Data processing agreement
How SiteNext handles the personal data your organization records in its workspace, on your behalf and on your instructions.
Last updated: 9 October 2026
1. Parties and purpose
This agreement is concluded between the organization that subscribes to SiteNext (“you”, the controller) and Sagar Luniya, Entrepreneur individuel (EI) (RCS Rennes 844 903 443), 4 place de Bretagne, 35000 Rennes, France (“we”, the processor). It forms part of the terms of service and applies for as long as we process personal data for you. It is the contract required by article 28 of the General Data Protection Regulation (GDPR).
It covers the personal data that you and your team record in your workspace. The data we handle for our own purposes — your account, billing, support — is described in the privacy policy.
2. Your instructions
We process the personal data of your workspace only to provide the service, on your documented instructions: these terms, this agreement, and the settings and actions you and your team choose in the application. We do not use it for any purpose of our own, and we do not sell it. If the law requires us to process it otherwise, we tell you first unless that law forbids it.
If we believe one of your instructions breaks data protection law, we tell you without delay.
3. Your responsibilities
You decide what is recorded in your workspace and why. You make sure you may record it: a legal basis, clear information given to the people concerned, the consultation of employee representatives and an impact assessment where the law asks for them.
This matters most for the attendance options. Position at clock-in, positions during the shift and photos are off unless you switch them on. Before you do, check the law that applies to you. In France, the data protection authority (CNIL) considers that:
- the position of employees may serve to check working time only when no other means exists, and never to follow an employee permanently;
- a photo at every clock-in is excessive unless a particular reason justifies it;
- positions should not be kept for more than two months as a rule, which is why the retention period is 60 days by default.
4. Confidentiality
The people who act for us and can reach your data are bound by confidentiality, and reach it only when support, maintenance or security requires it.
5. Security
We apply the technical and organizational measures of annex 2 and keep them at least at that level. If a personal data breach affects your workspace, we tell you without undue delay, and within 72 hours of becoming aware of it at the latest, with what we know: what happened, the data and people concerned, the likely consequences and what we are doing about it. We then help you meet your own obligations towards the authority and the people concerned.
6. Sub-processors
You authorize us to use the sub-processors of annex 3. Each is bound by a contract that gives your data protection at least equal to this agreement, and we remain responsible to you for what they do.
Before adding or replacing a sub-processor, we update this page and tell the owners of your organization by email at least 30 days in advance. If you object on data protection grounds and we cannot offer an alternative, you may end the subscription, and we refund the part of the period already paid that remains.
7. Transfers outside the European Union
Your workspace is hosted in the European Union. Personal data leaves it only through the sub-processors of annex 3 that operate elsewhere, under the European Commission’s standard contractual clauses or the provider’s certification under the EU–US Data Privacy Framework.
8. Helping you answer people and authorities
The application lets you find, correct, export and delete most of what your workspace holds. Where it does not, we help you answer a request from a person exercising their rights — access, correction, erasure, restriction, portability, objection — within the time the law gives you. If such a request reaches us directly, we pass it on to you and do not answer it ourselves.
We also give you the information we hold that you need for an impact assessment, a consultation of the authority, or to show that your use of the service meets the law.
9. At the end of the subscription
When the subscription ends, your workspace is locked and kept for 90 days. During that time you can resubscribe, which gives everything back as it was, or ask us to return the personal data of your workspace — as the exports of the application — or to delete it sooner: we do so, and delete the remaining copies, within 30 days of your request.
Without an instruction from you, the workspace is deleted at the end of those 90 days, and never without warning. The people who manage billing for your organization receive an email on the day the subscription ends, with the date of the deletion, then a reminder 30 days and another 7 days before that date. Nothing is deleted until both reminders have been sent; if one leaves late, the deletion is pushed back so that the notice it gives stays whole. We keep only what the law requires us to keep, such as invoices.
10. Showing that we comply
We give you the information needed to show that we meet this agreement and answer reasonable written questions about it. You may also have an audit carried out, by yourself or by an independent auditor bound by confidentiality, once a year and with 30 days’ written notice. It takes place during working hours, at your cost, and without access to the data of other customers.
11. Liability and precedence
The liability clause of the terms of service applies to this agreement. If the two texts disagree on the protection of personal data, this agreement prevails. French law governs it, as it does the terms.
If your organization needs a signed copy of this agreement, write to hello@sitenext.io.
Annex 1 — The processing
- Subject and purpose
- Providing SiteNext: hosting, displaying and processing what your team records to manage projects, site diaries, tasks, RFIs, attendance, conversations, photos and reports.
- Duration
- The subscription, then the period of section 9.
- People concerned
- Your employees and other team members, the workers of your subcontractors, your clients’ contacts, and anyone named or pictured in what your team records.
- Personal data
- Name, email address, phone number, role and trade; hours worked, breaks and absences; messages, voice notes and their transcripts; photos and documents; and, if you switch these options on, the position of the phone and a photo at clock-in and clock-out, and positions during the shift.
- Sensitive data
- None is required. An absence can be recorded as sick leave; do not record medical details.
Annex 2 — Security measures
- Hosting with OVH SAS, in Germany (European Union).
- Encrypted connections (HTTPS) between your devices and the service.
- Passwords stored as a hash, a minimum length, a check against passwords known from breaches, and two-factor authentication available to every account.
- Sign-in attempts limited and locked after repeated failures; sessions that expire; the password asked again before sensitive actions such as deleting a project, changing a role or exporting payroll.
- Access inside a workspace limited by each person’s role and projects, checked on the server for every request, and separated between organizations.
- A log of sensitive actions, with who did what and when.
- Uploaded files checked for their real type; images re-encoded, which removes their hidden data such as the place a photo was taken.
- A database that cannot be reached from the internet, used by the application through an account limited to its own tables.
- Protections against injected scripts and requests forged from another site, and monitoring of the software we depend on for known vulnerabilities.
- Positions and attendance photos deleted automatically after the retention period you set.
Annex 3 — Sub-processors
- OVH SAS
- Hosting of the application, its database and the files of your workspace. Germany (European Union).
- OpenAI
- Only when someone uses one of these features: scanning a paper form into a template, importing a project from files, transcribing a voice note, filling a diary entry from a spoken report. It receives the file, the recording or the transcript concerned. United States.
- Namecheap (Private Email)
- Sending the emails of the service: invitations, reminders and notifications, which can quote a name, a project or a task. United States.
- Browser notification services
- Google, Mozilla, Apple or Microsoft, depending on the browser, and only for the people who turn on push notifications. The notification travels encrypted for their device. United States.
Other providers take part in the service without receiving the personal data of your workspace: maps, weather, company logos and company search receive site addresses, coordinates or company names, and the mobile app receives its updates from Expo. They are listed in the privacy policy, with the providers we use for our own account, billing and support data.