← Back to Home

Privacy Policy

Last updated: 5 August 2026

1. Data Controller

Site Flow, operated by Other World Media Ltd (“we”, “us”, “our”), is the data controller for personal data processed through this platform. We are committed to protecting your privacy in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Registered office: 48 West George Street, Glasgow, G2 1BP. ICO registration: ICO:00014390343. You can reach us about privacy at privacy@siteflow.app.

2. Personal Data We Collect

  • Account information: name, email address, phone number, password (hashed)
  • Organisation data: organisation name, building addresses
  • Usage data: jobs created, comments, assigned tasks, login timestamps
  • Technical data: IP address, browser type, push notification subscriptions

3. Legal Basis for Processing

  • Contract performance: Processing necessary to provide the facilities management service you signed up for
  • Legitimate interests: Platform security, fraud prevention, service improvement
  • Consent: Push notifications, optional analytics cookies
  • Legal obligation: Record-keeping required by law

4. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, we anonymise personal data rather than deleting records to preserve audit trail integrity. Anonymised data is retained indefinitely as it can no longer identify you.

5. Your Rights

Under UK GDPR, you have the following rights:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate personal data via your profile settings
  • Right to erasure: Request deletion of your account (we anonymise data to preserve system integrity)
  • Right to data portability: Download your data in a machine-readable format (JSON)
  • Right to restrict processing: Request limitation of processing in certain circumstances
  • Right to object: Object to processing based on legitimate interests

To exercise any of these rights, visit your Profile page where you can download your data or delete your account.

6. Cookies

We use the following types of cookies:

  • Essential cookies: Session authentication, CSRF protection, and preferences (theme, sidebar state). These are necessary for the platform to function.
  • Functional cookies: Remember your settings and preferences across sessions.

We do not use third-party advertising or tracking cookies.

7. Data Sharing & Sub-processors

We do not sell your personal data. We may share data with your organisation's administrators who manage user accounts, and with law enforcement where required by law. We also use the following third-party sub-processors to provide the service. Each is bound by a data processing agreement (DPA) and processes data only on our instructions:

Sub-processorPurposeLocation
RailwayApplication hosting, PostgreSQL database and Redis (cache / rate-limiting / realtime)US / EU region — configurable
Cloudflare (R2 & CDN)File and document (attachment) storage and CDN deliveryCloudflare, Inc. — region-configurable
ResendTransactional email (verification, password reset, notifications)United States
StripeSubscription billing and payment processingUnited States / EU
SentryError monitoring and diagnosticsUnited States
Xero (only if you connect it)Accounting / invoice synchronisationNew Zealand / international
Google (only if you connect it)Calendar synchronisation and optional Google sign-inUnited States

This list is current as of the date above and may change as the service evolves; an up-to-date register is available on request.

8. International Data Transfers

Some of our sub-processors are located outside the United Kingdom. Where personal data is transferred outside the UK, we ensure an appropriate safeguard is in place — namely the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, and/or reliance on a UK adequacy decision where one applies to the destination country. You can request details of the safeguards applying to a specific transfer using the contact details below.

9. Data Security

We implement appropriate technical and organisational measures including password hashing, HTTPS encryption, encryption of sensitive tokens at rest, role-based access controls, and audit logging.

10. Contact & Complaints

For privacy-related enquiries, contact us at privacy@siteflow.app.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.