Contents
1. Who is responsible
Two different relationships exist, and they matter:
- Your organisation is the controller of the personal information inside your workspace — your staff, your contractors, your clients. You decide what goes in and who sees it. We process it on your instructions, under the Data Processing Addendum.
- We are the controller of the information we hold about you as a customer: your account, billing contact and your use of our website.
This policy covers both. Where they differ, it says so.
2. What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Name, email address, role, the organisation you belong to | Entered by your administrator when they invite you |
| Authentication | Password (stored hashed, never in readable form), sign-in times | You, at sign-in |
| Project content | Projects, tasks, notes, documents, drawings, photographs, estimates, invoices, contracts | Uploaded by your team |
| Site records | Daily logs, incident reports, punch lists, check-ins, site photographs | Entered on site, often from a phone |
| Location | Coordinates and timestamp of a crew check-in — see section 3 | The device, with the operating system's permission |
| Communications | Messages sent inside the platform | Your team |
| Technical | IP address, browser and device type, error diagnostics | Automatically, when the service is used |
3. Crew location
This deserves its own section, because it is the most sensitive thing the platform handles.
- Location is recorded only for users with a crew role, and only when their organisation has enabled tracking for them.
- It is recorded only between 7am and 6pm Nassau time. Outside those hours the system refuses to record a position at all — this is enforced on the server, not only in the app, so it cannot be bypassed by a modified client.
- A position is a coordinate and a time. It is not a continuous track, and it is not shared outside the organisation.
- Only project managers, administrators and site inspectors within the same organisation can see it.
- Location records cannot be edited or deleted through the app, so the site record stays trustworthy.
If you are a crew member and want to know whether tracking is on for you, ask your administrator — they control it, not us.
4. Why we process it
- To provide the service — this is the bulk of it, and the basis is the contract with your organisation.
- To keep it secure — detecting misuse, investigating incidents.
- To meet legal obligations — including record-keeping and tax.
- To bill and support you.
We do not use your data for advertising and we do not sell it.
5. Where data is stored
Data is stored on Google Cloud Platform in the
us-east1 region, in the United States. This means personal
information about people in The Bahamas is transferred to and stored in the
United States.
6. Who else processes it
We use these providers to run the service. Each receives only what its function needs.
| Provider | Purpose | Data it sees | Location |
|---|---|---|---|
| Google Cloud / Firebase | Hosting, database, file storage, authentication, push notifications | All service data | United States |
| Anthropic | AI drafting of estimates and code-compliance checks | Only the project content sent with a request — see section 7 | United States |
| Twilio | SMS and WhatsApp notifications | Recipient phone number and message text | United States |
| OpenWeatherMap | Weather and storm alerts | Site coordinates only — no personal information | Europe |
| Web Hosting Canada | Outbound email delivery | Recipient address and message content | Canada |
We will give notice before adding a sub-processor that handles personal information.
7. AI features
Two features send content to an AI provider: drafting an estimate, and checking project information against building code requirements.
- Only the content needed for that request is sent — the project scope, the relevant records — not your whole workspace.
- Your content is not used to train the provider's models.
- Output is a draft for review. Section 9 of the Terms covers what that means for responsibility.
8. How long we keep it
While your organisation has an account, we keep your data so the service works. Messages are never hard-deleted, so the project record stays complete; they are marked deleted and hidden instead.
9. Security
- Encrypted in transit (TLS) and at rest, by the cloud platform.
- Access is role-based and enforced on the server, not only in the app. A user cannot reach data outside their organisation even by calling the database directly.
- Each customer organisation's data is separated, and that separation is tested automatically against the live rules on every change.
- Passwords are stored hashed. Nobody at ConstructIQ can read them.
- Administrative access to customer data is limited to named operators and is logged.
We hold no security certification. We would rather say so than imply one.
10. Your rights
Under Bahamian data protection law you may ask for access to your personal information, correction of it, and in some cases its deletion.
If your data is in a customer's workspace, ask that organisation first — they control it. If you contact us instead, we will pass the request to them and help them answer it.
For information we hold about you as our own customer, contact us directly.
11. Cookies
The application uses browser storage to keep you signed in and to hold an offline copy of your work so the app functions without a connection. These are necessary for the service and are not used for tracking or advertising.
This marketing site sets no analytics or advertising cookies.
12. Children
The service is for business use. It is not directed at children and we do not knowingly collect their information.
13. Changes
We will post changes here and update the date above. Material changes affecting how we handle personal information will be notified to account administrators.
14. Contact
support@constructiq.dev
Nassau, Commonwealth of The Bahamas