reports and advice | Performance of a contract — Article 6(1)(b); legitimate interests — Article 6(1)(f), where third-party data is referenced |
| To invoice, take payment, and keep accounting records | Performance of a contract — Article 6(1)(b); legal obligation under tax and company law — Article 6(1)(c) |
| To comply with anti-money-laundering and counter-financial-crime obligations | Legal obligation — Article 6(1)(c) |
| To meet our regulatory obligations to RICS, including, where required, disclosure of records to RICS Regulation | Legal obligation — Article 6(1)(c); legitimate interests — Article 6(1)(f) |
| To maintain a complaints log and to investigate, respond to, and learn from complaints about our services | Legal obligation under RICS rules — Article 6(1)(c); legitimate interests in service quality — Article 6(1)(f) |
| To notify, manage, and defend any actual or potential professional indemnity claim arising from our work | Legitimate interests in defence of legal claims — Article 6(1)(f); performance of contract — Article 6(1)(b) |
| To maintain business records, support our own internal training and CPD, and develop the firm's services | Legitimate interests — Article 6(1)(f) |
| To send marketing communications about our services to professional contacts and to those who have opted in | Consent — Article 6(1)(a), for B2C; legitimate interests — Article 6(1)(f), for B2B contacts, with a right to object at any time |
| To invite you, once your report has been issued, to leave a review of our service | Legitimate interests — Article 6(1)(f), in understanding and improving the service and in the honest public record of it |
| To maintain statutory company registers and meet Companies Act 2006 obligations | Legal obligation — Article 6(1)(c) |
Where we rely on legitimate interests, we have considered whether your interests, rights, and freedoms override our interests, and we are satisfied that they do not in the context described. You can ask us at any time to explain the balancing test for a particular processing activity.
Use of artificial intelligence
The firm uses AI tools in delivering its services, including a locally-hosted transcription tool and general-purpose AI assistants. We use them under a clear rule: your personal and confidential data is not sent to any third-party AI service. Where a task on your engagement would involve such data, it is either handled by a model running on our own equipment, or the material is stripped of personal and confidential data (by a local model, programmatically, or by hand) before any external service is used. AI assists our professional work; it does not make decisions about you, and it does not replace professional judgement.
Your rights regarding our use of AI. You may ask how AI has been used in your engagement, raise a concern about that use, and ask us not to use AI on your work; we will tell you of any effect that has on the fee or timescale before you decide. If you believe our use of AI has affected you and we cannot put it right between us, our complaints procedure and independent redress route are open to you.
Who we share your personal data with
We share personal data only where necessary, and only with parties bound to appropriate confidentiality and data-protection obligations. The categories of recipient are:
- Hosting and infrastructure providers: a UK-based provider hosts our email, our website, and the business applications we run ourselves (such as our client-records, e-signature, and time-recording systems). The provider supplies the infrastructure; we run the applications.
- Encrypted synchronisation and backup services: we use zero-knowledge encrypted services to synchronise our files, calendar, and contacts across our own devices, and to keep secure off-site backups. These providers hold only encrypted data and cannot read its content.
- Our professional indemnity insurer and brokers, on notification of a circumstance, claim, or potential claim, and at renewal.
- Our independent ADR provider (the Centre for Effective Dispute Resolution, CEDR), on escalation of a complaint to Stage 2 of our Complaints procedure.
- RICS Regulation, where the regulator requires disclosure under its Rules.
- Solicitors, accountants, and other professional advisers engaged by the firm, where their input is required.
- Tax and statutory authorities such as HMRC, Companies House, and the ICO, where required by law.
- Other parties to your engagement, where appropriate to the work.
We do not sell personal data, and we do not share it for third-party marketing.
International transfers
Some of the services we use are provided from outside the United Kingdom. Where that is so, we rely on a lawful transfer mechanism: an adequacy decision, or the UK International Data Transfer Agreement or Addendum to the EU Standard Contractual Clauses. For our encrypted synchronisation and backup services, zero-knowledge encryption means the provider cannot access the content in any event.
