Beta documentation
Privacy policy
How AEC Spec Validator processes account and project data during the beta.
Who we are
AEC Spec Validator (“AEC”) processes account and project data so architecture and construction teams can validate specifications against BIM models. The data controller is the organisation that operates your deployment.
Data we process
Depending on how you use the product we process:
- Account data: email address, authentication identifiers, plan assignment.
- Project data: project names, members, specification packages, normalised models, validation results, reviews, evidence metadata, audit events.
- Technical data: request IDs, rate-limit keys (hashed), structured logs with automatic redaction of secrets and document content.
- Usage analytics (opt-in): aggregate page views, referrer and coarse device/country data collected by Vercel Web Analytics, and only after you accept it in the consent banner. Rejecting means the collector is never loaded. It is cookieless, sets no persistent identifier, and never captures form contents, uploaded models, requirement text or validation results. Your choice is stored in browser local storage and can be changed from the footer.
Purposes and legal bases
We process data to provide the service (contract), secure the service (legitimate interest / legal obligation), and improve reliability (legitimate interest). Optional AI explanations send only server-verified findings to the configured provider — never raw project documents.
Retention
Soft-deleted projects are hidden immediately and purged after the plan retention window (Starter 30 days, Professional 365 days, Enterprise as contracted). Account export is available to the signed-in owner. You may request permanent deletion of owned projects.
Your rights
Depending on applicable law you may request access, correction, export, restriction, or deletion of personal data. Use Export account data in the workspace or contact the incident address below.
Subprocessors
Current subprocessors are listed on the Security overview and Subprocessors page. We will update that list when processors change.
Incident contact
Security or privacy incidents: damir@andrijanic.com. Include a request ID from the UI or logs when available.