Privacy Policy
Field 2 Service
| Effective date | 6 September 2026 |
|---|---|
| Version | 1.0 |
| Applies to | field2service.com and all Field 2 Service websites, the Field 2 Service application, and the customer portal and public booking pages we host for our customers |
| Governing law | EU General Data Protection Regulation (EU) 2016/679 and the Data Protection Act 2018 (Ireland); UK GDPR and the Data Protection Act 2018 (United Kingdom), as amended by the Data (Use and Access) Act 2025 |
In short
- We are the controller of your data if you deal with us directly — you visit our website, ask us a question, open a Field 2 Service account, pay us, contact our support desk, or join our affiliate programme. This policy is about that data.
- We are only the processor of the data inside a customer's account. If a business you deal with uses Field 2 Service to manage its work, that business decides what it holds about you and why. It is the controller; we hold that data on its instructions. Contact that business first — see section 3.
- We do not use personal data to train any AI model, we do not provide it to anyone else to train theirs, and we do not sell it or share it for advertising. The terms on which the configured AI provider handles data sent to it, including its position on training, are recorded on our Sub-processor list — see section 13. Only one of the listed AI providers is engaged at a time; the platform console names which.
- Our website, the customer portal and the public booking page load no third-party resources at all — no analytics, no advertising tags, no third-party fonts.
- You have rights over your data, and you can complain to the Data Protection Commission (Ireland) or the Information Commissioner's Office (United Kingdom). See sections 10 and 12.
1. Who we are
Field 2 Service is field-service-management software operated by:
| Legal entity | Go Gadgets Ltd |
|---|---|
| Registered address | Cupidstown, Kilteel, Co. Kildare, Ireland |
| Company registration number | 565656 |
| General contact | hello@field2service.com |
| Privacy contact / Data Protection Officer | [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
We are established in Ireland. Our lead supervisory authority is the Irish Data Protection Commission. Because we also serve businesses in the United Kingdom, UK data protection law applies to that activity and the Information Commissioner's Office is the relevant regulator for people in the UK. Both are named in section 12.
ICO registration: [[OWNER: ICO registration number, if registered]]
We have not appointed an Article 27 representative, because we are established in the EU and therefore do not require an EU representative.
2. The two roles we hold — and why it matters
This is the most important thing to understand about our service, so we say it plainly.
When we are the controller. For everything you send us directly, we decide what is collected and why, and this policy governs it. That covers:
- visitors to our website who use the contact form;
- people who register for a trial or a subscription (the account holder);
- billing contacts for a paying account;
- people who contact our support desk;
- people who join our affiliate/partner programme;
- our own platform administrators.
When we are the processor. Businesses use Field 2 Service to run their own operations — their customers, their jobs, quotes, invoices, messages, photographs, and their own staff records. Each business decides what it puts in, why, how long it keeps it, and who it shares it with. That business is the controller; we are the processor and we act on its instructions. Its data is held in a separate database from every other customer's.
Our obligations as a processor are set out in our Data Processing Agreement, which forms part of the contract with every customer. It covers the security we apply, the sub-processors we use, how we help with data-subject requests, what happens when a customer's contract ends, and what we do if there is a security incident.
This policy does not describe how any individual business uses the data it holds about you. Only that business can tell you that.
3. If your data is inside a business's Field 2 Service account
If a tradesperson, contractor, service company or similar business holds your details because you are its customer — you booked a job, received a quote or an invoice, used its customer portal, or received a message from it — then:
- that business is the data controller, not us;
- its privacy notice, not this one, tells you what it does with your data;
- you should contact that business first to ask for a copy of your data, to correct it, to have it erased, or to object to how it is used;
- if that business gives you a customer-portal login, you can do two of those things yourself from the portal's privacy page: download a copy of what the business's account holds about you, and ask the business to erase you. The erasure is a request, not a switch — only the business can decide it, because only the business knows what it must keep for tax and legal reasons. Your request is recorded and the business is notified.
If you contact us instead, we will not answer your request as if we were the controller and we will not disclose the data to you. What we will do is pass your request on to the business without undue delay — normally within 3 business days — tell you that we have done so, and help that business respond. Write to hello@field2service.com with the name of the business and we will route it.
The one exception is data we hold about you as controller — for example, if you also emailed our support desk or used our website contact form. We answer those requests ourselves, under section 10.
4. What we collect
4.1 Website enquiries
When you use the contact form on our website we collect your name, email address, subject, message, the time of submission and your IP address. A copy is emailed to hello@field2service.com and a record of whether that email was delivered is kept.
Our website sets no cookies and loads no third-party resources. See section 14.
4.2 Trial and account registration
When you register we collect your name, business name, email address, country (all required), and, if you give them, your phone number, VAT number, chosen plan, preferred payment method, any notes you type, and the referral or promotion code you arrived with. We also record the date and version of the terms you accepted.
4.3 Your login and account security
We store your password as a bcrypt hash — never in a readable form. If you turn on two-factor authentication we store your authenticator seed encrypted and your recovery codes hashed. We record when your account was last active.
4.4 Billing
For a paying account we hold your subscription and invoice records (plan, amounts, currency, dates, payment method, VAT number where given) and the customer and subscription identifiers issued by our payment provider.
We never see or store your card number. Card details are entered on our payment provider's own hosted payment page and go directly to them.
4.5 Support
When you contact our support desk — from our website or from inside the application — we hold your name, email address, the category and subject you chose, your message, any files you attach, and the whole message thread, including our replies.
4.6 Affiliate and partner programme
If you join our affiliate programme we hold your name, email address, your password as a hash, your payout details (account name, bank name, IBAN, account number, sort code, BIC/SWIFT and/or PayPal email address, as you choose to supply them), and your commission and payout records.
4.7 Security and technical records
We keep an activity log of changes made in the application, recording who made the change, what changed, when, and the IP address it came from. Administrative actions on our platform are logged separately. Failed login attempts are counted temporarily to enforce rate limits; that counter is transient and is not kept as a permanent record. Our servers also produce application error logs.
4.8 What we do not collect
- We do not collect any special-category data (health, racial or ethnic origin, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation) or criminal-offence data through our website forms, our signup or our support desk. Please do not send it to us.
- We do not collect date of birth or age, and we perform no age verification. See section 15.
- We run no analytics, advertising, profiling or lead-enrichment tools of any kind.
