1. Overview & Identity of the Data Controller
This Privacy Policy governs the collection, processing, storage, and use of personal data by Wolsten Studios LTD, a company incorporated in the Republic of Cyprus (Registration Number: ΗΕ 485976), operating the Siteproof software platform.
As a Cypriot-registered entity, Wolsten Studios LTD is subject to the General Data Protection Regulation (GDPR) (EU) 2016/679 and the applicable Cypriot national data protection legislation administered by the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
Registered Entity
- Company Name: Wolsten Studios LTD
- Registration Number: ΗΕ 485976
- Jurisdiction: Republic of Cyprus
- Platform: Siteproof — Utility Workforce Management Software
Operational Presence
- Registered Office & Support: Cyprus
- Training Centre: United Kingdom
2. Scope of This Policy
This policy applies to all users of the Siteproof platform, including main contractors, subcontractors, field operatives, supervisors, and administrative personnel who access the software in any capacity. It covers data collected through our web application, mobile interfaces, and any associated communication channels.
Siteproof is a business-to-business (B2B) platform. We do not hold or process end-customer personal data on behalf of client organisations. The data we process relates solely to the registered users, operatives, and administrators who interact with the platform directly.
3. Personal Data We Collect
We collect only the minimum personal data necessary to provide and improve the Siteproof platform. The categories of data we may process include:
- Identity Data: Full name, job title, and role within your organisation
- Contact Data: Work email address and telephone number
- Authentication Data: Login credentials and session tokens (managed via Clerk — see Section 6)
- Usage Data: Feature interactions, access logs, page views, and session duration for security and improvement purposes
- Technical Data: IP address, device type, browser type, and operating system
- Communication Data: Support tickets, training enquiries, and correspondence submitted to us
- Audit & Activity Data: Job records, sign-off actions, photo uploads, and workflow events created within the platform for compliance and accountability purposes
We do not collect, store, or process sensitive personal data (special category data) under Article 9 of the GDPR, such, biometric, or financial data.
4. Legal Basis for Processing
We process personal data under one or more of the following lawful bases in Article 6 of the GDPR:
| Legal Basis | Description |
|---|---|
| Contractual Necessity | Processing required to provide the Siteproof service under our software licence or service agreement with your organisation. |
| Legitimate Interests | Platform security, fraud prevention, abuse detection, and product improvement — where not overridden by the rights of data subjects. |
| Legal Obligation | Compliance with applicable Cypriot, EU, and UK laws including tax, corporate, and data protection obligations. |
| Consent | For optional communications such updates, newsletters, or training announcements, where explicitly provided. |
5. Data Storage & Infrastructure
Enterprise-grade infrastructure. Your data is hosted on Supabase, a PostgreSQL-based cloud database platform. Supabase provides ISO 27001-aligned infrastructure hosted on AWS data centres. Data residency and region configuration are applied at the project level.
Wolsten Studios LTD uses the following third-party infrastructure to store and process platform data:
All platform data — including job records, audit trails, user accounts, and uploaded files — is stored within Supabase. Supabase processes data on AWS infrastructure. Data may be stored in the EU (Frankfurt) or US regions depending on project configuration. Supabase acts Data Processor under our agreement with them. Their DPA is available at supabase.com/privacy.
User authentication, login sessions, and access tokens are managed by Clerk (clerk.com). Clerk processes authentication credentials on your behalf and is classified Data Processor. Clerk is SOC 2 Type II certified and GDPR-compliant. Their DPA is available at clerk.com/legal/dpa.
We have entered into Data Processing Agreements (DPAs) with all sub-processors handling personal data. A full list of sub-processors is available upon request by contacting privacy@siteproof.io.
6. Data Retention
We retain personal data only for to fulfil the purposes for which it was collected, to meet legal obligations, and to resolve disputes or enforce agreements.
- Active account data is retained for the duration of your organisation's subscription or service agreement
- Audit trail records (job completions, sign-offs, evidence logs) may be retained for up to 7 years to satisfy regulatory and contractual compliance requirements typical in the utilities sector
- Support correspondence is retained for 2 years after resolution
- Authentication logs are retained for 90 days for security and incident investigation
- Upon account termination, data is anonymised or deleted within 90 days, unless a longer retention period is required by law or agreed contractually
7. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights with respect to your personal data. You may exercise any of these rights by contacting us at the details provided in Section 11.
We will respond to all verified requests within 30 days. In complex cases, this may be extended by a further 60 days with prior notice. We reserve the right to verify your identity before fulfilling a request.
8. International Transfers
Personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including by our sub-processors Supabase and Clerk who may operate infrastructure in the United States. Where such transfers occur, we ensure they are protected by appropriate safeguards including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements incorporating GDPR-compliant transfer mechanisms
Our UK Training Centre operates in accordance with the UK GDPR and the Data Protection Act 2018. No personal data is routinely transferred to the UK Training Centre; it is used solely for delivery of training services.
