SiteCtrlSiteCtrl

Privacy Policy

Last updated: 30 September 2026

1. Introduction

SiteCtrl (“we”, “our”, or “us”) is committed to protecting the privacy of individuals who visit our website and use our construction site management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at sitectrl.com (the “Site”) or use our platform (the “Service”).

We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 (IT Act) of India. By using the Site or the Service, you consent to the practices described in this policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: When you sign up or request a demo, we collect your name, phone number, email address, and company name.
  • Communications: Information you provide when contacting our support team, responding to surveys, or participating in promotions.
  • Platform Data: Data you enter into the Service, including project details, procurement documents, task information, and user assignments.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the Site and Service, referring URLs, and interaction patterns.
  • Device Information: IP address, browser type and version, operating system, device type, and language preferences.
  • Cookies: We use essential cookies required for the Site and Service to function. We do not deploy tracking or advertising cookies without your explicit consent. See Section 11 for details.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To provide, operate, and maintain the Site and Service
  • To process your account registration and manage your subscription
  • To communicate with you regarding your account, including billing and support
  • To send service-related announcements and updates
  • To improve and personalise the Service based on usage patterns
  • To detect, prevent, and address fraud, abuse, or security incidents
  • To comply with legal obligations and regulatory requirements
  • To send marketing communications (only with your consent — you may opt out at any time)

4. Legal Basis for Processing

Under the DPDP Act, 2023, we process personal data on the following grounds:

  • Consent: For marketing communications and non-essential cookies, we obtain your explicit consent.
  • Contractual Necessity: To perform our obligations under the Terms of Service and provide the Service you have subscribed to.
  • Legitimate Interests: For improving the Service, ensuring security, and managing our business operations, where such interests do not override your fundamental rights.
  • Legal Obligation: To comply with applicable laws, court orders, or regulatory requirements.

5. Data Sharing and Disclosure

We may share your information with the following categories of recipients:

5.1 Service Providers

We engage trusted third-party service providers to help us operate the Service. These providers are contractually bound to process data only on our instructions and to maintain appropriate security measures:

5.2 Legal and Regulatory Disclosures

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

We do not sell your personal information to third parties.

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements:

  • Account data: Retained for the duration of your subscription plus a period of [X] months after termination to allow for data export and legal compliance.
  • Usage data: Retained in anonymised or aggregated form for analytics purposes for up to 24 months.
  • Communications: Retained for the duration of the relevant business relationship.

When data is no longer required, we securely delete or anonymise it in accordance with our data retention and disposal policies.

7. Data Security

We implement appropriate technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access:

  • Encryption in transit using TLS 1.3
  • Encryption at rest using AES-256
  • Role-based access controls and multi-factor authentication
  • Regular security assessments and penetration testing
  • 24/7 monitoring and intrusion detection systems
  • Employee training on data protection and confidentiality

For more details, see our Security page.

8. Your Rights (Under DPDP Act, 2023)

You have the following rights regarding your personal data:

  • Right to Access: Request a summary of the personal data we hold about you and how it has been processed.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Grievance Redressal: Lodge a complaint with our Grievance Officer regarding the processing of your personal data.
  • Right to Withdraw Consent: Withdraw your consent at any time for processing based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Right to Nominate: Nominate a person to exercise your rights in the event of death or incapacity.

To exercise any of these rights, please contact our Grievance Officer using the details in Section 11.

9. International Data Transfers

Your data may be transferred to and processed in countries other than India where our service providers operate (including the United States for Vercel hosting). We ensure that such transfers are governed by appropriate safeguards, including standard contractual clauses or equivalent mechanisms as recognised under the DPDP Act.

10. Children’s Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete it promptly.

11. Cookies

We use essential cookies and similar technologies that are strictly necessary for the operation of the Site and Service. These cookies enable core functionality such as authentication, session management, and security.

We do not deploy tracking, advertising, or analytics cookies without your explicit consent. You can manage your cookie preferences through your browser settings at any time.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. We will notify you of material changes by:

  • Posting the updated policy on this page with a revised “Last updated” date
  • Sending an email notification to the address associated with your account
  • Displaying a notice within the Service

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

13. Grievance Officer

In accordance with the DPDP Act, 2023, we have appointed a Grievance Officer who is responsible for addressing any concerns or complaints regarding the processing of your personal data:

Grievance Officer

[Name]

[Email address]

[Registered address]

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

SiteCtrl

[Email address]

[Registered address]