5. Why we use it, and our legal basis
| # | What we do | Data used | Legal basis |
|---|---|---|---|
| 1 | Create your account, provision your workspace, let you log in, and provide the service you signed up for | 4.2, 4.3 | Contract — GDPR Art. 6(1)(b). Necessary to perform our contract with you, or to take steps at your request before entering it |
| 2 | Take payment for your subscription, issue invoices, chase unpaid invoices, and manage suspensions and cancellations | 4.2, 4.4 | Contract — Art. 6(1)(b) |
| 3 | Keep accounting, tax and VAT records | 4.4 | Legal obligation — Art. 6(1)(c). Companies Act 2014 (Ireland) and VAT record-keeping requirements; the equivalent UK requirements where they apply |
| 4 | Send you service messages — account invitations, password resets, billing notices, suspension and cancellation notices, security notices, and notice of changes to our terms, this policy or our sub-processors | 4.2 | Contract — Art. 6(1)(b). These are not marketing and you cannot unsubscribe from them while you hold an account |
| 5 | Answer an enquiry you send us through the website contact form | 4.1 | Contract — Art. 6(1)(b) where you are asking about buying or trialling the service (steps at your request before a contract). Otherwise legitimate interests — Art. 6(1)(f): answering a question that you have addressed to us |
| 6 | Run our support desk and keep a record of the conversation so we can follow up and improve our answers | 4.5 | Contract — Art. 6(1)(b) for account holders. Legitimate interests — Art. 6(1)(f) for everyone else: responding to a request for help that you have addressed to us |
| 7 | Keep the service secure — rate-limit our forms and login pages, resist automated abuse and credential-stuffing, and keep an audit trail of changes and administrative actions | 4.1, 4.7 | Legitimate interests — Art. 6(1)(f): protecting our service, our customers and the personal data in it from unauthorised access, fraud and abuse, and being able to investigate if something goes wrong |
| 8 | Attribute a signup to the affiliate or promotion code you arrived with, and calculate the commission owed | 4.2, 4.6 | Contract — Art. 6(1)(b) for our agreement with the affiliate partner. The referral code stays in the web address as you move between pages on our site and is read from it at the moment you submit the sign-up form. It is not stored in your browser, and if you never submit the form it is never recorded |
| 9 | Register affiliate partners, pay commission, and keep the associated financial records | 4.6 | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for the accounting records |
| 10 | Provide the service to our business customers as their processor | the data in their account | Determined by that customer as controller. Our instructions come from them and from our Data Processing Agreement |
| 11 | Comply with the law, respond to lawful requests from authorities, and establish, exercise or defend legal claims | any of the above, as strictly necessary | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f): defending our legal position and enforcing our agreements |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your interests, rights and freedoms. You can object at any time — see section 10 — and you can ask us for our assessment.
We do not use any of this data for marketing to you without your consent, and we operate no marketing mailing list. We do not use personal data to train any AI model, we do not provide it to anyone else to train theirs, and we do not sell it or share it for advertising.
6. Do you have to give us this data?
You are never under a statutory obligation to give us personal data. Some of it is a contractual requirement, in the sense that we cannot do what you are asking without it:
| Where | Required | Optional | If you do not provide the required data |
|---|---|---|---|
| Trial / account registration | Name, business name, email address, country | Phone, VAT number, notes, plan, payment method, referral code | We cannot create an account or provision a workspace for you |
| Website contact form | Email address, message | Name, subject | We cannot reply to you |
| Support desk | Email address, message | Name, subject, category, attachments | We cannot open or answer a ticket |
| Affiliate programme | Name, email address, password | Payout details (until you want to be paid) | We cannot register you, and we cannot pay commission without payout details |
| Subscription billing | Payment details, entered on our payment provider's page | — | We cannot take payment, and the subscription cannot start or continue |
7. Who we share it with
We share personal data only with the providers we need in order to run the service, and only with the data they need. Most of them act on our instructions and are not permitted to use it for their own purposes; the few that act on their own account, or that a business chooses for itself, are separated out in section 7.3 rather than mixed in with the rest.
We keep two separate lists, because they are two different populations of data. The definitive, dated list — with each provider's legal entity, the categories of data it receives, its country and its transfer mechanism — is our Sub-processor list. What follows is the summary.
7.1 Providers that receive data about you as an account holder, enquirer, support contact or partner
(Field 2 Service is the controller of this data.)
| Recipient | What it receives | Why |
|---|---|---|
| Our hosting provider — [[OWNER: hosting provider and data-centre location]] | All data stored by the service, as the infrastructure it runs on | Hosting the application and databases |
| Stripe | Your subscription billing: amount, currency, invoice description, your email address, and the customer/subscription identifiers | Taking payment for your Field 2 Service subscription |
| Our outbound email provider (named on the Sub-processor list) | Your name and email address, and the content of the account email being sent — invitations, password resets, billing and suspension notices | Delivering account email to you |
| Professional advisers — accountants, auditors, lawyers, insurers | Only what is necessary, and under a duty of confidence | Running the business, tax and legal advice |
| Public authorities, regulators and courts | Only what we are legally required to disclose | Complying with the law |
| A buyer or successor, if the business is sold or reorganised | The data necessary for the transaction, under confidentiality | Business transfer — you would be told before your data was transferred |
7.2 Providers reached when a business uses the product
(Field 2 Service is the processor of this data; the customer business is the controller. Each of these is engaged only if that business turns on the corresponding feature.)
| Recipient | What it receives | Engaged when |
|---|---|---|
| Stripe | Invoice description, amount, currency and the paying customer's email address | The business enables Stripe card payments |
| Twilio | The recipient's phone number and the full text of the SMS, which may include a customer name and job or appointment details | The business configures SMS |
| The configured AI provider — one of Anthropic PBC, X.AI LLC, or OpenAI OpCo, LLC / OpenAI Ireland Ltd. The live name is on the Sub-processor list and in the platform console | Whatever the AI feature needs to answer the request — this can include customer names, email addresses, phone numbers, addresses, job titles, descriptions and notes, quote and invoice figures, staff schedules, and photographs uploaded to a job or receipt | The business enables the AI assistant, and each time it is used, and only the configured provider is engaged. Switching the AI features off, or a platform per-tenant opt-out, means no Customer Personal Data is sent to any AI provider. See section 13 |
| Google (fonts and maps loaded in the browser) | The IP address and browser details of the member of staff using the application. These are browser requests made by the staff application only, and Google is the only company they reach | A member of staff opens the staff application |
The customer portal, the public booking page and our marketing website load nothing from third parties. Only the staff application does.
7.3 Recipients that act on their own account, not ours
Two of the providers a business can switch on are not our processors. PayPal and Google Maps Platform decide for themselves how they handle the data they receive, under their own terms with the business and with you — we pass them the minimum the feature needs and nothing more. Anything a business sends to a webhook endpoint it has configured is that business's own transfer.
| Recipient | What it receives | Engaged when |
|---|---|---|
| PayPal | Order amount, currency, invoice description and reference identifiers (no customer email address) | The business enables PayPal payments |
| Google Maps Platform | Address and postcode text for lookup, and job origin/destination addresses for travel-time estimates | The business uses address lookup or travel-time features |
| The business's own email provider | The recipient's address, the subject, the body and any attached PDF documents | The business configures its own outgoing email, using its own credentials |
| Any webhook endpoint the business configures (for example Zapier) | Full records, including complete customer records on customer events | The business sets up a webhook. This is an onward transfer the business chooses and is responsible for |
8. International transfers
Some of the providers above are outside the European Economic Area, principally in the United States. Where personal data leaves the EEA or the UK, we rely on one of the following, in this order:
- An adequacy decision — including the EU–US Data Privacy Framework, or its UK Extension, where the receiving organisation is currently certified under it for the type of data concerned; or
- Standard contractual clauses — the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914) for data from the EEA, and the ICO's International Data Transfer Agreement, or the UK Addendum to the EU clauses, for data from the United Kingdom — supported by a transfer risk assessment. The EU clauses alone are not valid for UK data, which is why we use the UK instruments as well.
Transfers between Ireland and the United Kingdom are covered by adequacy decisions in both directions and need no additional safeguard.
The mechanism that applies to each individual provider — and the date we last verified it — is recorded against that provider on our Sub-processor list. Certifications can lapse, so we record the mechanism per provider rather than making a single blanket claim here.
To obtain a copy of the safeguards we rely on for any transfer, email hello@field2service.com and we will send you the relevant clauses, redacted only where necessary to protect confidential commercial terms.
