1. About this privacy notice
SiteBind is a construction project, drawing, document-control and issue-management platform operated by Ironmark Digital Ltd.
This privacy notice explains how Ironmark Digital Ltd collects, uses, stores and shares personal information in connection with:
- the SiteBind website and application;
- SiteBind user accounts;
- free accounts and trials;
- customer organisations and subscriptions;
- customer support and service communications;
- billing and payment administration;
- security, audit logging and service improvement; and
- customer projects, drawings, images, comments, markups, files and other uploaded content.
This notice should be read alongside SiteBind’s terms of service, acceptable-use requirements, cookie information and any data-processing agreement entered into between Ironmark Digital Ltd and a customer organisation.
2. Who we are
SiteBind is operated by:
Ironmark Digital Ltd Registered in England and Wales Company number: 17132407
Registered office:
167–169 Great Portland Street 5th Floor London W1W 5FP United Kingdom
Privacy enquiries and data-protection complaints should be sent to:
Ironmark Digital Ltd has not appointed a formal Data Protection Officer. Privacy matters are handled through the contact address above.
3. When Ironmark is a controller and when it is a processor
Our legal role depends on why information is being processed.
Ironmark as controller
Ironmark Digital Ltd is generally the controller where we decide why and how personal information is used for our own purposes, including:
- creating and administering SiteBind accounts;
- managing customer organisations, trials and subscriptions;
- processing billing and payment records;
- sending account, security and service communications;
- providing support;
- protecting SiteBind against fraud, misuse and unauthorised access;
- maintaining system and security logs;
- operating and improving the SiteBind service;
- complying with legal, tax and accounting obligations; and
- establishing, exercising or defending legal claims.
Ironmark as processor
Where a customer organisation uploads or creates project information in SiteBind, that customer will normally be the controller and Ironmark Digital Ltd will act as its processor.
This includes information contained in:
- drawings and drawing revisions;
- photographs and images;
- comments and file attachments;
- markups;
- issues and tasks;
- task assignments;
- project records;
- audit trails;
- approval and revision histories; and
- other files uploaded by a customer or its users.
In these circumstances, the customer organisation decides why the information is used, who may access it and how long it should be retained. Ironmark processes it to provide SiteBind and in accordance with the customer’s instructions, our agreement with the customer and applicable law.
Questions or rights requests relating to customer-controlled project information should normally be directed to the relevant customer organisation first. We will assist customer organisations with valid requests where required.
4. Who this notice applies to
This notice applies to:
- visitors to SiteBind;
- people who create a SiteBind account;
- customer administrators;
- customer employees and workers;
- sole traders;
- subcontractors;
- consultants;
- architects and designers;
- clients and client representatives;
- building and facilities managers;
- external guests;
- trial users;
- billing contacts; and
- people whose information appears in customer-uploaded content.
A customer organisation may invite internal users, viewers and external guests. Access to projects and information depends on the permissions assigned by the relevant organisation.
5. Information we collect
5.1 Account and profile information
We may collect:
- email address, which is also used as the username;
- first name;
- last name;
- job title;
- organisation;
- optional telephone number;
- account status;
- organisation memberships;
- user roles and permissions;
- invitation records;
- account creation and activation information;
- multi-factor authentication configuration;
- login history;
- failed login attempts; and
- password authentication information.
Passwords are stored in hashed form. We do not store readable copies of user passwords.
SiteBind does not currently provide profile-photo functionality.
5.2 Organisation and subscription information
We may collect:
- organisation name;
- organisation membership and administrator details;
- subscription plan;
- trial start and expiry information;
- usage and account limits;
- subscription status;
- failed-payment status;
- project and drawing allowances;
- account downgrade information; and
- records showing whether information has been placed into read-only storage because account limits have been exceeded.
Subscriptions may be arranged directly with Ironmark and may be bespoke to the customer.
New organisations may receive a 30-day trial. Free accounts may continue with the limits and functionality displayed by SiteBind.
5.3 Billing and payment information
We may collect:
- billing contact names;
- billing addresses;
- invoice details;
- purchase-order references;
- VAT and company information;
- subscription charges;
- payment status;
- failed-payment information;
- Stripe transaction references; and
- limited card information made available by Stripe, such as payment method type or partial card details.
Payment-card processing is provided by Stripe. Ironmark does not receive or store full payment-card numbers or card security codes.
Billing and accounting records may also be processed using QuickBooks.
