Privacy Policy
Last updated: 31 July 2026
1. Who we are
Buildlr is a business platform for construction and remodeling companies, operated by Buildlr Ltd, a private limited company registered in Cyprus (registration number HE 465133, VAT number CY60106289I), registered office Charilaou Xylophorou 13, Agios Athanasios, 4103 Limassol, Cyprus. Email: support@buildlr.com.
Buildlr Ltd is the data controller for the processing described in this policy. Buildlr Ltd is established in Cyprus and is supervised by the Cyprus Commissioner for Personal Data Protection. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and, for customers in the United Kingdom, the UK GDPR.
2. Two roles: when this policy applies
Buildlr processes personal data in two distinct capacities.
Buildlr as controller - for data about you as our (prospective) customer: account and signup data, billing data, support communications and security logs. This Privacy Policy governs that processing.
Buildlr as processor - for the data our customers store inside their Buildlr workspace: their clients, leads, estimates, quotes, invoices, projects, employees, messages, photos and files. For that data, the Buildlr customer (the construction company) is the controller and Buildlr processes it only on their instructions under our Data Processing Agreement. If you are a client or employee of a company that uses Buildlr, please direct privacy requests to that company - we will assist them in fulfilling your request as their processor.
3. Personal data we collect as controller
Account and signup data. Name, work email address, phone number, company name and website, and your password (stored only as a salted cryptographic hash). During signup we verify your phone number via a one-time SMS code and perform automated checks on the provided company details to prevent fraudulent signups. If you start but do not complete a signup, we retain the submitted details only for the period stated in the retention section below, after which they are deleted. We do not use incomplete signups for marketing.
Billing data. Subscription plan, billing currency and invoicing history. Card details are collected directly by our payment processor (Stripe) and never touch Buildlr's servers; we store only a payment-method reference.
Support and communication data. Messages you send us, and transactional emails and SMS we send you (e.g. verification codes, password resets).
Technical and security data. IP address, browser and device information, and authentication events - collected for account security, abuse prevention and error diagnosis. Error reports are processed via Sentry (EU data center) and are configured to minimize personal data.
Marketing data (B2B). If you represent a company we believe may benefit from Buildlr, we may process your business contact details (name, role, company, work email and phone) collected from you or from public sources, to contact you about our services. When we first contact you, we tell you where we obtained your details and link to this policy. You can object or unsubscribe at any time and we will stop.
4. Purposes and legal bases
- Providing the service (account, workspace, sync, support) - contract (Art. 6(1)(b) GDPR).
- Signup verification and fraud prevention - legitimate interest (Art. 6(1)(f)): preventing fraudulent or abusive accounts.
- Billing and accounting - contract, and legal obligation (Art. 6(1)(c)) for bookkeeping.
- Security monitoring and error diagnosis - legitimate interest: keeping the service and customer data secure.
- B2B marketing - legitimate interest: marketing our services to businesses; you may object at any time.
- Product notifications (push) - consent: you enable notifications explicitly and can revoke them in settings or your operating system.
- Establishing or defending legal claims - legitimate interest.
The signup company checks are automated, but a rejected signup is not a solely automated decision with legal effect - contested outcomes are reviewed by a human. Contact us if you believe a signup was rejected in error.
5. Cookies and tracking
The Buildlr application uses no advertising trackers, no analytics cookies and no third-party marketing pixels. The only locally stored data is what the application needs to function: your login session and the offline copy of your workspace. This marketing website is served through Cloudflare's global edge network (EU-US Data Privacy Framework certified); as with any web host, visitor IP addresses are processed to deliver and protect the site. It has its own cookie notice.
6. AI features (Buildlr Cortex)
Buildlr includes an AI assistant ('Cortex') that reads context from your workspace to produce suggestions, briefings and assisted actions. Key commitments:
- Prompts are processed via OpenRouter, our AI routing provider, under strict data controls enforced on every request: routing is restricted to endpoints with a zero-data-retention policy (prompts and responses are processed in memory and not stored) and to providers that do not collect or train on inputs. OpenRouter is a US provider; transfers are protected by EU Standard Contractual Clauses.
- Your data is never used to train AI models.
- If no endpoint meeting these controls is available, the request fails - it is never re-routed to a less-protective endpoint. Anthropic is available as an alternative route a workspace can be configured to use, under equivalent no-training terms; it is not an automatic failover.
- Cortex operates within a constrained tool surface and cannot take actions with legal or similarly significant effect without human confirmation (Art. 22 GDPR).
