← Back to OpenConstructionERP

Privacy Policy

Last updated: April 15, 2026

1. Who We Are (Verantwortliche Stelle)

OpenConstructionERP is developed by DataDrivenConstruction, founded by Artem Boiko.
Contact: info@datadrivenconstruction.io
Website: datadrivenconstruction.io

2. Data We Collect

2.1 Data you provide during registration

DataPurposeLegal basis (GDPR)
Email addressAccount login, service notificationsArt. 6(1)(b) — contract performance
Full nameDisplay in the applicationArt. 6(1)(b) — contract performance
Password (hashed)AuthenticationArt. 6(1)(b) — contract performance
Company nameUnderstanding user context, product improvementArt. 6(1)(f) — legitimate interest
Job title / roleUnderstanding user context, product improvementArt. 6(1)(f) — legitimate interest
How you found usMarketing attribution, product improvementArt. 6(1)(f) — legitimate interest

2.2 Data collected automatically

DataPurposeLegal basis (GDPR)
IP addressSecurity (rate limiting, abuse prevention), approximate geolocationArt. 6(1)(f) — legitimate interest
Browser user-agentTechnical support, compatibility analysisArt. 6(1)(f) — legitimate interest
Referrer URLUnderstanding traffic sourcesArt. 6(1)(f) — legitimate interest
Browser languageAutomatic language selectionArt. 6(1)(f) — legitimate interest

2.3 Project data

All data you create within the application (BOQ, documents, estimates, CAD/BIM files, photos) is stored on your server or our demo server. We do not access or analyse your project data.

3. How We Use Your Data

4. Data Storage and Retention

Self-hosted: All data stays on your server. We have no access to it.

Demo server: Data on our demo server (openconstructionerp.com/demo) is periodically cleaned and not backed up. Do not store production data there.

Retention: Account data is kept as long as your account exists. You can delete your account at any time, which removes all associated personal data.

5. Third-Party Services

We do not use analytics services (Google Analytics, Mixpanel, etc.) or advertising trackers.

6. Your Rights (GDPR Art. 12-23)

You have the right to:

To exercise any of these rights, contact info@datadrivenconstruction.io.

7. Cookies

We use only essential cookies (session token, language preference). No tracking cookies. No advertising cookies. No cookie consent banner is required because we do not use non-essential cookies.

8. Security

Passwords are hashed with bcrypt. API access requires JWT authentication. All data transfers use HTTPS/TLS 1.3. The application source code is open-source (AGPL-3.0) for security auditing.

9. International Data Transfers

For self-hosted deployments, data remains on your server in your jurisdiction. For the demo server, data is stored on Hetzner servers in the EU (Germany).

10. Changes

We may update this policy. Changes will be posted on this page with a new "Last updated" date. Significant changes will be communicated via the application.

11. Contact

For privacy questions or data subject requests:
Email: info@datadrivenconstruction.io
Website: datadrivenconstruction.io
GitHub: OpenConstructionERP