5.4 Project and drawing information
Basic project information may include:
- project name;
- project number;
- site address;
- project status;
- project membership;
- drawing names and references;
- drawing revisions;
- issue and task information;
- assigned users;
- audit records;
- comments;
- markups;
- uploaded PDFs;
- photographs and images; and
- other file attachments.
SiteBind is intended for drawings, construction documentation, project information, markups and related project-management records.
Because customers control uploaded PDFs and images, those files may incidentally contain personal information, including names, signatures, identifiable people, apartment or property details, access information or information embedded within an image.
SiteBind does not currently remove EXIF or other embedded metadata from uploaded photographs or images.
5.5 Information that must not be uploaded
SiteBind is not intended for storing:
- CCTV recordings or CCTV still images;
- identity documents;
- passports or driving licences;
- DBS information;
- personnel files;
- medical records;
- detailed accident or injury records containing health information;
- biometric information;
- criminal-offence information;
- disciplinary records;
- information about racial or ethnic origin;
- religious or philosophical beliefs;
- trade-union membership;
- sexual orientation or sex-life information; or
- other unnecessary special-category or highly sensitive personal information.
Customers and users must not upload this information unless Ironmark has expressly agreed to the proposed use in writing and the customer has established all necessary lawful bases, conditions, notices and safeguards.
SiteBind does not routinely inspect, classify or automatically detect sensitive information within customer-uploaded PDFs or images. Customers remain responsible for reviewing files before upload and ensuring that their use of SiteBind is lawful.
5.6 Technical, usage and security information
We may collect:
- IP address;
- approximate country, region or city derived from an IP address;
- browser type and version;
- operating system;
- device type;
- login date and time;
- session information;
- authentication events;
- multi-factor authentication events;
- pages or features accessed;
- actions taken within projects;
- files viewed, uploaded, changed or exported;
- audit events;
- error and crash information;
- server logs;
- suspected fraud, spam or abuse indicators;
- referring pages;
- first-party identifiers; and
- cookie or local-storage information.
Approximate IP-derived location is used for security, fraud prevention, spam prevention and identifying suspicious activity. SiteBind does not collect precise GPS location and does not currently require location permission for its intended features.
5.7 Communications and support information
When someone contacts us, we may collect:
- their name and contact details;
- their organisation;
- the content of their enquiry;
- correspondence history;
- technical diagnostic information;
- information needed to investigate a problem; and
- any attachments they choose to send.
Users should avoid sending customer project files or personal information unless it is necessary for us to investigate the issue.
6. How we obtain information
We obtain information:
- directly from users when they register, use SiteBind or contact us;
- from customer organisations and administrators who invite users or manage their accounts;
- automatically through SiteBind, server logs, cookies and similar technologies;
- from uploaded files, drawings, photographs and project records;
- from Stripe in connection with payments;
- from QuickBooks in connection with invoicing and accounting;
- from security and fraud-prevention processes; and
- from integrations enabled by a customer organisation.
Where a customer organisation gives us a person’s information, including by inviting them to SiteBind, the customer is responsible for ensuring that it is entitled to do so.
7. Why we use information and our lawful bases
Providing SiteBind and administering accounts
We use account, organisation, project and subscription information to:
- create accounts;
- authenticate users;
- provide the service;
- administer organisations;
- apply roles and permissions;
- operate trials and subscriptions;
- provide exports and audit histories; and
- preserve project data in accordance with the applicable plan.
We rely on:
- performance of a contract or steps requested before entering a contract, particularly for sole traders and direct account holders; and
- our legitimate interests in providing SiteBind to business customers and their authorised users.
Processing customer project information
Where we process customer-controlled project information as a processor, we do so under the documented instructions of the relevant customer organisation.
The customer organisation is responsible for identifying its own lawful basis and, where applicable, any additional condition required for special-category or criminal-offence information.
Billing, payment and accounting
We process billing and payment information to:
- issue invoices;
- collect payment;
- administer subscriptions;
- manage failed payments;
- maintain financial records;
- prevent payment fraud; and
- comply with tax and accounting obligations.
We rely on:
- performance of a contract;
- compliance with legal obligations; and
- our legitimate interests in managing payments, debts and commercial records.
Security, fraud prevention and audit trails
We process technical, device, IP, login, permission and audit information to:
- secure accounts;
- detect unauthorised access;
- identify spam and abuse;
- investigate suspicious activity;
- preserve the integrity of project records;
- provide audit histories;
- diagnose faults; and
- protect SiteBind, Ironmark, customers and users.
