Legal document
Privacy Policy
What the website and the service do with personal data, who is responsible for what, and how to have data corrected or deleted.
Draft - pending legal review. This text was written by the product team, not by a lawyer, and it is published for comment while the company behind the product is being set up. It is not part of any contract until we say so in writing, and it will change after the legal review.
Square brackets mark a detail that is not decided yet. We would rather leave the gap visible than fill it with something that is not true.
1. The short version
This policy covers two different things. The website you are reading: we decide what happens on it, it sets no advertising or analytics cookies, and the only personal data it collects is what you type into the demo request form. The service itself, where a construction company runs its deliveries: there the customer company decides what goes in and why, and we run the system on its instructions.
We do not sell personal data, we do not use customer content to train AI models, and we do not follow visitors across other websites.
2. Who we are and how to reach us
The service is operated by [to be completed before launch], [to be completed before launch].
Privacy questions, requests and complaints go to [to be completed before launch]. We answer within five working days, and within one month for a formal request under data protection law.
No data protection officer has been appointed. Our own reading of Article 37 GDPR is that we do not need one: monitoring people is not our core activity and we do not handle special category data at scale. This is one of the points the legal review has to confirm, and if the answer changes the contact above changes with it.
3. Our role: processor for customer data, controller for our own
Data protection law splits responsibility in two. The controller decides why and how data is processed. The processor only follows the controller's documented instructions. Which hat we wear depends on whose data it is.
- Customer content - deliveries, receiving photos, supplier and invoice data, and the customer's own staff accounts: the customer company is the controller and we are the processor. What we may do with that data is set by the contract and the Data Processing Addendum, not by us.
- Our own users and visitors - the person who opens an account, billing contacts, people who fill in the demo form, anyone who writes to support: here we are the controller and this policy is the full answer.
- California: for customer content we act as a service provider under the CCPA. We do not sell or share personal information, and we do not use it for any purpose other than providing the service.
4. What the service holds
- Accounts: name, work email, phone if it is given, role and permissions, company, language and theme, sign-in times and the IP address of the session.
- Deliveries and receiving: what was ordered and what arrived, quantities and comments, photos taken at the gate, the time of the scan and, when the phone allows it and the person agrees, the coordinates of the place where receiving was confirmed.
- Field users: foremen and receivers work through a QR link without an account. What is kept is the name or code they type in, the result of the PIN check, the type of device, and the same photo, time and location as above.
- Suppliers and money: supplier company details, contact names and email addresses, invoices and delivery notes with everything printed on them, amounts, payment dates, and bank details when they appear on the document.
- Messages: chat messages and voice notes inside the account, and the email we exchange with support.
- Technical: server logs - IP address, browser, pages, errors - kept to keep the system running and to investigate abuse.
Special categories of data - health, beliefs, trade union membership, biometrics - have no place in this product. Please do not put them into delivery comments or photographs.
5. What the website collects
- The demo request form: your name, your company, your work email and the message you write. It is used to answer you and to prepare the demo, and nothing else.
- Your browser: the light or dark theme, the language you picked and whether the fonts are already cached. This is local storage in your own browser, not cookies, and none of it reaches us. The Cookie Policy lists every key by name.
- Server logs: the usual web server record of requests, kept for a short period and used only to keep the site up and to spot attacks.
6. Why we are allowed to hold it
For data where we are the controller, the legal bases under Article 6 GDPR are:
- Contract - running the account of a customer who signed up, taking payment, answering a demo request that you sent us.
- Legitimate interests - keeping the service secure, preventing abuse, keeping records of what was agreed, and improving the product from aggregated usage figures that do not identify anyone.
- Legal obligation - invoices and accounting records that tax law requires us to keep.
- Consent - anything optional, such as product news by email or reading the location of a phone during receiving. Consent can be withdrawn at any time, and withdrawing it does not make what happened before unlawful.
For customer content the legal basis is the customer company's, not ours. We process it because the contract with that company tells us to.
7. Documents, questions and AI
Reading an invoice or a delivery note from a photograph, comparing quotes and answering questions in the assistant are done by AI models that we do not own. The request leaves our system through our gateway and reaches the model provider.
Masking before sending. The rule we work to is that a document is stripped of what recognition does not need before it leaves us: names of individuals, phone numbers, handwritten signatures and any faces that ended up in the frame. What goes out is the commercial content - supplier, items, quantities, prices, dates. Masking is automatic, it cannot be perfect, and it is one of the items the pre-launch review has to sign off.
