overview

1. Overview & Identity of the Data Controller

This Privacy Policy governs the collection, processing, storage, and use of personal data by Wolsten Studios LTD, a company incorporated in the Republic of Cyprus (Registration Number: ΗΕ 485976), operating the Siteproof software platform.

As a Cypriot-registered entity, Wolsten Studios LTD is subject to the General Data Protection Regulation (GDPR) (EU) 2016/679 and the applicable Cypriot national data protection legislation administered by the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.

Registered Entity

  • Company Name: Wolsten Studios LTD
  • Registration Number: ΗΕ 485976
  • Jurisdiction: Republic of Cyprus
  • Platform: Siteproof — Utility Workforce Management Software

Operational Presence

  • Registered Office & Support: Cyprus
  • Training Centre: United Kingdom
scope

2. Scope of This Policy

This policy applies to all users of the Siteproof platform, including main contractors, subcontractors, field operatives, supervisors, and administrative personnel who access the software in any capacity. It covers data collected through our web application, mobile interfaces, and any associated communication channels.

Siteproof is a business-to-business (B2B) platform. We do not hold or process end-customer personal data on behalf of client organisations. The data we process relates solely to the registered users, operatives, and administrators who interact with the platform directly.

data-collected

3. Personal Data We Collect

We collect only the minimum personal data necessary to provide and improve the Siteproof platform. The categories of data we may process include:

  • Identity Data: Full name, job title, and role within your organisation
  • Contact Data: Work email address and telephone number
  • Authentication Data: Login credentials and session tokens (managed via Clerk — see Section 6)
  • Usage Data: Feature interactions, access logs, page views, and session duration for security and improvement purposes
  • Technical Data: IP address, device type, browser type, and operating system
  • Communication Data: Support tickets, training enquiries, and correspondence submitted to us
  • Audit & Activity Data: Job records, sign-off actions, photo uploads, and workflow events created within the platform for compliance and accountability purposes

We do not collect, store, or process sensitive personal data (special category data) under Article 9 of the GDPR, such, biometric, or financial data.

data-storage

5. Data Storage & Infrastructure

Enterprise-grade infrastructure. Your data is hosted on Supabase, a PostgreSQL-based cloud database platform. Supabase provides ISO 27001-aligned infrastructure hosted on AWS data centres. Data residency and region configuration are applied at the project level.

Wolsten Studios LTD uses the following third-party infrastructure to store and process platform data:

SupabaseDatabase & Storage Provider

All platform data — including job records, audit trails, user accounts, and uploaded files — is stored within Supabase. Supabase processes data on AWS infrastructure. Data may be stored in the EU (Frankfurt) or US regions depending on project configuration. Supabase acts Data Processor under our agreement with them. Their DPA is available at supabase.com/privacy.

ClerkAuthentication & Identity Management

User authentication, login sessions, and access tokens are managed by Clerk (clerk.com). Clerk processes authentication credentials on your behalf and is classified Data Processor. Clerk is SOC 2 Type II certified and GDPR-compliant. Their DPA is available at clerk.com/legal/dpa.

We have entered into Data Processing Agreements (DPAs) with all sub-processors handling personal data. A full list of sub-processors is available upon request by contacting privacy@siteproof.io.

retention

6. Data Retention

We retain personal data only for to fulfil the purposes for which it was collected, to meet legal obligations, and to resolve disputes or enforce agreements.

  • Active account data is retained for the duration of your organisation's subscription or service agreement
  • Audit trail records (job completions, sign-offs, evidence logs) may be retained for up to 7 years to satisfy regulatory and contractual compliance requirements typical in the utilities sector
  • Support correspondence is retained for 2 years after resolution
  • Authentication logs are retained for 90 days for security and incident investigation
  • Upon account termination, data is anonymised or deleted within 90 days, unless a longer retention period is required by law or agreed contractually
rights

7. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights with respect to your personal data. You may exercise any of these rights by contacting us at the details provided in Section 11.

Right of Access: Request a copy of the personal data we hold about you (Subject Access Request).
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data where no legitimate basis for continued processing exists.
Right to Restrict Processing: Request that we limit how we use your personal data in certain circumstances.
Right to Data Portability: Receive your personal data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.

We will respond to all verified requests within 30 days. In complex cases, this may be extended by a further 60 days with prior notice. We reserve the right to verify your identity before fulfilling a request.

international

8. International Transfers

Personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including by our sub-processors Supabase and Clerk who may operate infrastructure in the United States. Where such transfers occur, we ensure they are protected by appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Data Processing Agreements incorporating GDPR-compliant transfer mechanisms

Our UK Training Centre operates in accordance with the UK GDPR and the Data Protection Act 2018. No personal data is routinely transferred to the UK Training Centre; it is used solely for delivery of training services.

security

9. Security Measures

We implement and maintain appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include:

  • End-to-end encryption in transit using TLS 1.2+ for all data communications
  • Encryption at rest for database records and file storage via Supabase
  • Multi-factor authentication support and session management via Clerk
  • Role-based access control (RBAC) limiting data access to authorised personnel only
  • Regular security assessments and dependency audits
  • Incident response procedures with breach notification processes compliant with Article 33 GDPR (72-hour reporting window)
breach

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Wolsten Studios LTD will notify the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.