We rely on our legitimate interests in operating a secure, reliable and auditable business service and, where applicable, compliance with legal obligations.
Support and service communications
We use contact, account and diagnostic information to:
- respond to enquiries;
- investigate technical problems;
- provide account and security notices;
- communicate changes to the service;
- warn users about incidents or disruption; and
- provide information required for the operation of an account.
We rely on performance of a contract and our legitimate interests in supporting and administering SiteBind.
Essential operational and security communications are not marketing messages and cannot always be opted out of while an account remains active.
Service analysis and improvement
We may use usage, performance, error and technical information to:
- understand how SiteBind is used;
- diagnose faults;
- improve reliability;
- develop new features;
- assess demand and capacity; and
- produce aggregate or anonymous statistics.
We rely on our legitimate interests in maintaining and improving SiteBind. Where cookies or similar technologies require consent under applicable electronic-communications law, we will request consent before using them.
Where we rely on an exception for statistical analytics, the technology will be limited to statistical service-improvement purposes and users will be provided with information and a simple way to object.
Trial follow-up and product information
We may contact a person who has requested or used a SiteBind trial to ask about their experience or discuss continuing the service.
Where a communication amounts to direct marketing, we will only send it where permitted by applicable law. Relevant messages will provide a clear way to opt out.
We do not automatically share SiteBind contact details with other Ironmark products for marketing.
Legal compliance and claims
We may use relevant information to:
- comply with legal and regulatory obligations;
- respond to lawful requests from courts, regulators or public authorities;
- establish, exercise or defend legal claims;
- enforce our agreements;
- investigate misuse; and
- protect the rights, property or safety of Ironmark, our customers, users or others.
We rely on legal obligations and our legitimate interests in protecting our business and legal rights.
8. Our legitimate interests
Where we rely on legitimate interests, those interests include:
- providing a business software service requested by a customer organisation;
- administering customer organisations and authorised users;
- maintaining accurate drawing, project and audit histories;
- securing accounts and systems;
- preventing fraud, abuse and unauthorised access;
- diagnosing technical faults;
- improving SiteBind;
- recovering debts;
- protecting legal rights; and
- communicating with business customers about their service.
We consider whether the processing is necessary and balance these interests against the rights and reasonable expectations of affected individuals.
9. Cookies and similar technologies
SiteBind uses cookies, local storage and similar technologies.
Strictly necessary technologies
Strictly necessary technologies may be used for:
- user login;
- session management;
- account security;
- multi-factor authentication;
- load balancing;
- fraud prevention;
- preserving user-requested settings; and
- providing features requested by the user.
These technologies are required for the logged-in service to operate and do not require consent where the applicable legal exception is satisfied.
Analytics and Ironmark Insights
With your consent, SiteBind uses the self-hosted Ironmark Insights system to understand use of the website and application, diagnose problems and improve the service.
Depending on its configuration, this may involve first-party cookies, local storage, IP information, device or browser information, unique identifiers and interaction data.
We will only use analytics without consent where the applicable statistical or other legal exception is fully satisfied. This requires, among other things, that the technology is used for the permitted purpose, appropriate information is provided and users have a simple and free way to object.
Optional analytics is not activated until the user accepts it through SiteBind's cookie controls. The choice is stored in the browser's local storage and can be changed at any time using the Cookie settings control.
Being logged in does not, by itself, amount to consent to non-essential cookies or tracking technologies.
SiteBind does not use this information for third-party advertising and does not share SiteBind analytics data with Ironmark’s other products for their marketing.
Further details, including the technologies used, their purposes and their duration, are provided through SiteBind’s cookie information and cookie controls.
10. Who can access customer information
Customer information may be accessible to:
- administrators of the relevant customer organisation;
- users and viewers within that organisation;
- external guests invited by that organisation;
- people given access to a specific project, drawing, issue or task;
- authorised Ironmark personnel where access is necessary for support, security or administration; and
- service providers acting on our behalf.
Customer administrators control organisation membership, permissions and project access. They may be able to view user activity, project contributions, audit histories, task assignments, comments and files associated with their organisation.
Removing a user account from an organisation does not necessarily remove that user’s previous project contributions, comments, markups, assignments or audit records. These records may remain under the control of the customer organisation to preserve the integrity of its project and audit history.
