Your business data is safe with Contraq

We hold your data to the same standard we'd expect if someone else held ours. Transparent practices, UK infrastructure, and no surprises.

GDPR Compliant TLS 1.3 Encrypted Stripe Payments UK Data Storage
Data Storage — UK Servers
Your data is stored exclusively on UK and EU-based infrastructure using Supabase (Postgres database) and Vercel (application hosting), both of which maintain data residency within the European Economic Area.

We do not store any data on servers located outside the UK or EU, and we will never transfer your data to jurisdictions without adequate data protection laws. Supabase · Vercel · AWS EU-West
Encryption — In Transit & At Rest
All data transmitted between your browser and our servers is encrypted using TLS 1.3 — the latest and most secure transport layer protocol. We enforce HTTPS on all connections and reject legacy protocols.

Data stored in our database is encrypted at rest using AES-256 encryption. Database backups are also encrypted before being written to storage. TLS 1.3 in transit · AES-256 at rest
Access Control & Audit Logs
Access to your company data is governed by role-based access control (RBAC). Admins can assign permissions per team member — view only, edit, or full admin.

Every significant action (invoice raised, project edited, engineer record changed) is written to an immutable audit log — timestamped, attributed to a named user, and retained for 12 months. RBAC · Immutable audit trail
Backups & Recovery
Production infrastructure will include automated daily backups with point-in-time recovery and geo-redundant storage. Backup and recovery specifications will be published at launch.

In the event of a serious incident, our Recovery Time Objective (RTO) is under 4 hours and Recovery Point Objective (RPO) is under 24 hours. Daily backups · 30-day retention · Multi-region
GDPR & Your Rights
Contraq acts as a data processor on your behalf. You remain the data controller for all information relating to your employees, clients and subcontractors.

We honour all data subject rights under UK GDPR: right to access, rectification, erasure, portability and restriction. Submit a request to [email protected] and we will respond within 30 days.

A full Data Processor Agreement (DPA) is available on request. UK GDPR · ICO registered · DPA available
Payment Security — Stripe
All subscription payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. Contraq never stores, transmits or has access to your card details — they are handled entirely by Stripe's infrastructure.

Stripe is used by millions of businesses worldwide including Amazon, Google and Deliveroo. Their security practices exceed the requirements of PCI DSS and ISO 27001. PCI DSS Level 1 · No card data stored by Contraq
ISO 27001 Certification — In Progress
We are currently working through the ISO 27001 information security management certification process with our accredited auditor. We expect to receive certification in Q3 2025. In the meantime, our security practices already meet or exceed the ISO 27001 standard in all material respects.
Responsible Disclosure
If you discover a security vulnerability in Contraq, please report it responsibly to [email protected]. We commit to acknowledging your report within 48 hours and resolving confirmed vulnerabilities within 30 days. We do not take legal action against good-faith security researchers.
Request a Data Processor Agreement

If your business requires a formal Data Processor Agreement (DPA) for compliance purposes — for example to satisfy your own ISO 27001 audit or client requirements — we can provide one. Click below to email our DPO with a pre-filled request.

CONTRAQ
All trades

Sound familiar?

How Contraq solves it

No credit card required · Cancel anytime · UK-based support

Welcome back

Sign in to your CONTRAQ account

Start your free trial

14 days free · No credit card needed

Contraq Beta · £99/mo after trial · Founding member rate locked for life
Let's set you up
3 quick steps and you're live
Your Trade
Select the trades your business operates in — we'll personalise your platform accordingly.
Insulation
& Lagging
Ductwork
& Lagging
Pipework
Electrical
Plumbing
& Heating
Fire
Protection
Cladding
Other
Company Details
CONTRAQ Professional
14-day free trial, then billed monthly
£149/mo
256-bit SSL encrypted  ·  Powered by Stripe
Dashboard