9. How long we keep it
| Data | How long we keep it |
|---|---|
| Website contact-form enquiries (4.1) | 24 months from your last contact with us, then deleted. Since 6 September 2026 an enquiry stores a one-way fingerprint of the IP address rather than the address itself, and a daily sweep removes expired enquiries automatically where the site's private storage directory is configured on the host; where it is not, the 24 months rest on our half-yearly manual review. Enquiries recorded before 6 September 2026 still hold the raw IP address until they expire |
| Account records — the account holder's name, business name, email, phone, country, terms acceptance (4.2, 4.3) | For as long as the account exists, and for 6 years after it closes, because the account record is part of our contractual and accounting record |
| Billing, invoice, subscription and affiliate-commission records (4.4, 4.6) | 6 years from the end of the financial year they relate to, as required by Irish company and tax law (and the equivalent UK requirements where they apply) |
| Affiliate payout details — bank and PayPal details (4.6) | For as long as you are a partner. Deleted on request once no payment is outstanding; the record of payments made is kept for the 6 years above |
| Support tickets and their attachments (4.5) | 24 months after the ticket is closed, or for the life of the account if longer. Deletion is carried out by a manual review, not automatically |
| Application activity log and administrative audit log (4.7) | For the life of the account. These are our security and accountability record; we do not currently delete them automatically |
| Application error logs | Held on the server. They are not rotated or deleted automatically |
| Login session | 2 hours, then the session expires |
| Password-reset link | 1 hour |
| Staff invitation link | 7 days by default; the business can change this |
| Failed-login counters | The counter that enforces the rate limit is transient, held in a short-lived cache. Since 6 September 2026 the event is also written to a durable security-event record — the time, the IP address, the browser's user-agent string and the account the attempt named — so that an attack leaves evidence behind. An attempt against an address that matches no account is not recorded at all, because such a row could not be attributed to any one business. It holds no email address, password, code or token. It has no automatic deletion period today |
| Data inside a customer's account | Decided by that customer, not by us. Our retention obligations to them are in the Data Processing Agreement; some retention windows are settings the business controls |
Where our hosting arrangements include backups, deletion takes effect in the live systems immediately and works through to backup copies on that provider's ordinary backup cycle. Our hosting arrangements are with [[OWNER: hosting provider and data-centre location]].
Since 6 September 2026 we also take our own encrypted backups of the databases, using a key kept separately from the application's own, recording the size and checksum of each backup, and keeping thirty days of them — never fewer than one copy per database. We can decrypt and re-read a backup, and restore one into a scratch database to check it. Being straight about the limits: no copy is held off-site yet, no key custody arrangement is in place, we state no recovery time or recovery point, and no restore rehearsal has been carried out on the live host. We make no backup or disaster-recovery commitment on the strength of it.
10. Your rights
Over the data for which we are the controller, you have the right to:
| Right | What it means | Article |
|---|---|---|
| Access | Ask whether we hold data about you, get a copy of it, and be told why we hold it, who we share it with, and how long we keep it | Art. 15 |
| Rectification | Have inaccurate data corrected, and incomplete data completed | Art. 16 |
| Erasure | Have data deleted where we no longer have a good reason to hold it. We may have to keep some records — for example accounting records for the statutory period, or the record of a dispute | Art. 17 |
| Restriction | Ask us to stop using data while a dispute about its accuracy or our legal basis is resolved. We do not have an automatic "restrict" switch, so we do this by hand — it is effective, but it is a manual process | Art. 18 |
| Portability | Receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider where that is technically feasible | Art. 20 |
| Objection | Object to processing we base on legitimate interests, including profiling. We will stop unless we can show compelling legitimate grounds that override your interests, or we need the data for legal claims | Art. 21 |
| Objection to direct marketing | An absolute right. We do not market to you without consent, but if we ever do, you can stop it at any time and we must comply | Art. 21(2)–(3) |
We will also tell each recipient we have disclosed your data to about any correction, deletion or restriction, unless that proves impossible or involves disproportionate effort.
How to exercise them
Email hello@field2service.com, or write to us at the address in section 1. Say which right you are exercising and give us enough detail to find your records.
- We respond without undue delay, and in any event within one month of receiving your request.
- If your request is complex, or you have made several, we may extend that by up to two further months. We will tell you within the first month if we need to, and why.
- There is no charge. We may charge a reasonable fee, or refuse, only if a request is manifestly unfounded or excessive — and it is for us to show that it is.
- If we have reasonable doubts about who you are, we may ask for enough information to confirm it. We will ask for the minimum needed and will not use it as an obstacle.
- If we do not act on your request, we will tell you within one month why not, and that you can complain to a supervisory authority and seek a judicial remedy.
We handle these requests ourselves. There is no self-service export or deletion button for the data we hold about you as controller: we record each request in our internal data-subject-request register, which tracks the one-month deadline and the ground for any refusal or extension, and we assemble the extract with our own tooling. Please allow us the time above rather than expecting an immediate automated answer.
Inside a business's Field 2 Service account it is different: if that business has given you a customer-portal login, you can download a copy of your data and lodge an erasure request from the portal yourself — see section 3.
If your data is inside a business's Field 2 Service account, these rights are exercised against that business, not against us — see section 3.
11. Withdrawing consent
We do not rely on consent for anything. Every purpose in section 5 runs on contract, legal obligation or legitimate interests, and our website stores nothing that requires your consent. If that ever changes, this section will tell you what we ask consent for and how to withdraw it — and withdrawing will be as easy as giving it.
That is true of every surface we operate, including the staff application our customers' own staff sign in to: everything it stores in a browser is either strictly necessary or a record of a choice that member of staff made. Every item is listed by name, purpose and lifetime in our Cookie Policy, which also explains how to clear it.
Service emails about your account (row 4 of the table in section 5) are not based on consent and cannot be switched off while you hold an account — they include security and billing notices you need to receive.
12. Complaints
Please tell us first — email hello@field2service.com and we will try to put it right. You do not have to come to us first, and doing so does not affect your right to go to a regulator at any time.
If you are in the European Union or the EEA, or you are unhappy with how we have handled your data under EU law:
Data Protection Commission (Ireland) How to contact the DPC and how to make a complaint: www.dataprotection.ie/en/contact/how-contact-us
You may also complain to the supervisory authority in the EU country where you live or work, or where the problem happened.
If you are in the United Kingdom, or you are unhappy with how we have handled your data under UK law:
Information Commissioner's Office (United Kingdom) Helpline 0303 123 1113 · www.ico.org.uk/make-a-complaint
A note for people in the UK. UK law requires us to make it easy for you to complain to us about how we handle your personal data, to acknowledge your complaint within 30 days, and to tell you the outcome without undue delay. Send a complaint to hello@field2service.com with "Data protection complaint" in the subject line; we will acknowledge it within 30 days, keep you informed, and tell you the outcome and what we have done. The ICO normally expects you to have raised it with us first.
You also have the right to an effective judicial remedy against us or against a supervisory authority.
If you are anywhere else in the world, the regulator you can complain to, and any rights your local law gives you beyond those in section 10, are in the jurisdiction addendum at section 19.
13. Artificial intelligence and automated decisions
For the data we hold as controller — your account, your billing, your enquiry, your support ticket, your affiliate record — we make no automated decisions. Nothing is decided about you solely by automated means, there is no profiling, no automated scoring, and no automated acceptance or refusal of an application. A person decides.
About the AI features inside the product, for transparency, and because our customers ask:
- The AI assistant works by proposing and then asking a person to confirm. Changes it suggests are held as proposals and are applied only when a user presses Confirm. Every applied change is logged and can be undone.
