Data processing terms
When you store your clients' details in SiteSums, you are the controller of that data and we process it for you. UK GDPR (Article 28) requires a written agreement setting out how. This is it. It forms part of the Terms of service for every account.
1. The roles
You (the account holder) are the controller of the personal data you put into SiteSums about your clients, their sites, the people you pay, and anyone else you record. Nikita-Jade Hancock ("SiteSums") is your processor. For your own account details, SiteSums is the controller, as described in the privacy policy.
2. What we process, and for how long
Subject matter: the business records you keep in SiteSums. Data subjects: your clients and their contacts; people you pay; anyone named in your documents. Categories: names, contact details, addresses, job descriptions, prices, payments, wage payments, and — for shared links — the fact a document was opened or approved, with the approver's typed name, time and IP address. Duration: for as long as your account is open, then deleted as set out in section 8.
3. Our obligations
- We process personal data only on your documented instructions — which are: providing the SiteSums service as you use it. We will tell you if we believe an instruction breaks data protection law.
- Everyone with access to your data is bound by confidentiality.
- We apply the technical and organisational measures in section 5.
- We help you meet requests from data subjects — the export and delete tools in the app do most of this instantly; anything else, email us and we will respond within 10 working days.
- We help you with security, breach notification and impact assessments where our processing is involved.
- At the end of the service we delete your data (section 8), unless the law requires us to keep it.
- We make available the information needed to show compliance, and allow audits on reasonable notice — by questionnaire in the first instance.
4. Sub-processors
You authorise us to use the sub-processors below. Each is bound by a written agreement imposing equivalent data protection obligations. We will give at least 30 days' notice by email before adding or replacing one; if you object on reasonable grounds and we cannot resolve it, you may terminate and export your data.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Supabase | Database, sign-in and file storage | London, UK (eu-west-2) | None — data at rest stays in the UK |
| Vercel Inc. | Application hosting | USA (global edge network) | UK Addendum to the EU Standard Contractual Clauses, via Vercel's DPA |
| Stripe | Card payments and subscriptions | USA / Ireland | UK Addendum via Stripe's DPA. Card numbers never reach SiteSums. |
| Resend | Sending email on your behalf | USA | UK Addendum via Resend's DPA |
| Shopify | Template shop orders (email and product only) | Canada / USA | UK Addendum via Shopify's DPA |
5. Security measures
- Isolation by the database. Row-level security policies enforced by the database itself mean an account can only read and write its own rows — this is not left to application code.
- Encryption in transit (TLS) and at rest, including backups.
- Least access. Files that should be private (receipts, template masters) are in private storage, readable only by the owning account. Logos and project cover images are public web addresses by design, because they appear on pages your clients open.
- Public links are unguessable. Document, portal and approval links carry 128-bit random tokens and can be regenerated by you at any time.
- No card data. Payments are handled by Stripe; card numbers never reach SiteSums.
- Monitoring. Errors are logged with the account affected, kept 90 days, and reviewed.
- Access control. Sign-in is by emailed link; there are no shared passwords to leak. Administrative access to production is limited to named individuals.
6. International transfers
Your data at rest is held in the UK. Some sub-processors operate from outside the UK; those transfers rely on the UK Addendum to the EU Standard Contractual Clauses contained in each provider's data processing agreement, as listed above.
7. Personal data breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and within 48 hours, with what we know: what happened, whose data, the likely consequences, and what we are doing about it. That gives you time to meet your own 72-hour duty to the ICO where it applies. We will not notify your data subjects or the ICO on your behalf unless you ask us to or the law requires it.
8. Deletion and return
You can export all your data at any time from Settings, and delete your account and everything in it yourself. When an account is closed — by you, or by us under the Terms — we delete its data immediately from live systems; encrypted backups age out within 30 days. We will keep only what the law requires us to keep, for only as long as it requires.
9. Your obligations
You confirm you have a lawful basis for the personal data you put into SiteSums — for most trades, the contract or enquiry with the client — and that you will tell your clients how their data is used where the law requires. You will not upload special category data (health, religion, and so on) unless a document genuinely needs it and you have the right to hold it.
10. General
These terms apply for as long as we process personal data for you, survive termination of the Terms of service to the extent needed, and are governed by the law of England and Wales. Where these terms and the Terms of service conflict on data protection, these terms prevail.