S+

Privacy Policy

SiteGuardPlus — GDPR Compliance

Privacy Policy

Last updated: 27 July 2026

1. Who we are

SiteGuardPlus is a construction site intelligence platform that manages worker access, safety inductions, and site logistics. We are the data controller for the personal data processed through this platform. For any privacy enquiry, contact your site manager or use the Contact page.

2. Data we collect

To operate site access control and safety compliance, we collect:

  • Identity: Name, email, phone number.
  • Employment: Company, trade, CSCS/ECS card number and expiry.
  • Emergency contact: Name and phone number of a nominated contact.
  • Biometric data: A facial photograph used for face-recognition access control (special category data under GDPR).
  • Access credentials: Proximity card number.
  • Access logs: Timestamp and terminal location each time you enter or exit site.
  • Commute data: Home postcode (optional) used only to calculate CO₂ and local-labour reporting.

3. Lawful basis for processing

  • Contract: Processing your data to manage your site access and induction as part of your engagement on site.
  • Legal obligation: Health & safety regulations require us to verify certifications (CSCS/ECS) and maintain access records.
  • Legitimate interest: Maintaining a secure construction site and producing safety/attendance records.
  • Explicit consent: For biometric (face recognition) data, we rely on your explicit, opt-in consent given during the induction process.

4. Consent

During induction you are asked to give explicit, granular consent for each processing purpose (access control, biometric face recognition, and certification verification). Consent boxes are not pre-ticked. You may withdraw consent at any time by contacting your site manager; withdrawal does not affect the lawfulness of processing before withdrawal.

5. Data minimisation

We only collect data that is strictly necessary for site access, safety compliance, and statutory reporting. Optional fields (such as home postcode) are clearly marked and used solely for the purpose stated.

6. Data retention

Access logs and induction records are retained for the duration of your engagement on site and for the statutory audit period required by health & safety law. When your site access is removed (for example, on CSCS/ECS card expiry or a disciplinary red card), your personal data is retained for a 14-day grace period to allow card renewal or red-card resolution. If your access is reinstated within this window (for example, your CSCS/ECS card is renewed), the retention timer is reset and you are re-enrolled automatically — no re-onboarding is needed. If the 14-day period elapses without reinstatement, your personal data is fully erased: biometric face data and proximity card are deleted from all access terminals, and all identifying fields on your record (name, contact details, photo, company, trade, card numbers, certifications, and emergency contact) are anonymised. Anonymised attendance event records may be retained for aggregate safety reporting and audit.

7. Your rights

Under GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data ("right to be forgotten").
  • Restriction & objection — limit or object to certain processing.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — at any time, for consent-based processing.

To exercise any of these rights, contact your site manager or use the Contact page. For your right of access and data portability, your site manager can generate a complete export of all personal data we hold about you (worker record, certifications, access logs, disciplinary records, permits, toolbox talks, incidents, and presence) as a machine-readable JSON file or a printable report — simply ask and they will provide it. We respond to access requests within one calendar month. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

8. Security measures

  • Access to personal data is restricted by role-based access control and site-level authorisation.
  • All access-control terminals require authenticated, encrypted connections.
  • Audit logs record who accessed or modified records.
  • A Data Protection Impact Assessment (DPIA) has been carried out for biometric processing.

9. Sharing

We do not sell your data. Data is shared only with your employer/subcontractor for site-management purposes, and with regulators where legally required. Biometric data is processed on-site terminals and is not shared with third parties.