11. Service providers and recipients
We may provide personal information to the following service providers where necessary:
OVHcloud
OVHcloud provides:
- UK-based virtual private servers;
- database infrastructure;
- object storage;
- backups;
- domain registration;
- DNS; and
- related infrastructure services.
SiteBind’s primary application, database and customer file-storage infrastructure is hosted in the United Kingdom.
Zoho
Zoho is used for email delivery and related communication services. Email addresses, names, message content and delivery information may be processed through Zoho.
Stripe
Stripe processes payments and may process:
- customer and billing contact information;
- payment method information;
- transaction information;
- fraud-prevention information; and
- payment status.
Stripe may act as our processor for some activities and as an independent controller for activities it determines itself, such as meeting its own legal obligations and preventing payment fraud.
QuickBooks and Intuit
QuickBooks is used for invoicing and accounting. Billing contact information, invoice details, payment status and financial records may be processed through QuickBooks and Intuit.
Customer-selected integrations
Where an organisation enables an integration, relevant information may be exchanged with the selected integration provider.
The customer administrator is responsible for deciding whether to enable an integration and for ensuring that the integration is appropriate for the organisation’s use.
Other disclosures
We may also disclose information to:
- professional advisers;
- accountants;
- auditors;
- insurers;
- legal representatives;
- debt-recovery providers;
- courts;
- regulators;
- law-enforcement bodies;
- other public authorities; or
- a purchaser, investor or successor in connection with a proposed or completed sale, merger, restructuring or transfer of SiteBind or Ironmark.
We do not sell personal information.
12. International transfers
SiteBind’s primary application servers, database and OVH object storage are located in the United Kingdom.
Some providers, including Zoho, Stripe and Intuit, operate internationally and may process information outside the United Kingdom or permit access from other countries.
Where a transfer is subject to the UK’s international-transfer restrictions, we use an applicable legal safeguard. Depending on the circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved standard contractual clauses; or
- another safeguard permitted by UK data-protection law.
Further information about safeguards relevant to a particular provider may be requested from privacy@ironmarkdigital.co.uk.
13. Data retention
We retain personal information only for as long as reasonably necessary for the relevant purpose, taking account of:
- the customer’s instructions;
- whether an organisation or account remains active;
- the need to provide access to project and revision history;
- contractual obligations;
- audit and security requirements;
- legal and accounting obligations;
- limitation periods for legal claims; and
- the need to investigate fraud, abuse or security incidents.
Customer project information
Customer-controlled project information is retained while required by the customer organisation, including where project data is retained in read-only form after an account exceeds free-plan limits or is downgraded.
An authorised customer administrator may request deletion of the organisation’s project information.
Following a verified deletion request, the relevant information will be removed from active SiteBind systems promptly, subject to:
- information that Ironmark must retain by law;
- information required to establish, exercise or defend legal claims;
- records required to document the deletion or honour an opt-out; and
- temporary residual copies held within rotating backups.
Accounts
Account information is retained while the account is active or associated with a customer organisation.
Where an account is removed, some information may be retained where necessary to:
- preserve customer project and audit histories;
- prevent fraud or repeated abuse;
- resolve disputes;
- comply with legal obligations; or
- establish or defend legal claims.
Billing and accounting records
Invoices, transaction records and associated billing information are generally retained for at least six years from the end of the relevant company financial year, or longer where required by law, an ongoing enquiry or a legal claim.
Security and audit records
Login, security, permission and audit information is retained for as long as reasonably necessary to:
- protect SiteBind;
- investigate suspicious activity;
- provide project audit histories;
- resolve disputes; and
- establish or defend legal claims.
Project audit records may be retained for the same period as the associated project.
Support records
Support correspondence is retained for as long as needed to resolve the issue and thereafter where reasonably necessary to document the support provided, identify recurring faults or manage legal claims.
Analytics
Identifiable analytics and technical information is retained only for the period needed for security, diagnosis or service improvement.
Aggregate or effectively anonymous statistics that no longer identify an individual may be retained for longer.
Backups
Deleted information may remain temporarily in protected backup copies until those backups are overwritten through the ordinary backup-rotation process.
Backup information is not used for routine business purposes. If a backup containing previously deleted information must be restored for disaster recovery, relevant deletion controls will be reapplied where reasonably practicable.
14. Security
We use technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.
