Legal information

Privacy notice

How we use and protect information when you create an account, join a project or contact SiteAlta.

Last updated: 31 August 2026

1. Who we are

SiteAlta is operated by London AV Supplies, trading as SiteAlta, at 124 City Road, London, EC1V 2NX, United Kingdom. For privacy questions or rights requests, email privacy@sitealta.com.

We have not appointed a data protection officer for the controlled pilot. We will review that position if our scale, risk profile or legal duties change.

2. Scope and data-protection roles

This notice covers the SiteAlta iPhone and iPad app, account invitations, controlled beta testing and support. London AV Supplies acts as controller for account administration, service security, qualification reminders and support. A customer organisation may be the controller for project and site records its admins upload or direct others to upload, with London AV Supplies acting as its processor. Customer agreements will confirm those roles.

3. Information we use

SiteAlta does not use customer information for cross-app advertising and does not include an advertising or behavioural-tracking SDK.

4. Why we use information

PurposeLawful basis
Accounts, authentication, projects, collaboration, reports and supportPerformance of a contract or steps requested before entering a contract
Organisation administration, invitations, roles and project recordsPerformance of a contract and documented customer instructions where we act as processor
Account protection, misuse investigation, audit evidence and reliabilityOur legitimate interests in protecting users, customer information and the service; legal obligation where applicable
Required account, invitation, support and qualification-expiry messagesPerformance of a contract and legitimate interests in operating the service
Accounting, regulatory duties, legal claims and security incidentsLegal obligation and legitimate interests in establishing, exercising or defending legal claims

The pilot does not send optional advertising or marketing messages. We do not make solely automated decisions which produce legal or similarly significant effects. CAPTCHA may assess whether an authentication request is automated.

5. Who can see information

6. Service providers and international transfers

Core providers are Supabase for authentication, database, private storage and server functions; Resend for transactional email; Apple for iOS/iPadOS and TestFlight/App Store services; and Cloudflare for authentication abuse protection.

The Supabase project’s primary database region is London. Some providers or subprocessors may process information outside the UK. For restricted transfers we use an appropriate safeguard such as UK adequacy regulations or contractual protections incorporating the UK International Data Transfer Addendum, and carry out proportionate provider and transfer checks. Contact privacy@sitealta.com for more information.

7. Retention and deletion

InformationDefault retention
Active project/customer recordsFor the customer relationship and project lifetime, reviewed at least annually
Closed project records and reportsSix years after project closure unless the customer contract requires a shorter lawful period
Operational account/profile after closureDeleted or anonymised within 30 days; limited security, accounting, tax or legal-claim records may be retained for the applicable statutory period
Qualification documentsUntil replaced, deleted or the account is deleted, subject to the encrypted-backup window
Support queries24 months after closure unless needed for an active dispute or incident
Security and audit logsUp to 12 months by default
Owner-managed encrypted backups35 days; deletion is reapplied if a backup is restored

Deleting an ordinary account removes private qualification documents and its operational profile. Where business project records must remain, the former user’s name is anonymised. An organisation owner must first transfer ownership or close the organisation. Data deleted from the live service may remain unavailable in encrypted backups until those backups expire.

8. Security

Controls include encrypted HTTPS connections, private storage buckets, database row-level security, organisation and project roles, protected server-side secrets, iOS Keychain sessions, protected local caches, optional Face ID or Touch ID unlock, CAPTCHA and uploader/date/time records. No system is risk-free; report suspected misuse promptly.

9. Your rights

Depending on the circumstances, you may have rights to be informed, access information, correct it, erase it, restrict processing, receive or transfer certain information, object to processing and withdraw consent where consent applies.

Your right to object: where we rely on legitimate interests, you may object by emailing privacy@sitealta.com. We normally verify requests through the signed-in account and, where necessary, confirmation from an authorised organisation admin or proportionate additional evidence.

You may complain to the UK Information Commissioner’s Office through ico.org.uk. We would appreciate the opportunity to address the concern first.

10. Children and required information

SiteAlta is a workplace project-management service and is not intended for children. The minimum user age is 18. Account email and authentication information are required to provide the service. Other information is required only where the customer workflow or contract calls for it.

11. Changes

We will update this notice when our processing, providers or legal requirements change. Material changes will be communicated through the app, email or SiteAlta website as appropriate.