How long we keep your personal data
We keep personal data only for as long as we need it for the purpose we collected it, or for as long as the law or a regulatory obligation requires. Our default for engagement records (correspondence, reports, working records, photographs) is six years from the end of the engagement, in line with the limitation period for civil claims. Some records are kept longer where a specific engagement, a regulatory requirement, or the nature of the work requires it. Financial records are kept for six years and anti-money-laundering records for five; statutory company registers are kept for the life of the company.
Where we keep personal data beyond active use, access is restricted and the data is kept secure.
How we keep your personal data secure
We maintain appropriate technical and organisational measures to protect your personal data against loss and against unauthorised access, alteration, or disclosure, including encrypted storage and backups, access limited to those who need it for the work, and secure (TLS-encrypted) transport for email and web traffic.
No system is completely secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the ICO within 72 hours of becoming aware and, where the risk is high, notify you directly.
Your rights
Under the UK GDPR, you have the following rights in respect of personal data we hold about you:
- Right of access: to ask for a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete personal data.
- Right to erasure: in certain circumstances, to ask us to delete personal data we hold about you. This right is not absolute: it does not override our retention obligations for engagement files, tax records, or other records held under legal or regulatory obligation.
- Right to restrict processing: in certain circumstances, to ask us to stop using personal data while a question about its accuracy, or about our use of it, is resolved.
- Right to object: to object to our processing where we rely on legitimate interests, including in respect of B2B marketing.
- Right to data portability: for data you provided to us, processed by automated means on the basis of consent or contract, the right to receive that data in a structured, commonly-used, machine-readable format.
- Right to withdraw consent: where we rely on consent (for example, for some marketing communications), the right to withdraw that consent at any time.
- Rights relating to automated decision-making and profiling: we do not make decisions about you by purely automated means. AI tools assist our professional work; they do not make decisions affecting you without human involvement.
To exercise any of these rights, please write to privacy@cooperandcodex.co.uk, addressed to the Principal. We will respond within one month of receiving a verifiable request. We do not charge a fee for responding to a request unless it is manifestly unfounded or excessive.
How to complain about how we handle your personal data
If you are unhappy with how we have handled your personal data, there are two routes open to you. We would ask that you raise the matter with us first, but you can complain to the Information Commissioner's Office (ICO) at any time. (If your complaint is about our service or conduct rather than your personal data, our Complaints procedure applies instead.)
Step 1 — Complain to us as data controller
Cooper & Codex Ltd is the data controller for your personal data, and you have the right to complain to us directly about how we have handled it. We will make it straightforward for you to do so: write to us at privacy@cooperandcodex.co.uk, addressed to the Director, or by post to our trading address, and tell us what has gone wrong and what you would like us to put right. A complaints form is available from us on request, if that is easier for you.
When we receive a data-protection complaint, we will:
- acknowledge it within 30 days of receiving it, in writing; and
- respond without undue delay, taking appropriate steps to look into the complaint and to tell you the outcome.
This reflects the duty placed on data controllers by the Data (Use and Access) Act 2025, in force from 19 June 2026. We would always rather have the chance to put a thing right ourselves.
Step 2 — Complain to the ICO
Whether or not you have complained to us first, you have the right to complain to the Information Commissioner's Office, the UK's independent data-protection regulator, at any time:
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Telephone: 0303 123 1113
- Online: ico.org.uk/make-a-complaint
Changes to this notice
We review this notice at least annually, and whenever there is a material change to how we handle personal data: for example, when we adopt a new sub-processor, when our service offering changes materially, or when there is a relevant change to data-protection law or regulator guidance.
When we make a change, we update the Last revised date below and re-publish the notice. Where a change materially affects you (for example, the introduction of a substantively new category of processing), we tell you directly, where we have your contact details, before the change takes effect.