No training on your data. Our contract with a model provider has to forbid training on customer content and has to limit how long the provider keeps a request. A provider that will not agree to that is not used. The providers in use are named on the Subprocessors page.
AI does not decide anything. What the model returns is a suggestion in a form that a person checks. No payment, no approval, no supplier rating and no decision about a person is made automatically. Where you are talking to the assistant, the interface says so, because you have a right to know when you are talking to a machine.
It can be switched off. An account that does not want documents leaving the system can run without the AI features. Everything else keeps working.
8. Who else sees the data
Only the services we need to run the product, and only for that. Each one is listed on the Subprocessors page with what it does and what reaches it. Each one is under a written contract with the same obligations we owe our customers.
Beyond that: nobody. We do not sell personal data, we do not share it for advertising, and we do not hand it to anyone else unless the law requires it. If we ever receive a legally binding demand for customer data, we tell the customer unless we are forbidden to.
If the business is ever sold or merged, customer data goes with it and customers are told before it happens, with time to leave and take their data.
9. Where the data is stored
Customer data is hosted in [to be completed before launch]. The exact provider and location go into the contract before you sign, and they are on the Subprocessors page.
Where a subprocessor sits outside the European Economic Area or the United Kingdom, the transfer runs on the European Commission's standard contractual clauses, with the UK addendum or an international data transfer agreement for UK data, plus a check that the destination country does not make those clauses meaningless in practice.
For customers in Armenia, the Law on Protection of Personal Data allows a transfer abroad with the consent of the person concerned, to a country on the regulator's list, or with the regulator's permission. Which route applies is written into the contract.
10. How long it is kept
- While the account is live: everything stays, because a delivery from two years ago is still evidence in an argument with a supplier.
- Unpaid subscription: seven days of reminders, then thirty days read-only, then the account is archived. Archived data is handed over on request for another ninety days and deleted after that.
- End of contract: the customer chooses - a machine readable export or deletion. We do it within thirty days of the choice, and the data leaves the backups within thirty days after that.
- Demo requests: twelve months, unless the conversation turns into a contract.
- Support email: twenty four months.
- Server logs: ninety days.
- Invoices and accounting records: as long as tax law requires, which is six to ten years in most of the countries we sell in.
11. Your rights
Under the GDPR and the UK GDPR you can ask for a copy of your data, ask for it to be corrected or deleted, ask us to limit what we do with it, ask for it in a portable format, object to processing based on legitimate interests, and withdraw any consent you gave. You can also complain to the data protection authority in your country - you do not have to go through us first.
Under the CCPA, residents of California can ask what personal information is held, where it came from and who it went to, ask for it to be deleted or corrected, and limit the use of sensitive information. We do not sell or share personal information as the CCPA defines those words, and nobody is treated worse for exercising a right.
One practical point. If your data sits inside a customer's account - you are a foreman, a receiver or a supplier contact - that company is the controller. Send the request to them and we will help them answer it. If you do not know who to ask, write to [to be completed before launch] and we will pass it on and tell you that we did.
12. Keeping it safe
Traffic is encrypted in transit. Passwords are stored as salted hashes, never in readable form. Access inside the product follows the role a person was given. Our own access to customer data is limited to the people who need it to run the service and to answer support requests, under a confidentiality obligation. Backups are taken regularly and restores are tested.
We hold no security certification. There is no ISO 27001 certificate and no SOC 2 report behind this text. If we ever get one, it will be named here in plain words rather than hinted at.
If personal data is breached, we tell the affected customer without undue delay and with what we know, so that the customer can notify its supervisory authority inside the seventy two hours the GDPR allows. Where we are the controller, we notify the authority ourselves.
13. Children
This is a tool for work. It is not meant for anyone under sixteen, and we do not knowingly collect data about children. If a child's data has ended up in an account, write to us and it will be removed.
14. Changes to this policy
The current version is always on this page with its date. If a change matters to you - new subprocessor, new purpose, shorter protection - account administrators get an email at least thirty days before it takes effect, and the Subprocessors page carries the same notice period.
Version 1.0, 18 September 2026. This page always shows the current version; earlier versions are kept and sent on request.
Questions about this document: [to be completed before launch].
Other legal documents