Last updated: August 2026
DATA_CONTROLLER_NAME and
DATA_CONTROLLER_EMAIL in your deployment .env file before publishing
this policy to users.
This privacy policy describes how [DATA_CONTROLLER_NAME not configured] ("we", "us", "our") processes personal data in connection with the Sigtura document management platform ("the Platform").
For the purposes of the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU General Data Protection Regulation (EU GDPR), we are the data controller.
Contact: [DATA_CONTROLLER_EMAIL not configured]
EU users (Article 27 GDPR): If we are not established within the European Union, we are required to designate an EU representative. Details of our EU representative are available on request from the contact address above.
Your name, email address, username, and role on the Platform are stored when your account is created by your organisation's administrator.
We store a one-way cryptographic hash of your password — we never store your password in readable form. If you enrol in multi-factor authentication (MFA), we store your authenticator key and any recovery codes you generate.
Every significant action on the Platform (creating, approving, or modifying documents; submitting transmittals; completing inspections; etc.) is recorded in an audit log that includes your username, the action taken, the time, and your IP address. This log cannot be edited or deleted by users.
Failed login attempts and other security-relevant events are logged with a timestamp and IP address to protect the Platform against unauthorised access.
When you sign in, a session is created on our servers and a session identifier is stored in a cookie in your browser. This allows the Platform to keep you signed in. The session expires when you sign out, or automatically after a period of inactivity.
We process data you upload or create within the Platform — including documents, photographs, inspection records, technical queries, site diary entries, and transmittals — as part of delivering the service. This data may contain personal information depending on its content.
We send email notifications (for example, when a document is submitted for your review or a transmittal is received). These include your name, email address, and content relevant to the notification.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing secure access to the Platform | Account data, password hash, MFA credentials, session cookie | Contract — Art 6(1)(b): necessary to provide the service |
| Delivering Platform features (documents, transmittals, inspections, etc.) | Project and document data | Contract — Art 6(1)(b) |
| Sending email notifications | Name, email address | Contract — Art 6(1)(b) |
| Security monitoring and fraud prevention | Audit log, security events, IP addresses | Legitimate interests — Art 6(1)(f): protecting users and the Platform |
| Regulatory and contractual accountability | Audit log, activity records | Legitimate interests — Art 6(1)(f): demonstrating compliance with contractual and regulatory obligations |
| "Stay signed in" / Remember Me | Persistent authentication token (cookie) | Consent — Art 6(1)(a): you opt in by ticking "Remember me" at sign-in; you may withdraw at any time by signing out |
We use the following cookies. We do not use advertising, analytics, or third-party tracking cookies.
| Cookie | Purpose | Duration | Consent required? |
|---|---|---|---|
sessionid |
Maintains your signed-in session | Until you sign out, or automatically on idle/absolute timeout | No — strictly necessary |
csrftoken |
Prevents cross-site request forgery attacks | Session or up to 1 year (browser-managed) | No — strictly necessary |
| Remember Me token | Automatically signs you back in when your session expires, if you opted in | Up to 30 days, or until you sign out | Yes — only set when you tick "Remember me" at sign-in |
We do not sell or rent your personal data. We may share it only with:
If any of our data processors (e.g. our email delivery or hosting provider) process data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs), in accordance with UK GDPR and EU GDPR respectively.
| Data category | Retention period |
|---|---|
| Account data | For the lifetime of your account. Accounts are deactivated rather than deleted so that audit records remain attributable. Contact us to request deletion. |
| Audit log | Configured per deployment by your system administrator (typically 7 years for compliance environments) |
| Document records | Configured per deployment by your system administrator |
| Transmittal records | Configured per deployment by your system administrator |
| Session data | Deleted when you sign out; automatically expired per system session timeout settings |
| Remember Me token | Up to 30 days, or deleted when you sign out (whichever is sooner) |
| Security event log | Configured per deployment by your system administrator |
Under UK GDPR and EU GDPR you have the right to:
To exercise any of these rights, contact us at: [DATA_CONTROLLER_EMAIL not configured]. We will respond within one calendar month.
If you are unhappy with how we handle your personal data, you have the right to complain to your supervisory authority.
Information Commissioner's Office (ICO)
ico.org.uk
0303 123 1113
Contact your national supervisory authority. A full list is available at:
edpb.europa.eu
We may update this policy from time to time. The date at the top of this page indicates when it was last revised. Where changes are material, we will notify users via the Platform or by email.