1. Who we are
FieldProof is a web application for documenting field work — customers, sites and areas, jobs, visits, observations, checklists and photographic evidence — and for generating Word (.docx) reports from that information. FieldProof is provided by CloudFM Solutions, Lda, with registered office at Rua Cimo da Vinha, 40-C, 7300-658 Fortios, registration number PT510123864 and VAT number PT510123864 (“FieldProof”, “we”, “us”).
For the personal data needed to run FieldProof itself — accounts, sign-in, access requests, billing, security, support and our website — we are the controller.
For the information that a subscribing organization and its users record in FieldProof about their own work (“Customer Data”), the organization is the controller and we process that data on its behalf as a processor. If you are a member of an organization, or a person whose information appears in an organization's records or photographs, please contact that organization first about that information. We will help it respond.
You can contact us about privacy at support@cloudfmsolutions.com.
2. Data we collect
Account and sign-in data
FieldProof does not use passwords. You sign in with a Google or Microsoft account. When you do, we receive and store your name, your email address and the unique account identifier issued by Google or Microsoft (for Microsoft, also the identifier of your organization's directory, known as the tenant). We also store your preferred language, the organizations you belong to, your role in each one and the status of your access.
We never receive your Google or Microsoft password, and we do not store your profile photo.
Organization data
When an organization is created we store its name, country and language and, if an Owner or Administrator adds them, its address, postal code, city, email, phone, website and logo, which can appear in the reports it generates. We also store the organization's settings, Word report templates, checklist templates, team members and roles, and its plan and subscription status.
Access and trial requests
Access to a FieldProof workspace is reviewed before it is granted. If you request a trial on our website we collect your name, email address, company, team size and language and, if you provide them, your phone number and a message. If you sign in without access to a workspace, we record an access request with your sign-in details. We keep the status of each request and the outcome of our review.
If you send an Enterprise enquiry through our contact form, your name, email address, company, team size and message are sent to our team by email. They are not stored in the FieldProof application database.
Customer Data recorded in FieldProof
Depending on how the organization uses FieldProof, its users may record:
- Customers: name, email, phone, business identifier, address and notes;
- Sites and areas: names, addresses, optional coordinates, descriptions and notes;
- Jobs: reference, title, description, status, schedule and assigned users;
- Visits: dates, status, general notes, weather and the technicians involved;
- Observations: title, description, category, severity, status, location and recommendation;
- Checklists: templates, answers and notes;
- Evidence: photographs (JPEG, PNG or WebP) and PDF documents, with their original filename, size, an integrity fingerprint (SHA-256), who uploaded them and when;
- Reports: every generated Word report version, with a snapshot of the data it was generated from.
Customer Data can include personal data about people who are not FieldProof users — for example a customer's contact person, the occupants of a building or anyone visible in a photograph. The organization is responsible for having a lawful basis to record that information (see our Terms of Service).
We keep each original evidence file exactly as uploaded, so that its integrity can be verified. Photographs can contain metadata written by the camera or phone, such as the capture date, the device model and, if location tagging is enabled on the device, GPS coordinates. FieldProof does not currently read or display that metadata, but it remains inside the stored original file. The smaller preview image that your browser creates for display does not keep it. If you do not want location data inside your photographs, turn off location tagging in your camera settings.
Storage connection data
If an Owner or Administrator connects Google Drive, Microsoft OneDrive or SharePoint, we store the connected account's email address and identifier, the identifiers and names of the destination folder, site or library, and the authorization tokens needed to keep the connection working. Tokens are stored encrypted. Sections 5 and 6 explain these connections in detail.
Billing data
Paid subscriptions are processed by Stripe. When an Owner starts a subscription, we send Stripe the organization's name, the Owner's email address and our internal organization identifier. We store the Stripe customer and subscription identifiers, the plan, price, currency, billing interval, subscription status and the related dates. Payment card details are entered directly with Stripe; we do not receive or store card numbers.
Technical, security and usage data
- Session records: when a session was created, when it was last used, when it expires and which organization is active;
- An activity history (audit log) of actions in each organization — for example records created or deleted, evidence uploaded, reports generated or storage connected — with the user and time;
- Internal product events, such as the first job or visit created by an organization, linked to the organization and user, which we use to understand how the product is adopted;
- Operational logs generated by our hosting platform, which may include technical request information such as IP address, browser type, the requested page and errors;
- For trial requests, a daily value derived from your IP address in a non-reversible form (a keyed hash), used to limit abuse and valid for 24 hours;
- Aggregate statistics about our public website: how many times a named event (for example “pricing page visited”) occurred on a given page and day. These statistics contain no IP addresses, cookies, user identifiers or browser details.
