Data governance and IT security
SiteHive provides construction environmental monitoring (noise, dust, vibration and weather) as a hosted service. This page summarises how your monitoring data is stored, secured and governed, who can see it, what the devices record, and how all of that applies when devices are hired rather than owned. It is written for the people who ask these questions on a project: IT, procurement and the environmental lead.
Where your data is stored and hosted
-
SiteHive is hosted on Amazon Web Services (AWS), entirely in the AWS Sydney region.
Customer data is stored exclusively in Australia.
Data sent from devices to the SiteHive cloud is encrypted in transit (TLS), and cloud-stored data is encrypted at rest.
SiteHive follows the AWS Well-Architected Framework and is working toward ISO 27001 certification.
Photos and audio clips
Devices can capture a still image and a 6-second audio clip, used only to help identify the source of an event (for example, a truck reversing rather than background traffic).
This is not continuous audio or video surveillance. There is no live feed, and a capture only fires when an event is detected.
For noise, only the loudest event in each aggregation period (for example, 15 minutes) is captured by default.
Captured media is encrypted and stored in the same access-controlled AWS environment as all other monitoring data.
Media capture can be configured or switched off in SiteHive Enviro, so a project controls whether that media is collected at all. See Set up media triggers and Enhanced media: photos, audio and video from your devices.
Who can see your data
Authentication is managed through Auth0, with role-based access control enforced per site and project on a least-privilege basis, so users only see the sites and data they are authorised for.
Access to a hired device's data is governed identically to an owned device: control sits at the account and site level, not the hardware.
You manage who has access to each site yourself. See Add and manage users.
Privacy
SiteHive complies with the Privacy Act 1988 and the Australian Privacy Principles.
SiteHive holds only enough personally identifiable data to allow you to log in and be contacted as part of our notifications and support process.
Environmental data is tokenised and stored separately from anything identifiable, and contains no personal information itself.
The platform is built around collecting no more personal data than is needed to operate it.
Data retention, backups and the hire model
By default, data is retained for 7 years after project completion, as the project's environmental compliance record, or as set out in your contract.
Data can be exported at any time, via the dashboard or API (see Export a CSV report). Earlier secure deletion can be arranged by written agreement, with written confirmation of deletion available on request.
Backups are automated and encrypted. Databases are snapshotted daily with continuous point-in-time recovery, media storage is versioned and replicated, and search indexes are snapshotted hourly.
Hiring devices rather than owning them changes none of the above. Data governance sits entirely with SiteHive's cloud platform, not the physical hardware.
ℹ️ Need this as a document for a tender, an IT review or a security questionnaire? Your Regional Success Manager can prepare a copy for your project.
What's next
Add and manage users (roles and access, site by site)
Set up media triggers (turn photo and audio capture on or off, and set the level)
Maintaining your site (the routine this page sits beside)