- Every Cortex interaction is recorded in a tamper-evident, per-workspace audit log you can export and verify.
You can disable Cortex for your workspace at any time in settings.
7. Where data is stored; offline copies on your devices
All service data is hosted with Hetzner Online GmbH in Germany (EU). Backups are stored in the EU.
Buildlr is offline-first: your workspace synchronizes to the devices you log in from, so you can work without connectivity. Sensitive fields (for example client identity numbers and employee personal details) are encrypted at rest on the device, and the device encryption key is deleted when you log out. You are responsible for basic device hygiene (device lock, OS updates) on hardware you use with Buildlr.
8. Retention
- Account data - for the duration of the customer relationship, then deleted within 90 days of account termination.
- Incomplete signups - deleted after 30 days.
- Signup verification and fraud-check records - 12 months.
- Billing and bookkeeping records - as required by statutory retention periods (typically 6-10 years depending on jurisdiction).
- Support correspondence - 24 months after the case is closed.
- Security logs (IP addresses, authentication events) - 12 months.
- AI (Cortex) run history - 12 months, then purged.
- Marketing contact data (prospects) - until objection, or 24 months after last contact.
Workspace content (your clients, projects, invoices and similar) is retained per your instructions under the DPA and deleted or returned on termination, except where statutory retention applies (e.g. issued invoices).
9. Your rights
Subject to the conditions in the GDPR you have the right to: access your data (Art. 15), rectify it (Art. 16), have it erased (Art. 17), restrict processing (Art. 18), data portability (Art. 20), object to processing based on legitimate interest including marketing (Art. 21), and withdraw any consent at any time with future effect.
To exercise these rights, contact support@buildlr.com. We respond within one week. You can also delete your account, and the personal details held with it, at any time in the application under Settings > Profile.
You may lodge a complaint with a supervisory authority - the authority supervising Buildlr is the Cyprus Commissioner for Personal Data Protection (dataprotection.gov.cy), and you may always complain to the authority of your own country instead, e.g. IMY in Sweden, the ICO in the UK, or your local authority in Germany, Austria, Denmark, Finland or Norway.
If you are a client or employee of a Buildlr customer, direct your request to that company (see section 2); we will support them in answering it.
10. Who we share data with; international transfers
We use a small number of service providers ('sub-processors' where they process customer workspace data), including Hetzner (hosting, Germany), OpenRouter and Anthropic (AI processing), Sentry (error monitoring, EU), Stripe (payments), Vonage (SMS verification), Twilio SendGrid (transactional email), CloudMailin (inbound email), Google Firebase (push notifications), Cloudflare (bot protection), and the accounting providers you choose to connect (e.g. Fortnox, QuickBooks). The full, current sub-processor list with locations and transfer safeguards is published on our sub-processor page and forms part of our Data Processing Agreement.
We aim to keep processing in the EU/EEA; where a provider is outside the EU/EEA, transfers are protected by an adequacy decision (including the EU-US Data Privacy Framework where certified) or EU Standard Contractual Clauses.
Maps and address search. These features load content directly from the OpenStreetMap Foundation: your device requests map tiles and geocoding results straight from OpenStreetMap servers, which receive your search text and IP address and process them as an independent controller under the OpenStreetMap Foundation privacy policy. This traffic does not pass through Buildlr's servers.
Disclosure required by law. We disclose personal data where required by law, court order or a binding request from a competent authority; where legally permitted, we inform you before disclosing and disclose no more than required.
Business transfers. If Buildlr is involved in a merger, acquisition or transfer of assets, personal data may be transferred as part of that transaction under confidentiality safeguards; we will inform you before your data becomes subject to a different privacy policy.
We never sell personal data.
11. Security
We protect personal data with technical and organizational measures appropriate to the risk, including: TLS encryption in transit; strict per-workspace isolation enforced at the API layer; passwords stored with a modern adaptive hash; strong hashed session and access tokens; encryption of integration credentials at rest; field-level encryption of sensitive data on user devices; and a tamper-evident audit log for AI activity.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify the competent authority and affected parties as required by Articles 33-34 GDPR.
12. Children
Buildlr is a business tool for construction companies and is not directed at children. We do not knowingly process children's data.
13. Changes to this policy
We may update this policy. Material changes will be announced in the application or by email, with reasonable notice. The current version and its effective date are always available on this page.
14. Contact
Buildlr Ltd (HE 465133)
Charilaou Xylophorou 13, Agios Athanasios, 4103 Limassol, Cyprus
Email: support@buildlr.com