Privacy Policy
Last updated: 10 August 2026
This policy explains what personal data BuildWork collects, why, who it is shared with, and the rights you have over it. It covers the BuildWork website and the application behind it.
Who is responsible for your data
The company below operates BuildWork and is the data controller for the personal data described in this policy. Data-protection questions and requests go to the same address. We have not appointed a Data Protection Officer — we are not required to — so requests are handled directly.
- Registry code:
- 16403875
- Registered address:
- Türi 10d, Tallinn, Harjumaa
- Contact:
- info@buildwork.app
Two different roles we play
For your account and your company’s subscription we decide what is collected and why — we are the controller. For the content your company puts into the service — templates, orders, materials, and the client records that may name and give contact details for your own customers — your company decides what to enter and why; there we act only on your company’s instructions, as its processor. If you are someone’s customer and want your details removed from a company’s records, ask that company; we cannot make that decision for them, but we will help them carry it out.
Account data
To create and keep an account we store your name, email address, a hashed password (never the password itself), whether your email has been confirmed, and which version of the Terms of Service and this policy you accepted and when. Each sign-in creates a session record holding its expiry, your IP address and your browser’s user-agent string, so you can stay signed in and so we can spot suspicious access.
Company and content data
A company workspace stores its name, its members and their roles, and any pending invitations — including the email address an invitation was sent to. The work you do inside it (templates, orders, materials, units, saved views, notes and client records) is stored as you enter it. Every change is written to an activity log with the acting user, what changed and when, which is what makes the audit trail and the undo window work.
Billing data
Payments run through Stripe. Card numbers never reach our servers and we never store them — Stripe collects them directly. We store the identifiers Stripe gives us (customer, subscription and subscription-item ids), the subscription status, the billing interval, the number of seats and the current period end, which is what tells the app whether a company is on the free or paid tier.
Technical data
Sign-in, sign-up, password-reset and invitation requests are rate-limited by IP address, so we briefly store a counter keyed to the requesting address. This is what stops password guessing and account farming; the counters are swept once they expire and are never used to build a profile of you. Our hosting provider also processes IP addresses and request metadata in the ordinary course of serving the site.
Analytics and cookie consent
We use PostHog, hosted in the European Union, to understand how BuildWork is used so we can improve it. Nothing is written to your device before you answer the cookie banner: until then — and permanently if you decline — analytics runs cookieless, counting the visit without storing anything on your device and without identifying you. Only if you accept do we set analytics cookies and connect events to your account. You can change your mind by clearing this site’s data in your browser, which brings the banner back.
Why we process it, and on what legal basis
To provide the service and bill for it, because that is the contract you entered into (GDPR Art. 6(1)(b)) — accounts, workspaces, content, subscriptions and service email such as verification, password reset, invitations and the weekly stock digest. To keep the service secure and working, as our legitimate interest (Art. 6(1)(f)) — rate limiting, abuse prevention, error reports and the activity log. To understand product usage, only with your consent (Art. 6(1)(a)) — the analytics described above, which you may refuse without losing any functionality. To meet accounting and tax obligations, because the law requires it (Art. 6(1)(c)) — invoices and payment records.
Cookies and local storage
Strictly necessary: a session cookie that keeps you signed in. Functional: small entries remembering the language and theme you chose, and a record of your cookie-banner answer so we do not ask again — that last one is written only after you have answered. Analytics: set by PostHog only if you accept, and not at all if you decline. There are no advertising or cross-site tracking cookies.
Who else processes it
We keep the list of suppliers short and use each for one job: Convex (the database and backend that stores your workspace data), Cloudflare (serving the application and protecting it from abuse), Stripe (payments and subscriptions), Resend (sending service email), and PostHog (product analytics, on its European hosting). Each acts as our processor under a data-processing agreement and may use your data only to provide us that service. We do not sell personal data and we do not share it for advertising.
Transfers outside the EEA
Our database is hosted in the United States, and some of the suppliers above process data outside the European Economic Area. Those transfers rely on the European Commission’s Standard Contractual Clauses together with the technical measures described under Security. Analytics data stays in the European Union. You can ask us for details of the safeguards that apply to a specific transfer.
How long we keep it
Account and workspace data is kept for as long as the account and company exist, and is deleted on request when your use of the service ends. Records you delete inside the app enter a 24-hour undo window and are then permanently removed by a scheduled job. Rate-limit counters live only as long as their window. Accounting records are kept for seven years, as Estonian law requires, regardless of account deletion. Backups age out on our providers’ own cycles, so a deleted record can persist in a backup for a short period after it has gone from the live system.
How we protect it
All traffic runs over encrypted connections. Passwords are stored only as hashes. Every company’s data is isolated at the query layer, so one company’s workspace cannot be read from another’s session, and access inside a company is limited by the roles that company defines. Access to production systems is restricted to those who need it. No system is perfectly secure, and we do not claim otherwise; if a breach affects your personal data we will notify the supervisory authority and, where required, you.
Your rights
Under the GDPR you may ask us for a copy of your personal data, correct it, have it deleted, restrict or object to how we use it, receive it in a portable format, and withdraw consent for analytics at any time without affecting what was done before. Write to the contact address above and we will answer within one month. We may need to confirm your identity first. Where the data belongs to a company’s workspace rather than to your own account, we will pass the request to that company and support them in answering it.
Complaints
If you believe we have handled your personal data unlawfully, please tell us first — most things are quickest to fix directly. You also have the right to complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or to the supervisory authority of the EU country where you live or work.
Automated decisions
We do not make decisions about you by automated means alone, and we do not profile you in a way that produces legal effects. Free-tier limits are applied by rule to a company account, not to you as an individual.
Children
BuildWork is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us their data, contact us and we will delete it.
Changes to this policy
We may update this policy as the service develops. The date at the top always reflects the current version, and material changes will be announced in the product or by email before they take effect.