This policy explains what personal information [LEGAL ENTITY NAME] ("we") collects when you use this preventative-maintenance compliance service ("the Service"), why we collect it, who it is shared with, and what you can do about it.
The Service is used by trade contracting businesses to record maintenance and compliance work. Two distinct groups appear in it:
For the second group we act as a processor: the contracting business decides what is entered and why, and is the controller of that information. Requests about site or client records should be directed to the business that entered them.
| Category | Details | Why |
|---|---|---|
| Account | Name, email address, password (stored only as a hash), role | To create and secure your account |
| Session | A first-party cookie holding a session identifier | To keep you signed in |
| Business details | Trading and legal name, licence number, address, phone, contact email, logo | To place on the certificates you issue |
| Site records | Site names and addresses, client names, service schedules, notes, identifiers from your job system | To schedule and evidence the work |
| Visit records | Date, technician name and email, checklist results, measurements, defects | To produce the compliance record |
| Photographs and signatures | Images captured on site, including a customer's signature where taken | Evidence attached to the visit |
| Integration credentials | API keys and OAuth tokens for your job system and cloud storage | To create jobs and file report copies |
| Invitations | Email address and a single-use token | To let you add colleagues |
We do not use tracking or advertising cookies, and we do not run third-party analytics in the application.
SameSite=Lax.The Service passes information to the providers you connect, and to the infrastructure it runs on:
| Recipient | What is sent |
|---|---|
| DigitalOcean, Sydney, Australia | All application data, at rest and in transit |
| [EMAIL PROVIDER] | Recipient address and message content for invitations and reminder digests |
| Your job-management system (e.g. Fergus), if connected | Job details and a completion note containing the date, technician, pass/fail counts and a link |
| Your cloud storage (Google Drive, Dropbox, OneDrive), if connected | A copy of each report filed into your own folders |
| DigitalOcean, Sydney, Australia (stored on the same server as the application) | Photographs, signatures and generated certificates |
We do not sell personal information, and we do not disclose it to anyone else except where required by law.
Data is hosted in Australia, in DigitalOcean’s Sydney data centre. If you connect a cloud-storage or job-management provider, copies also reside wherever that provider stores them, under their terms.
Compliance records are kept for as long as your organisation keeps its account, because they are the evidence your clients and insurers may need years later. [STATE YOUR RETENTION PERIOD AND WHAT HAPPENS AFTER CLOSURE — e.g. deleted within 90 days of account closure, subject to any legal obligation to retain.] Invitations expire automatically and unused tokens become invalid.
You may ask us to access, correct or delete the personal information we hold about you, and to provide it in a portable form. Where we hold that information on behalf of a contracting business, we will refer your request to them. Contact us at [PRIVACY CONTACT EMAIL]. If you are not satisfied with our response you may complain to [RELEVANT PRIVACY REGULATOR].
If we change this policy we will update the date at the top and, for material changes, notify account holders by email.