- There are hard limits enforced by our software, not by the AI: no more than 10 proposed changes and no more than 5 destructive actions in a single exchange, whatever the AI is asked to do.
- The AI available to a business's own customers through the customer portal is read-only, is limited to the single signed-in customer's own records, and is off unless the business turns it on.
- There is one optional exception: a scheduling "auto-pilot" that a business can switch on for its dispatch board. When it is on, up to six scheduling actions per exchange — reassigning or re-sequencing work between that business's own engineers — apply without a confirmation step. It is off by default, it cannot touch money or delete anything, and every action is logged and reversible. Whether to enable it is the business's decision, and it is the business — not us — that must tell its staff about it.
- We do not use personal data to train any AI model, we do not provide it to anyone else to train theirs, and we do not sell it or share it for advertising. The AI features use the configured provider named on our Sub-processor list and in the platform console (one of Anthropic PBC, X.AI LLC, or OpenAI OpCo, LLC / OpenAI Ireland Ltd.). The terms on which that provider handles data sent to it, including its position on training and retention, are recorded on that list, with the date we last checked them. Only that one provider is engaged; switching the features off, or a platform per-tenant opt-out, means no Customer Personal Data is sent to any of them.
- Images uploaded to the AI assistant are stored outside our web root and deleted automatically after 60 minutes.
Where a business uses these features on data about you, that business is the controller and is responsible for telling you about it in its own privacy notice.
14. Cookies and browser storage
- Our marketing website sets no cookies, loads no third-party resources and stores nothing in your browser except a note that you dismissed our storage notice.
- The application and the customer portal use two strictly necessary first-party cookies: one to keep you logged in, and one security token that protects forms from cross-site request forgery. Both expire after 2 hours. There is no "remember me" cookie and no analytics or advertising tag anywhere in the application. The application and the portal also keep an unsaved form you are typing in your own browser for up to 7 days, so a refresh does not lose your work.
- The staff application — the part used by our customers' own staff — additionally loads fonts and maps from Google, as listed in section 7.2. Nothing it stores in a browser requires consent.
The full, itemised list — every cookie and every piece of browser storage, with its name, purpose, lifetime and whether it needs your consent — is in our Cookie Policy, which also explains how to clear or block any of it.
15. Children
The service is not intended for children. We do not knowingly collect personal data from children. Our customers are instructed not to enter a child's personal data into the platform. Where we hold such data as controller we will delete it on request; where it sits inside a customer's account, that customer is the controller and we will pass the request to them and carry out the erasure on their instruction. Where local law sets a specific age of consent, that law applies to our customer as the controller of the record.
Field 2 Service is a business-to-business service. It is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect personal data from children.
We should be clear about what that means in practice: we collect no date of birth and perform no age verification anywhere in our website, our signup, our support desk or the product. Our statement is about who the service is for, not a technical control that filters children out.
If you believe a child's personal data has reached us, email hello@field2service.com and we will look into it and delete it where we hold it as controller. If it is inside a business's account, we will pass the matter to that business — see section 3.
16. How we protect personal data
These are the measures we actually operate. We have deliberately not listed anything we do not do.
Keeping accounts separate
- Every customer's data lives in its own database. One class is responsible for connecting to a customer's database, and until a customer has been positively identified, the application is pointed at a database that does not exist — so a stray query fails rather than reading someone else's data.
- Every query inside the application is additionally scoped to the customer's own company record.
- The AI is locked to the calling customer's data, and for a field engineer, to that engineer's own jobs.
Accounts and access
- Passwords are stored as bcrypt hashes, never in readable form, and are removed from the session and from every API and AI response.
- Two-factor authentication using standard time-based one-time codes is available; seeds are encrypted at rest and recovery codes are stored hashed.
- Stored secrets — outgoing email passwords, payment API keys, OAuth tokens — are encrypted at rest (AES-256 with an HMAC-SHA-512 integrity check) and decrypted only at the moment they are used. They are never written to a log.
- Roles and permissions limit what each user can see and do.
Resisting attack
- Rate limits on the paths attackers target: 5 login attempts per IP address and 5 per email address in 10 minutes; 20 password-reset requests per hour per IP address and 5 per hour per email address; 5 customer-portal login attempts per IP address in 10 minutes; 5 website contact-form submissions per hour per IP address.
- We never reveal whether an account exists. Login, password reset, portal reset and signup all return the same response either way.
- Cross-site request forgery protection on every request that changes data, with a randomised token. The few public forms that cannot carry one — signup, public booking, support intake — are protected by origin checks, a hidden honeypot field and per-IP throttling instead.
- Session cookies are HttpOnly, SameSite=Lax and Secure in production, and expire after 2 hours.
- Public payment and quote links are unforgeable: each carries an HMAC-SHA-256 signature that cannot be guessed or constructed. Since 6 September 2026 they also expire — 90 days from issue by default, and the business can change that — and can be revoked one at a time, or all of one customer's at once. We store only a one-way hash of each link, so the register behind them cannot be turned back into links.
- Since 6 September 2026 security-relevant events — failed sign-ins, lockouts, password changes, two-factor removals, API-key changes, data exports, bulk permanent deletions and content-security-policy violations — are written to a durable record that nothing in the application updates or deletes, and four alert rules fire on it: repeated failed sign-ins from one address, one address attacking several accounts, an export outside working hours, and a batch of twenty-five or more permanent deletions. We do not describe this as monitoring, and §19.15 says exactly what it is not.
- Every change to a customer's email or SMS contact preference is recorded — the old and new value, where the change came from, who made it and from which IP address.
- Uploaded files are stored outside the web root and are not directly reachable by URL.
- The application sends anti-framing and strict-transport-security headers.
Accountability
- Every change is logged — who made it, what changed, when, and from which IP address. Administrative actions on our platform are logged separately.
- Data is encrypted in transit by TLS.
What we do not claim. We do not hold ISO 27001, SOC 2 or any other independent security certification, and we do not claim to. No system is perfectly secure; if something does go wrong, we have committed to our business customers, in the Data Processing Agreement, to tell them without undue delay so they can meet their own obligations.
17. Changes to this policy
We may update this policy — for example when we add a feature, change a provider, or the law changes.
- The version number and effective date at the top always tell you which version you are reading.
- If we make a material change, we will tell account holders by email and in the application before it takes effect.
- If we ever want to use personal data we already hold for a genuinely new purpose, we will tell you about that new purpose, and give you the information in this policy that relates to it, before we start — and where the new purpose needs your consent, we will ask for it.
- Changes to the providers we use are announced on the Sub-processor list in advance, as set out in our Data Processing Agreement.
18. Contact us
| Reason | Where to write |
|---|---|
| Anything about this policy, or to exercise a right | hello@field2service.com |
| Privacy contact / Data Protection Officer | [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
| Data held by a business that uses our software | That business, first — see section 3 |
| Post | Go Gadgets Ltd, Cupidstown, Kilteel, Co. Kildare, Ireland |
Related documents: Terms of Service · Data Processing Agreement · Sub-processor list · Cookie Policy · Acceptable Use Policy · Government and law-enforcement requests
19. Jurisdiction addendum
19.0 How this section works
We apply the GDPR standard to everyone, everywhere. Where your local law gives you rights beyond it we honour those rights, and they are listed below. We do not claim to be subject to a law that does not apply to us; where a law does apply to us directly it is named.
