These Terms and Conditions ("Terms") govern your access to and use of the SiteLog website at sitelog.uk, the SiteLog web console, and the SiteLog mobile application (together, the "Service"). The Service is operated by Crintea LTD ("we", "us", "our"), a company registered in England and Wales. These Terms, together with your order or subscription selection (the "Order"), our Privacy Policy, and the Data Processing Addendum in Schedule 1, form the agreement between you and us (the "Agreement"). By ticking to accept these Terms, creating an account, connecting the Service to a third party such as HM Revenue and Customs or your bank, or otherwise using the Service, you agree to the Agreement. If you are entering into the Agreement on behalf of a business, you confirm you have authority to bind that business. If you do not agree, do not use the Service.
- Definitions
- The Service
- Accounts and eligibility
- Acceptable use
- Subscriptions, fees, and payment
- Open Banking and bank data
- Payment initiation (paying from the app)
- Payroll, CIS, and tax calculations
- Making Tax Digital and HMRC submissions
- Customer Data and data protection
- Third-party services
- Intellectual property
- Availability and support
- Warranties and disclaimers
- Limitation of liability
- Indemnity
- Suspension and termination
- Changes to these Terms
- Governing law and jurisdiction
- Contact us
- Schedule 1 - Data Processing Addendum
- Schedule 2 - Sub-processors
1. Definitions
- "Customer" means the business or organisation that holds a SiteLog account and is the party to this Agreement.
- "User" means any individual the Customer authorises to use the Service (for example an administrator, office user, or site worker).
- "Customer Data" means the data a Customer or its Users submit to or generate in the Service, including projects, timesheets, invoices, financial and payroll records, bank transaction data, photos, and compliance records.
- "Personal Data", "Controller", "Processor", "Data Subject", and "Processing" have the meanings given in UK Data Protection Law.
- "UK Data Protection Law" means the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations, each as amended.
- "Sub-processor" means a third party engaged by us to Process Personal Data in connection with the Service.
- "Open Banking" means account access and payment services provided under the UK's open banking framework and the Payment Services Regulations 2017.
- "Account Information Service" (AIS) means the read-only retrieval of your bank account and transaction data. "Payment Initiation Service" (PIS) means initiating a payment from your bank account on your instruction.
- "Open Banking Provider" means the FCA-authorised or -registered third-party provider we use to deliver AIS and PIS (currently Plaid Financial Ltd, or such other provider as we may appoint).
- "Subscription" means a paid plan that grants access to the Service.
2. The Service
SiteLog is a construction management and business administration platform. It provides tools for projects, workforce and timesheets, compliance, plant and equipment, purchasing, and accounting and tax functions - including, where enabled, bank feeds via Open Banking, payment initiation, payroll and Construction Industry Scheme (CIS) calculations, and Making Tax Digital (MTD) submissions to HMRC. We may add, change, or remove features from time to time to improve the Service. Some features are optional and are only active if you choose to enable and configure them.
3. Accounts and eligibility
- You must be at least 18 years old and able to enter into a contract to open an account.
- Accounts for Users are created by the Customer's administrator. The Customer is responsible for the actions of its Users and for ensuring they comply with the Agreement.
- You are responsible for keeping sign-in credentials secure and for all activity under your account. Tell us promptly if you suspect unauthorised access.
- You must provide accurate account and company information and keep it up to date.
4. Acceptable use
You agree not to:
- use the Service unlawfully or in breach of any applicable regulation;
- attempt to gain unauthorised access to the Service, other Customers' data, or our systems;
- probe, scan, or test the vulnerability of the Service without our written permission, or circumvent its security;
- upload malicious code, or content that is unlawful, infringing, or that you have no right to share;
- resell, sublicense, or make the Service available to any third party except as expressly permitted; or
- use the Service in a way that damages, disables, or overburdens it.
5. Subscriptions, fees, and payment
- Access to paid features requires an active Subscription. Fees, billing frequency, any free-trial period, and any per-company or per-seat charges are shown at the point of purchase.
- Subscription payments are handled by our payment processor, Stripe. You authorise us and Stripe to charge the payment method on file for recurring Subscription fees until you cancel. We do not store your full card details.
- Where a free trial is offered, we may collect payment details at sign-up but will not charge Subscription fees until the trial ends. You may cancel before the trial ends to avoid charges.