Communications
We keep the emails we exchange with you, for example about an access request or a support question.
3. How we use personal data
We use personal data only for the following purposes:
- to provide FieldProof: create and manage workspaces, store records and evidence and show them to authorized users;
- to authenticate you, keep you signed in and apply your role and your organization's permissions;
- to review access and trial requests and set up approved organizations;
- to store files in FieldProof's internal storage or in the storage provider chosen by your organization;
- to generate Word reports from the visits, jobs and information that users select;
- to manage plans, subscriptions and plan limits, such as the number of users and monthly reports;
- to send transactional emails, such as a notice that your access request was approved, and to answer enquiries;
- to provide support when you ask for it;
- to protect the service, our users and their data: checking that public forms are submitted by people, limiting abuse, investigating incidents and keeping an activity history;
- to understand, in aggregate, how the website and the product are used, so that we can improve them;
- to comply with legal obligations, such as accounting and tax rules, and to establish or defend legal claims.
We do not sell personal data. We do not use personal data or Customer Data for advertising, and FieldProof does not send marketing emails from the application. If we want to use personal data for a new purpose that is not compatible with these, we will update this policy first and, where required, ask for your consent.
4. Legal basis
Under the General Data Protection Regulation (GDPR) we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): providing the account, sign-in, workspace, storage, reports, billing, transactional emails and support, and taking the steps you ask for before a contract, such as reviewing a trial request;
- Legitimate interests (Article 6(1)(f)): keeping the service secure and preventing abuse, keeping an activity history, understanding aggregate use of the website and the product, communicating with business contacts about the service, and establishing or defending legal claims. We balance these interests against your rights, and you can object (section 12);
- Legal obligation (Article 6(1)(c)): keeping billing and accounting records and responding to lawful requests from authorities.
We do not currently rely on consent as the legal basis for any processing. Connecting Google Drive, OneDrive or SharePoint requires an explicit authorization on the provider's screen; that authorization is a permission you can withdraw at any time (sections 5 and 6), separate from the legal bases above.
For Customer Data, the organization, as controller, determines the legal basis for recording information about its own customers, contacts and other people. We process that data on the organization's behalf to provide the service.
5. Google user data
FieldProof uses Google in two separate, optional ways: signing in with Google, and connecting Google Drive as the storage destination for an organization's files. Each requires its own consent on Google's screen.
Sign in with Google
When you choose “Continue with Google”, FieldProof requests the openid, email and profile scopes. From Google we receive your Google account identifier, your email address, whether that address is verified and your name. We use them only to identify you, to create or link your FieldProof user, to check whether you have access to a workspace and to keep you signed in. Sign-in does not give FieldProof access to your Gmail, Calendar, Contacts, Drive or other Google data, and we do not keep the Google access token issued at sign-in.
Google Drive connection
An Owner or Administrator can connect Google Drive in Settings. FieldProof then requests the scope https://www.googleapis.com/auth/drive.file, which only gives access to files and folders that FieldProof creates or that you explicitly open with FieldProof. It does not give FieldProof access to your other Drive files.
When the connection is made and while it is in use, FieldProof:
- reads the connected Google account's email address, display name and account identifier, to show which account is connected and to avoid linking files to the wrong account;
- creates a FieldProof folder in that Drive and, inside it, subfolders organized by job, visit, area and observation. Folder names can include the job reference, the customer and site names, the visit date and the area and observation names;
- when Google Drive is the organization's active destination, uploads the organization's evidence files (originals and previews), generated Word reports, Word templates and logos to that folder; reads them back to show them in FieldProof and to build reports; and deletes them when an authorized user deletes them and the organization's settings ask for files to be removed immediately;
- stores a Google refresh token, encrypted, so that the connection keeps working without asking for consent each time.
FieldProof accesses Google Drive only to carry out actions that a user of the organization starts or configures, such as uploading evidence, generating a report or opening a file. It does not scan, index or analyze the Drive.
Files stored in Google Drive are subject to the sharing settings of that Google account and to Google's own terms. The records themselves (text, file metadata and report snapshots) remain in FieldProof's database.
