Privacy Policy
This is a translation provided for comprehension. The Czech wording governs — where the two differ, the Czech text prevails. View the Czech wording.
Buildify Digital s.r.o., Company ID 29541743, Korunní 2569/108, Vinohrady, 101 00 Prague 10, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 447453.
Version 1.0 · effective from 1 September 2026 · contact kluch@buildify.cz
1.Who we are and how to reach us
1.1 This policy describes how we handle personal data in operating the Buildify CDE service (the web application cde.buildify.cz, the identity server api.buildify.cz) and the marketing website buildify.cz.
1.2 The operator is Buildify Digital s.r.o., Company ID 29541743, registered office at Korunní 2569/108, Vinohrady, 101 00 Prague 10, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, file no. C 447453. The managing director is Lukáš Kluch, who represents the company individually.
1.3 Write to us at kluch@buildify.cz. Send requests to exercise the rights in Article 9 to the same address.
1.4 We have not appointed a Data Protection Officer. We do not meet the conditions in Art. 37 GDPR — we are not a public authority, we do not monitor people on a large scale, and we do not process special categories of data on a large scale. Data protection matters are handled directly by the managing director.
2.Two roles: when we are a controller and when a processor
2.1 Our position differs according to the data in question.
2.2 We are the controller of user account data and the service's operational data: e-mail, first and last name, avatar, password hash, e-mail verification status, sign-in method, last sign-in time, audit log, sessions and tokens, billing details, and enquiries from the website. We decide about this processing and it is governed by this policy.
2.3 We are a processor of everything you upload into projects: documents, CAD and DWG, IFC and BIM models, LandXML, point clouds, photographs, defects, forms, tasks, comments and markups. The controller of that content is the company that acquired the service. We work with it only on that company's instructions and under the data processing agreement in place.
In plain terms: We run your account. What you upload into it belongs to your company. If you want to know why your personal data appears in someone else's project, ask the company running that project. We will help them handle it.
3.What we process as a controller
3.1 An overview of the processing we decide about:
| Purpose | Data | Legal basis | For how long |
|---|---|---|---|
| Account and sign-in | e-mail, first name, last name, avatar, password hash, e-mail verification status, sign-in provider (password, Microsoft, Google), external ID, last sign-in time | performance of a contract, Art. 6(1)(b) | for the life of the account and 30 days after it is closed |
| Multi-factor authentication for super-admins | TOTP secret | legitimate interest in security, Art. 6(1)(f) | while the role is active |
| Invitations to an organisation and projects | invitee's e-mail, who invited, invitation status | performance of a contract and legitimate interest | the invitation is valid for 14 days, then it is voided |
| Audit log | userId, e-mail, action, entity, old and new values, IP address, User-Agent, project | legitimate interest in accountability and security, Art. 6(1)(f) | 24 months |
| Sessions and tokens | access token, refresh token, list of revoked tokens, IP address | performance of a contract | refresh token 30 days, revoked tokens until they expire |
| Notifications and transactional e-mails | e-mail, notification settings, delivery status | performance of a contract | for the life of the account |
| Website enquiry form | name, e-mail, phone, company, enquiry text | legitimate interest in pre-contractual dealings, Art. 6(1)(f) | 24 months from the last contact |
| Website traffic measurement | identifiers from Google Analytics 4 cookies, IP address, pages visited, technical browser data | consent, Art. 6(1)(a) | per Google's settings; your consent is valid for 12 months |
| Invoicing and accounting | billing details, documents, payment history | legal obligation, Art. 6(1)(c) | 10 years |
| Operational logs and telemetry | IP address, technical identifiers, error records | legitimate interest in operation and debugging, Art. 6(1)(f) | 90 days |
| Marketing (newsletter, commercial communications) | e-mail, name, consent record | consent, Art. 6(1)(a), or the exemption for existing customers | until withdrawn, at most 3 years |
| Defence of legal claims | data from contractual and e-mail communication, audit log | legitimate interest, Art. 6(1)(f) | for the limitation period |
3.2 The audit log is the core of what a CDE is for. Under ISO 19650, it must be demonstrable at any time who approved what, who changed a revision code and when. That is why we record who performed an action and from where. Without it, output from the CDE would carry no evidentiary weight.
3.3 The audit log therefore outlives the account. When you close your account we delete the profile, but the records of actions in projects remain for the rest of the 24-month period. Otherwise it would be possible to erase the trace of one's own approval retrospectively. This is our legitimate interest and that of the other parties to the construction project. You may object to it under Article 9.
3.4 We record the IP address and User-Agent only at sign-in, for actions in the audit log, and in operational logs. We do not track which pages you move through and we do not profile you.
3.5 We handle a website enquiry as pre-contractual dealings. If no contact occurs within 24 months, we delete the enquiry. Commercial communications beyond a reply to the enquiry are sent only with consent.
3.6 The identity server api.buildify.cz is also used by the sister product bpulse from the same provider; these are two separate processing operations by the same controller, and Buildify CDE data is not used for bpulse.
3.7 Traffic measurement runs only on the marketing website buildify.cz and only after your consent given in the cookie banner. We do not send your name, e-mail, phone number or enquiry text into measurement. No analytics or advertising tool runs in the web application or on the identity server. What exactly is stored, and how to withdraw consent, is described in the Cookie Policy.