- Unless stated otherwise, fees are exclusive of VAT, which is added where applicable.
- Fees already paid are non-refundable except where required by law. We may change our fees on reasonable notice, effective from your next billing period.
- If a payment fails, we may suspend access to paid features until the amount due is paid.
The fees in this section are for the SiteLog Subscription only. They are separate from any charges relating to Open Banking or payment initiation (see sections 6 and 7) and from any amounts you instruct to be paid to third parties.
6. Open Banking and bank data
The Service can, where you enable it, connect to your business bank account through Open Banking to retrieve account and transaction information (an Account Information Service) so that transactions feed into your reconciliation and accounting records. You acknowledge and agree that:
- A regulated provider delivers the connection. Bank connections are provided through our Open Banking Provider, which is authorised or registered by the Financial Conduct Authority to provide account information services. We are not a bank and are not ourselves an authorised payment institution.
- You authorise the access. You connect your bank and grant consent directly at your bank and/or through the Open Banking Provider. That consent is limited to the accounts you choose and, under Open Banking rules, typically expires and must be renewed periodically (usually around every 90 days).
- Read-only. Account information access is read-only. We do not receive or store your online-banking login credentials; those are handled by your bank and the Open Banking Provider.
- You can withdraw consent at any time in your account settings, through the Open Banking Provider, or with your bank. Withdrawing consent stops further data retrieval but does not affect data already imported.
- Accuracy. Imported data is provided by your bank via the Open Banking Provider. We are not responsible for errors, omissions, delays, or unavailability in data originating from your bank or the provider. You remain responsible for reviewing and reconciling your records.
- Some banks only make a limited history of transactions available, and availability can vary by bank.
7. Payment initiation (paying from the app)
Where this feature is enabled, the Service can help you initiate payments from your business bank account - for example to pay suppliers, subcontractors, staff, or HMRC - using a Payment Initiation Service. This feature may not be available to all Customers or for all banks. You acknowledge and agree that:
- We do not hold or control your money. Payments move directly from your bank account to the payee via the Open Banking Provider and your bank. We are not a bank, e-money institution, or payment institution, and we never take possession of your funds.
- You authorise every payment. Each payment or payment run is initiated on your instruction and must be authorised by you (or an authorised User) directly with your bank, including any Strong Customer Authentication your bank requires. We cannot move money without that authorisation.
- You are responsible for the details. You are responsible for the accuracy of payee details (name, sort code, account number, amount, and reference) and for ensuring sufficient funds. A payment sent to details you provided may not be recoverable.
- Execution, limits, and timing are determined by your bank and the Open Banking Provider, including any cut-off times, payment limits, and fraud checks. We are not responsible for a bank delaying, declining, or failing to execute a payment.
- Charges. Payment initiation may be subject to charges, which will be made clear before you use the feature. Your bank's own charges may also apply.
- Records only. Marking an amount as "paid" in the Service, or generating a payment run, records your bookkeeping intent; it does not by itself move money unless a payment is initiated and authorised as described above.
8. Payroll, CIS, and tax calculations
The Service can calculate pay, PAYE income tax, National Insurance, CIS deductions, VAT, and related figures from the information you enter (such as rates, hours, tax codes, and worker or subcontractor details). You acknowledge and agree that:
- You are the employer or contractor of record. You remain solely responsible for your obligations to workers, subcontractors, and HMRC, including correct worker classification, real-time PAYE reporting, CIS verification and returns, and payment of amounts due.
- Garbage in, garbage out. Calculations depend entirely on the accuracy of the data you enter and the settings you choose. You must review calculated figures before you rely on, pay, or file them.
- SiteLog is software, not an adviser. The Service does not provide accounting, tax, legal, or payroll advice. You are responsible for obtaining professional advice where you need it.
- We are not responsible for tax, penalties, interest, underpayments, or overpayments arising from data you enter, settings you choose, or your failure to meet a deadline.
9. Making Tax Digital and HMRC submissions
Where you enable the Service's tax features, SiteLog can prepare and submit VAT returns and CIS information to HMRC through HMRC's official APIs, and can retrieve related information from HMRC, in each case on your authorised instruction. You acknowledge and agree that:
- You are responsible for the figures. You must review every return and confirmation before it is submitted. You remain responsible to HMRC for the accuracy, completeness, and timeliness of anything filed through the Service.
