S SiteSums
PrivacyTermsData processingCookiesSecurity

Data processing terms

When you store your clients' details in SiteSums, you are the controller of that data and we process it for you. UK GDPR (Article 28) requires a written agreement setting out how. This is it. It forms part of the Terms of service for every account.

Last updated 16 September 2026 · SiteSums is operated by Nikita-Jade Hancock, 124 City Road, London EC1V 2NX. Questions: privacy@sitesums.co.uk

1. The roles

You (the account holder) are the controller of the personal data you put into SiteSums about your clients, their sites, the people you pay, and anyone else you record. Nikita-Jade Hancock ("SiteSums") is your processor. For your own account details, SiteSums is the controller, as described in the privacy policy.

2. What we process, and for how long

Subject matter: the business records you keep in SiteSums. Data subjects: your clients and their contacts; people you pay; anyone named in your documents. Categories: names, contact details, addresses, job descriptions, prices, payments, wage payments, and — for shared links — the fact a document was opened or approved, with the approver's typed name, time and IP address. Duration: for as long as your account is open, then deleted as set out in section 8.

3. Our obligations

  • We process personal data only on your documented instructions — which are: providing the SiteSums service as you use it. We will tell you if we believe an instruction breaks data protection law.
  • Everyone with access to your data is bound by confidentiality.
  • We apply the technical and organisational measures in section 5.
  • We help you meet requests from data subjects — the export and delete tools in the app do most of this instantly; anything else, email us and we will respond within 10 working days.
  • We help you with security, breach notification and impact assessments where our processing is involved.
  • At the end of the service we delete your data (section 8), unless the law requires us to keep it.
  • We make available the information needed to show compliance, and allow audits on reasonable notice — by questionnaire in the first instance.

4. Sub-processors

You authorise us to use the sub-processors below. Each is bound by a written agreement imposing equivalent data protection obligations. We will give at least 30 days' notice by email before adding or replacing one; if you object on reasonable grounds and we cannot resolve it, you may terminate and export your data.

Sub-processorPurposeLocationTransfer safeguard
SupabaseDatabase, sign-in and file storageLondon, UK (eu-west-2)None — data at rest stays in the UK
Vercel Inc.Application hostingUSA (global edge network)UK Addendum to the EU Standard Contractual Clauses, via Vercel's DPA
StripeCard payments and subscriptionsUSA / IrelandUK Addendum via Stripe's DPA. Card numbers never reach SiteSums.
ResendSending email on your behalfUSAUK Addendum via Resend's DPA
ShopifyTemplate shop orders (email and product only)Canada / USAUK Addendum via Shopify's DPA

5. Security measures

  • Isolation by the database. Row-level security policies enforced by the database itself mean an account can only read and write its own rows — this is not left to application code.
  • Encryption in transit (TLS) and at rest, including backups.
  • Least access. Files that should be private (receipts, template masters) are in private storage, readable only by the owning account. Logos and project cover images are public web addresses by design, because they appear on pages your clients open.
  • Public links are unguessable. Document, portal and approval links carry 128-bit random tokens and can be regenerated by you at any time.
  • No card data. Payments are handled by Stripe; card numbers never reach SiteSums.
  • Monitoring. Errors are logged with the account affected, kept 90 days, and reviewed.
  • Access control. Sign-in is by emailed link; there are no shared passwords to leak. Administrative access to production is limited to named individuals.

6. International transfers

Your data at rest is held in the UK. Some sub-processors operate from outside the UK; those transfers rely on the UK Addendum to the EU Standard Contractual Clauses contained in each provider's data processing agreement, as listed above.

7. Personal data breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay and within 48 hours, with what we know: what happened, whose data, the likely consequences, and what we are doing about it. That gives you time to meet your own 72-hour duty to the ICO where it applies. We will not notify your data subjects or the ICO on your behalf unless you ask us to or the law requires it.

8. Deletion and return

You can export all your data at any time from Settings, and delete your account and everything in it yourself. When an account is closed — by you, or by us under the Terms — we delete its data immediately from live systems; encrypted backups age out within 30 days. We will keep only what the law requires us to keep, for only as long as it requires.

9. Your obligations

You confirm you have a lawful basis for the personal data you put into SiteSums — for most trades, the contract or enquiry with the client — and that you will tell your clients how their data is used where the law requires. You will not upload special category data (health, religion, and so on) unless a document genuinely needs it and you have the right to hold it.

10. General

These terms apply for as long as we process personal data for you, survive termination of the Terms of service to the extent needed, and are governed by the law of England and Wales. Where these terms and the Terms of service conflict on data protection, these terms prevail.

Nikita-Jade Hancock, 124 City Road, London EC1V 2NX · ICO ZC244828 · privacy@sitesums.co.uk

© 2026 SiteSumsPrivacy · Terms · Data processing · Cookies · Security · Contact