Security & Data Protection Statement
Last updated: 27 August 2026
This Security & Data Protection Statement describes the organisational and technical measures SiteSync applies to protect Customer Data and the confidentiality, integrity, and availability of the Service.
1. Scope
This statement applies to the SiteSync platform, including the web application, mobile application, and associated infrastructure. Where the Customer deploys SiteSync on-premise or in its own private cloud, additional measures may apply as documented in the deployment agreement.
2. Organisational measures
- Access to Customer Data is limited to personnel with a legitimate need, bound by confidentiality.
- Personnel receive security and data-protection training.
- Security roles and responsibilities are defined.
- We conduct periodic reviews of our security posture.
3. Technical measures
- Encryption in transit: all traffic to the Service is encrypted with TLS (HTTPS).
- Encryption at rest: Customer Data is encrypted at rest using industry-standard encryption.
- Access control: authentication and role-based access control protect the Service; customer users are scoped by role and, where applicable, project.
- Audit logging: key actions are logged to support security monitoring and customer audit requirements.
- Backups: Customer Data is backed up to enable recovery, with retention as described in the Privacy Policy.
4. Incident management
In the event of a security incident affecting Customer Data, we will:
- Contain and investigate the incident promptly.
- Notify affected customers without undue delay, as required by ourDPA.
- Take reasonable steps to mitigate harm and prevent recurrence.
5. Compliance
We process personal data in accordance with the UAE PDPL and applicable law. Our processing on behalf of customers is governed by ourData Processing Agreement.
6. Customer responsibilities
Customers are responsible for:
- Maintaining strong credentials and protecting accounts.
- Configuring the Service appropriately for their environment.
- Complying with applicable law in their use of the Service, including informing workers about processing of their data.
7. Contact
Security reports: security@sitesync.ae