Last updated: [date]
This document is a working draft for the D50 OS website. Replace the bracketed placeholders with your company details and have it reviewed by legal counsel before publication.
D50 OS is a construction management platform operated by [Legal company name], [Company registered address]. In this policy, "we", "us" and "our" refer to [Legal company name]. "You" refers to any visitor to this website or user of the D50 OS platform.
We collect only what we need to run the service and to answer you when you ask us something.
Where data protection law requires a legal basis, we rely on: performance of a contract (providing the platform), legitimate interests (securing and improving the service, responding to business enquiries), consent (marketing email and non-essential cookies) and legal obligation (accounting and tax records).
Data your organisation stores inside D50 OS - drawings, reports, budgets, photos and contacts - belongs to your organisation. We process it only to deliver the service, on documented instructions from your organisation. We do not sell it, share it with third parties for their own purposes, or use it to train machine-learning models outside your own account.
We share personal data only with: hosting and infrastructure providers that run the platform under written data-processing terms; payment and accounting providers where a purchase is involved; and authorities where we are legally required to do so. We do not sell personal data.
Contact enquiries are kept for up to 24 months. Customer project data is retained for the term of the agreement and remains available for export for 90 days after termination, after which it is deleted from production systems and, within a further 90 days, from backups.
Depending on where you live, you may have the right to access, correct, delete, restrict or port your personal data, to object to certain processing, and to withdraw consent at any time. To exercise any of these rights, write to [privacy@yourdomain.com]. We respond within 30 days.
We encrypt data in transit and at rest, apply least-privilege access controls, keep an immutable audit trail of changes and run annual third-party penetration testing. Detail is available on our Security page.
Where data is transferred outside your country, we rely on recognised transfer mechanisms and contractual safeguards with our processors. Enterprise customers may select the hosting region for their tenant.
We may update this policy. Material changes are announced on this page and, for customers, by email at least 30 days before they take effect.
Questions about this policy: [privacy@yourdomain.com], or write to [Company registered address].