Skip to content

Legal

Privacy notice

What we collect, why, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be technically defensible.

Last updated 1 July 2026. In this document, Projexio, “we”, “us” and “our” mean the provider of the Projexio service, and “you” means the customer or visitor.

1. Who this notice covers

This notice explains how we handle personal data when you visit this website, when you use the Projexio service, and when you contact us. It applies wherever you are located.

There are two distinct relationships to keep separate, because your rights differ between them.

  • Account data: information about you as a customer, prospective customer or website visitor. For this, we are the data controller and this notice governs our handling of it.
  • Project content: the tasks, files, comments, time entries and personal data your team and your clients put into a workspace. For this we act as a processor on your instructions, and our Data Processing Addendum governs it rather than this notice.

If you are an employee or client of one of our customers and you want to exercise rights over project content held in their workspace, contact that customer directly. We will assist them, but we cannot act on their data without their instruction.

2. What we collect and where it comes from

We collect only what we need to run the service, bill for it and support you. We do not buy personal data from brokers and we do not enrich your record from third-party datasets.

Information you give us directly:

  • Account details: name, work email address, password (stored only as a hash), and optionally a display picture and job title.
  • Workspace details: workspace name, your role, and the region you select for hosting.
  • Billing details: billing contact, billing address, tax registration number where you supply one, and a payment token from our payment processor. We never receive or store full card numbers.
  • Correspondence: the content of support tickets, sales enquiries and any messages you send us.

Information generated by your use of the service:

  • Authentication and security events: sign-in times, IP address, and changes to permissions or sharing settings.
  • Product usage: which features are used and how often, recorded pseudonymously and excluding the content of your projects.
  • Technical diagnostics: browser and device type, error reports and performance traces.

Information from third parties:

  • Identity confirmation from your single sign-on provider, if your organisation uses SAML.
  • Payment and subscription status from our payment processor.
  • Metadata from a connected integration where you have authorised the connection, limited to what that integration requires.

3. Why we use it, and our legal basis

Where the GDPR or UK GDPR applies, the relevant legal basis is given in brackets. Where the PDPO or PDPA applies, we collect for the purposes described below and no other purpose without telling you first.

  • To provide the service, including creating workspaces, authenticating you and enforcing permissions (performance of a contract).
  • To bill you and keep accounting records (performance of a contract, and compliance with a legal obligation for retention).
  • To provide support and respond to your enquiries (performance of a contract, or legitimate interests where you are not yet a customer).
  • To keep the service secure, investigate abuse and prevent fraud (legitimate interests, and compliance with a legal obligation).
  • To understand which features are useful so we can improve the product (legitimate interests, using pseudonymous aggregate data).
  • To send service and security notices you cannot opt out of while holding an account, such as breach notifications or material changes to terms (performance of a contract, and legal obligation).
  • To send product update emails, which are optional and which you can unsubscribe from at any time (consent).

We do not use your data for automated decision-making that produces legal effects, and we do not profile you for advertising.

4. We do not train models on your content

Your project content is not used to train machine learning models, ours or anyone else's. It is not sold, rented or shared with advertisers, data brokers or any other customer.

Where a specific feature needs to send content to a third-party processor in order to function, that processor is named on our sub-processor list, is contractually barred from using your content for its own purposes, and is barred from retaining it beyond what the feature requires.

5. Who we share it with

We share personal data only in the following circumstances.

  • Sub-processors who help us run the service, such as our hosting provider, transactional email provider and payment processor. Each is named on our published sub-processor list, is bound by a written agreement, and may process data only on our instructions.
  • Other users of your workspace, to the extent your permissions and sharing settings allow. Your workspace administrators can see membership, roles and audit events.
  • Professional advisers, such as accountants or lawyers, where necessary and under a duty of confidence.
  • Authorities, where we are legally compelled. We will notify you unless we are legally prohibited from doing so, and we will not volunteer your data without a valid legal instrument.
  • An acquirer, if the business is sold or merged. You would be notified before your data became subject to a different privacy notice, and the acquirer would be bound by commitments no less protective than these.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy laws.

