Stavo

Security and data protection · last updated 24 September 2026

How Stavo protects the record of a job

Stavo holds the evidence of building work: stamped photographs, inspection stages, sign-offs, documents and the conversations around them. Building Control officers, SAP assessors, warranty inspectors, clients and builders each rely on it. This page sets out how that record is held and protected, plainly and without claims beyond what is true today.

Where the record is held

WhatWhere
The databaseAccounts and the record of each job, held by Neon (PostgreSQL) in the European Union.
Photographs and filesCloudflare R2 private storage. Nothing is publicly addressable; every file is served through the checks below. Confining this storage to Cloudflare's EU jurisdiction is in progress.
The applicationServed by Cloudflare's network over HTTPS.
On a phoneThe app keeps a copy of the part of the record that person may see, and a queue of what they did with no signal, so it works on site. Signing out clears it once the queue has been sent. The phone is never the only copy.

Who sees what

A person sees a job only if the builder or developer running it has named them on it, by email address and in their role, and they have joined it with the job's code. Within a job, each role sees its own part:

RoleSeesDoes not see
Building ControlThe inspection stages, their photographs, the Building Control conversation, documents shared with them.Quotations, payments, variations, EPC evidence, other conversations.
SAP assessorThe EPC evidence items and their photographs, the EPC conversation.Building Control's stages and notes, money, other conversations.
Warranty inspectorThe warranty stages and the photographs filed to them, the warranty conversation.Money, EPC evidence, Building Control's notes.
ClientTheir own job: progress, their conversation, documents shared with them, the quotation, variations and payments.Draft variations, other jobs, conversations they are not in.
Builder on a developer's jobThe work on that job, and their own quotation, variations and payments.Any other builder's prices.

These rules live in one place and run on the server for every request: what is sent to a phone is already cut down to that person's part. A file — a photograph, a document, an attachment — is served only if it is in that person's part of the record. Nobody at Stavo reads the content of a job in the course of running the service.

Accounts and sign-in

The integrity of the evidence

What is logged

Alongside the record of every change, Stavo keeps an access log: each sign-in and sign-out, each refused sign-in with the reason, each time a person opens a job's record or a file on it, and each report taken away — with the time and the network address. It is kept for twelve months, then deleted. It means the question "who has seen this job?" can be answered.

Protection in transit and at rest

Getting data out

Keeping and deleting

The record of a job is kept for as long as the job exists on Stavo. When a job or an account is deleted at the request of the person entitled to ask, it is removed from the live service within 30 days and from backups within a further 90. Records that others on the job rely on, such as a sign-off, may be exported first.

If something goes wrong

If a breach of personal data occurs, we will tell the organisations and people affected without undue delay, and report it to the Information Commissioner's Office within 72 hours where the law requires. To report a security concern, write to [email protected]; it is read and acted on promptly.

The services Stavo runs on

ServiceWhat it does
CloudflareServes the application and the API; stores photographs and files.
NeonThe database, in the European Union.
ResendSends the password-reset email.
OpenStreetMap, postcodes.ioMap tiles behind a photograph's location and the look-up of a job's position from its address. No account or name is sent.
Google FontsThe typeface on the web pages.

For a council or other organisation, a data processing agreement setting out these terms is available on request. How personal information is handled is described in full in the privacy notice.