- Authorisation. You authorise the Service to interact with HMRC on your behalf using the connection you establish, and you may withdraw that authorisation at any time in your account settings or via your HMRC account.
- Fraud prevention data. HMRC requires software to send technical header information with each request. By using the tax features you consent to the Service transmitting that information to HMRC as described in our Privacy Policy.
- We are not responsible for penalties, interest, or other liabilities arising from figures you enter, from your failure to submit on time, or from any HMRC service outage outside our control.
10. Customer Data and data protection
- As between you and us, the Customer owns its Customer Data. You grant us the rights needed to host, process, and display that data to operate, secure, and support the Service.
- For Personal Data contained in Customer Data, the Customer is the Controller and we are the Processor. We Process that Personal Data only on the Customer's documented instructions and in accordance with the Data Processing Addendum in Schedule 1, which forms part of this Agreement.
- We process personal data as described in our Privacy Policy. Where we determine the purposes and means of processing (for example for account administration, billing, and security), we act as a Controller.
- You are responsible for having a lawful basis to provide any Personal Data about your Users, workers, subcontractors, or other third parties to the Service, and for providing them with any privacy information required by law.
- On termination you may export your Customer Data using the Service's export tools. After a reasonable period we may delete Customer Data in line with our retention practices and Schedule 1.
11. Third-party services
The Service relies on third parties to deliver certain features - including HMRC (tax submissions), Stripe (Subscription payments), our Open Banking Provider (bank data and payment initiation), and our hosting and infrastructure providers. Your use of those features may be subject to the third party's own terms, and their availability is outside our control. We are not responsible for the acts, omissions, or availability of third parties, but we will use reasonable efforts to work with reputable providers and to maintain the integrations.
12. Intellectual property
The Service, including its software, design, and content (excluding Customer Data), is owned by Crintea LTD and its licensors and is protected by intellectual property laws. We grant you a limited, non-exclusive, non-transferable right to use the Service during your Subscription in accordance with the Agreement. You may not copy, modify, reverse engineer, or create derivative works from the Service except to the extent the law permits.
13. Availability and support
We aim to keep the Service available and reliable but we do not guarantee uninterrupted or error-free operation. We may carry out maintenance, and we may suspend the Service where necessary for security or legal reasons. Some features depend on third parties (for example HMRC, banks, the Open Banking Provider, hosting, and payment providers) whose availability is outside our control.
14. Warranties and disclaimers
The Service is provided "as is" and "as available". To the fullest extent permitted by law, we exclude all implied warranties, including fitness for a particular purpose and non-infringement. We do not warrant that any calculation, tax figure, or bank data is accurate where it depends on data you provide or on a third party. Nothing in the Agreement limits any rights you have as a consumer that cannot be excluded under law, or excludes liability that cannot lawfully be excluded.
15. Limitation of liability
To the fullest extent permitted by law:
- we are not liable for loss of profits, revenue, goodwill, or anticipated savings, or for any indirect or consequential loss;
- we are not liable for loss or corruption of data to the extent it results from your failure to maintain your own records or to use available export tools;
- we are not liable for tax liabilities, penalties, interest, or mis-payments to the extent they arise from data you entered, settings you chose, payee details you provided, or a third party such as HMRC, a bank, or the Open Banking Provider; and
- our total liability arising out of or in connection with the Service in any 12-month period is limited to the fees you paid us for the Service in that period.
Nothing in the Agreement excludes or limits our liability for death or personal injury caused by our negligence, for fraud, or for any other liability that cannot be limited by law.
16. Indemnity
You agree to indemnify us against reasonable losses and costs we suffer arising from your breach of the Agreement, your misuse of the Service, or your Customer Data infringing the rights of a third party or breaching applicable law.
17. Suspension and termination
- You may cancel your Subscription at any time; cancellation takes effect at the end of the current billing period.
- We may suspend or terminate access if you materially breach the Agreement, fail to pay, or use the Service in a way that risks harm to us, other Customers, or third parties.
- On termination your right to use the Service ends. Clauses that by their nature should survive (including data protection, intellectual property, liability, and governing law) continue to apply.
18. Changes to these Terms
We may update these Terms from time to time. The "Version" and "Last updated" fields above reflect the current version. For material changes we will give reasonable notice within the app or by email, and where appropriate we may ask you to accept the updated Terms. Continuing to use the Service after changes take effect means you accept the updated Terms.
