Privacy notice
Last updated: [DATE — set at legal review]
This notice explains how JobDocs ([LEGAL ENTITY NAME], registered in [JURISDICTION], company number [NUMBER]) processes personal data. It covers three groups of people: customer users (people at organisations that subscribe to JobDocs Manage), contractor participants (people who respond to requests or maintain a Trade account) and business prospects (people we contact about the service).
1. Data we process
- Account and contact data — names, work email addresses, organisation details and role information for customer users and contractor participants.
- Compliance and work records — documents, credentials, quotations, RAMS and related review decisions uploaded by or about contractors at a customer's request. These may contain personal data such as names on certificates or insurance documents.
- Billing data — subscription and payment records. Card details are handled by our payment processor (Stripe) and are not stored by us.
- Prospect and marketing data — business contact details of prospective customers, sourced from [SOURCES — complete at review], and correspondence history.
- Technical and security data — access logs, audit trails and device information used to secure accounts and investigate misuse.
2. Our roles: controller and processor
Our role depends on the activity. [CONFIRM MAPPING WITH COUNSEL — blueprint §13.2.]
- When a customer organisation uploads contractor records and runs its compliance process, the customer is normally the controller and JobDocs acts as its processor under a Data Processing Agreement.
- For platform accounts, billing, fraud prevention and security logs, JobDocs acts as an independent controller.
- For our own prospect research and marketing, JobDocs is the controller.
- Where a contractor independently maintains a reusable profile shared with several clients, roles may vary and are documented per activity. [COMPLETE AT REVIEW.]
A current list of subprocessors is available on request. [ATTACH SUBPROCESSOR LIST AND DPA AT REVIEW.]
3. Retention and deletion
- Customer organisations can configure retention for their own records within platform minimum and maximum policies. [STATE DEFAULTS AT REVIEW.]
- Operational records are soft-deleted first, then irreversibly purged after a recovery period. [STATE PERIODS AT REVIEW.]
- Billing and tax records are retained for the applicable statutory periods.
- Marketing suppression records are retained in minimised form so that people who opt out are not contacted again.
- Export is available before account closure; some records cannot be deleted immediately for legal or security reasons, and we document which.
4. Marketing and your right to object
We contact business prospects on the basis of legitimate interests [CONFIRM LAWFUL BASIS AND LEGITIMATE-INTEREST ASSESSMENT AT REVIEW]. Every marketing email includes a working unsubscribe link. If you opt out, hard bounce or complain, we immediately stop pending sends to you and add you to a suppression list so you are not re-contacted. You can also object at any time by contacting us using the details below.
5. Your rights
Depending on your location you may have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to a supervisory authority such as the UK Information Commissioner's Office. Where we act as a processor, we will refer your request to the controller (the customer organisation) and assist them in responding. [COMPLETE AT REVIEW.]
6. Contact
Privacy questions and requests: [PRIVACY CONTACT EMAIL].
Postal address: [REGISTERED ADDRESS].
Data protection contact: [DPO OR RESPONSIBLE PERSON — confirm whether a DPO is required at review].