9. Security Measures
We implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include:
- End-to-end encryption in transit using TLS 1.2+ for all data communications
- Encryption at rest for database records and file storage via Supabase
- Multi-factor authentication support and session management via Clerk
- Role-based access control (RBAC) limiting data access to authorised personnel only
- Regular security assessments and dependency audits
- Incident response procedures with breach notification processes compliant with Article 33 GDPR (72-hour reporting window)
10. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Wolsten Studios LTD will notify the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay. Affected client organisations will be notified promptly and provided with a breach summary including the nature of the incident, categories of data affected, and remediation steps taken.
12. Contact & Supervisory Authority
For any privacy-related enquiries, subject access requests, or concerns regarding how we process your personal data, please contact us at:
You also have the right to lodge a complaint with the competent supervisory authority. As a Cypriot-registered company, our lead supervisory authority is:
If you are based in the United Kingdom and your concerns relate to our UK Training Centre activities, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.
13. Policy Updates
We reserve the right to update this Privacy Policy periodically to reflect changes in legislation, our services, or our data processing practices. Material changes will be communicated to registered users via email or an in-platform notification at least 14 days before taking effect.
The version date at the top of this page indicates when the policy was last reviewed. Continued use of the Siteproof platform after the effective date of any update constitutes acceptance of the revised policy.
This Privacy Policy was last reviewed in March 2026. Continued use of the Siteproof platform constitutes acceptance of this policy.
How We Use Your Information
We use the information we collect about you for the following purposes:
- To provide, operate, and maintain the Siteproof platform and its features
- To process your account registration and verify your identity
- To send you service-related communications, including security alerts and support messages
- To analyse usage patterns and improve platform performance and reliability
- To comply with legal obligations and enforce our Terms of Service
- To detect, investigate, and prevent fraudulent or unauthorised activity
- To respond to your enquiries and provide customer support
Sharing Your Information
Siteproof does not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your data only in the following limited circumstances:
- Service Providers: Trusted third-party vendors who assist in operating our platform (e.g., cloud hosting, analytics, payment processing) under strict confidentiality agreements
- Your Organisation: Information shared within your organisation's Siteproof account is accessible to authorised administrators and team members by your account settings
- Legal Requirements: Where required by law, regulation, or valid legal process such court order or subpoena
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity with prior notice
- Safety & Security: To protect the rights, property, or safety of Siteproof, our users, or the public
Data Retention
We retain your personal information for account remains active or to provide you with our services. Specifically:
- Account data is retained for the duration of your subscription plus 90 days after account closure
- Project and field records may be retained for up to 7 years to meet legal and regulatory obligations in the utilities sector
- Audit logs are retained for a minimum of 3 years
- Anonymised and aggregated data may be retained indefinitely for analytics purposes
- You may request earlier deletion of your data subject to our legal retention obligations
Data Security
Protecting your data is a core responsibility at Siteproof. We implement industry-standard security measures including:
- AES-256 encryption for data at rest across all storage systems
- TLS 1.3 encryption for all data in transit between your device and our servers
- Role-based access controls (RBAC) to limit data access to authorised personnel only
- Multi-factor authentication (MFA) available for all user accounts
- Regular third-party security audits and penetration testing
- Automated monitoring and alerting for suspicious access patterns
While we take every reasonable precaution, no system can be guaranteed 100% secure. We encourage you to use strong passwords and enable MFA on your account.
Your Rights & Choices
Depending on your location, you may have certain rights regarding your personal information under applicable privacy laws (including the Australian Privacy Act 1988 and GDPR where applicable):
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to or restrict certain types of data processing
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact our Privacy Officer at privacy@siteproof.com.au. We will respond to all verified requests within 30 days.
Cookies & Tracking
Siteproof uses cookies and similar tracking technologies to operate and improve our platform. These include:
- Essential Cookies: Required for platform functionality, authentication, and security — cannot be disabled
- Analytics Cookies: Help us understand how users interact with the platform to improve performance (e.g., session duration, page views)
- Preference Cookies: Remember your settings and preferences for a personalised experience
You can manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your core use of the platform. We do not use third-party advertising cookies.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes:
- We will update the "Last Updated" date at the top of this page
- We will notify account administrators via email at least 14 days before significant changes take effect
- Continued use of Siteproof after the effective date constitutes acceptance of the updated policy
We encourage you to review this policy periodically. Previous versions are available upon request.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact our Privacy Officer:
This Privacy Policy was last updated on 1 July 2025 and applies to all users of the Siteproof platform. By using Siteproof, you acknowledge that you have read and understood this policy.