Privacy
Privacy Policy
Last updated: 22 July 2026
FieldTaskora provides software that captures field-operations evidence and turns it into job records, safety documentation and reports. Handling that information carefully is core to what we sell, so we have tried to be specific in this policy rather than vague.
1. Who this policy applies to
This policy applies to FieldTaskora (“we”, “us”, “our”), whose place of business is Ireland. It explains how we handle personal information when:
- you visit or interact with our website at fieldtaskora.com;
- your organisation uses the FieldTaskora product, or you use it as a worker, supervisor or administrator;
- we deal with you as a prospective customer, supplier or contractor; and
- we carry out the ordinary activities of running our business.
Some parts of our product or our recruitment process may have their own, more specific privacy notice. Where that happens, the specific notice applies to that activity.
2. Controller and processor — an important distinction
Our role, and therefore our obligations, depend on whose data it is:
- We are the controller for personal information we handle for our own purposes — website visitors, enquiries, marketing contacts, suppliers and our own staff. This policy governs that information.
- We are the processorfor personal information inside a customer's workspace — their workers' details, the evidence their crews capture, and details of their own customers. The customer organisation is the controller of that data. We act on their documented instructions under our agreement with them, and their privacy policy governs it.
If you are a field worker whose employer uses FieldTaskora and you want to access or correct your data, the fastest route is usually your employer. You can still contact us and we will help direct the request.
3. The laws we work to
Because we are based in Ireland, our baseline is the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. We apply that standard to everyone's data, wherever they are, rather than running a weaker standard in some countries.
Where other regimes apply to a customer or an individual, we work to those as well — including the UK GDPR and Data Protection Act 2018, and, for our Australian customers, the Australian Privacy Principles in the Privacy Act 1988(Cth). We also comply with the electronic-marketing rules that apply where we are sending — the EU ePrivacy rules, and equivalents such as Australia's Spam Act 2003 (Cth).
Our information security is governed by an Information Security Management System aligned to ISO/IEC 27001, with independent certification in progress.
4. What we collect, and why
Website visitors and enquiries
If you submit a form on our website we collect your name, work email, organisation, an indication of team size and anything you write in the message, so that we can respond to you and — if you asked for early access — contact you when access opens. Our web host also processes standard technical information such as IP address and request logs for security and reliability.
Prospective customers
We collect business contact details of people at organisations that may need our product, from sources such as company websites, public professional profiles and business-data providers. We use these for business-to-business outreach only, and you can opt out at any time.
Customer users — workers, supervisors and administrators
On our customers' instructions we handle names, work contact details, phone numbers, role, licence and competency details, sign-in and device information, and the field evidence generated in the course of work — including photographs, voice notes, form responses, safety checks, timestamps and location data associated with a job.
Location and time data is central to the product's purpose: it is what makes a job record verifiable. Customers configure what is captured on their jobs.
End-customers of our customers
Job records may include the name, signature, contact details or property details of the person a job was done for, where the customer captures a sign-off.
Suppliers, contractors and applicants
We collect contact and account details of the people we work with, and the information necessary to assess and manage job applications and engagements.
5. Cookies and analytics
This marketing website uses only cookies that are strictly necessary for it to function. It does not run third-party advertising or analytics tracking, and it does not profile you across other websites.
The product itself uses a small number of strictly-necessary cookies for sign-in and security and — where the customer or user consents — product analytics to understand feature usage. Declining optional analytics does not affect the service.
6. How we use artificial intelligence
Your data is never used to train foundation models — ours or anyone else's.
The product uses AI to read and structure what crews capture: describing and tagging photographs, drafting job summaries, checking a job against the required evidence, and assembling reports. This processing runs on a managed AI service inside our own cloud environment, under terms that prohibit your data being used to train the underlying models.
AI outputs are drafts and aids, not decisions. They are intended to be reviewed by a person before being relied on, and we do not use AI to make decisions that produce legal or similarly significant effects about an individual.
7. Our legal bases for processing
Under the GDPR we rely on the following legal bases:
- Contract — to provide the product and support to the organisation that engaged us.
- Legitimate interests — to operate, secure and improve our service, to run business-to-business marketing, and to protect our legal position; balanced against your rights.