6. International transfers

We operate across Asia-Pacific, the Americas and other regions, so personal data may be transferred across borders. Your workspace's primary hosting region is one you select at creation, from the United States, Singapore or Hong Kong SAR.

Where a transfer leaves a jurisdiction that restricts onward transfer, we rely on an appropriate safeguard: standard contractual clauses approved by the relevant authority, an adequacy decision where one exists, or your explicit consent where neither applies. The specific mechanisms for each sub-processor are set out in our Data Processing Addendum.

Support and engineering personnel may access production data only where necessary to resolve an issue you have raised, under access that is logged and time-limited.

7. How long we keep it

We keep personal data only as long as we need it for the purpose it was collected for, then delete or irreversibly anonymise it.

  • Account and workspace data: for the life of the account. After cancellation the workspace becomes read-only for 90 days so you can export, then is scheduled for irreversible deletion.
  • Project content: deleted with the workspace, subject to the same 90-day export window. Individual items you delete are removed from backups within 35 days.
  • Billing and accounting records: retained for seven years after the transaction, because tax law in our operating jurisdictions requires it.
  • Support correspondence: three years from the last message, so we can understand the history of a recurring issue.
  • Security and audit logs: as set out on the security page, ranging from 90 days to configurable retention depending on plan.
  • Marketing consent records: for as long as the consent stands, plus three years after withdrawal so we can evidence that we honoured it.

8. Your rights, and how to use them

Depending on where you are, you have some or all of the following rights over personal data we hold as controller.

  • Access: ask what we hold about you and receive a copy.
  • Correction: have inaccurate data corrected.
  • Deletion: have data erased where we have no continuing lawful basis to keep it.
  • Portability: receive your data in a structured, machine-readable format.
  • Restriction and objection: ask us to pause processing, or object where we rely on legitimate interests.
  • Withdraw consent: for anything we do on the basis of consent, including product update emails.
  • Opt out of sale or sharing: we do not sell or share personal information for advertising, so there is nothing to opt out of, but the right exists and we honour it.
  • Non-discrimination: exercising any of these rights will not affect your service or pricing.

To exercise a right, email support@projexio.org from the address on your account. We respond within 30 days, and will tell you if we need longer and why. We may ask you to confirm your identity, but only to the extent necessary to avoid disclosing your data to someone else.

If you are unhappy with how we have handled a request, you may complain to your local supervisory authority. In Hong Kong SAR that is the Office of the Privacy Commissioner for Personal Data. In Singapore it is the Personal Data Protection Commission. In the European Economic Area or the United Kingdom it is your national data protection authority. We would prefer you raise it with us first at support@projexio.org so we have a chance to fix it.

9. How we protect it

Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest, including backups. Access to production systems requires multi-factor authentication, is limited to named personnel and is logged.

Our security page sets out the specific controls across encryption, authentication, authorisation, tenancy isolation, infrastructure, backups, audit logging, incident response and secure development. It also states plainly which third-party certifications we do not hold.

If a personal data breach affects you, we will notify you without undue delay and, where we are your processor, within 72 hours of confirming it, so you can meet your own notification obligations.

10. Children

Projexio is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email support@projexio.org and we will delete it.

11. Cookies and similar technologies

This website uses a small number of essential cookies to function, and optional analytics cookies that load only if you accept them. Declining leaves the site fully usable.

Our cookie notice lists each category, what it is for, and how to change your choice later.

12. Changes to this notice

We update this notice when our practices change. The date at the top of the page always reflects the current version.

If a change materially reduces your rights or expands how we use your data, we will notify account owners by email at least 30 days before it takes effect, so you have time to object or to leave.

Questions about this document

Email support@projexio.org, or use the contact page.