Privacy at JobSite
Who is accountable, what JobSite handles and why, where it can go, how long it is kept, and how to ask for access, correction, export or deletion. Optional location, recording, AI and marketing uses start switched off.
Effective and last updated · English (Canada)
Who is accountable
Your builder organization
The participating builder decides why its project, worker, client and trade records are used, who takes part in a project, and which optional features it enables. Contact the builder first for a project-specific request.
BaldwIndustries Inc. / JobSite
BaldwIndustries Inc. operates JobSite as the builder's service provider for most tenant records, and is directly accountable for platform security, service administration and its own required business records. Access is purpose-bound.
A contract or a system setting does not remove either organization's duties under applicable law. JobSite is software, not legal advice.
Personal-data inventory
JobSite collects information at the point a documented purpose needs it. This is the platform inventory; an individual builder may use fewer categories.
| Category | Purpose and authority | Sources and recipients | Stores | Default |
|---|---|---|---|---|
| Account, identity and membershipsensitive | Authenticate users and enforce tenant and role access.Authority: contract and legal obligation | From Individual, tenant administrator and identity providerTo Authorized tenant administrators and Baldwin security operations | postgres and backups | Informational: Required |
| Project, contract and decision recordssensitive | Deliver and evidence construction project workflows.Authority: contract and legal obligation | From Tenant users, clients, trades and integrationsTo Authorized project participants and approved service providers | postgres, object storage, search, mail, integrations and backups | Informational: Required |
| Accounting, payment and tax evidencehighly sensitive | Budget, invoice, payment, tax and reconciliation workflows.Authority: contract and legal obligation | From Tenant users and payment and accounting providersTo Authorized finance users, tenant accountant and approved processors | postgres, object storage, integrations and backups | Informational: Required |
| Safety, labour and certification evidencehighly sensitive | Site safety, accepted time and worker compliance.Authority: contract and legal obligation | From Workers, tenant supervisors and WSIB and compliance evidenceTo Authorized safety and payroll roles and required authorities | postgres, object storage and backups | Informational: Required |
| Raw precise location pointshighly sensitive | Accepted travel, arrival/departure, safety check-in or enabled time evidence.Authority: consent and contract | From Worker device during an active disclosed sessionTo Authorized operations or safety roles | postgres and backups | Inactive: Off until enabled |
| Call recording and full transcripthighly sensitive | Disclosed call purpose, quality, dispute resolution or approved workflow evidence.Authority: consent and contract | From Call participants after notice and consentTo Authorized communications roles and approved telephony processors | object storage, postgres, integrations and backups | Inactive: Off until enabled |
| AI retrieved context, prompt and output payloadhighly sensitive | Execute a specifically approved or permitted AI capability.Authority: consent and contract | From Authorized JobSite records and user instructionTo Authorized user and approved AI gateway/provider | postgres, analytics and backups | Inactive: Off until enabled |
| Marketing consent and suppression proofsensitive | Prove consent or exemption and prevent prohibited contact.Authority: consent and legal obligation | From Contact, tenant user and compliance providerTo Authorized communications roles and approved delivery providers | postgres, mail, integrations and backups | Inactive: Off until enabled |
| Support attachments and diagnostic bundleshighly sensitive | Resolve a tenant-authorized support case.Authority: contract and consent | From Tenant user and authorized diagnostic collectionTo Named approved support operators | postgres, object storage and backups | Inactive: Off until enabled |
| Authentication and security telemetrysensitive | Detect abuse, investigate incidents and protect tenant boundaries.Authority: legitimate interest and legal obligation | From JobSite systems and identity and edge providersTo Baldwin security operations and required authorities after review | postgres, analytics and backups | Informational: Required |
Consent and choices
- Precise location, call recording and full transcription, optional AI payload processing, marketing, and support diagnostic collection are disabled until the applicable disclosure, authority and tenant policy are satisfied.
- A consent receipt records the notice version, language, purpose, channel, actor and time. A withdrawal creates a new retained receipt; it does not rewrite history. Consent records are append-only at the database level, so this is structural rather than a policy anyone has to remember.
- Withdrawal stops future optional processing and starts suppression or deletion work where applicable. It cannot erase a contract, safety, financial, security or legal-hold record that must still be retained.