These measures include, as appropriate:
- encryption in transit;
- password hashing;
- optional multi-factor authentication;
- role-based access controls;
- organisation and project permissions;
- audit logging;
- separation of application, database and object-storage infrastructure;
- UK-based primary infrastructure;
- restricted administrative access;
- hardware security keys for administrative access;
- separation of production information from development environments;
- backups;
- security monitoring; and
- incident-response procedures.
Access to customer information by Ironmark personnel is restricted to circumstances where it is required for support, security, maintenance, legal compliance or service administration.
No internet-connected service can guarantee absolute security. Customers are responsible for using appropriate passwords, protecting authentication methods, managing user permissions and promptly removing users who should no longer have access.
Where Ironmark becomes aware of a personal-data breach affecting information we process for a customer, we will notify the relevant customer without undue delay. Where Ironmark is the controller, we will make any legally required notifications to the Information Commissioner’s Office and affected individuals.
15. Required and optional information
Certain information is required to create an account, authenticate a user, associate the user with an organisation or provide SiteBind.
Where required information is not provided, we may be unable to:
- create or maintain the account;
- authenticate the user;
- provide access to an organisation or project;
- process a subscription or payment;
- respond to a support request; or
- provide the requested service.
Information identified as optional, such as a telephone number, does not have to be provided.
16. Automated processing
SiteBind may use automated security controls to identify suspicious login attempts, spam, abuse or other activity that may threaten the service.
We do not currently use personal information to make solely automated decisions that produce legal effects or similarly significant effects on individuals.
17. Children
SiteBind is a professional construction and business service and is not directed at children.
We do not set a general minimum age for every invited user because customer organisations may have legitimate reasons to provide supervised access to apprentices or other younger workers.
Customer organisations that invite or authorise a user under 18 are responsible for ensuring that:
- access is appropriate;
- the user is properly authorised and supervised;
- only necessary information is entered;
- appropriate privacy information is provided; and
- the organisation complies with applicable employment, safeguarding and data-protection obligations.
Children should not independently create a customer organisation, purchase a subscription or upload personal information without appropriate organisational authority.
18. Your data-protection rights
Depending on the circumstances and the lawful basis used, you may have the right to:
- be informed about how your information is used;
- request access to your personal information;
- request correction of inaccurate information;
- request completion of incomplete information;
- request deletion of your information;
- request restriction of processing;
- receive certain information in a portable format;
- object to processing based on legitimate interests;
- object to direct marketing;
- withdraw consent where processing is based on consent; and
- complain about how your information has been handled.
These rights are not absolute and may be subject to legal exemptions.
To exercise a right relating to information controlled directly by Ironmark, contact:
We may need to verify your identity before acting on a request.
Where the request concerns project information controlled by a customer organisation, you should normally contact that organisation. We will assist the organisation where required by our contractual and legal obligations.
Your right to object
You have the right to object to processing based on our legitimate interests. You also have an absolute right to object to the use of your personal information for direct marketing.
Objections may be sent to privacy@ironmarkdigital.co.uk.
Where we have sent a marketing communication, any unsubscribe or opt-out method included in that communication may also be used.
19. Data-protection complaints
A complaint about how Ironmark has handled personal information may be sent to:
Please include enough information for us to understand:
- what has happened;
- which account, organisation or project is involved;
- which information is affected; and
- the outcome you are seeking.
We will acknowledge a data-protection complaint within 30 days, investigate it appropriately and communicate the outcome without undue delay.
Where the complaint concerns customer-controlled project information, we may need to refer the matter to or work with the relevant customer organisation.
You also have the right to complain to the UK supervisory authority:
Information Commissioner’s Office Wycliffe House Water Lane Wilmslow Cheshire SK9 5AF United Kingdom
Telephone: 0303 123 1113
We ask that you contact us first where possible so that we have an opportunity to investigate and resolve the issue.
20. Changes to this privacy notice
We may update this notice to reflect:
- changes to SiteBind;
- new service providers or integrations;
- changes in how information is processed;
- changes in legal requirements; or
- changes to our security and retention arrangements.
The latest version will be made available through SiteBind.
Where a change materially affects how existing personal information is used, we will take reasonable steps to bring the change to the attention of affected users or customer organisations before the new use begins.
21. Contact
Questions about this notice or Ironmark’s handling of personal information should be sent to:
Ironmark Digital Ltd 167–169 Great Portland Street 5th Floor London W1W 5FP United Kingdom