Privacy: Site diary trial
Built to UK GDPR and Data Protection Act 2018 requirements. This page covers the trial at sitediary.enyinc.uk only.
Who is responsible
The controller is eny (enyinc.uk). Contact: info@enyinc.uk.
What we collect, and why
At signup: your business name and work email. Nothing else. We use them to run your trial (contract) and to follow up about it (legitimate interest). eny staff can see the trial signup name, email and usage counts (how many actions, which features, when last used) to support the trial, under legitimate interest.
Anything you type into the trial is stored only to show it back to you. The trial is for demo or test data. Please do not enter real personal details of your operatives.
How long we keep it
30 days from signup. Then the whole workspace is deleted: every diary entry, check, timesheet, audit record, your business name and email. There are no backups of trial data. You can delete it sooner yourself.
Your rights
Once signed in, Account lets you download everything held for your workspace as JSON (access and portability, Articles 15 and 20) and delete it all immediately (erasure, Article 17). For anything else, email info@enyinc.uk. You can complain to the Information Commissioner's Office at ico.org.uk.
Security
HTTPS only. Sign-in uses a signed session cookie (HttpOnly, Secure, SameSite=Lax). PINs are stored hashed (PBKDF2), never in clear. Roles limit what an operative can do. Sign-in and signup are rate-limited. Every change is written to an audit log that cannot be edited.
Cookies and tracking
One cookie: the session cookie that keeps you signed in. No analytics, no advertising tags, no tracking cookies on this site. The only third-party script is Cloudflare Turnstile on the signup page, to stop bots.
Where it is stored
On Cloudflare (Workers and D1). Signup notifications are sent to eny through Brevo.