1. Scope and roles
This Privacy Policy applies to the SiteReport website, web application and related services. SiteReport may process information both for its own business purposes and on behalf of organizations that use the service.
For customer workspace content, the customer organization generally determines what operational information is entered, who may access it and why it is processed. SiteReport provides the service and applies the customer’s authorized instructions subject to the product’s security and legal requirements.
2. Information we collect
Depending on how you interact with SiteReport, information may include account and profile details; workspace and project membership; contact details; authentication/session data; device, browser and diagnostic information; support communications; billing or transaction metadata when commercial billing is enabled; and cookie or preference choices.
Operational workspace content may include reports, field updates, comments, incidents, risks, actions, inspections, defects, permits, project locations, expenses, crew-hour records, asset/equipment information, materials, deliveries, documents, attachments, evidence metadata, client/partner interactions and audit events.
3. How we use information
Information may be used to provide and secure the service; authenticate users; enforce tenant, workspace and project permissions; operate reporting and approval workflows; provide support; diagnose errors; prevent abuse; maintain auditability; communicate service changes; administer plans and entitlements; and improve product reliability and usability.
Where applicable law requires a particular legal basis for processing, the final production policy will identify the relevant basis for the applicable jurisdiction and processing purpose.
4. Customer content and operational data
Customers and authorized users retain responsibility for deciding what lawful data they place into SiteReport and for ensuring they have the rights, notices and permissions required to process that information.
SiteReport is designed to keep workspace data tenant-scoped. Internal workspace data is not made public merely because a customer uses a client portal, partner portal or share link; external access must be explicitly scoped to the resources the customer chooses to share.
5. AI and external providers
AI-assisted features are designed to send only the authorized operational context needed for the requested task through an approved provider boundary. SiteReport validates structured outputs, preserves provenance where the workflow requires it and keeps human review or confirmation in the loop for material lifecycle decisions.
SiteReport-managed AI, customer-approved bring-your-own-provider configurations and future MCP clients must all remain subject to normal authentication, tenant authorization and data-minimization rules. Provider credentials must remain server-side.
Production provider names, retention terms, regional processing details and any model-training restrictions that SiteReport contractually commits to will be published before those configurations are generally available.
8. Retention and deletion
SiteReport keeps information only for as long as needed for the service, customer instructions, security, backup/recovery, dispute resolution and legal obligations. Different data classes may require different retention periods.
The final production retention schedule, customer deletion workflow, backup deletion lag and any legally required preservation periods must be documented before general availability. SiteReport will not imply that deletion is instantaneous where backups or legal obligations make that untrue.
9. Security
SiteReport uses server-side authorization, tenant/workspace scoping, short-lived access sessions with protected refresh handling, request validation, security headers, abuse controls, audit events and operational health checks as part of its security model.
No online service can guarantee absolute security. Users must protect their credentials, use individual accounts rather than shared logins and promptly report suspected unauthorized access.
SiteReport does not claim certifications or formal compliance attestations until they have actually been established.
10. International processing
SiteReport may rely on infrastructure or service providers that process information in more than one country. The final production hosting regions, transfer mechanisms and data-residency options will be documented once the production infrastructure and provider contracts are selected.
11. Privacy rights and choices
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent or review of certain processing. Requests concerning data controlled by an employer or customer organization may need to be directed to that organization first.
SiteReport will publish the production privacy contact and request process before general availability.
12. Children
SiteReport is intended for professional and organizational field operations, not for children. The production service is not intended for use by individuals under 18 unless a specific lawful organizational use case and appropriate safeguards are established.
13. Changes to this policy
SiteReport may update this policy as the product, law or processing practices change. Material changes should be communicated through an appropriate website, in-product or direct notice before they take effect where required.
14. Contact and launch particulars
Before general availability, this section must identify the SiteReport data-controller/service-provider legal entity, registered address, privacy contact and any required representative or data-protection contact.
Until those production particulars are finalized, questions can be raised through the SiteReport contact route used for product access.