This Privacy Policy explains how DailyWorks.io (“DailyWorks”, “we”, “us”), operated by [Company Legal Name], collects, uses, and protects personal data when you use our Service. We act as a data controller for account and security data, and as a data processor for the data your company submits while using the Service.
1. Data We Collect
- Account data: your name, email address, role, and hashed password.
- Company & operational data: clients, projects, daily reports, photographs, and scaffolding records your company enters.
- Security & sign-in data: when you sign in, we record the date and time, your IP address, an approximate country derived from that IP address, and your browser user-agent. This is used to protect accounts and detect suspicious activity.
- Authentication data: if you enable two-factor authentication, we store an encrypted secret used to verify your codes.
- Cookies: a session cookie required to keep you signed in. See “Cookies & Sessions” below.
2. How We Use Data
- to provide, operate, and secure the Service;
- to authenticate users and protect against unauthorized access, brute-force attempts, and fraud;
- to maintain a sign-in audit trail for security and compliance;
- to communicate with you about your account (e.g. password resets); and
- to comply with legal obligations.
3. Legal Bases (GDPR)
Where the EU/UK General Data Protection Regulation applies, we process personal data on the basis of: performance of a contract (providing the Service); our legitimate interests (securing the Service and preventing abuse); and compliance with legal obligations.
4. How We Share Data
We do not sell personal data. We share data only with service providers (sub-processors) that help us run the Service, under appropriate contractual safeguards, including:
- Hosting & compute (application hosting infrastructure);
- Database (managed PostgreSQL hosting);
- Email delivery (transactional email for password resets and notifications).
We may also disclose data where required by law or to protect our rights, users, or the public.
5. Cookies & Sessions
We use a strictly necessary session cookie to keep you authenticated. Normal sessions last up to 12 hours; choosing “remember me” extends this to 7 days. We do not use third-party advertising or tracking cookies.
6. Data Retention
We retain account and Customer Data for as long as your account is active or as needed to provide the Service. Sign-in audit records are retained for a limited period for security purposes. We delete or anonymize data when it is no longer required, subject to legal retention obligations.
7. Security
We apply technical and organizational measures to protect personal data, including encryption in transit, password hashing, encryption of two-factor secrets at rest, account lockout after repeated failed sign-ins, and role-based access controls that isolate each company’s data. No method of transmission or storage is completely secure, but we work to protect your information.
8. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. Many of these can be exercised directly within the Service or via your company administrator; otherwise, contact us using the details below. You also have the right to lodge a complaint with your local data protection authority.
9. International Transfers
Personal data may be processed in countries other than your own. Where data is transferred outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Children
The Service is intended for business use and is not directed to individuals under the age of 16. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified through the Service or by email, and the “last updated” date above will be revised.
12. Contact
For privacy questions or to exercise your rights, contact us at privacy@dailyworks.io.