4.Photographs from the construction site
4.1 In field mode, photographs from the site are uploaded into defects and documentation. They often show people, their faces, company clothing and vehicle registration plates. That is personal data.
4.2 For these photographs we are a processor. The controller is the company that uploaded them into the project. It decides why the photographs are taken, how long they are kept and who sees them. It also discharges the duty to inform the people in them.
In plain terms: If you are in a site photograph and do not want to be, contact the company that took it. We do not view photographs uploaded into a project and we do not pass them to anyone. We cannot judge for ourselves who is in them.
4.3 Text extraction from documents runs locally on our servers using the Tesseract library. The content of your files does not leave our environment for it.
5.Share links and the printout verification page
5.1 A user can create a share link that lets someone without an account reach a document. The company running the project decides whether to create the link — we are a processor there. For the access itself we record the technical data needed for security and accountability: time of access, IP address and User-Agent. It serves to defend against abuse of the link.
5.2 The public printout verification page is anonymous. You scan the QR code from the print stamp and the page shows only whether the printout is still valid and which version it belongs to. The document content is not displayed there and verification requires neither a sign-in nor any details about you.
6.Who we pass data to
6.1 We do not sell personal data. We pass it only to the suppliers we need in order to run the service:
| Entity | Legal entity | Purpose | Where |
|---|---|---|---|
| Google Cloud | Google Cloud EMEA Limited, Ireland | Cloud Run, Cloud SQL, Cloud Storage, Firebase Hosting, logs | europe-west3, Frankfurt |
| Stripe | Stripe Payments Europe, Limited, Ireland | payments and subscriptions | EU; standard contractual clauses within the group |
| Brevo | Sendinblue SAS, France | transactional e-mails | EU |
| MailerSend | MailerSend, the MailerLite group | transactional e-mails | EU |
| Microsoft | Microsoft Ireland Operations Limited | optional sign-in with a Microsoft account | EU |
| Google Ireland Limited | optional sign-in with a Google account | EU |
6.2 In-browser document editing via Collabora Online is operated by us on our own virtual infrastructure in Google Cloud. It is not a sub-processor and documents do not leave our environment while being edited.
6.3 We may also pass data to public authorities where the law requires it, and to our legal or accounting adviser.
6.4 We notify customers of a change of sub-processor 30 days in advance.
7.Data stays in the EU
7.1 All processing takes place in the European Union. The application, the database and the storage run in Google Cloud in the europe-west3 (Frankfurt) region. Backups are held there too.
7.2 The single exception is Stripe, which may pass payment data within its group. This happens on the basis of the standard contractual clauses under Commission Implementing Decision (EU) 2021/914.
In plain terms: Your files stay in Frankfurt. The only thing that leaves the EU is what is needed to settle a card payment.
8.How long we keep data
| What | For how long |
|---|---|
| Project content | for the term of the contract |
| Recycle bin | 30 days, then permanent deletion |
| After the contract ends | 30 days of read-only access and export, a further 60 days of backup, then irreversible deletion |
| ZIP export for download | 3 days |
| Audit log | 24 months |
| Backups | daily, 30-day retention |
| User account after closure | 30 days |
8.1 Longer periods apply only where the law prescribes them (accounting records, 10 years) or where we need the data to defend a legal claim.
9.Your rights
9.1 You have the right of access to your data, to rectification of inaccurate data, to erasure, to restriction of processing, to portability of data processed on the basis of a contract or consent, to object to processing based on legitimate interest, and to withdraw consent at any time. Withdrawal does not affect processing carried out before it.
9.2 Write to kluch@buildify.cz. We will handle it within one month. If the request is complex or several arrive at once, we may extend the period by a further two months — we will tell you within a month of your request, and why.
9.3 We have to verify that it is really you. Usually it is enough that you write from the e-mail address you use to sign in. Where that is not enough, we will ask for an additional detail. We do not want a copy of your identity document.
9.4 Where the request concerns content in a project, for which we are only a processor, we cannot handle it ourselves. We will pass it without undue delay to the company that is the controller and tell you to whom. We have undertaken to our customers to cooperate within 10 working days.
9.5 The basics you can do yourself: edit your profile in account settings, turn off notifications in notification settings, and unsubscribe from marketing e-mails via the link in the footer.
10.Automated decision-making
10.1 We carry out no automated decision-making and no profiling with legal effects concerning you.
11.Complaint to the supervisory authority
11.1 If you believe we are handling your data badly, please come to us first. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
12.Security, children and changes to this policy
12.1 We protect data with technical and organisational measures — database-level isolation of each customer's data, granular folder permissions, mandatory e-mail verification, multi-factor authentication for super-admins, encrypted transport and encryption at rest on the Google Cloud side, rate limiting, and auditing of actions. The full description of the measures is an annex to the data processing agreement we conclude with the customer.
12.2 The service is not intended for persons under 16 and we do not create accounts for them.
12.3 We may change this policy when the service or the law changes. A new version is published on the website with its effective date. For substantial changes we notify you by e-mail or in the application.
