SiteRelay

Security & GDPR

How your company's data is stored, isolated and protected.

Where your data lives

SiteRelay is hosted on Supabase in London (AWS eu-west-2). Your data does not leave the UK region in normal operation. Databases are backed up automatically by the platform.

How companies are isolated

Every record belongs to exactly one company and is protected by database row-level security — enforced in the database itself, not just the application. One company can never read another's data, even in the event of an application bug. Within your company, a role and permission system controls who can see and change what, and personnel records (NI numbers, home addresses, emergency contacts) are additionally restricted so they only ever reach managers' devices.

Offline devices

SiteRelay works offline by keeping a copy of your company's working data on each signed-in device, scoped to what that person's role allows. Signing out removes access. If a device is lost or someone leaves, disable the staff member in SiteRelay: their login can no longer read, write or sync any company data, and the copy already on the device is removed the next time it connects.

Accounts and passwords

Passwords are stored only as bcrypt hashes, handled by Supabase's authentication service. Password resets are self-serve by email. We recommend directors enable a password manager policy for staff.

GDPR roles

Your company is the data controller for the information you put into SiteRelay; SiteRelay is the data processor. The platform operator's console is designed for data minimisation — it sees seat counts and usage numbers, not your staff's names, contact details or job content. A data processing agreement is available on request.

Your data is yours

Every register — jobs, timesheets, staff, vehicles, forms, audits — exports to Excel at any time from inside the app. If you leave, you take everything with you.

Questions

Ask anything: get in touchand you'll get a straight answer from the people who built it.