- Consent — for optional analytics and certain communications, which you can withdraw at any time.
- Legal obligation — where we must retain or disclose information to meet a legal or regulatory requirement.
8. Who we share information with
We do not sell personal information, and we do not disclose it for unrelated purposes without your authorisation. We use a deliberately short list of service providers to run the service, each bound by contract to protect the information and to act only on our instructions. They fall into these categories:
- Cloud hosting and infrastructure — hosting, storage, identity and sign-in.
- Managed AI services — the AI processing described in section 6, within our cloud environment.
- Communications — transactional email, including messages sent from this website's forms.
- Security and abuse prevention — bot protection and network security.
- Business tools — our own CRM and marketing systems. These handle our business contacts only, and are never used for customer workspace data.
We name the specific providers behind each category in our sub-processor list, which we make available to customers and to anyone evaluating us — see section 15 to request it.
We may also disclose information to professional advisers, or to law enforcement, regulators or other authorities where we are required to by law or where there is a legal or professional duty to do so. Our current sub-processor list is available to customers on request, and we notify customers of material changes as required by their agreement.
9. Where your data is stored
Customer data is hosted with a major cloud provider in enterprise-grade data centres. We can confirm the specific hosting locations for your account on request — see section 15.
Some personal information may be accessed from, or transferred to, other countries. We are based in Ireland, our team and contractors work from several countries — including Ireland, Australia, the United States and Chile — and some of our providers operate internationally.
Where personal data leaves the EEA we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with our providers' own transfer terms and a transfer risk assessment where one is required. Our providers are contractually bound not to handle the data inconsistently with this policy.
10. How we protect information
We run a formal Information Security Management System aligned to ISO 27001, with independent certification in progress. Our controls include:
- encryption in transit (TLS) and at rest, with field-level encryption for sensitive values;
- tenant isolation so one customer's workspace is separated from another's;
- role-based access control, multi-factor authentication and the ability for administrators to revoke sessions immediately;
- least-privilege access for our own staff, granted only where needed to support the service;
- logging, monitoring and backup; and
- staff training on privacy and security obligations.
No system can be guaranteed completely secure, but if a data breach occurs that is likely to result in serious harm we will act on it and notify affected parties and regulators as required — including under the Notifiable Data Breaches scheme. You can read more on our security page.
11. How long we keep it
- Customer job and evidence datais kept for the life of the customer's account because it is their compliance record, and is deleted or returned on their instruction in line with their agreement.
- Enquiry and prospect data is kept until it is no longer needed or you opt out.
- Operational logs are kept only as long as useful for security and reliability.
- Staff and financial records are kept for the periods required by law.
12. Your rights
Depending on where you are, you may have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- request erasure of your information;
- restrict or object to how we process it;
- receive a portable copy, or ask us to transfer it; and
- withdraw consent where our processing relies on it.
To exercise a right, contact us using the details in section 15. We will verify your identity before acting. Where the information sits inside a customer's workspace, we will pass your request to that customer as the controller, or act on their instruction.
13. Marketing and opting out
We may send you information about our product where you have asked for it or where it is permitted for business-to-business contact. Every marketing email includes an unsubscribe link, and you can also ask us to stop at any time using the details below. We will not use your information to market third parties' products.
14. Children
Our website and product are intended for business use and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, please contact us and we will delete it.
15. Contact us, and how to complain
For any privacy question, request or complaint, contact our privacy contact at privacy@fieldtaskora.com. For security-specific matters, including requesting our sub-processor list or a security review, contact security@fieldtaskora.com.
We take complaints seriously. We will acknowledge your complaint promptly, investigate it, and let you know the outcome.
If you are not satisfied with our response, you can complain to a data protection authority. Because we are established in Ireland, our lead supervisory authority is the Irish Data Protection Commission. You may also complain to the authority where you live or work — for example the UK Information Commissioner's Office in the United Kingdom, or the Office of the Australian Information Commissioner in Australia.
16. Changes to this policy
We will update this policy as our practices change, and the “Last updated” date above shows when the current version was published. Where a change is material we will take reasonable steps to tell affected customers. We encourage you to review this page periodically.