Skip to content
Pre-launch legal draft

Privacy Policy

Privacy should stay connected to the operational context.

This policy explains the personal information and customer operational data SiteReport may process, why it is processed, how browser storage and AI provider boundaries work, and the choices available to users.

Last updated: September 27, 2026

This is a substantive pre-launch draft for product and website readiness. Before general availability, SiteReport must insert the final contracting/controller entity, legal contact, governing law/forum and any production-specific data-processing particulars. Those items are intentionally not invented here.

1. Scope and roles

This Privacy Policy applies to the SiteReport website, web application and related services. SiteReport may process information both for its own business purposes and on behalf of organizations that use the service.

For customer workspace content, the customer organization generally determines what operational information is entered, who may access it and why it is processed. SiteReport provides the service and applies the customer’s authorized instructions subject to the product’s security and legal requirements.

2. Information we collect

Depending on how you interact with SiteReport, information may include account and profile details; workspace and project membership; contact details; authentication/session data; device, browser and diagnostic information; support communications; billing or transaction metadata when commercial billing is enabled; and cookie or preference choices.

Operational workspace content may include reports, field updates, comments, incidents, risks, actions, inspections, defects, permits, project locations, expenses, crew-hour records, asset/equipment information, materials, deliveries, documents, attachments, evidence metadata, client/partner interactions and audit events.

3. How we use information

Information may be used to provide and secure the service; authenticate users; enforce tenant, workspace and project permissions; operate reporting and approval workflows; provide support; diagnose errors; prevent abuse; maintain auditability; communicate service changes; administer plans and entitlements; and improve product reliability and usability.

Where applicable law requires a particular legal basis for processing, the final production policy will identify the relevant basis for the applicable jurisdiction and processing purpose.

4. Customer content and operational data

Customers and authorized users retain responsibility for deciding what lawful data they place into SiteReport and for ensuring they have the rights, notices and permissions required to process that information.

SiteReport is designed to keep workspace data tenant-scoped. Internal workspace data is not made public merely because a customer uses a client portal, partner portal or share link; external access must be explicitly scoped to the resources the customer chooses to share.

5. AI and external providers

AI-assisted features are designed to send only the authorized operational context needed for the requested task through an approved provider boundary. SiteReport validates structured outputs, preserves provenance where the workflow requires it and keeps human review or confirmation in the loop for material lifecycle decisions.

SiteReport-managed AI, customer-approved bring-your-own-provider configurations and future MCP clients must all remain subject to normal authentication, tenant authorization and data-minimization rules. Provider credentials must remain server-side.

Production provider names, retention terms, regional processing details and any model-training restrictions that SiteReport contractually commits to will be published before those configurations are generally available.

6. How information is shared

Information may be shared with service providers that help operate SiteReport, with an organization’s authorized administrators and users, with client or partner users when the customer explicitly shares resources, when required by law or valid legal process, or as part of a business transaction subject to appropriate safeguards.

SiteReport is not designed around selling customer operational data to advertisers.

7. Cookies and browser storage

SiteReport may use essential cookies or browser storage for authentication/session security, preferences, localization and remembering cookie choices. The current public site does not need optional advertising storage to function.

Optional analytics or marketing storage must remain disabled unless it is deliberately configured and, where required, the user has consented.

8. Retention and deletion

SiteReport keeps information only for as long as needed for the service, customer instructions, security, backup/recovery, dispute resolution and legal obligations. Different data classes may require different retention periods.

The final production retention schedule, customer deletion workflow, backup deletion lag and any legally required preservation periods must be documented before general availability. SiteReport will not imply that deletion is instantaneous where backups or legal obligations make that untrue.

9. Security

SiteReport uses server-side authorization, tenant/workspace scoping, short-lived access sessions with protected refresh handling, request validation, security headers, abuse controls, audit events and operational health checks as part of its security model.

No online service can guarantee absolute security. Users must protect their credentials, use individual accounts rather than shared logins and promptly report suspected unauthorized access.

SiteReport does not claim certifications or formal compliance attestations until they have actually been established.

10. International processing

SiteReport may rely on infrastructure or service providers that process information in more than one country. The final production hosting regions, transfer mechanisms and data-residency options will be documented once the production infrastructure and provider contracts are selected.

11. Privacy rights and choices

Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent or review of certain processing. Requests concerning data controlled by an employer or customer organization may need to be directed to that organization first.

SiteReport will publish the production privacy contact and request process before general availability.

12. Children

SiteReport is intended for professional and organizational field operations, not for children. The production service is not intended for use by individuals under 18 unless a specific lawful organizational use case and appropriate safeguards are established.

13. Changes to this policy

SiteReport may update this policy as the product, law or processing practices change. Material changes should be communicated through an appropriate website, in-product or direct notice before they take effect where required.

14. Contact and launch particulars

Before general availability, this section must identify the SiteReport data-controller/service-provider legal entity, registered address, privacy contact and any required representative or data-protection contact.

Until those production particulars are finalized, questions can be raised through the SiteReport contact route used for product access.

Related SiteReport documents

Review security posture and the companion legal page.