Sigtura

Privacy Policy

Last updated: August 2026

Configuration required: Set DATA_CONTROLLER_NAME and DATA_CONTROLLER_EMAIL in your deployment .env file before publishing this policy to users.

1. Who we are

This privacy policy describes how [DATA_CONTROLLER_NAME not configured] ("we", "us", "our") processes personal data in connection with the Sigtura document management platform ("the Platform").

For the purposes of the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU General Data Protection Regulation (EU GDPR), we are the data controller.

Contact: [DATA_CONTROLLER_EMAIL not configured]

EU users (Article 27 GDPR): If we are not established within the European Union, we are required to designate an EU representative. Details of our EU representative are available on request from the contact address above.

2. Personal data we collect

2.1 Account information

Your name, email address, username, and role on the Platform are stored when your account is created by your organisation's administrator.

2.2 Authentication data

We store a one-way cryptographic hash of your password — we never store your password in readable form. If you enrol in multi-factor authentication (MFA), we store your authenticator key and any recovery codes you generate.

2.3 Activity and audit records

Every significant action on the Platform (creating, approving, or modifying documents; submitting transmittals; completing inspections; etc.) is recorded in an audit log that includes your username, the action taken, the time, and your IP address. This log cannot be edited or deleted by users.

2.4 Security events

Failed login attempts and other security-relevant events are logged with a timestamp and IP address to protect the Platform against unauthorised access.

2.5 Session data

When you sign in, a session is created on our servers and a session identifier is stored in a cookie in your browser. This allows the Platform to keep you signed in. The session expires when you sign out, or automatically after a period of inactivity.

2.6 Project and document data

We process data you upload or create within the Platform — including documents, photographs, inspection records, technical queries, site diary entries, and transmittals — as part of delivering the service. This data may contain personal information depending on its content.

2.7 Email notifications

We send email notifications (for example, when a document is submitted for your review or a transmittal is received). These include your name, email address, and content relevant to the notification.

3. Why we process your data

PurposeData usedLegal basis
Providing secure access to the Platform Account data, password hash, MFA credentials, session cookie Contract — Art 6(1)(b): necessary to provide the service
Delivering Platform features (documents, transmittals, inspections, etc.) Project and document data Contract — Art 6(1)(b)
Sending email notifications Name, email address Contract — Art 6(1)(b)
Security monitoring and fraud prevention Audit log, security events, IP addresses Legitimate interests — Art 6(1)(f): protecting users and the Platform
Regulatory and contractual accountability Audit log, activity records Legitimate interests — Art 6(1)(f): demonstrating compliance with contractual and regulatory obligations
"Stay signed in" / Remember Me Persistent authentication token (cookie) Consent — Art 6(1)(a): you opt in by ticking "Remember me" at sign-in; you may withdraw at any time by signing out

4. Cookies

We use the following cookies. We do not use advertising, analytics, or third-party tracking cookies.

CookiePurposeDurationConsent required?
sessionid Maintains your signed-in session Until you sign out, or automatically on idle/absolute timeout No — strictly necessary
csrftoken Prevents cross-site request forgery attacks Session or up to 1 year (browser-managed) No — strictly necessary
Remember Me token Automatically signs you back in when your session expires, if you opted in Up to 30 days, or until you sign out Yes — only set when you tick "Remember me" at sign-in

5. Who we share your data with

We do not sell or rent your personal data. We may share it only with:

6. International transfers

If any of our data processors (e.g. our email delivery or hosting provider) process data outside the UK or European Economic Area, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement (IDTA) or EU Standard Contractual Clauses (SCCs), in accordance with UK GDPR and EU GDPR respectively.

7. How long we keep your data

Data categoryRetention period
Account dataFor the lifetime of your account. Accounts are deactivated rather than deleted so that audit records remain attributable. Contact us to request deletion.
Audit logConfigured per deployment by your system administrator (typically 7 years for compliance environments)
Document recordsConfigured per deployment by your system administrator
Transmittal recordsConfigured per deployment by your system administrator
Session dataDeleted when you sign out; automatically expired per system session timeout settings
Remember Me tokenUp to 30 days, or deleted when you sign out (whichever is sooner)
Security event logConfigured per deployment by your system administrator

8. Your rights

Under UK GDPR and EU GDPR you have the right to:

To exercise any of these rights, contact us at: [DATA_CONTROLLER_EMAIL not configured]. We will respond within one calendar month.

9. How to complain

If you are unhappy with how we handle your personal data, you have the right to complain to your supervisory authority.

United Kingdom

Information Commissioner's Office (ICO)
ico.org.uk
0303 123 1113

European Union

Contact your national supervisory authority. A full list is available at:
edpb.europa.eu

10. Changes to this policy

We may update this policy from time to time. The date at the top of this page indicates when it was last revised. Where changes are material, we will notify users via the Platform or by email.