Skip to main content
Notice privacy-2026-08-17

Privacy at JobSite

Who is accountable, what JobSite handles and why, where it can go, how long it is kept, and how to ask for access, correction, export or deletion. Optional location, recording, AI and marketing uses start switched off.

Effective and last updated · English (Canada)

Accountability

Who is accountable

Controller

Your builder organization

The participating builder decides why its project, worker, client and trade records are used, who takes part in a project, and which optional features it enables. Contact the builder first for a project-specific request.

Processor

BaldwIndustries Inc. / JobSite

BaldwIndustries Inc. operates JobSite as the builder's service provider for most tenant records, and is directly accountable for platform security, service administration and its own required business records. Access is purpose-bound.

A contract or a system setting does not remove either organization's duties under applicable law. JobSite is software, not legal advice.

Inventory

Personal-data inventory

JobSite collects information at the point a documented purpose needs it. This is the platform inventory; an individual builder may use fewer categories.

Personal-data categories, their purpose, sources, recipients, stores and default state
CategoryPurpose and authoritySources and recipientsStoresDefault
Account, identity and membershipsensitiveAuthenticate users and enforce tenant and role access.Authority: contract and legal obligationFrom Individual, tenant administrator and identity providerTo Authorized tenant administrators and Baldwin security operationspostgres and backupsInformational: Required
Project, contract and decision recordssensitiveDeliver and evidence construction project workflows.Authority: contract and legal obligationFrom Tenant users, clients, trades and integrationsTo Authorized project participants and approved service providerspostgres, object storage, search, mail, integrations and backupsInformational: Required
Accounting, payment and tax evidencehighly sensitiveBudget, invoice, payment, tax and reconciliation workflows.Authority: contract and legal obligationFrom Tenant users and payment and accounting providersTo Authorized finance users, tenant accountant and approved processorspostgres, object storage, integrations and backupsInformational: Required
Safety, labour and certification evidencehighly sensitiveSite safety, accepted time and worker compliance.Authority: contract and legal obligationFrom Workers, tenant supervisors and WSIB and compliance evidenceTo Authorized safety and payroll roles and required authoritiespostgres, object storage and backupsInformational: Required
Raw precise location pointshighly sensitiveAccepted travel, arrival/departure, safety check-in or enabled time evidence.Authority: consent and contractFrom Worker device during an active disclosed sessionTo Authorized operations or safety rolespostgres and backupsInactive: Off until enabled
Call recording and full transcripthighly sensitiveDisclosed call purpose, quality, dispute resolution or approved workflow evidence.Authority: consent and contractFrom Call participants after notice and consentTo Authorized communications roles and approved telephony processorsobject storage, postgres, integrations and backupsInactive: Off until enabled
AI retrieved context, prompt and output payloadhighly sensitiveExecute a specifically approved or permitted AI capability.Authority: consent and contractFrom Authorized JobSite records and user instructionTo Authorized user and approved AI gateway/providerpostgres, analytics and backupsInactive: Off until enabled
Marketing consent and suppression proofsensitiveProve consent or exemption and prevent prohibited contact.Authority: consent and legal obligationFrom Contact, tenant user and compliance providerTo Authorized communications roles and approved delivery providerspostgres, mail, integrations and backupsInactive: Off until enabled
Support attachments and diagnostic bundleshighly sensitiveResolve a tenant-authorized support case.Authority: contract and consentFrom Tenant user and authorized diagnostic collectionTo Named approved support operatorspostgres, object storage and backupsInactive: Off until enabled
Authentication and security telemetrysensitiveDetect abuse, investigate incidents and protect tenant boundaries.Authority: legitimate interest and legal obligationFrom JobSite systems and identity and edge providersTo Baldwin security operations and required authorities after reviewpostgres, analytics and backupsInformational: Required
Consent

Consent and choices

  • Precise location, call recording and full transcription, optional AI payload processing, marketing, and support diagnostic collection are disabled until the applicable disclosure, authority and tenant policy are satisfied.
  • A consent receipt records the notice version, language, purpose, channel, actor and time. A withdrawal creates a new retained receipt; it does not rewrite history. Consent records are append-only at the database level, so this is structural rather than a policy anyone has to remember.
  • Withdrawal stops future optional processing and starts suppression or deletion work where applicable. It cannot erase a contract, safety, financial, security or legal-hold record that must still be retained.
  • Essential project and service messages are not treated as marketing. Marketing suppression is shared across the matching email or SMS purpose without blocking an essential safety or project update.
Your rights

Access, correction, export and deletion

Under PIPEDA you may ask for access to your personal information, for its correction, for a copy of it, and for its deletion where no overriding retention obligation applies. An organization is ordinarily required to answer an access request within thirty days, subject to lawful extensions and notice.