- Essential project and service messages are not treated as marketing. Marketing suppression is shared across the matching email or SMS purpose without blocking an essential safety or project update.
Access, correction, export and deletion
Under PIPEDA you may ask for access to your personal information, for its correction, for a copy of it, and for its deletion where no overriding retention obligation applies. An organization is ordinarily required to answer an access request within thirty days, subject to lawful extensions and notice.
The request channel is not open
Contact is being provisioned. JobSite is pre-release and does not yet have a monitored public mailbox. Until one is published here, this site cannot accept a message — please do not send project details, credentials or personal information to any address on this page.
This notice previously directed requests to a contact route whose only addresses bounced. JobSite therefore does not represent that a request sent to this site will be received or answered within any period. Two routes do work in the meantime: if your question concerns a project, the builder running it is the accountable organization and can be contacted directly; and the Office of the Privacy Commissioner of Canada is an independent escalation that does not depend on this site.
When the channel exists, a request is handled in this order:
- 1Identity and authority are verified without collecting more than is necessary.
- 2The request is scoped across database records, object storage, search, mail, integrations, analytics and backups.
- 3Third-party, privileged and legal-hold material is reviewed, and any lawful refusal or redaction is explained.
- 4An authorized person approves the response; the fulfillment package and its completion record are retained as evidence.
Retention defaults
These governed defaults apply at launch. A tenant contract may require longer periods. A legal hold always pauses deletion, and a shorter setting requires policy validation and cannot remove statutory evidence.
| Class | Starts when | Default period | Then |
|---|---|---|---|
| Project, contract and decision records | Project lifecycle closes | Project life plus 15 years | delete |
| Accounting, payment and tax evidence | Applicable fiscal year ends | Fiscal year end plus 7 years | delete |
| Safety, training, certification and accepted labour evidence | Relationship or incident closes | Relationship or incident close plus 7 years | delete |
| Warranty enrolment, claim and resolution | Warranty coverage ends, but never before nine years after possession | Coverage end plus 2 years, never under 9 years after possession | delete |
| Raw precise location points | Point is captured | 30 days | delete |
| Call recording and full transcript | Call ends | 730 days | delete |
| AI context, prompt and output operational payload | AI run completes | 90 days | delete |
| Marketing consent, unsubscribe and compliance proof | Consent is withdrawn or last relied upon | Active use plus 3 years and 14 days | retain minimum proof |
| Support attachments and diagnostic bundles | Support case closes | 730 days | delete |
| Authentication and security telemetry | Security event is recorded | 400 days | deidentify |
| Deleted tenant export window and backup expiry | Contract ends | 30 days | delete |
Tenant deletion has a 30 day export window; backups expire through the 35 day cycle unless held. A restore must reapply deletion tombstones before restored records can serve traffic.
Providers and transfers
JobSite does not sell personal information. An approved provider receives only the categories its documented purpose needs, and a provider cannot be enabled until contract, security, deletion, incident and data-location review evidence exists. Some providers or support personnel may process information outside Canada under contractual and security safeguards, where it may be subject to foreign law.
Safeguards and incidents
Controls in force include tenant-bound authorization and row-level security under a runtime role that cannot bypass it, transaction-local tenant context on every tenant query, secure cookies and strict origin checks, encryption in transit with HSTS, private service boundaries, minimized and redacted telemetry, and append-only audit and consent evidence. A content-security policy is applied to every page and API response, with a per-request nonce and 'strict-dynamic' on the signed-in workspace, the client and trade portals, the sign-in pages, the API routes and builder-hosted site pages.
Described as designed rather than demonstrated: malicious-file quarantine is modelled in the schema and an approvals queue exists for high-risk automated actions, but no operating evidence for either was produced. No internet service can promise absolute security, and nothing here should be read as a formal attestation.
A suspected incident is contained, preserved, assessed and documented. Where a breach creates a real risk of significant harm, the responsible organization supports required reporting and individual notification. Breach records are kept for the legally required period, including decisions where notification was not required.
Questions or complaints
If your question concerns a project, name the builder and contact that organization first — it is the one accountable for the project record. You may also contact the Office of the Privacy Commissioner of Canada at any time, independently of JobSite.