Everything in sections 1 to 18 applies to you wherever you are. The European standard is the strictest of the regimes we have looked at on almost every point — the reasons we may hold data, the terms we impose on providers, the rights you have, and the way data may cross a border — so applying it to everyone means nobody gets a weaker standard because of where they live.
But it is not strictest on every point, and this section is where we say so. Each entry below states three things and nothing more: the rights your law gives you beyond the ones in section 10; the regulator you can complain to; and how your data reaches us in Ireland lawfully. Where your law imposes a duty on us directly, we name the provision. Where it imposes the duty on the business whose account holds your data, we say that instead, and section 3 tells you what to do about it.
One rule governs the whole section. We say "we comply with" a law only where that law binds us directly and our software can actually meet it. Everywhere else we say either "your law gives you the following rights, which we honour" or "this is your provider's obligation, and here is how we support them in meeting it". Anything our software cannot do is written as a limitation, in section 19.15, and not dressed up.
19.1 United Kingdom
| Rights beyond section 10 | None. UK GDPR and the Data Protection Act 2018 give the same rights as the EU regime |
|---|---|
| Extra duty we take on | UK law requires us to make complaining to us easy, to acknowledge a complaint within 30 days and to tell you the outcome without undue delay — see section 12 |
| Regulator | Information Commissioner's Office — www.ico.org.uk/make-a-complaint · helpline 0303 123 1113. ICO registration number: [[OWNER: ICO registration number, if registered]] |
| How your data reaches Ireland | Adequacy decisions run in both directions between the UK and the EEA, so no additional safeguard is needed |
⚠ The UK's adequacy finding in favour of the EEA was not verified from a primary source in the research behind this section; the EU's finding in favour of the UK was. Both are recorded in section E of the owner notes.
19.2 United States — California
California is treated separately from the other states because it is the only US state privacy law that does not exempt business contacts or staff records. Its business-to-business and employment exemptions (Civ. Code §1798.145(m) and (n)) both became inoperative on 1 January 2023, so a Californian business's staff records and its business customers' contact details are fully within the CCPA.
| Rights beyond section 10 | The right to opt out of the sale or sharing of personal information; the right to limit the use of sensitive personal information; and the right to non-discrimination for exercising a right. California has no separate portability right — it sits inside the right to know |
|---|---|
| What we are | For a Californian business using our software we are a service provider, and we contract on the ten terms 11 CCR §7051(a) requires — they are in section 18 of our Data Processing Agreement. We are not a "business" under Civ. Code §1798.140(d): we meet none of its three thresholds and we do not expect to |
| ⭐ Why there is no "Do Not Sell or Share My Personal Information" link | Two independent reasons, and we would rather explain them than post a link that does nothing. First, Civ. Code §1798.135 binds a "business", and we are not one. Second, the duty is triggered by selling or sharing, and we do neither — every provider on our Sub-processor list is operational, none is an advertising network, and no page we operate carries an advertising or analytics tag |
| A duty that binds us with no threshold | Civ. Code §1798.82(b): anyone who maintains computerised data it does not own must notify the owner immediately following discovery of a breach. That is how our Data Processing Agreement is drafted — immediately, with no risk filter applied at our end, and in no event later than twenty-four hours |
| Regulator | California Attorney General — oag.ca.gov/privacy/ccpa · and the California Privacy Protection Agency — www.cppa.ca.gov. Those two enforce the CCPA's general obligations. ⚠ Separately, Civ. Code §1798.150 gives a California resident a direct right to sue over a breach of unencrypted, unredacted personal information, with statutory damages per consumer per incident; that right is not affected by anything in this policy |
| How your data reaches Ireland | The CCPA contains no cross-border transfer restriction at all, so no instrument is required |
| How to exercise | Email hello@field2service.com. If your data is inside a business's account, that business is the "business" for CCPA purposes and we will route your request to it and tell you we have done so — 11 CCR §7050(c) requires exactly that of a service provider, and section 3 explains it |
19.3 United States — the other states
Twenty-two other states have enacted comprehensive consumer privacy laws that we have examined — twenty-three including California, or twenty-four if Florida's narrower Digital Bill of Rights is counted. Eighteen of those twenty-two, together with California, are in force today; the remaining four take effect between 2027 and 2028. Their rights are near-identical, so we state them once rather than twenty-two times, and we honour them for any US resident who asks — whichever state you are in, and whether or not your state's law happens to reach us.
| Rights we honour | Confirm and access the personal data we hold about you · correct inaccuracies · delete it · obtain a portable copy in a readable format where processing is automated · opt out of its sale, of targeted advertising and of profiling with legal or similarly significant effects · and appeal a refusal |
|---|---|
| Response time | 45 days, which we may extend once by a further 45 days where the request is complex, telling you why inside the first period |
| ⭐ How to appeal | If we refuse a request, we will tell you why and how to appeal. Reply to that answer with "Appeal" in the subject line to hello@field2service.com. We respond to an appeal within 60 days, in writing, with our reasons — and if we still refuse, we will give you a way to complain to your State Attorney General |
| Regulator | Your State Attorney General, who is the sole enforcer in every one of these states. Some route consumer complaints through a consumer-protection division first — Utah through the Division of Consumer Protection, Maryland through the Division of Consumer Protection, Delaware through the Department of Justice, Oregon through the Department of Justice (www.doj.state.or.us), New Jersey through the Division of Consumer Affairs (www.njoag.gov), Colorado through the Attorney General (coag.gov) |
| ⚠ No private right of action | None of these comprehensive privacy laws creates a right for an individual to sue over a breach of it; enforcement is by the Attorney General. ⚠ Two qualifications: in Nebraska and Alabama the statutes contain no express exclusion and we state no position; and a state's separate breach-notification statute may allow a claim — Virginia's, for example, expressly preserves recovery of direct economic damages |
| How your data reaches Ireland | None of these laws restricts international transfers. There is nothing to put in place |
| ⚠ Business and employment contacts | Every one of these laws excludes an individual acting in a commercial or employment context, so if you deal with us as the owner, a director, an employee or a contractor of a business, you are generally not a "consumer" under them. We honour the rights above anyway, but we say this plainly rather than implying a statutory footing we do not have |
| ⚠ Opt-out preference signals (Global Privacy Control) | Several states require a business to honour a browser opt-out signal. We do not read the signal, and we say so. There is nothing on any page we operate for such a signal to switch off: we set no analytics or advertising storage, we never sell personal data, we never share it for advertising, and we do not carry out targeted advertising or profiling. The outcome the signal exists to produce is the outcome you already get. If we ever add anything a signal would control, we will implement the signal first — see section 19.15 |
19.4 Canada
| Rights beyond section 10 | Access to your personal information and the right to challenge its accuracy; the right to challenge our compliance with the fair information principles; and the right to withdraw consent, subject to legal and contractual restrictions. Canadian federal law has no general right to erasure and no portability right — where you ask for either, we will apply the European standard in section 10 anyway |
|---|---|
| Response time | 30 days, which the law lets us extend by a further 30 days where necessary. We will tell you if we need to |
| ⭐ The foreign-processing warning | Canadian guidance requires us to tell you this in plain language, and European law does not, so it is stated here in full: your personal information is processed outside Canada, in Ireland and in the other countries named on our Sub-processor list. While it is there it is subject to the laws of those countries, and may be accessible to their courts, law enforcement agencies and national security authorities under those laws. Our Government and law-enforcement requests policy says what we do when such a request reaches us — in short, we require a valid legal instrument, we tell the affected customer first unless we are legally prohibited, we challenge a request that appears unlawful or excessive, and we disclose only the minimum required |
| Regulator | Office of the Privacy Commissioner of Canada — www.priv.gc.ca. ⚠ You must raise the matter with us first; the OPC will not normally take a complaint you have not brought to us. The OPC issues non-binding findings, after which you may apply to the Federal Court, which can award damages |
| How your data reaches Ireland | Canada has no adequacy list and no standard clauses. Sending personal information to a processor abroad is treated as a use, not a disclosure, so no additional consent is required. What is required is a contract achieving a comparable level of protection — our Data Processing Agreement does considerably more than that — and the disclosure above |
| Who is accountable | We have designated an individual accountable for our compliance: [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
19.5 Canada — Quebec
Quebec's Law 25 is the most demanding privacy regime in Canada and several of its rights have no European equivalent.
