Privacy Policy
This policy explains how Construway collects, uses, and protects your personal data when you visit our website or use our platform.
1. Who We Are
Construway is the Data Controller for personal data collected through our website and demo request forms. For data processed within the platform on behalf of your organisation, Construway acts as a Data Processor and your organisation is the Data Controller.
For questions about this policy or to exercise your rights, contact us.
2. What Data We Collect
We collect data in two distinct contexts: as a Data Controller (website and account registration) and as a Data Processor (content you create inside the platform on behalf of your organisation).
Website & account data (we are Data Controller)
-
Contact data — name, email address, company name, and role, when you submit a contact or demo request form.
-
Account data — login credentials, name, email, role, and profile information when you create an account.
-
Billing data — subscription tier, billing contact, and payment reference (we do not store full card details; payments are handled by our payment processor).
-
Usage data — pages visited, features used, and session activity collected automatically when you use our website or platform.
-
Technical data — IP address, browser type, device identifiers, and cookies. See our Cookie Settings page for details.
Platform content data (we are Data Processor on your behalf)
When your organisation uses the platform, you control the content you create. This may include personal data about your team members, contractors, and project stakeholders. Categories include:
-
Project data — project names, site addresses, schedules, budgets, and scope descriptions.
-
Punch list & defect records — item descriptions, locations, assigned responsible parties (names/roles), status updates, resolution notes, and supporting evidence.
-
Submittal & document data — uploaded drawings, specifications, submittal packages, review comments, and approval records, which may identify contractors, designers, or reviewers by name.
-
Schedule & EVM data — work breakdown structures, activity assignments, progress percentages, and earned value metrics linked to team members or work packages.
-
Risk register data — risk descriptions, probability/impact assessments, and risk owners identified by name or role.
-
Logistics & material data — supplier names, delivery schedules, material quantities, and logistics contacts.
-
Photo reports — photographs uploaded to the platform, which may include EXIF metadata such as timestamps and GPS coordinates of the capture location.
-
Team & assignment data — user names, roles, task assignments, approvals, and audit trail entries generated by platform activity.
-
Communications & comments — messages, comments, and annotations entered within the platform in connection with project records.
Your organisation, as Data Controller for this content, is responsible for ensuring it has a lawful basis for processing any personal data entered into the platform and for responding to data subject requests relating to that content.
3. How We Use Your Data
-
To respond to demo requests and general enquiries.
-
To provide and maintain access to the platform.
-
To send transactional communications such as account notifications and billing updates.
-
To analyse usage patterns and improve the platform (in anonymised or aggregated form where possible).
-
To comply with legal obligations.
4. Legal Basis for Processing
We rely on the following lawful bases under GDPR Article 6:
-
Contract — processing necessary to provide the services you have subscribed to.
-
Legitimate interests — responding to enquiries, improving our platform, and preventing fraud.
-
Legal obligation — where we are required to process data to comply with applicable law.
5. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by law. Contact and enquiry data is retained for up to 3 years. Account data is retained for the duration of your subscription and deleted within 90 days of account closure, unless we are required to retain it longer.
6. Sharing with Third Parties
We do not sell your personal data. We may share data with trusted third-party service providers (e.g. cloud hosting, email delivery, analytics) under strict data processing agreements. We may also disclose data if required by law or to protect the rights and safety of our users.
7. Your Rights
Under GDPR, you have the right to: access the data we hold about you; request correction of inaccurate data; request erasure of your data; object to or restrict certain processing; and request data portability. To exercise any of these rights, contact us. We will respond within 30 days.
8. International Transfers
The Construway platform is hosted on infrastructure located in Brazil. Where personal data is submitted by users outside Brazil, it is transferred to and processed in Brazil. We ensure appropriate safeguards are in place to protect that data in accordance with applicable law.
In addition to GDPR obligations, Construway processes data in compliance with Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13,709/2018), overseen by the Autoridade Nacional de Proteção de Dados (ANPD). Brazilian data subjects have equivalent rights of access, rectification, erasure, and portability under the LGPD.
9. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure. These include encryption at rest and in transit, access controls, and regular security reviews. For more detail, see our Security & Trust page.
10. Cookies
We use cookies to operate our website and platform. For full details of the cookies we use and how to manage them, see our Cookie Settings page.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes by email or through the platform. The date at the top of this page reflects the most recent revision.
12. Contact
If you have questions about this policy or wish to exercise your data rights, please contact us. You also have the right to lodge a complaint with your local data protection authority.