Disconnecting and revoking access
An Owner or Administrator can disconnect Google Drive in Settings. FieldProof then asks Google to revoke the authorization, deletes the stored authorization tokens and stores new files in its internal storage; files already in Drive stay there. You can also check or remove the permission yourself at any time on your Google Account permissions page. While access is revoked, files previously stored in Drive are not available in FieldProof.
How we treat Google user data
- We use Google user data only to provide and improve the user-facing features described above;
- We do not sell Google user data;
- We do not use Google user data for advertising, including personalized, retargeted or interest-based advertising;
- We do not transfer Google user data to third parties, except to the service providers that host FieldProof for us (section 8), when necessary to comply with the law, or as part of a merger, acquisition or sale of assets with notice to you;
- Our staff do not read Google user data unless you ask us to (for example, for support), it is necessary for security purposes such as investigating abuse, or it is required by law;
- We do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
FieldProof's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Microsoft data
FieldProof can also use Microsoft in two separate, optional ways: signing in with Microsoft, and connecting Microsoft OneDrive or SharePoint as the storage destination.
Sign in with Microsoft
FieldProof requests the openid, profile, email and User.Read permissions. From Microsoft we receive your account identifier, the identifier of your organization's directory (tenant), your name and your email address or user principal name. We use them only to identify you, check your access and keep you signed in. Personal and work or school Microsoft accounts are accepted.
OneDrive and SharePoint connection
An Owner or Administrator can connect OneDrive or SharePoint in Settings. In addition to the sign-in permissions, FieldProof then requests offline_access, so that the connection keeps working, and Files.ReadWrite, so that it can create and write files. For SharePoint, which requires a work or school account, FieldProof also requests Sites.Read.All, used to find the SharePoint site whose address you enter and to list its document libraries so that you can choose one. Your Microsoft administrator may need to approve these permissions.
Files.ReadWrite is a broad Microsoft permission. FieldProof uses it only to create or locate the destination folder you configure and to upload, read and delete the files FieldProof manages there: evidence files, previews, Word reports, templates and logos, organized in subfolders named after, for example, the job reference, customer and site, visit date, area and observation. FieldProof does not browse, index or analyze other files.
We store the connected account's identifier and email, the tenant, drive, site, library and folder identifiers and names, and encrypted access and refresh tokens.
Disconnecting and revoking access
An Owner or Administrator can disconnect OneDrive or SharePoint in Settings, which deletes the stored tokens. Files already stored remain in your Microsoft account. You can also remove FieldProof's access from your Microsoft account (personal accounts) or My Apps (work or school accounts), or ask your Microsoft administrator.
We apply the same commitments to Microsoft data as to Google user data: we do not sell it, we do not use it for advertising and we use it only to provide the features described above.
7. Where records and files are stored
Records — such as customers, sites, jobs, visits, observations, checklist answers, file metadata and report snapshots — are stored in FieldProof's database, hosted by Cloudflare.
Files — evidence, previews, Word reports, templates and logos — are stored in the organization's active storage destination:
- FieldProof internal storage (Cloudflare R2), used by default;
- the organization's Google Drive;
- the organization's Microsoft OneDrive; or
- a SharePoint document library chosen by the organization.
Only an Owner or Administrator can connect a provider or change the active destination. A change applies to new files; existing files stay where they were stored. Files kept in Google Drive, OneDrive or SharePoint are held in the organization's own account, under its settings and its agreement with that provider, and remain there if the connection is removed.
8. Service providers
We use the following providers to run FieldProof. They process personal data only as needed for the service they provide:
- Cloudflare: hosting of the application, database and internal file storage, delivery of transactional emails, bot protection on public forms (Turnstile) and operational logs;
- Google: sign-in with Google and, when an organization connects it, Google Drive storage;
- Microsoft: sign-in with Microsoft and, when an organization connects them, OneDrive or SharePoint storage;
- Stripe: payment processing and subscription management for paid plans.
The role of each provider depends on the service. Cloudflare acts on our instructions. When an organization connects its own Google Drive, OneDrive or SharePoint, the provider holds those files under the organization's own account and agreement. Stripe may act as an independent controller for some payment data, under its own privacy policy. We will provide more details on request at support@cloudfmsolutions.com.
We may also disclose personal data to professional advisers bound by confidentiality, to authorities when the law requires it, or to a successor in a merger, acquisition or sale of assets, in which case we will inform you.