19. Governing law and jurisdiction
The Agreement and any dispute arising out of it are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save that if you are a consumer you may also have the right to bring proceedings in the courts of the part of the United Kingdom in which you live.
20. Contact us
Registered in England and Wales, company number 16932110
Registered office: 3 Bower Close, Eaton Bray, Dunstable, LU6 2DU
VAT number: GB 517897246
Email: hello@sitelog.uk
See also our Privacy Policy.
Schedule 1 - Data Processing Addendum
This Data Processing Addendum ("DPA") applies where we Process Personal Data on the Customer's behalf as a Processor. It forms part of the Agreement. Where there is a conflict on data protection matters, this DPA prevails.
1. Roles and scope
The Customer is the Controller and Crintea LTD is the Processor of the Personal Data within Customer Data. We will Process that Personal Data only on the Customer's documented instructions (including as set out in the Agreement and as given through the Service's features), unless required by law, in which case we will tell you first unless the law prohibits it.
2. Subject-matter, duration, nature, and purpose
Subject-matter and duration: Processing for the term of the Agreement plus any retention period. Nature and purpose: hosting, storage, and processing of Customer Data to provide the Service, including project and workforce management, timesheets and payroll calculations, compliance records, invoicing and accounting, bank data reconciliation, payment initiation, and tax submissions.
3. Types of Personal Data and categories of Data Subject
Types of Personal Data may include: names, contact details, job roles, photographs, right-to-work and training records, timesheets and hours, pay rates, National Insurance numbers, tax codes, payroll and CIS figures, bank account details you enter, and bank transaction data. Categories of Data Subject may include: the Customer's Users, employees, site workers, subcontractors, and business contacts such as customers and suppliers.
4. Our obligations
- Process Personal Data only on the Customer's documented instructions;
- ensure persons authorised to Process the Personal Data are under an appropriate duty of confidentiality;
- implement appropriate technical and organisational security measures (see clause 5);
- respect the conditions in clause 6 for engaging Sub-processors;
- taking into account the nature of Processing, assist the Customer by appropriate measures to respond to Data Subject requests, and to meet its obligations on security, breach notification, data protection impact assessments, and prior consultation;
- at the Customer's choice, delete or return Personal Data at the end of the provision of the Service, and delete existing copies unless the law requires storage (see clause 8); and
- make available information reasonably necessary to demonstrate compliance and allow for and contribute to audits as set out in clause 9.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest; role-based access control and tenant isolation enforced at the database layer; least-privilege access to production systems; segregation of Customer accounts; logging and monitoring; and regular review of our controls. Bank login credentials are never received or stored by us; they are handled by the bank and our Open Banking Provider.
6. Sub-processors
The Customer authorises us to engage the Sub-processors listed in Schedule 2 to Process Personal Data. We impose data protection obligations on each Sub-processor no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended addition or replacement of a Sub-processor (for example by updating Schedule 2), giving the Customer the opportunity to object on reasonable data protection grounds.
7. Personal data breaches
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Customer's Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations.
8. Return and deletion
On termination the Customer may export Customer Data using the Service's tools. After a reasonable period we will delete or anonymise Customer Data containing Personal Data, unless retention is required by law (for example financial and tax records, which must be retained for the statutory period).
9. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once a year (unless required by a supervisory authority or following a breach), allow the Customer or its mandated auditor to verify compliance, subject to confidentiality and to not unreasonably disrupting our operations.
10. International transfers
Where Personal Data is transferred outside the UK, we will ensure an appropriate safeguard is in place, such as an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. Our primary data hosting is located in the UK or European Economic Area; see Schedule 2.
Schedule 2 - Sub-processors
We use the following Sub-processors to provide the Service. We may update this list on notice as described in Schedule 1, clause 6.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase | Application database and authentication (Customer Data hosting) | UK / EEA |
| Cloudflare (R2) | File and photo storage | UK / EEA |
| Netlify | Web application hosting and delivery | Global CDN |
| Stripe | Subscription payment processing | UK / EU / US |
| Plaid Financial Ltd | Open Banking - bank data access and payment initiation | UK / EEA |
| HM Revenue & Customs | VAT and CIS submissions (on your instruction) | UK |
| Push and email delivery providers | Transactional notifications and email | UK / EEA / US |
Sub-processor names and regions are provided for transparency and may change as our infrastructure evolves; the current list is maintained here.