Route

The request channel is not open

Contact is being provisioned. JobSite is pre-release and does not yet have a monitored public mailbox. Until one is published here, this site cannot accept a message — please do not send project details, credentials or personal information to any address on this page.

This notice previously directed requests to a contact route whose only addresses bounced. JobSite therefore does not represent that a request sent to this site will be received or answered within any period. Two routes do work in the meantime: if your question concerns a project, the builder running it is the accountable organization and can be contacted directly; and the Office of the Privacy Commissioner of Canada is an independent escalation that does not depend on this site.

When the channel exists, a request is handled in this order:

  1. 1Identity and authority are verified without collecting more than is necessary.
  2. 2The request is scoped across database records, object storage, search, mail, integrations, analytics and backups.
  3. 3Third-party, privileged and legal-hold material is reviewed, and any lawful refusal or redaction is explained.
  4. 4An authorized person approves the response; the fulfillment package and its completion record are retained as evidence.

The Privacy Commissioner's guidance on access requests

Retention

Retention defaults

These governed defaults apply at launch. A tenant contract may require longer periods. A legal hold always pauses deletion, and a shorter setting requires policy validation and cannot remove statutory evidence.

Retention classes, their trigger, default period and end action
ClassStarts whenDefault periodThen
Project, contract and decision recordsProject lifecycle closesProject life plus 15 yearsdelete
Accounting, payment and tax evidenceApplicable fiscal year endsFiscal year end plus 7 yearsdelete
Safety, training, certification and accepted labour evidenceRelationship or incident closesRelationship or incident close plus 7 yearsdelete
Warranty enrolment, claim and resolutionWarranty coverage ends, but never before nine years after possessionCoverage end plus 2 years, never under 9 years after possessiondelete
Raw precise location pointsPoint is captured30 daysdelete
Call recording and full transcriptCall ends730 daysdelete
AI context, prompt and output operational payloadAI run completes90 daysdelete
Marketing consent, unsubscribe and compliance proofConsent is withdrawn or last relied uponActive use plus 3 years and 14 daysretain minimum proof
Support attachments and diagnostic bundlesSupport case closes730 daysdelete
Authentication and security telemetrySecurity event is recorded400 daysdeidentify
Deleted tenant export window and backup expiryContract ends30 daysdelete

Tenant deletion has a 30 day export window; backups expire through the 35 day cycle unless held. A restore must reapply deletion tombstones before restored records can serve traffic.

Providers

Providers and transfers

JobSite does not sell personal information. An approved provider receives only the categories its documented purpose needs, and a provider cannot be enabled until contract, security, deletion, incident and data-location review evidence exists. Some providers or support personnel may process information outside Canada under contractual and security safeguards, where it may be subject to foreign law.

The customer-visible provider inventory

Safeguards

Safeguards and incidents

Controls in force include tenant-bound authorization and row-level security under a runtime role that cannot bypass it, transaction-local tenant context on every tenant query, secure cookies and strict origin checks, encryption in transit with HSTS, private service boundaries, minimized and redacted telemetry, and append-only audit and consent evidence. A content-security policy is applied to every page and API response, with a per-request nonce and 'strict-dynamic' on the signed-in workspace, the client and trade portals, the sign-in pages, the API routes and builder-hosted site pages.

Described as designed rather than demonstrated: malicious-file quarantine is modelled in the schema and an approvals queue exists for high-risk automated actions, but no operating evidence for either was produced. No internet service can promise absolute security, and nothing here should be read as a formal attestation.

A suspected incident is contained, preserved, assessed and documented. Where a breach creates a real risk of significant harm, the responsible organization supports required reporting and individual notification. Breach records are kept for the legally required period, including decisions where notification was not required.

Federal breach guidance

Complaints

Questions or complaints

If your question concerns a project, name the builder and contact that organization first — it is the one accountable for the project record. You may also contact the Office of the Privacy Commissioner of Canada at any time, independently of JobSite.

The PIPEDA fair-information principles · Contact status