| Rights beyond section 10 | Portability of the computerised information you gave us, in a structured and commonly used technological format — narrower than the European right, because it covers what you provided rather than what we inferred · cessation of dissemination or de-indexing, where our dissemination of information about you causes you serious injury · and, where a decision about you is based exclusively on automated processing, the right to be told at the latest when the decision is communicated to you, to have the information used corrected, to present your observations to a member of our staff who can review the decision, and to have the decision reviewed by a person. Quebec attaches no "legal or similarly significant effects" threshold to that notice — it is unconditional |
|---|---|
| Children | Personal information about a minor under 14 may not be collected without the consent of a parent or guardian. We do not knowingly collect it — see section 15 |
| ⭐ Person in charge | Quebec requires the title and contact details of the person in charge of the protection of personal information to be published. Ours: [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
| Regulator | Commission d'accès à l'information du Québec — www.cai.gouv.qc.ca. A complaint must be in writing. ⚠ The CAI has told the public that it cannot order an organisation to pay damages — that is for the courts |
| How your data reaches Ireland | Quebec has no adequacy list and no approved standard clauses. The mechanism is that your provider, before entrusting your information to us outside Quebec, must complete a privacy impact assessment (an évaluation des facteurs relatifs à la vie privée) covering the sensitivity of the information, the purpose, the protective measures including contractual ones, and the legal regime in Ireland; conclude that the protection is adequate; and enter a written agreement tethered to what that assessment found. Section 26 of our Data Processing Agreement is drafted for exactly that, and we keep a standing support pack — a data map, the sub-processor list, our security measures and a summary of the Irish and European legal regime — that a Quebec provider can use to complete it |
19.6 Brazil
| Rights beyond section 10 | The Article 18 list, of which four go beyond the European rights: blocking — you may ask us to block data that is unnecessary, excessive or processed unlawfully, as a remedy in its own right, without asking for deletion · ⭐ the identities of the public and private entities with which we have shared your data — the actual entities, not categories · information about the possibility of not giving consent, and what happens if you refuse · and the right to complain to a consumer-protection body (Procon) as well as to the regulator |
|---|---|
| Response time | Confirmation that we hold data about you, or access to it in simplified form, immediately; a full declaration within 15 days. Free of charge — Brazilian law gives us no fee escape |
| ⭐ Who is responsible for what | Brazilian law requires this to be published, and European law does not. For your own account data we are the controlador. For data inside a business's Field 2 Service account that business is the controlador and we are the operador — we act on its instructions, and section 3 tells you how to reach it |
| Our contact point | [[OWNER: privacy/DPO contact or statement that no DPO is required]], published here as the encarregado |
| Regulator | Autoridade Nacional de Proteção de Dados (ANPD) — www.gov.br/anpd. ⭐ You may also take the matter to a Procon consumer-protection body, which is a separate route with no European equivalent |
| ⭐ How your data reaches Ireland | ANPD Board Resolution No. 32 of 26 January 2026 recognises the European Union as providing an adequate level of protection. Transfers from Brazil to Ireland therefore rest on Article 33, item I, and need no Brazilian standard contractual clauses, no binding corporate rules and no specific consent. Our Data Processing Agreement says so rather than bolting on clauses Brazilian law no longer requires |
19.7 Australia
| Rights beyond section 10 | ⭐ Anonymity and pseudonymity — you have the option of not identifying yourself, or of using a pseudonym, when you deal with us about a particular matter, unless the law requires otherwise or it is impracticable. In practice: you may use a pseudonym on our contact form and we will not check it; you cannot hold an account anonymously, because an account is a contract and we must be able to bill and support it · ⭐ a statement attached to data we decline to correct, so that our refusal is visible alongside the record · and the right, if we ever use your information for direct marketing, to require us to stop and to tell you where we got it |
|---|---|
| Access | We respond within 30 days, and there is no charge for making a request |
| ⚠ What Australian law does not give you | There is no general right to erasure and no portability right under the Australian Privacy Principles. We apply the European standard in section 10 anyway |
| ⭐ The countries | Australian law expects us to name the countries where practicable, so: Ireland and the United States, plus [[OWNER: hosting provider and data-centre location]]. Section 1.0 of our Sub-processor list carries the same closed list — which covers the recipients we choose, not one a business using our software configures for itself |
| Regulator | Office of the Australian Information Commissioner — www.oaic.gov.au/privacy/privacy-complaints. ⚠ You must complain to us first; the OAIC says so on its own complaints page |
| ⚠ Our own status | We believe the small business operator exemption in s.6D of the Privacy Act 1988 currently applies to us, so the Australian Privacy Principles do not bind us as an entity today. We apply their standards regardless, and we will comply in full once our turnover crosses the threshold. This is a reasoned position, not a certainty: the regulator publishes no guidance on how the exemption applies to a cloud provider, and the statutory tort for serious invasions of privacy, in force since 10 June 2025, reaches entities that are not covered by the Principles at all |
| How your data reaches Ireland | ⚠ No country has ever been prescribed as having substantially similar laws, and the OAIC publishes no list. The route we take instead is to make APP 8 inapplicable: our Data Processing Agreement limits us to the functions the contract specifies, binds every subcontractor to the same obligations, and leaves your provider the power to access, modify, retrieve and delete its data at any time — so the provider retains effective control, the transfer is a use rather than a disclosure, and the strict onward liability in s.16C never engages |
19.8 New Zealand
| Rights beyond section 10 | ⭐ A statement of correction. If we decline to correct information about you, you may give us a statement of the correction you sought, and we must attach it to the information in a way that ensures it will always be read with the information. This is stronger than the European right and we honour it · and you must be told when we collect information about you indirectly, not from you |
|---|---|
| ⚠ What New Zealand law does not give you | No general right to erasure and no portability right. We apply the European standard in section 10 anyway |
| ⭐ Our address and our privacy officer | New Zealand expects a name and a physical address, not just an email. Go Gadgets Ltd, Cupidstown, Kilteel, Co. Kildare, Ireland. Privacy officer: [[OWNER: privacy/DPO contact or statement that no DPO is required]] |
| Regulator | Office of the Privacy Commissioner — www.privacy.org.nz/your-rights/making-a-complaint-to-the-privacy-commissioner/. ⚠ You must try to resolve it with us first — the Commissioner will not accept a complaint until you have — and the complaint form requires a self-assessment before it can be submitted |
| How your data reaches Ireland | Where a New Zealand business sends us information to hold or process as its agent, that is not a disclosure under the Privacy Act 2020 and the cross-border principle does not apply to it. Where it does apply, the route is a contract requiring comparable safeguards — which our Data Processing Agreement provides. ⚠ No country and no binding scheme has been identified as prescribed under IPP 12(1)(d)–(e) |
| ⚠ A consequence for your provider | Because we are its agent, what we know about an incident counts as what it knows, and its notification clock starts when ours does. Our Data Processing Agreement is drafted to notify immediately for that reason |
19.9 South Africa
| Rights beyond section 10 | ⭐ Access that names names — a description of the information we hold including the identity of all third parties, or categories of third parties, who have or have had access to it · ⭐ an objection that is an absolute stop: once you object on the statutory grounds we may no longer process the information, with no override for compelling legitimate grounds · and rights over automated decisions that include being able to make representations and to be told the underlying logic, with consent not available to us as an exception |
|---|---|
| ⭐ Juristic persons have rights too | POPIA protects an identifiable existing juristic person as well as a natural person. If you are a company, a close corporation or a trust, the rights above are yours as well. Section 20 of our Data Processing Agreement extends our protections to juristic-person data for that reason — European standard clauses protect natural persons only |
