Privacy Policy
Document version: `privacy-v1.1`
> This is the single Privacy Policy for BuildManager. It supersedes every earlier version,
> including `privacy-v2-DRAFT`, the separate in-app text, and Document D of the Supporting
> Policies pack. The same document is served on the website and inside the application.
BuildManager.Cloud Pty Ltd (ACN 702 052 202) ("BuildManager", "we", "us", "our") provides a cloud-based construction project management platform (the "Service"). This Privacy Policy explains how we collect, use, hold, disclose and protect personal information, and how we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
By creating an account or using the Service, you acknowledge the practices described in this Policy.
1. Who this Policy applies to
This Policy covers personal information we handle about:
- Account holders and team members — the builders, staff and contractors who log in and use the Service.
- Directory contacts — subcontractors, suppliers and other contacts that account holders add to their workspace.
- Visitors to our website and signup pages.
Each customer organisation (a "tenant") is the controller of the data it enters; we process that data on the tenant's behalf and to operate the Service.
2. Information we collect
Account and identity information: name, email address, and authentication credentials (passwords are stored only as salted hashes by our authentication provider — we never see them in plain text).
Tenant and workspace data: company details, jobs, cost centres, budgets, quotes, variations, site diaries, tasks, schedules, and directory contacts you enter.
Uploaded files: documents and images you upload, including subcontractor compliance documents (such as insurance certificates and licences), site induction records, White Cards, and ID photos. Some uploaded documents and photos are read by automated technology to extract key details (see Section 5).
Usage and technical data: log data, device and browser information, IP address, and actions taken in the Service, collected automatically to operate, secure and improve the platform.
Billing information (if and when paid plans are enabled): plan selection and subscription status. Card payment details, if collected, are handled by our payment processor and are not stored by us.
We generally do not seek sensitive information. Please do not upload sensitive information (such as health information) unless it is necessary for a legitimate compliance purpose.
3. How we collect it
We collect information directly from you when you sign up, enter data, or upload files; and automatically through your use of the Service. Where an account holder adds a directory contact's details, that information is provided to us by the account holder. Subcontractors may also submit their own documents to a tenant through a secure upload link.
4. Why we use it
We use personal information to: create and administer accounts; provide and operate the Service; enforce tenant isolation and access controls; read uploaded documents and photos to extract details and reduce manual data entry (see Section 5); send service and compliance-related emails (such as document-expiry reminders); provide support; maintain security and prevent misuse; meet legal and record-keeping obligations; and improve the Service. We do not sell your personal information.
5. Automated processing and artificial intelligence
To save manual data entry, the Service uses automated data-extraction ("AI processing") to read certain documents and photos you or your subcontractors upload — such as insurance certificates, licences, White Cards and hand-written site diaries — and to extract key details (for example an insurer name, a policy or licence number, an expiry date, or the fields of a site-diary entry). It also offers AI features that help draft text such as messages, quote terms and notes.
Human review. Extracted details and drafted text are presented to a user to review and confirm before they are relied upon. The automated output is not used to make a legal or similarly significant decision about any individual without human involvement.
Our AI sub-processors do not train on your data. To perform this processing we disclose the relevant document, photo or context to a trusted AI service provider (listed in Section 6). That provider processes the data only to return a result to us; it does not use your data to train its models, and it does not retain your documents beyond what is necessary to return that result (where available, we use zero- or minimal-retention processing). Where we operate this processing in an Australian region, your document data is processed within Australia (see Section 7).
6. Disclosure and our service providers (sub-processors)
We do not sell personal information. We disclose information to trusted service providers who help us run the Service, under contractual confidentiality and security obligations:
- Supabase — database, file storage and authentication.
- Vercel — application hosting.
- Resend — transactional email delivery.
- AI document-processing provider — Anthropic (Claude) and/or Amazon Web Services (AWS Bedrock), used to read uploaded documents and photos and return extracted details (see Section 5). These providers do not train on your data.
- Xero — only where a tenant connects their Xero account, to sync financial data they authorise.
- Stripe — only if and when paid subscriptions are enabled, to process payments.
We may also disclose information where required by law, to enforce our Terms, or to protect the rights, safety and property of BuildManager, our customers or others.
7. Overseas disclosure
Our database and uploaded files are hosted on Supabase infrastructure located in Sydney, Australia (`ap-southeast-2`). Our AI document-processing (Section 5) is carried out either within Australia (AWS Bedrock, Sydney region) or, depending on configuration, by a provider located outside Australia, including in the United States (Anthropic). Some of the other service providers listed in Section 6 — including our email delivery and payment providers — may also store or process limited information overseas. Where information is disclosed to an overseas recipient, we take reasonable steps to ensure the recipient handles personal information consistently with the APPs, including through contractual data-protection terms and commitments not to train on or retain the data.
8. Storage, security and retention
We take reasonable steps to protect personal information, including row-level tenant isolation, access controls, and encryption of data in transit. No system is perfectly secure, and we cannot guarantee absolute security.
We retain personal information for as long as an account is active and as needed to provide the Service. When you cancel, your data remains exportable for 30 days. Some records — particularly financial records — are retained for at least 7 years to meet Australian legal obligations. When data is no longer required, we take reasonable steps to delete or de-identify it.
9. Notifiable data breaches
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
10. Access and correction
You may request access to, or correction of, the personal information we hold about you by emailing hello@buildmanager.cloud. We will respond within a reasonable period. If we decline a request, we will explain why where required. Account holders can also access and amend much of their data directly within the Service.
11. Cookies and local storage
The Service uses cookies and browser local storage to keep you signed in and to remember preferences. These are necessary for the Service to function. We do not use third-party advertising trackers.
12. Children
BuildManager is intended for use by adults in a professional context. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.
13. Complaints
If you believe we have breached the APPs, contact us at hello@buildmanager.cloud and we will investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Changes to this Policy
We may update this Policy from time to time. The current version will always be available within the Service, and material changes will be notified by reasonable means.
15. Contact us
BuildManager.Cloud Pty Ltd — ACN 702 052 202
Email: hello@buildmanager.cloud
Location: Gold Coast, Queensland, Australia