1. Overview
This Privacy Policy explains how Propsy (“we,” “us,” or “our”) collects, uses, discloses, and protects information about you when you use our construction and real estate project management platform.
We take data privacy seriously, particularly because the Service processes sensitive property data, inspection photographs, and project documentation on behalf of professional firms operating across multiple countries including Egypt, Saudi Arabia, UAE, and other markets.
2. What Data We Collect
We collect the following categories of information:
Account & Registration Data
- Full name, work email address, company name, and role.
- Billing contact information (processed and stored by Paddle, our payment processor).
- Company branding assets (logo, colors) for white-label configuration.
User-Generated Content
- Inspection photographs and site images uploaded to the Service.
- Defect observations, notes, and project documentation.
- Contractor-submitted fix evidence and verification records.
- PDF reports generated through the Service.
Usage & Technical Data
- Log data: IP addresses, browser type, pages visited, time spent.
- Device information and session identifiers.
- Feature usage patterns (aggregated, not linked to individual content).
3. How We Use Your Data
We use your data to:
- Provide, operate, and maintain the Service and your account.
- Process inspection photographs through AI defect detection services (see Section 4).
- Generate AI-assisted executive summaries, specialist notes, and defect registers.
- Send transactional emails (account notifications, defect ticket updates, report delivery).
- Improve platform reliability and performance using aggregated usage data.
- Comply with applicable legal obligations.
We do not sell your personal data to third parties. We do not use your content to train AI models beyond generating the outputs you explicitly requested.
4. AI Processing Disclosure
When you use AI features — including defect detection from photos, executive summary drafting, and specialist note generation — your inspection photographs and associated data are transmitted to our third-party AI provider(s) for processing.
Current AI service providers used by Propsy:
- [AI Provider Name — TBD, to be finalized before launch] — for image analysis and text generation.
Data transmitted to AI providers is used solely to generate the requested output for your account. It is subject to each provider's data processing agreements. We contractually require providers not to use your data for model training without explicit consent.
⚠ AI provider names and their data processing agreements must be confirmed and disclosed here before this policy is finalized.
5. Third-Party Processors
We use the following third-party services to operate the platform. Each is bound by appropriate data processing agreements:
6. Data Retention & Deletion
We retain your account data and project content for as long as your subscription is active. Upon cancellation or termination:
- You may request a data export within 30 days of termination.
- Account data and project content will be permanently deleted within 90 days of termination.
- Backups may retain data for up to an additional 30 days before permanent deletion.
- Billing records are retained by Paddle per their legal obligations.
To request early deletion of your data, contact us at privacy@propsy.app.
7. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data including:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing of your data in certain circumstances.
To exercise these rights, contact privacy@propsy.app. We will respond within 30 days.
⚠ Specific rights and response timelines vary by jurisdiction (GDPR, Egypt Data Protection Law, etc.) and must be reviewed by a legal professional.
9. Security Measures
We implement the following security measures to protect your data:
- Database isolation: Row-Level Security (RLS) on all database tables — each company's data is cryptographically isolated from other tenants.
- Encrypted storage: All data is encrypted at rest and in transit (TLS 1.2+).
- Access-controlled files: Inspection photographs and documents use signed, time-limited URLs.
- Authentication: Secure session management via Supabase Auth.
Despite our security measures, no system is completely immune to unauthorized access. Please notify us immediately if you suspect a security breach.
10. International Data Transfers
Propsy serves customers in multiple countries including Egypt, Saudi Arabia, UAE, and globally. Your data may be processed and stored in data centers outside your country of residence. We take appropriate safeguards to ensure your data receives adequate protection regardless of where it is processed.
⚠ Cross-border data transfer requirements differ by jurisdiction (GDPR adequacy decisions, Egypt Data Protection Law transfer rules, etc.) and must be addressed by a legal professional before this policy is finalized.
11. Privacy Contact
For privacy-related inquiries, data access requests, or to report a concern:
Privacy Officer — Propsy
Email: privacy@propsy.app
We aim to respond to all privacy inquiries within 30 days.