1. Information We Collect
IronNexus collects information in three broad categories: information needed to operate user accounts and the Service, information that customer organizations upload or create inside IronNexus, and technical information generated by normal use of a web application.
Account information may include:
- Name
- Email address
- Company or organization
- User role within an organization
- Phone number, if provided
- Profile picture, if provided
- Account and login information, including credentials managed by the authentication system and, where you choose it, sign-in through a third-party identity provider
Customer project information is information uploaded to, created in, or generated through IronNexus by customer organizations and their users. This may include projects, project contacts, PDF drawings, drawing revisions, markups, drawing status information, specifications, contract documents, RFIs, transmittals, schedules, delivery information, reports, images, other uploaded files, user comments, activity associated with project information, and — as the Service expands — IFC and other 3D model information.
Technical information is information reasonably necessary to operate and secure a web application, which may include:
- Device and browser information
- IP address
- Login, session and activity information
- Error and diagnostic information
- Security and access logs
IronNexus does not use advertising trackers or third-party marketing analytics in the application. If that ever changes, this policy will be updated before those technologies are introduced.
2. How Information Is Used
Information is used to operate the Service and support the organizations and users that rely on it, including to:
- Provide IronNexus functionality
- Authenticate users and maintain sessions
- Create and maintain accounts and organizations
- Display project information to authorized users
- Store, render and process uploaded files
- Synchronize information between authorized users
- Generate reports and exports
- Provide revision and document-control functionality
- Improve application reliability and performance
- Troubleshoot problems and respond to support requests
- Protect account, data and platform security
- Manage subscriptions and billing, once those features are implemented
- Comply with applicable legal obligations
IronNexus does not use customer project information to build advertising profiles.
3. Customer Project Data
Customer organizations retain ownership of their project information and uploaded files. Drawings, models, specifications, project documents, markups, comments, status information, reports and other project data belong to the organization that supplies them.
IronNexus does not take ownership of customer project data and uses it only as reasonably necessary to host, store, process, transmit, display, back up, secure and support the Service for the customer and the users that customer authorizes, and to comply with law.
Where a customer organization instructs IronNexus with respect to its data, IronNexus acts on the instructions of that organization's authorized administrators.
4. Organization Access
Users generally access IronNexus as members of a company or organization. That organization controls its own IronNexus environment.
Authorized company administrators may manage:
- Users and invitations
- Roles and permissions
- Company information
- Access to company and project information
Information uploaded into a company's IronNexus environment may be visible to other authorized users of that company according to their roles and permissions. Administrators may be able to view, export, modify or remove information stored under their organization's account, including information you contributed.
If you use IronNexus through an employer or client organization, privacy questions about that organization's data practices should be directed to that organization.
5. Data Separation
IronNexus is designed to keep customer organizations logically separated so that one company's users cannot access another company's project information without authorization. Access controls are applied at the application and database layers.
No system can be guaranteed to be free of defects or misconfiguration. IronNexus works to identify and correct access-control issues, but does not claim that unauthorized access is impossible.
7. Selling Customer Data
IronNexus does not sell customer project data. Drawings, models, project documents, markups, reports, contacts and other project information are not sold, licensed or otherwise transferred to advertisers, data brokers or unrelated third parties.
IronNexus does not sell user account information.
8. Advertising
IronNexus is professional business-to-business software. The Service does not display third-party advertising and does not use customer information for advertising targeting.
10. Data Security
IronNexus uses reasonable technical and organizational safeguards designed to protect information, including authenticated access, role and permission checks, database-level access rules, and transport security for data sent between your browser and the Service.
No method of transmission or storage is completely secure, and IronNexus does not guarantee absolute security. IronNexus does not currently claim any formal security certification or third-party compliance attestation. Any certification obtained in the future will be described here.
You are responsible for protecting your credentials, managing user access within your organization, and reporting suspected unauthorized access promptly.
11. Data Retention
Information is generally retained while an account or company relationship is active, and afterward for as long as reasonably necessary for service operation, backups and disaster recovery, security, legal and regulatory obligations, dispute resolution and other legitimate business requirements.
Formal retention schedules have not yet been established. Specific retention periods will be published in this policy once they are set.
12. Data Deletion and Account Closure
Users may request closure of their individual account. Requests to delete a company's information generally must come from an authorized administrator of that organization, since project information typically belongs to the organization rather than to an individual user.
Deletion requests are subject to:
- Administrative permissions within the organization
- Contractual obligations between the organization and IronNexus
- Routine backup and disaster-recovery processes
- Legal, regulatory and dispute-related retention requirements
- Other legitimate retention requirements
Information removed from the live Service may persist in backups for a period before it is overwritten in the ordinary course. IronNexus does not promise immediate deletion from every backup system.
13. Data Export
Customer organizations may obtain their information using export functionality available in the Service, where such functionality exists for the relevant information, or by submitting a request to IronNexus.
Export capabilities vary by area of the application and continue to be developed. This policy does not guarantee that any particular export format or feature is available today.
14. Children's Privacy
IronNexus is business software intended for use by adults in a professional capacity. The Service is not directed to children, and accounts require users to be at least 18 years old.
IronNexus does not knowingly collect personal information from children. If we learn that information from a child has been provided to the Service, we will take reasonable steps to delete it.
15. International Users
IronNexus is a cloud service. Information may be stored and processed in the jurisdictions where IronNexus and its service providers operate, which may differ from the jurisdiction where you are located, and may have different data-protection rules.
By using the Service, you understand that information may be transferred to and processed in those jurisdictions. Specific hosting regions will be identified here as they are finalized.
16. Legal Requests
IronNexus may disclose information when it reasonably believes disclosure is required by applicable law, subpoena, court order, warrant or other valid legal process, or where necessary to establish or defend legal claims.
Where permitted by law and reasonably practicable, IronNexus will attempt to notify the affected customer organization of a request for its information.
17. Business Transfers
If IronNexus is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its business or assets, information — including account information and customer project data — may be transferred as part of that transaction.
In that event, the receiving party will remain subject to privacy commitments materially consistent with this policy for the information transferred, and notice will be provided as required by applicable law.
18. Changes to This Privacy Policy
This Privacy Policy may be updated to reflect changes to the Service, business practices or legal requirements. The revised policy will be posted on this page with an updated Last Updated date.
Material changes will be communicated by reasonable means, which may include in-app notice or email. Continued use of the Service after an update takes effect indicates acceptance of the updated policy.
19. Contact Information
Privacy questions, deletion requests and data-export requests can be directed to the IronNexus team.
Privacy contact details will be published here. Until then, please reach the IronNexus team through your existing point of contact.
See also the User Agreement, which govern use of IronNexus.
