Legal
Privacy Policy
Last updated 27 August 2026. Your documents are yours: isolated, encrypted, and never used to train models.
1. Scope
This policy explains how IPSES Technologies handles information when you visit our website, request a review, or use our pre-construction analysis platform. It covers both personal information about individuals and the project documents your organization uploads.
2. Information we collect
Account and contact information: name, work email, company, role, and authentication metadata such as sign-in times and identity-provider identifiers.
Customer Content: the plans, specifications, addenda, BIM and quantity exports, RFI logs, proposed schedules, estimates and related materials that you choose to upload. We only ingest what you upload — we do not connect to systems you have not authorized.
Usage and diagnostic data: pages viewed, features used, findings opened or actioned, error traces and performance metrics, used to operate and secure the platform.
We do not collect special-category personal data, and you should not upload personal information beyond what is incidental to construction documents.
3. How we use information
To provide the Services: ingest and index your documents, reconcile them against your schedule and estimate, generate findings with evidence and confidence, model financial and schedule impact, and produce review packages and drafted correspondence.
To support and secure your account: authentication, access control, audit logging, abuse prevention, backup and incident response.
To communicate with you: review status, service notices, security advisories, and — where permitted — information about the platform. You can opt out of marketing messages at any time.
4. Model training — our commitment
We do not use Customer Content to train, fine-tune, or evaluate any machine learning model, ours or a third party's. Where frontier models are used to analyze your documents, they are accessed under enterprise agreements that contractually prohibit training on submitted data and provide zero-retention or short-retention processing.
Findings and models are never shared across tenants. Any benchmarking we publish uses aggregate figures that cannot identify a customer, project, owner or bid.
5. Security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Each customer's content is logically isolated in a dedicated tenant with row-level access enforcement. Access follows least privilege, is scoped per project and role, supports SAML 2.0 single sign-on and enforced multi-factor authentication, and is fully audit-logged.
Internal access to Customer Content is restricted to named personnel, requires a documented support reason, and is logged and reviewed. We run continuous dependency and vulnerability scanning, periodic third-party penetration testing, and maintain a documented incident-response plan with breach notification without undue delay.
6. Sharing and subprocessors
We do not sell personal information or Customer Content, and we do not share it for cross-context behavioral advertising. We use a small number of subprocessors for cloud hosting, model inference, error monitoring and email delivery, each bound by confidentiality and data-protection obligations. A current subprocessor list is available on request at colleen@ipses.tech.
We may disclose information where legally required, provided we will, where lawfully permitted, notify you first so you can seek protective relief.
7. Retention and deletion
Customer Content is retained for the duration of your engagement plus a configurable retention window, by default ninety days, after which it is deleted from active systems and purged from backups within a further thirty-five days. You may request earlier deletion of a project or an entire tenant at any time.
Account records and invoices are retained as required for tax and audit purposes. Audit logs are retained for twelve months.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal information, and to object to certain processing or withdraw consent. Submit requests to colleen@ipses.tech; we verify requests and respond within the period required by applicable law.
Where we act as a processor on behalf of your organization, we will direct individual requests concerning Customer Content to that organization as controller.
9. International transfers
We host data in the United States. Where personal information is transferred from the European Economic Area, the United Kingdom or Switzerland, we rely on Standard Contractual Clauses together with supplementary technical measures including encryption and tenant isolation.
10. Cookies
Our website uses strictly necessary cookies for session management and security, and privacy-respecting analytics that do not build cross-site profiles. The application itself uses only functional cookies required to keep you signed in.
11. Children
The Services are intended for business use and are not directed to anyone under sixteen. We do not knowingly collect information from children.
12. Changes and contact
We will post material changes to this policy and notify account administrators at least thirty days before they take effect. Questions, requests or concerns can be sent to colleen@ipses.tech.