Where a breach is likely to result in a high risk to affected individuals, we will also notify those individuals without undue delay. Affected client organisations will be notified promptly and provided with a breach summary including the nature of the incident, categories of data affected, and remediation steps taken.

cookies

11. Cookies & Tracking

Siteproof uses essential cookies and session tokens required for the platform to function, including authentication session cookies managed by Clerk. We do not use third-party advertising cookies, behavioural tracking, or cross-site tracking technologies.

  • Essential Cookies: Required for login, session management, and security (cannot be disabled)
  • Analytics (where applicable), aggregated usage data for platform improvement — no personal identifiers
  • No third-party advertising or retargeting cookies are used
contact

12. Contact & Supervisory Authority

For any privacy-related enquiries, subject access requests, or concerns regarding how we process your personal data, please contact us at:

Data ControllerWolsten Studios LTD (ΗΕ 485976)
Emailprivacy@siteproof.io
Registered JurisdictionRepublic of Cyprus

You also have the right to lodge a complaint with the competent supervisory authority. As a Cypriot-registered company, our lead supervisory authority is:

AuthorityOffice of the Commissioner for Personal Data Protection
Websitedataprotection.gov.cy
Address1 Iasonos Street, 1082 Nicosia, Cyprus
Emailcommissioner@dataprotection.gov.cy

If you are based in the United Kingdom and your concerns relate to our UK Training Centre activities, you may also contact the Information Commissioner's Office (ICO) at ico.org.uk.

updates

13. Policy Updates

We reserve the right to update this Privacy Policy periodically to reflect changes in legislation, our services, or our data processing practices. Material changes will be communicated to registered users via email or an in-platform notification at least 14 days before taking effect.

The version date at the top of this page indicates when the policy was last reviewed. Continued use of the Siteproof platform after the effective date of any update constitutes acceptance of the revised policy.

This Privacy Policy was last reviewed in March 2026. Continued use of the Siteproof platform constitutes acceptance of this policy.

Section 4

How We Use Your Information

We use the information we collect about you for the following purposes:

  • To provide, operate, and maintain the Siteproof platform and its features
  • To process your account registration and verify your identity
  • To send you service-related communications, including security alerts and support messages
  • To analyse usage patterns and improve platform performance and reliability
  • To comply with legal obligations and enforce our Terms of Service
  • To detect, investigate, and prevent fraudulent or unauthorised activity
  • To respond to your enquiries and provide customer support
Section 5

Sharing Your Information

Siteproof does not sell, rent, or trade your personal information to third parties for marketing purposes. We may share your data only in the following limited circumstances:

  • Service Providers: Trusted third-party vendors who assist in operating our platform (e.g., cloud hosting, analytics, payment processing) under strict confidentiality agreements
  • Your Organisation: Information shared within your organisation's Siteproof account is accessible to authorised administrators and team members by your account settings
  • Legal Requirements: Where required by law, regulation, or valid legal process such court order or subpoena
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity with prior notice
  • Safety & Security: To protect the rights, property, or safety of Siteproof, our users, or the public
Section 6

Data Retention

We retain your personal information for account remains active or to provide you with our services. Specifically:

  • Account data is retained for the duration of your subscription plus 90 days after account closure
  • Project and field records may be retained for up to 7 years to meet legal and regulatory obligations in the utilities sector
  • Audit logs are retained for a minimum of 3 years
  • Anonymised and aggregated data may be retained indefinitely for analytics purposes
  • You may request earlier deletion of your data subject to our legal retention obligations
Section 7

Data Security

Protecting your data is a core responsibility at Siteproof. We implement industry-standard security measures including:

  • AES-256 encryption for data at rest across all storage systems
  • TLS 1.3 encryption for all data in transit between your device and our servers
  • Role-based access controls (RBAC) to limit data access to authorised personnel only
  • Multi-factor authentication (MFA) available for all user accounts
  • Regular third-party security audits and penetration testing
  • Automated monitoring and alerting for suspicious access patterns

While we take every reasonable precaution, no system can be guaranteed 100% secure. We encourage you to use strong passwords and enable MFA on your account.

Section 8

Your Rights & Choices

Depending on your location, you may have certain rights regarding your personal information under applicable privacy laws (including the Australian Privacy Act 1988 and GDPR where applicable):

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data, subject to legal retention requirements
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to or restrict certain types of data processing
  • Withdrawal of Consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact our Privacy Officer at privacy@siteproof.com.au. We will respond to all verified requests within 30 days.

Section 9

Cookies & Tracking

Siteproof uses cookies and similar tracking technologies to operate and improve our platform. These include:

  • Essential Cookies: Required for platform functionality, authentication, and security — cannot be disabled
  • Analytics Cookies: Help us understand how users interact with the platform to improve performance (e.g., session duration, page views)
  • Preference Cookies: Remember your settings and preferences for a personalised experience

You can manage cookie preferences through your browser settings. Disabling non-essential cookies will not affect your core use of the platform. We do not use third-party advertising cookies.

Section 10

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes:

  • We will update the "Last Updated" date at the top of this page
  • We will notify account administrators via email at least 14 days before significant changes take effect
  • Continued use of Siteproof after the effective date constitutes acceptance of the updated policy

We encourage you to review this policy periodically. Previous versions are available upon request.

Section 11

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact our Privacy Officer:

NamePrivacy Officer, Siteproof
AddressLevel 4, 123 Collins Street, Melbourne VIC 3000, Australia
Response TimeWithin 30 business days

This Privacy Policy was last updated on 1 July 2025 and applies to all users of the Siteproof platform. By using Siteproof, you acknowledge that you have read and understood this policy.