eny Site diary

Privacy: Site diary trial

Built to UK GDPR and Data Protection Act 2018 requirements. This page covers the trial at sitediary.enyinc.uk only.

Who is responsible

The controller is eny (enyinc.uk). Contact: info@enyinc.uk.

What we collect, and why

At signup: your business name and work email. Nothing else. We use them to run your trial (contract) and to follow up about it (legitimate interest). eny staff can see the trial signup name, email and usage counts (how many actions, which features, when last used) to support the trial, under legitimate interest.

Anything you type into the trial is stored only to show it back to you. The trial is for demo or test data. Please do not enter real personal details of your operatives.

How long we keep it

30 days from signup. Then the whole workspace is deleted: every diary entry, check, timesheet, audit record, your business name and email. There are no backups of trial data. You can delete it sooner yourself.

Your rights

Once signed in, Account lets you download everything held for your workspace as JSON (access and portability, Articles 15 and 20) and delete it all immediately (erasure, Article 17). For anything else, email info@enyinc.uk. You can complain to the Information Commissioner's Office at ico.org.uk.

Security

HTTPS only. Sign-in uses a signed session cookie (HttpOnly, Secure, SameSite=Lax). PINs are stored hashed (PBKDF2), never in clear. Roles limit what an operative can do. Sign-in and signup are rate-limited. Every change is written to an audit log that cannot be edited.

Cookies and tracking

One cookie: the session cookie that keeps you signed in. No analytics, no advertising tags, no tracking cookies on this site. The only third-party script is Cloudflare Turnstile on the signup page, to stop bots.

Where it is stored

On Cloudflare (Workers and D1). Signup notifications are sent to eny through Brevo.