1. Who is responsible
Cuadrabot is the controller of account, billing, product-usage, and support information used to operate this service. The legal operator and tax identity are shown on your Checkout screen and invoice. You can contact us at [email protected].
2. Information we process
- Account details such as name, work email, company, and authentication records.
- Coarse business location such as country, region, and city from your profile or billing data.
- Private project materials, including plan PDFs, scope notes, generated quantities, marked plans, workbooks, and validation records.
- Billing references, subscription state, purchased and consumed credits, invoices, refunds, and disputes. Stripe stores complete payment-card data; Cuadrabot does not.
- Operational events such as uploads, job stages, downloads, support requests, service health, audit records, and security logs.
3. Why we process it
We process data to create and secure accounts; verify, measure, and validate plan sets; deliver files; collect payment; manage credits and subscriptions; provide support; prevent abuse; monitor reliability; improve the product using aggregated operational evidence; and meet legal, tax, accounting, and security obligations.
Depending on context, our legal bases include performing the service contract, legitimate interests in operating and securing the service, legal obligations, and consent where required.
4. Model and processor use
Project materials may be sent to contracted infrastructure and processing providers solely to provide the takeoff service. Cuadrabot does not use customer plans to train its own models without separate, explicit consent. Provider handling remains subject to the relevant business terms and data-processing commitments.
5. Sharing and international transfers
We use service providers for hosting, database and object storage, payment processing, email, monitoring, and automated analysis. We disclose only what each provider needs for its role. Where data moves outside the EEA, we use an available lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards.
6. Retention
Account and billing records are retained while the account is active and as required for tax, accounting, dispute, and legal obligations. Once an uploaded plan passes verification, its original PDF is kept in a private source archive for customer project history, recovery, support, and dispute handling while the account is active. The archive registry records ownership, file size, page count, and a SHA-256 fingerprint. Customers may download their original plan from the project workspace and may request deletion subject to identity verification and any applicable legal hold.
Unverified or abandoned uploads are removed after 24 hours. Processor working copies and generated deliverables are removed by a scheduled process after the terminal-job retention window has elapsed; the current window is available through support. Provider recovery copies, when enabled, follow a separate restricted and finite lifecycle. Job history, billing, credit, security, and audit records may be retained or de-identified for the purposes above. A legal hold or other obligation may require longer retention.
7. Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on it. You may also complain to your local data-protection authority. Email [email protected]. We may verify identity before acting on a request.
8. Security and changes
We use private storage, tenant-level access rules, short-lived signed links, server-only credentials, checksum-backed source records, scheduled object-presence checks, audit logs, and restricted administrative access. No system is completely secure. We will update this policy when processing materially changes and will post the new effective date.