Legal
Privacy notice
This page is maintained by the BuildOS team and describes current practice. It is not legal advice and it is not an independent certification.
Who we are
BuildOS is a construction project record platform for residential and SME contractors. This notice is maintained by the BuildOS team and describes how we handle personal data in the product and on this website.
BuildOS is the data controller for account and enquiry data, and acts as a data processor for the project content a builder's workspace uploads — in that content the builder is the controller, and their clients and subcontractors are the data subjects.
The product is currently offered as a demonstration environment. Where this notice describes a control, it describes what is implemented today — it is not a certification or an audit outcome.
What we collect
Account data: name, email address, workspace and role. Collected when you create an account or are invited to a workspace.
Project content: the scope, programme, costs, variations, diaries, photographs and documents you or your collaborators upload.
Enquiry data: the details you submit through the contact form, including company, contact preferences and the message itself.
Technical data: authentication sessions and basic error logs needed to keep the service running and secure.
Why we use it
To provide the service: authenticate you, show you the projects you are entitled to see, and keep an append-only record of changes and approvals.
To respond to enquiries you send us.
To keep the platform secure and diagnose faults.
We do not sell personal data, and we do not use your project content for advertising.
Our lawful bases
Contract: providing the workspace, authentication, project records and reporting you have signed up for.
Legitimate interests: keeping the service secure, diagnosing faults, and responding to enquiries you initiate. We balance these against your interests and use the minimum data needed.
Consent: optional communications you opt into. You can withdraw consent at any time.
Legal obligation: retaining records we are required to keep, and responding to lawful requests.
Processors and subprocessors
Cloud platform and hosting: Lovable Cloud, which provides the managed database, authentication, file storage and application hosting behind BuildOS.
AI drafting: the Lovable AI Gateway routes assistant requests to the underlying model provider. Only the project records needed for the requested draft are sent, and the content is not used to train models.
Email: transactional email for sign-in, invitations and notifications is sent through our managed email provider.
We keep this list current. Material changes to our subprocessors are reflected here before they take effect for your workspace.
International transfers
Our providers may process data outside the UK and EEA. Where that happens, transfers rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with the provider's own technical safeguards.
If you need the transfer documentation for a specific provider, email hello@buildsos.app and we will supply what we hold.
Retention schedule
Project records, approvals and the audit trail: kept while the workspace is active, then for 12 months after closure so a completed job can still be evidenced, unless you ask us to delete sooner.
Account data: deleted within 30 days of an account deletion request, except where we must retain it to meet a legal obligation.
Enquiry data: kept for up to 24 months after our last contact with you.
Demonstration workspace data: reset at any time and not intended for real project records.
Security incidents
If a personal data breach affects your workspace we will notify the workspace owner without undue delay, with what we know, what we are doing, and what you may need to do. Report a suspected issue to hello@buildsos.app.
Where it is stored
Data is stored in our managed cloud database and file storage, with access restricted per workspace by row level security. Access to the underlying infrastructure is limited to the people who operate the service.
How long we keep it
Project records are retained for as long as the workspace is active, because the value of the record is its permanence. Enquiry data is retained while we are in contact with you and for a reasonable period afterwards. Demonstration workspace data may be reset at any time.
Your rights
You can ask for a copy of your personal data, ask us to correct it, ask us to delete your account, or object to a particular use. Project archives can be exported in full, including the audit trail.
Send any request to hello@buildsos.app and we will respond as quickly as we reasonably can.
If you are not satisfied with how we handle a request, you can complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
Cookies
We use only the cookies and browser storage needed to keep you signed in and to remember interface preferences. We do not run third-party advertising trackers on this site.
Questions about this notice? Email hello@buildsos.app or use the contact form. See also our security page.