Last updated: 26 August 2026
Privacy Policy
This privacy policy explains how OnSite GbR (“OnSite”, “we”, “us”) collects, uses, and stores personal data when you use the OnSite iPhone and iPad app, the owner dashboard at dashboard.onsite.works, and the website at onsite.works. If the German and English versions differ, the German version prevails.
1. Controller
The controller responsible for processing personal data is OnSite GbR, Franz-Rücker-Allee 94, 60487 Frankfurt am Main, Germany.
OnSite GbR is represented by its partners Daniel Danon, Linus Kaiser, and Tobias Knecht. Further provider details are in the imprint at onsite.works/impressum.
For privacy questions, data-subject requests, and other enquiries, contact support@onsite.works or +49 1577 1253258.
2. Scope
This policy applies to the OnSite app, the dashboard, the public website, beta access requests, and related services such as quote and invoice generation, the AI assistant, voice input, and file imports.
OnSite is a business product for construction and trade companies. If you add client, employee, or supplier data, you are the controller for that data. We process it on your instructions as a processor under Article 28 GDPR, except where we process it for our own purposes (for example account administration, security, and billing).
3. Data we process
Depending on how you use OnSite, we process the following categories of data:
- Account data: name, email address, and sign-in details, including Sign in with Apple or email and password.
- Company data: company name, address, trade, tax identifiers, branding, team members, roles, and pricing settings.
- Job and document data: clients, job addresses, notes, photos, materials, labour, quotes, invoices, and related documents.
- Voice and chat: audio you send for transcription, transcripts, and assistant messages needed to carry out your requests.
- Imports: supplier lists, client lists, and files you upload or email to our import addresses (including material@onsite.works and clients@onsite.works).
- Website and beta requests: email address, company name, and the information you submit when requesting TestFlight access.
- Technical data: device, app, and log information needed to operate, secure, and troubleshoot the service, including IP address and approximate location derived from it.
4. Purposes and legal bases
We process personal data only where a legal basis under Article 6 GDPR applies:
- Article 6(1)(b) GDPR (contract): to create and operate your account, sync jobs, generate quotes and invoices, match materials and clients, transcribe voice, run the assistant, and provide support.
- Article 6(1)(f) GDPR (legitimate interests): to keep the service secure, prevent abuse, diagnose faults, improve reliability, and understand how the public website is used at a technical level. Our legitimate interest is operating a stable, secure SaaS product. You may object as described below.
- Article 6(1)(a) GDPR (consent): where we ask for consent, for example for optional notifications or where required for certain voice or device permissions. You may withdraw consent at any time without affecting processing that already took place.
- Article 6(1)(c) GDPR (legal obligation): where we must retain or disclose data under tax, commercial, or other mandatory law.
5. AI processing
OnSite uses artificial intelligence to transcribe speech, interpret requests, extract data from files, suggest materials and prices, and draft quotes, invoices, and other documents.
AI output can be incomplete, outdated, or wrong. It is a draft for you to review. We do not make decisions with legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR. You decide whether to use, send, or rely on any result.
We do not sell personal data. We do not use your job, client, team, or catalog data to train public AI models. AI providers receive only the data needed to fulfil the request you initiate, under their terms as processors or sub-processors.
6. Recipients and processors
We use specialist providers to operate OnSite. They process data only on our instructions and under data-processing agreements where required:
- Google (Firebase Authentication, Firestore, Cloud Storage, and Cloud Functions), hosted in region europe-west3 (Frankfurt) for core account, database, file, and backend processing.
- OpenAI and Anthropic for assistant replies, structured extraction, and related language-model processing.
- ElevenLabs for speech-to-text, realtime transcription, and text-to-speech.
- SendGrid and our mailbox provider for transactional email, beta-request notices, and inbound import mail.
- Apple for Sign in with Apple and TestFlight invitations.
- Komoot Photon (photon.komoot.io, based on OpenStreetMap) for address lookup suggestions you request in the product.
- Our website hosting provider for onsite.works and dashboard.onsite.works.
Authorised team members you invite can access company data according to the roles you assign. We may disclose data if required by law or to establish, exercise, or defend legal claims.
7. Transfers outside the EU/EEA
Some providers are based in the United States or other countries outside the EU/EEA, including OpenAI, Anthropic, ElevenLabs, Apple, and SendGrid.
Where a transfer is not covered by an adequacy decision, we rely on appropriate safeguards under Article 46 GDPR, in particular the EU Standard Contractual Clauses, and supplementary measures where needed. You can ask us for more information about these safeguards at support@onsite.works.
8. Retention
We keep account and company data for as long as your account is active and as long as needed to provide the service.
After deletion of an account, we delete or anonymise personal data unless a longer retention period is required or permitted by law (for example commercial and tax retention duties, or data needed to defend legal claims).
Managers can delete catalog, client, job, and document data in the product. Voice audio is processed to produce a transcript; we do not keep voice recordings longer than needed to complete transcription and troubleshoot failures.
Beta-request details are kept as long as needed to handle the request, send a TestFlight invite, and answer follow-up questions.
Technical logs are kept only as long as needed for security and operations.
9. Your rights
If the GDPR applies to you, you have the following rights, subject to statutory conditions:
- Access (Article 15 GDPR)
- Rectification (Article 16 GDPR)
- Erasure (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection to processing based on legitimate interests (Article 21 GDPR)
- Withdrawal of consent, where processing is based on consent
To exercise these rights, email support@onsite.works. We may need to verify your identity before fulfilling a request.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence, your workplace, or the place of the alleged infringement. For OnSite GbR this is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI). You may also contact the Federal Commissioner for Data Protection and Freedom of Information (BfDI) for guidance.
10. Cookies and the website
The public website stores your language preference locally on your device so that the site can be shown in the language you choose. This storage is necessary for the site to work as requested.
We do not use advertising cookies or sell website usage data. App and dashboard sign-in uses authentication cookies or equivalent session storage that are required to keep you signed in and to protect the account.
11. Security
We use technical and organisational measures appropriate to the risk, including transport encryption, access controls, regional hosting in the EU for core application data, and authentication via Firebase.
No online service can be guaranteed completely secure. You are responsible for keeping your login details confidential and for the people you invite to your company.
12. Children
OnSite is a business tool and is not directed at children under 16. We do not knowingly collect personal data from children.
13. Changes
We may update this privacy policy when the product, our providers, or the law changes. The current version is published at onsite.works/privacy. The date at the top shows when it was last revised. If a change is material, we will take reasonable steps to inform you, for example in the app or by email.