Last updated [DATE]
CMXDocs is operated by [COMPANY NAME], [ADDRESS]. For anything about your data, contact [EMAIL ADDRESS].
Accounts: your name, username, email address, and which projects you are assigned to.
Project records: the documents uploaded to the system, their revisions, submissions, transmittals, review comments and client responses, together with who did what and when.
Sign-in records: each attempt to sign in, with the username tried, the network address it came from, and whether it succeeded. These are kept for 90 days and exist to stop password guessing.
Mail settings: where a project sends its own transmittals, the sending credentials are stored encrypted.
To run the service: a document control system is a record of what was issued, to whom and when, and that record is the point of it.
To keep accounts secure, and to meet the record-keeping obligations that come with construction projects.
Project records are visible to the people assigned to that project, and to nobody else. Permissions are granted per project.
We use these providers to run the service: [HOSTING PROVIDER] for the application and database, [STORAGE PROVIDER] for uploaded files, and [EMAIL PROVIDER] to send transmittal emails. We do not sell data or share it for advertising.
[REGIONS — where your hosting and file storage physically are.]
Project records are kept for the life of the project and afterwards as the contract requires. Sign-in records are deleted after 90 days. Accounts are deactivated rather than deleted, so the record of who approved what stays intact.
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Write to [EMAIL ADDRESS].
We set a session cookie to keep you signed in and a security cookie to protect forms. There is no advertising or analytics tracking.
If this changes materially we will say so here and update the date at the top.