| Fees | Confirmation that we hold your information is free. South African law allows a fee for the record itself; if one would apply we will send you a written estimate first, and we would rather waive it than argue about it |
| What binds us directly | Section 20 — we process only with your provider's knowledge or authorisation, and we treat what we hold as confidential — and section 21(2), which requires us to notify your provider immediately where there are reasonable grounds to believe personal information has been accessed or acquired without authority. Both bind us whatever our contract says, and both are how we operate |
| Regulator | Information Regulator (South Africa) — inforegulator.org.za. ⚠ A complaint must be in writing on the prescribed Form 5 |
| How your data reaches Ireland | South Africa has no adequacy list — none, for any country. The mechanism is a binding agreement under s.72(1)(a), which must itself carry an onward-transfer restriction as strong as the original. Section 20 of our Data Processing Agreement is that agreement, and section 15 names every destination country |
| ⚠ An open item we will not paper over | The Regulator's guidance says the Information Officer of a multinational based outside South Africa must authorise a person within South Africa as Information Officer, and that officers may take up their duties only after being registered with the Regulator. We have made no such registration and authorised no such person. That guidance is not in the Act and its enforceability against a foreign company has not been established, but we record it as open rather than claim a compliance we do not have |
19.10 Switzerland
| Rights beyond section 10 | Portability where we process your data with your consent or in direct connection with a contract, in a conventional electronic format · and ⭐ automated individual decisions: where a decision about you is based exclusively on automated processing and has a legal consequence or a considerable adverse effect, we must tell you, and you may require that the decision be reviewed by a natural person. Swiss law creates no prohibition here — it creates a notice and a human-review route, which is why this section does not simply say "we make no automated decisions" |
|---|---|
| Access | Within 30 days, and free of charge as a rule |
| What binds us directly | We must tell your provider about every breach of data security as quickly as possible — unqualified, with the risk judgement left to it, not to us — and we may only pass processing to a further provider with its prior approval. Sections 7 and 24 of our Data Processing Agreement do both |
| Regulator | Federal Data Protection and Information Commissioner (FDPIC / EDÖB) — www.edoeb.admin.ch/en/submitting-a-complaint. ⚠ Two things worth knowing before you write: a person who reports a violation is not a party to the FDPIC's investigation — only the organisation under investigation is — and the FDPIC cannot order compensation or fine us; compensation is a matter for the civil courts |
| ⭐ How your data reaches Ireland | Ireland is on Annex 1 to the Swiss Data Protection Ordinance, so Switzerland treats it as providing adequate protection. No standard clauses, no binding corporate rules, no notification to the FDPIC and no derogation are needed for a Switzerland-to-Ireland transfer, and we do not pretend otherwise by attaching clauses the law does not ask for. What does need care is any onward transfer from Ireland to a country not on Annex 1 — our sub-processor list names every destination. ⚠ For that onward leg to the United States we rely on the EU Standard Contractual Clauses in each provider's own agreement with us, read for Swiss law; the precise adaptations the FDPIC requires were not verified in the research behind this section, and we have not confirmed that those providers' clauses carry a Swiss addendum, so no Swiss-specific instrument is in place for that leg today. Section 24 of our Data Processing Agreement states the position in full and what we will do about it |
| No Swiss representative is required | The obligation to appoint one applies to controllers established abroad, on five cumulative conditions. It does not extend to processors, and in our own controller capacity we do not meet the conditions |
19.11 Japan
| Rights beyond section 10 | The rights over retained personal data — disclosure, correction and cessation of use. Japan additionally requires us to publish two things, which we do here: ⭐ the security control measures we take — section 16 sets them out, other than any whose disclosure would itself weaken security — and ⭐ where to complain, which is hello@field2service.com |
|---|---|
| ⭐ The country where your data is handled | Ireland. Japanese guidance requires the country to be named in a form you can reasonably recognise. Information about Ireland's data-protection regime is encouraged rather than required, so: Ireland applies the EU General Data Protection Regulation, supervised by the Data Protection Commission, and we will send you a fuller summary on request. Our other destination countries are on the Sub-processor list |
| Regulator | Personal Information Protection Commission (PPC) — www.ppc.go.jp/en/. ⚠ Be accurate about what the PPC's telephone line is: the APPI inquiry line answers questions about the law, in Japanese only, and is not a complaints channel — it directs individual complaints to the company concerned, to an accredited personal information protection organisation, or to a local consumer affairs centre. Write to us first |
| ⭐ How your data reaches Ireland | The PPC's designation notice carves the thirty EEA states and the United Kingdom out of "foreign country" for the purposes of Article 28, so a transfer from Japan to Ireland needs no Article 28 consent. ⚠ That carve-out is conditional: it applies only where the recipient is subject to the GDPR. We are established in Ireland and we are subject to the EU GDPR, and section 23 of our Data Processing Agreement recites it for that reason |
| What your provider must do | Japanese law puts the duty on the entruster: before entrusting data to us it must confirm in advance that our security measures meet the standard it must meet itself. We support that with our security documentation rather than asking it to take our word |
⚠ Japan's breach-notification regime was not researched in the work behind this section, so nothing here states a Japanese breach position.
19.12 Singapore
| Rights beyond section 10 | Access and correction, and the right to withdraw consent on reasonable notice — after which your provider must stop processing your data and cause us to stop too |
|---|---|
| ⭐ Who those rights run against | Access and correction bind the organisation, not its data intermediary. Where we hold your data on a business's behalf, that business is the organisation and the right runs against it. Send us the request anyway and we will route it and tell you we have done so, but the answer has to come from them — section 3 explains |
| ⭐ What binds us directly | Two obligations, and they bind us whatever anyone's contract says: section 24 — reasonable security arrangements, and section 25 — we must stop retaining personal data once the purpose is served and retention is no longer needed for legal or business purposes. We must also notify the organisation of a breach without undue delay. ⚠ And you should know that Singapore lets you sue us directly for loss caused by a breach of either — you do not need a contract with us to do it |
| Marketing text messages | If a marketing text message reaches your Singapore number through our platform, we may be a "sender" of it in law even though it was sent for a customer's purposes, and being a data intermediary is no defence. Section 19.14 says what we do about that |
| Regulator | Personal Data Protection Commission — www.pdpc.gov.sg |
| ⭐ How your data reaches Ireland | Singapore has no adequacy concept at all: there is no whitelist, and the EEA is not recognised. Ireland is treated exactly like any other destination, and the mechanism is a contract that requires comparable protection and specifies the countries and territories the data may go to. Section 15 of our Data Processing Agreement is that clause and it names them: Ireland, the United States and [[OWNER: hosting provider and data-centre location]]. ⚠ That list covers the recipients we choose. Where a business using our software sends data to a webhook, a mail or SMS provider or a payment provider it configured, we do not select that recipient and cannot name its country — naming it is that business's own obligation |
| ⚠ A certification we do not hold | Singapore recognises APEC and Global CBPR / PRP certifications as a shortcut. We hold none of them and we claim none |
19.13 India
⚠ State of the law first, because it changes the answer. India's Digital Personal Data Protection Act 2023 is enacted, but its operative provisions are not yet in force. The obligations, the rights and the penalty power all commence around May 2027. Until then the operative Indian law for sensitive personal data remains section 43A of the Information Technology Act 2000 and the SPDI Rules 2011. ⚠ Those were not examined in the research behind this section, so nothing here states a position under them, and we make no claim of compliance with either regime.