9. International transfers
Our production database and internal file storage are configured to keep data at rest in Cloudflare's European Union jurisdiction. However, the providers listed above operate global infrastructure, and some processing — for example request handling on Cloudflare's network, email delivery, sign-in, payments, or files an organization keeps in Google or Microsoft — may take place outside the European Economic Area (EEA), including in the United States.
When personal data is transferred outside the EEA, we rely on the safeguards recognized by the GDPR that are available for each provider, such as a European Commission adequacy decision or standard contractual clauses. You can ask us for more information about these safeguards at support@cloudfmsolutions.com.
10. Data retention
We keep personal data only for as long as it is needed for the purposes in this policy:
- Account data: while you have access to a FieldProof organization and afterwards for as long as needed to keep the organization's records accurate, for example to show who created a record or a report;
- Customer Data: while the organization's account is active, until an authorized user deletes it or until the organization's account is closed (section 13); Organizations whose trial ended and did not move to a paid plan are permanently deleted 30 days after the trial ends, after we notify the Owner by email.
- Deleted records and files: when a user deletes a record or an evidence file, it is removed from the application. The organization's settings determine whether the stored file is kept for audit purposes (the default) or removed from storage immediately;
- Files in Google Drive, OneDrive or SharePoint: under the organization's control in its own account; they are not deleted when the connection is removed;
- Sessions: until you sign out, or 30 days after sign-in;
- Access and trial requests: for as long as needed to review the request and keep a record of the decision;
- Billing records: for the period required by tax and accounting law;
- Abuse-prevention values derived from IP addresses: 24 hours;
- Operational logs: for the retention period applied by our hosting provider;
- Aggregate website statistics: these contain no personal data.
11. Security
We use technical and organizational measures appropriate to the nature of the data, including encrypted connections (HTTPS), access restricted by organization and role, server-side sessions, encryption of stored authorization tokens, integrity fingerprints for evidence files, an activity history and bot protection on public forms. Access to production systems is limited to the people who need it.
No online service can be completely secure. If a personal data breach is likely to affect your rights, we will notify the competent authority and, where required, the affected people and organizations, as the GDPR requires.
12. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data erased when there is no longer a reason to keep it;
- restrict processing in certain circumstances;
- receive the data you provided in a structured, machine-readable format and have it transmitted to another controller (portability);
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent, without affecting earlier processing.
To exercise these rights, write to support@cloudfmsolutions.com. We may need to confirm your identity first. We will reply within one month, which may be extended in the cases allowed by the GDPR. If your request concerns Customer Data held by an organization, we will pass it on to that organization or help it respond, because it decides on that data.
You also have the right to lodge a complaint with a supervisory authority. In Portugal, this is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt. You may also contact the authority of the EU country where you live or work.
13. Account and data deletion
Authorized users can delete many records directly in FieldProof — customers, sites, areas, jobs, visits, observations, evidence and reports — according to their role and to protections such as the lock on completed visits. Owners and Administrators can suspend team members and disconnect storage providers.
Owners can delete their organization at any time in Settings → Delete organization. The deletion is immediate and permanent: all of the organization's records and the files held in FieldProof's internal storage are erased, and the members who belong to no other organization have their accounts anonymized. Files the organization keeps in its own Google Drive, OneDrive or SharePoint are not deleted by FieldProof and remain under its control. An active subscription must be cancelled first, and we keep only the billing records that the law requires.
Owners can also delete a user in Team. The user's access is removed and, if the person belongs to no other organization, the account is anonymized: name, email address and sign-in identifiers are erased. Records the person created stay in the organization — which is responsible for them — attributed to a deleted account; names that already appear as text in generated reports are not rewritten. Any person can also ask us to delete or anonymize their data at support@cloudfmsolutions.com; we will confirm your identity and respond within the legal deadlines.
15. Changes to this policy
We will update this policy when FieldProof or the way we handle personal data changes. The “Last updated” date at the top shows the current version. If a change is significant, we will inform the Owners of active organizations by email or in the application before it takes effect.
16. Contact
- Entity
- CloudFM Solutions, Lda
- Registered office
- Rua Cimo da Vinha, 40-C, 7300-658 Fortios
- Registration number
- PT510123864
- VAT number
- PT510123864
- Privacy
- support@cloudfmsolutions.com
- Support
- support@cloudfmsolutions.com
For privacy questions and requests, write to support@cloudfmsolutions.com. For product support, write to support@cloudfmsolutions.com.
See also: Terms of Service