Skip to content

Legal

Privacy Notice

How the current CostGrid implementation handles personal and organisation information.

Draft — not yet effective · Version 0.1.0

Draft for privacy and legal review. Publication is blocked until the controller contact, legal bases, transfer mechanism, retention criteria and contracted subprocessors are verified.

Scope and roles

This notice covers the CostGrid website, authentication, application, support and protected administration surfaces. The final controller identity, registered address and privacy contact route must be verified before publication. Customer organisations control the project content their authorised users enter.

Information handled

The implementation handles account and organisation information; roles and project memberships; construction projects, budgets, BOQs, costs and forecasts; vendor, contractor and consultant records; invoices, claims and payment-related records; uploaded files and evidence; usage, device, security and audit events; support communications; and trial, entitlement, subscription and future billing references.

Purposes

Information is used to authenticate users, enforce organisation and project access, operate financial-control workflows, calculate and reconcile authorised records, retain audit evidence, deliver invitations and service communications, answer support requests, prevent abuse, recover the service and administer trials and entitlements.

Legal bases

The applicable legal bases depend on the user, customer contract and jurisdiction and require qualified review before publication. They may include performance of a contract, legitimate interests, legal obligations and consent where a genuinely optional activity requires it.

Recipients, subprocessors and transfers

Infrastructure, authentication, storage, email, analytics, support and future payment providers may process limited information for their configured purpose. The verified provider list, contractual role and international-transfer mechanism must be completed in the Subprocessor List before publication. No data-residency claim is made.

Analytics and cookies

Optional first-party public-page analytics are disabled until a visitor chooses Allow. The current application also uses essential browser storage for authentication, preferences and application state. See the Cookie Notice for the current categories and controls.

AI-assisted processing

The repository contains an evidence-processing placeholder whose provider is unavailable. No active AI provider or training-use promise is stated. This notice must be revised before any AI provider is activated for customer content.

Retention

Retention follows objective criteria that still require approval: the active customer relationship, security and audit-evidence needs, correction and dispute windows, backup lifecycle, and applicable legal obligations. No fixed period is promised in this draft.

Security

CostGrid uses authentication, database-enforced access controls, protected server functions, tenant/project identifiers, restricted storage paths and audit records. No system is perfectly secure and no certification, encryption standard or audit outcome is claimed without evidence.

Rights and requests

Subject to applicable law and verified authority, people and customer organisations may request access, correction, export, deletion, restriction or objection. Organisation content requests should normally begin with the organisation administrator. The final verified privacy-contact and escalation route must be supplied before publication.

Change history

Version 0.1.0: initial governed draft. It is not effective and cannot be accepted as a published version.