D-01
Roles
For personal data you process through the platform in running your business, you are the data controller and ArchitectPro is your processor. For the account data we hold about you as our customer, we are the controller under the Privacy Policy.
D-02
Scope & instructions
We process personal data only to provide the service and on your documented instructions, which include your use of the product's features. We tell you if an instruction appears to breach applicable law.
D-03
Confidentiality
Personnel authorised to process the data are bound by confidentiality obligations.
D-04
Security
We keep appropriate technical and organisational measures — row-level isolation, encryption of secrets, least-privilege service access, and audit logging — to protect the data against unauthorised access, loss, or disclosure.
D-05
Sub-processors
You authorise the infrastructure sub-processors we use (hosting, database, AI, payments, email) to process data as needed to run the service. We remain responsible for their performance and will inform you of material changes.
D-06
Data-subject requests & breach
We help you respond to data-subject requests through the platform's export and deletion tools, and we notify you without undue delay if we become aware of a personal-data breach affecting your data.
D-07
International transfers
Where sub-processors transfer data across regions, the transfer relies on appropriate safeguards such as standard contractual clauses.
D-08
Return & deletion
On termination, you can export your data, and we delete it from active systems on request, subject to legal retention. Backups age out on a rolling schedule.