This policy explains how PV Roofers uses personal data in its booking, field operations, employee and fleet applications. PV Roofers is the data controller for the information described here, except where we clearly act on behalf of another organisation.
Who we are
PV Roofers, 12 Brookville Green, Borrisokane Road, Nenagh, Co. Tipperary, E45 VH34, Ireland. Privacy questions and rights requests can be sent to info@pvroofers.ie.
Information we process
- Account details such as name, work email, phone number, role and login security data.
- Customer, installer, job, site, scheduling, quotation and invoice information.
- Employee profile, employment, leave, attendance, pay-grade and emergency-contact data.
- Certificates and documents such as Safe Pass, training records and driving qualifications, including their issue, verification and expiry dates.
- Job notes, messages, issues, photographs, documents and quality or safety records.
- Precise phone location submitted when an employee deliberately checks in, checks out or records a job stage, together with accuracy and distance from the assigned site.
- Company-vehicle location, speed, route and ignition data supplied by an installed vehicle tracker. This can be personal data where it relates to an identifiable driver.
- Device, push-notification, app-version, security log and diagnostic information.
How location works
Before the first attendance location is requested, the employee app shows a versioned foreground-location notice and records that it was acknowledged. That record documents transparency; it is not PV Roofers' legal basis, and the operating-system permission is a separate choice. The app requests location only while it is open and only after the employee chooses a location-based action such as Check in or Check out. It does not request always-on or background phone location. A check-in records the coordinates, device-reported accuracy, server receipt time and calculated site distance. Low-accuracy or outside-site events are sent for review; location is not treated as infallible proof.
Dedicated trackers in company vehicles may report location while the vehicle is in use. Vehicle tracking is limited to fleet safety, dispatch, job logistics, theft prevention and other documented business purposes. It must not be used for general monitoring of employees, and authorised managers are responsible for respecting off-duty use and the company fleet policy.
Why we use information
We process information where necessary to:
- provide accounts, bookings, installations, navigation, job updates and support;
- plan teams, vehicles, equipment and materials and maintain accurate working-time records;
- manage employment, leave, training, safety, payroll inputs and legal obligations;
- protect staff, customers, vehicles, systems and company property;
- issue invoices, maintain business records and establish or defend legal claims; and
- send operational messages and notifications selected by the user or required for a job.
Depending on the context, our legal basis is performance of a contract, compliance with a legal obligation, or a legitimate business interest balanced against individual rights. Device permission allows the operating system to share location with the app; it is not by itself our legal basis under data-protection law. Health-related absence information and other special-category data is restricted and processed only where an additional lawful condition applies.
Who receives information
Access is role-based. Field workers see jobs assigned to them; installers see their company's bookings; HR and pay information is limited to authorised management. We use contracted providers for hosting, database and file storage, mapping and routing, push notifications, email/SMS, support and vehicle tracking. Providers may process only what is needed to deliver their service and are subject to data-protection and security terms. We do not sell personal data or use it for third-party advertising.
Retention
Records are kept only for a documented business or legal need. Raw employee attendance or stage coordinates and raw vehicle-position history are intended to be automatically removed after 90 days unless an incident, dispute or legal duty requires a temporary hold. Approved time records, employment records, invoices, safety evidence and job records may be retained longer under Irish employment, tax, insurance and limitation requirements. Expired device sessions and push tokens are routinely removed.
Account deletion
A signed-in user can start account deletion from the app or the Delete account page. A seven-day cancellation period is shown before processing. Login credentials, personal profile, device tokens and employee document files are deleted or anonymised. Information that must be retained for employment, tax, invoicing, safety, fraud prevention or legal claims is minimised, access-restricted and kept only for the applicable retention period. If a message has an unresolved workplace-safety or conduct report, it is hidden from ordinary conversations while its content and attachment evidence remain available only to authorised moderators. That temporary evidence is scrubbed after the final report is resolved.
International transfers and security
Where a provider processes data outside the European Economic Area, we use an approved transfer mechanism and assess appropriate safeguards. We use encrypted transport, private file storage, access controls, audit records, signed tracker ingestion and credential rotation. No service is completely risk-free; suspected incidents should be reported promptly to the address above.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection, and may complain to the Irish Data Protection Commission at dataprotection.ie. We may need to verify identity and explain when a legal retention duty limits a request.
Changes
Material changes will be announced in the app or by an appropriate company communication. The current version and effective date will remain available on this page.
