SiteQore Privacy Policy
Last updated: 01 January 2026 ยท Version 1.0
SiteQore attaches great importance to the protection of personal data. In this privacy policy we explain which personal data is processed through SiteQore, why we process it, how we protect it and which rights data subjects have.
SiteQore is provided by Noax Industrial B.V..
1. Who is responsible?
SiteQore is provided by Noax Industrial B.V..
- Trading/product name: SiteQore
- Address: Nassaulaan 43A, 4651 AA Steenbergen, The Netherlands
- Chamber of Commerce number: 84658479
This company is responsible for the processing of personal data insofar as it determines the purposes and means of that processing itself.
Where SiteQore is used by a customer organisation, that organisation may itself be the controller for certain personal data and SiteQore may act as processor.
2. Which personal data do we process?
Depending on how SiteQore is used, we may process the following data, among others:
Account and user data
- First name
- Last name
- Business email address
- Telephone number, if provided
- Job title
- Organisation
- User role
- Assigned work locations
- Account and security data
Organisation data
- Organisation name
- Address details
- Contact details
- Company logo
- Work locations
- Units
- Areas
- Specific locations
- Contractor details
- User and role structure
Pilot and subscription data
- Selected subscription
- Pilot status
- Pilot start and end date
- Usage data
- Billing and subscription status
- Contact details of the primary administrator
Data contained in safety reports
Depending on what the reporter enters, reports may contain:
- Location details
- Report type
- Category
- Work permit number
- Work order number
- Project number
- Contractor involved
- Description of the situation
- Risk estimate
- Photos or other attachments
- Name and contact details of the reporter if they do not report anonymously
- Date and time of the report
- Language in which the report was made
Where this option is available, reporters can submit a report anonymously.
Corrective actions and HSE follow-up
SiteQore may process data about:
- Corrective actions
- Responsible persons
- Priorities
- Due dates
- Status
- Evidence
- Verification
- Internal notes
- Audit and activity history
Technical data
We may process technical data that is necessary for the security and operation of SiteQore, such as:
- IP address
- Browser and device information
- Sign-in events
- Security logs
- Technical error reports
- Audit logs
3. What do we use personal data for?
We process personal data for purposes including:
- Creating and managing SiteQore accounts
- Providing the SiteQore service
- Recording and following up safety reports
- Managing corrective actions
- Performing risk assessments
- Generating dashboards and reports
- Sending scheduled reports
- Managing QR codes
- Managing organisations, locations, users and roles
- Running pilots
- Processing subscriptions
- Providing onboarding and support
- Securing the platform
- Preventing misuse
- Improving SiteQore
- Complying with legal obligations
4. Legal basis for processing
Depending on the processing, we rely on one or more of the following legal bases:
- Performance of a contract
- Legitimate interest
- Legal obligation
- Consent, where consent is required
Where a customer organisation uses SiteQore for its own HSE processes, that organisation may itself be responsible for determining the applicable legal basis for the personal data it processes through SiteQore.
5. Anonymous safety reports
SiteQore is designed to allow safety reports to be submitted without a user account wherever possible.
When a reporter chooses to report anonymously, we do not actively ask for the reporter's name or contact details.
Technical data may still be processed for the security and correct operation of the platform.
An organisation may apply its own policy regarding anonymous reports.
7. International transfers
If personal data is processed outside the European Economic Area, we ensure appropriate safeguards in line with the GDPR where required, for example by relying on adequacy decisions or appropriate contractual safeguards.
8. How long do we retain personal data?
We do not retain personal data longer than necessary for the purpose for which it was collected, unless a longer retention period is legally required or justified.
Different retention periods may apply to different categories of data. SiteQore may distinguish between, among others:
- Account data
- Organisation data
- Safety reports
- Audit logs
- Pilot data
- Subscription and financial data
- Technical logs
Final retention periods are determined on the basis of the purpose of the processing, legal obligations and agreements with customer organisations.
When data is no longer necessary, it is deleted or, where appropriate, anonymised.
9. Security
SiteQore takes appropriate technical and organisational measures to protect personal data. Where applicable this includes:
- Authentication
- Role-based access
- Organisation isolation
- Row-level security
- Logging
- Secure connections
- Controlled access rights
- Backup and recovery measures
- Security monitoring
Access to organisation data is limited to authorised users.
10. Rights of data subjects
Under the GDPR you may, depending on the situation, have the right to:
- Access your personal data
- Rectify inaccurate personal data
- Erase personal data
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent where processing is based on consent
A request can be submitted using the contact details included in your pilot or subscription agreement, or through your organisation administrator. A dedicated privacy email address will be published here once it is established.
We may ask for additional information to verify your identity before we act on a request.
11. Complaints
If you believe personal data is not being processed correctly, you can first contact SiteQore using the contact details in your pilot or subscription agreement.
You also have the right to lodge a complaint with the competent supervisory authority. In the Netherlands this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
13. Changes to this privacy policy
SiteQore may amend this privacy policy when the service, legislation or processing of personal data changes.
The most current version is always published at /privacy.
In the event of material changes, registered users may be informed separately. Previous versions and previously recorded acknowledgements are retained.
14. Contact
For questions about privacy or personal data:
- SiteQore โ a product of Noax Industrial B.V.
- Address: Nassaulaan 43A, 4651 AA Steenbergen, The Netherlands
- Chamber of Commerce number: 84658479
SiteQore ยท Version 1.0