← Back to home

Privacy Policy

Effective date: 8 June 2026

BuildPredict AI Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our construction profitability risk prediction platform at buildpredict.uk (the "Service").

1. Information We Collect

Account Information

  • Full name and email address
  • Encrypted password (hashed, never stored in plain text)
  • Company name (if provided)
  • Subscription tier and billing information

Project & Document Data

  • Project details (name, type, location, contract value, dates)
  • Uploaded documents (invoices, quotes, contracts, reports)
  • Extracted cost data and risk signals from document processing
  • User feedback on AI predictions (confirmations and corrections)

Technical Data

  • IP address, browser type, and device information
  • Usage logs (pages visited, features used, timestamps)
  • Cookies and similar tracking technologies

2. How We Use Your Information

  • To provide and operate the Service, including AI-powered cost extraction and risk scoring
  • To process and analyse your uploaded construction documents
  • To generate project reports and risk assessments
  • To improve our AI models using anonymised training data (direct identifiers such as email, phone, postcode and account numbers are stripped before any document text enters the training set)
  • To manage your account, subscriptions, and billing
  • To send service-related communications (verification emails, password resets, important updates)
  • To detect and prevent fraud, abuse, or security incidents

3. Data Storage & Security

Your data is stored securely using industry-standard measures:

  • Application servers and databases are hosted on Hetzner in the European Union (Nuremberg, Germany)
  • Your uploaded documents are stored in encrypted Cloudflare R2 object storage, under UK GDPR Standard Contractual Clauses
  • Databases are encrypted at rest and in transit
  • Passwords are hashed using bcrypt with salting
  • All connections use TLS/HTTPS encryption
  • Access to production systems is restricted and monitored

4. Third-Party Services and International Transfers

We rely on a small number of sub-processors to deliver the Service. Some of these process your data outside the UK and EEA. Where that happens, the transfer is governed by Standard Contractual Clauses (SCCs) under UK GDPR Art. 46, plus an adequacy decision where one applies (e.g. transfers to the EEA).

Categories of sub-processor:

  • Hosting & storage: Hetzner (Germany, EU) for application servers, database, and the document search index. Cloudflare R2 (under UK GDPR Standard Contractual Clauses) for your uploaded document files. Vercel (frontend CDN) and Cloudflare (DNS).
  • Payments (US, PCI-DSS): Stripe. We never see or store your full card details.
  • Email delivery (EU/US): Resend.
  • AI inference (US): Google (Gemini) as the primary provider, with Groq (Llama models) as a fallback when Gemini is unavailable and as the vision reader during document extraction. When the Service performs LLM-based cost extraction or risk analysis, the relevant document text is sent to whichever provider handles the request, under SCCs. They do not retain inputs for training and do not receive your account profile. See the sub-processor list for details.
  • Operational monitoring (US): Sentry, Google Analytics, Vercel Web Analytics, Logfire. None of these receive document content; they receive request metadata, performance traces, and anonymised usage events. Vercel Web Analytics is cookieless and receives page addresses and coarse device details only, with no identifier that can be traced back to your account.

The full, current list (with the categories of data each processes) is published on our Sub-Processors page. We update it whenever a sub-processor is added or removed.

4a. Lawful Basis for Processing

  • Contract (Art. 6(1)(b)): account creation, document analysis, risk scoring, billing.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, security monitoring, product analytics in aggregated form.
  • Consent (Art. 6(1)(a)): non-essential cookies, optional product communications. You can withdraw consent at any time without affecting the contract path.
  • Legal obligation (Art. 6(1)(c)): tax, accounting, and audit-trail records we are required to keep.

5. Cookies

We use essential cookies to keep you signed in and maintain your session. We may also use analytics cookies to understand how the Service is used. You can control cookie preferences through your browser settings.

6. Your Rights (GDPR)

If you are in the UK or European Economic Area, you have the following rights under GDPR:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Request correction of inaccurate personal data
  • Erasure: Request deletion of your personal data ("right to be forgotten")
  • Portability: Request your data in a machine-readable format
  • Restriction: Request that we limit how we process your data
  • Objection: Object to processing of your data for certain purposes
  • Withdraw consent: Withdraw consent at any time where we rely on consent

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

7. Data Retention

We retain your account data for as long as your account is active. When you ask us to delete your account, we follow a two-step process:

  • Your profile is anonymised immediately and the account becomes unusable. You can sign back in within 30 days to undo the deletion.
  • After the 30-day grace window, all personal data is permanently removed: database rows, original document files in object storage, and the semantic search vectors stored in our vector database.
  • Soft-deleted documents on free-tier accounts are permanently purged 90 days after the deletion timestamp.
  • Audit-trail entries (logins, security-relevant events) are kept for up to 7 years to satisfy UK accounting and tax obligations, then deleted.
  • Anonymised data used for AI model improvement may be retained indefinitely.

8. Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: [email protected]
BuildPredict AI Ltd
41 Albert Street, Maidstone, England, ME14 2RW
Registered in England and Wales, company number 17395079