| Rights when the Act commences | Access to a summary of the personal data being processed and the processing activities · correction, completion, updating and erasure · grievance redressal · nomination of another person to exercise your rights · and ⭐ the identities of all other Data Fiduciaries and Data Processors with whom your data has been shared |
|---|---|
| Response time | We will publish, and meet, a grievance-response period not exceeding 90 days, as rule 14(3) will require of your provider. In practice we work to the one-month European standard in section 10 |
| Contact point | [[OWNER: privacy/DPO contact or statement that no DPO is required]] — published here and repeated in every reply we send about your rights, which is the form Indian law will require |
| Regulator | Data Protection Board of India, established 13 November 2025 and operating as a digital office; appeals lie to the Telecom Disputes Settlement and Appellate Tribunal. The framework and the Rules are published by the Ministry of Electronics and Information Technology — meity.gov.in/data-protection-framework. ⚠ There is no private right of action: the Act removes civil court jurisdiction over matters the Board can decide |
| ⭐ How your data reaches Ireland | India uses a negative-list model — transfers are permitted unless the Central Government notifies a restricted country, and the power to do so is not yet in force, so no country can have been notified. No adequacy decision, no standard clauses, no binding corporate rules, no certification, no consent and no transfer impact assessment are required. Our Data Processing Agreement deliberately contains no European-style transfer machinery for India, because importing it would overstate what Indian law asks |
| ⚠ What we are, and are not | The Act imposes no obligation and no penalty on a Data Processor — every duty falls on the Data Fiduciary. So we cannot and do not describe ourselves as "DPDPA compliant" as a processor: there would be nothing to comply with. What we do instead is contract on the terms an Indian customer will need — a valid contract, the security provision the Rules require, breach notification fast enough for its own clock, and the one-year minimum retention the Rules will impose, which runs the opposite way from European storage limitation |
| ⚠ Children | The Act will require verifiable parental consent before processing any data of anyone under 18. Our software cannot do this — see section 19.15 |
19.14 Marketing messages, and what we do about them
Our software sends messages for the businesses that use it, and it is those businesses that decide what to send and to whom. Two things follow, and we state them plainly rather than making a compliance claim.
- ⭐ We can be a "sender" in our own right. Singapore's Do Not Call rules treat anyone who sends a message, causes it to be sent or authorises its sending as a sender — including a platform transmitting it for someone else's purposes — and being a data intermediary is expressly no defence. We therefore treat ourselves as a potential sender rather than a mere conduit.
- ⚠ A person's contact preference cannot separate marketing messages from operational ones. Since 6 September 2026 our software does classify each message it sends as transactional, automated, marketing or account-security when it decides whether to send, and applies a person's preference to every one of them — including the direct "send quote" and "send invoice" actions, which used to go round it. But there is still one pair of contact preferences per person, so switching a channel off switches off all of those classes together — with the single deliberate exception of a message about the person's own portal access that they asked for in that request, which is always sent so that an opt-out cannot lock somebody out of their own records — and there is no field recording why a person is on a list. Our software also has no campaign or bulk-messaging feature, so there is no marketing send list within it to separate. Those are limitations, recorded in section 19.15 and in Annex 5 of our Data Processing Agreement, and they are the reason we make no marketing-compliance claim for any jurisdiction.
Where a business uses our software to send an appointment confirmation, an arrival window, a completion notice or an invoice, that is an operational message and is treated as such everywhere we have looked. A promotional message is a different thing in law, and it is the sending business's responsibility to have a lawful basis for it — under South African law, consent in the prescribed form; under Singaporean law, an express consent or a register check, because neither legitimate interests nor deemed consent can carry marketing there; under Indian law, consent, because the closed list of other lawful uses contains no marketing limb.
⚠ Four regimes that plainly bear on this were not researched: Canada's anti-spam law, the United States Telephone Consumer Protection Act, the UK and EU e-privacy direct-marketing rules, and Australia's Spam Act and Do Not Call Register Act. We make no marketing-compliance claim for Canada, the United States, the United Kingdom, the European Union or Australia, and nothing in this policy should be read as one.
19.15 What our software cannot do — stated, not implied
Every entry below is a limitation of the product, not a drafting choice. Each is also recorded in Annex 5 of our Data Processing Agreement, where the businesses that use the software can see it.
| Limitation | What it means for the rights above |
|---|---|
| We do not read opt-out preference signals such as Global Privacy Control | Nothing we operate does anything a signal would switch off — no analytics, no advertising, no sale, no sharing, no targeted advertising, no profiling. If we ever add one, we will implement signal handling first. Until then we do not claim to honour the signal, because we do not read it |
| There is no self-service export or deletion of the data we hold about you as controller | A request under section 10 or under this addendum, about data we hold as controller, is handled by us within the times stated. Inside a business's Field 2 Service account the position is different, and better: since 6 September 2026 the software does have a one-click subject-access package and an erasure action, and a portal customer can download their own copy and lodge an erasure request themselves — see section 3. What the package still does not contain is uploaded file binaries — photographs, signed sheets and imported documents |
| There is no age verification and no parental-consent capture anywhere | We cannot meet India's requirement of verifiable parental consent before processing anyone under 18, and we do not claim to. The honest position is the one in section 15: the service is not for children, we do not knowingly collect their data, our customers are instructed not to enter it, and we delete it on request where we are the controller — inside a business's account we act on that business's instruction, by hand, with the limits in this table |
| A statement attached to data we decline to correct (Australia, New Zealand) is a manual act | Where we are the controller we will record and attach it. Inside a business's account the software has no such field, so the business must handle it — we will tell it so when we route your request |
| We record security signals; we do not operate security monitoring or intrusion detection | Since 6 September 2026 failed sign-ins, lockouts, password changes, two-factor removals, API-key changes, data exports, bulk permanent deletions and content-security-policy violations are kept in a durable record, and four alert rules fire on it — repeated failed sign-ins from one address, one address attacking several accounts, an export outside working hours, and a large batch of permanent deletions. That is signalling on sign-in and on bulk extraction. There is no intrusion detection, no log shipping, no protection of the logs against alteration, no alerting on our administrative audit log, and no impossible-travel or privilege-change rule, and a sign-in attempt against an address that exists in no account is not recorded at all. Detection may still be by human report, which is why our breach commitments are about speed of notification once we know |
| ⚠ Product defaults have not been audited against Quebec's confidentiality-by-default requirement | Quebec requires a technological product offered to the public to provide the highest level of confidentiality by default. Several settings in the software — including whether staff location is recorded — are configured by the business, not by us. We have not assessed the defaults against that standard and we do not claim to meet it |