Effective date: 1 May 2025 · Last updated: 19 September 2026 · Version 1.6
1. Who we are
GRAFTIX is a trading name of Echo Thirteen Capital Ltd, a company registered in England and Wales under company number 15053443, with its registered office at 128 City Road, London, EC1V 2NX ("we", "us", "our").
We are the data controller in respect of personal data collected through the GRAFTIX platform and website. We are registered with the Information Commissioner's Office (ICO) under registration number ZC139440.
2. Personal data we collect
We collect the following categories of personal data:
Account data — your name, email address, company name, job title and password (stored in hashed form).
Profile data — your trade type, qualifications, professional certifications and any photograph you choose to upload.
Usage data — pages and features accessed, actions performed (e.g. tasks created, plans viewed), timestamps and session information.
Device and technical data — IP address, browser type and version, operating system, device identifiers, and time zone.
Communications data — messages sent through the GRAFTIX in-app chat; form responses submitted via eForms.
Vault data — credentials and other sensitive project information you store in the Vault are encrypted in your browser before they reach us, using AES-256-GCM under a key derived locally from your passphrase (Argon2id at 64 MiB and 3 iterations, falling back to PBKDF2-HMAC-SHA256 at 600,000 iterations where WebAssembly is unavailable). We store only ciphertext and wrapped keys. We hold no master key, no organisation key and no recovery key, and we are not able to decrypt, read or disclose Vault contents — including in response to a legal request. Your Vault PIN is verified server-side to enforce rate limiting; only a bcrypt hash of it is stored, never the PIN itself. Organisation recovery is performed using a recovery key your organisation generates and controls, to which Graftix has no access. Vault access events are recorded in an append-only audit log.
Payment data — we do not collect or store payment card data directly. All payment data is processed by our payment processor. We receive only summary transaction information (plan type, payment status, invoice amounts).
Third-party sign-in data — if you sign in using Google, we receive your name and email address from Google as part of the authentication process.
Workforce records — where your organisation keeps an operatives register, the record held about a person includes their employment type, their qualifications and any evidence uploaded for them, and an emergency contact (next of kin) where one has been recorded.
Customer and contact records — where your organisation uses the service side of GRAFTIX, it records its own customers, their sites and the people to contact at them, including names, email addresses and telephone numbers.
Site induction records — where your organisation publishes a site induction, a person completing it gives an email address and whatever the induction asks for, without holding a GRAFTIX account. Their answers, signature and any qualification evidence are held against that submission.
Voice recordings and transcripts — the Journal can record a meeting. When it does, GRAFTIX stores the audio file itself and a speech-recognition transcript of it. A meeting recording captures the voice of everyone speaking, including clients, consultants and subcontractors who hold no GRAFTIX account. Where the member asks for minutes, a summary or a list of actions, the transcript is sent to our AI sub-processor to produce them.
Calendar data — events, their times and locations, and the people invited. Attendees who are not GRAFTIX users are invited by email and their email address is stored on the event. Each member may also enable a personal subscription feed, a long unguessable URL that returns their own events to an external calendar application without a sign-in.
Working time records — hours worked, travel time, visit start and finish times, and the approval state of each week. Where an organisation exports a payroll file, that file contains the same hours against named people.
Visit and dispatch records — for service work, which engineer attended which site, when they set off, when they arrived and when they finished.
Monitored device data — where an organisation uses Graftix Live, the agent reports the status, network address and identifiers of the equipment it has been told to watch on a customer’s network.
Location data
GRAFTIX captures GPS coordinates in the following specific circumstances:
Attendance sign-in and geofenced check-in — if your project has a geofence configured, your device's GPS position is checked at sign-in to verify you are on site. The coordinate captured at sign-in is retained as part of your attendance record and is visible to your project's admins, project managers and supervisors. No continuous location tracking occurs — only a single point at the moment of sign-in. Legal basis: legitimate interests (site safety and attendance verification).
Task photo uploads — photographs taken on a GPS-enabled device may contain location coordinates in their EXIF metadata. GRAFTIX extracts and stores this coordinate alongside the attachment so work can be geographically referenced. This data is visible to anyone with access to the task. You can disable EXIF location extraction in Profile Settings, under Location on photos — when disabled, no coordinate is stored. Legal basis: your own action in uploading the photo, with the ability to opt out in Settings at any time.
Chat location sharing — you can voluntarily share your current location in an in-app conversation (as a static pin or a live-updating share). The coordinate is stored for the duration of the share and is visible only to participants in that conversation. Live shares expire after the duration you choose; static pins remain until you delete them. Legal basis: your own action in initiating the share.
SOS alert — when you trigger an SOS, your GPS coordinates (if location permission has been granted on your device) are captured and sent to all admins and supervisors in your organisation. The location is retained in the SOS Log for audit and safety review purposes and is not automatically deleted when the alert is resolved. Legal basis: legitimate interests (safety of workers).
Who decides what goes in. For everything an organisation puts into GRAFTIX — projects, photographs, workforce records, recordings, customer contacts — the organisation is the controller and GRAFTIX is its processor. The organisation decides what is captured and is responsible for telling the people concerned. If your organisation records meetings, it is responsible for informing everyone present before recording starts.
3. How we use your personal data
We use your personal data for the following purposes, under the legal bases shown:
To provide and maintain the GRAFTIX service — including account creation, authentication, project management features and customer support. Legal basis: performance of a contract (Article 6(1)(b) UK GDPR).
To send service communications — such as password reset emails, subscription notifications and invitation emails. Legal basis: performance of a contract or legitimate interests.
To improve the platform — analysing usage patterns to understand how the platform is used and to identify areas for improvement. Legal basis: legitimate interests (Article 6(1)(f) UK GDPR) — we have balanced our interest in improving the service against your rights and found that this processing does not unduly prejudice you.
To ensure security and prevent fraud — monitoring for suspicious activity, unauthorised access or misuse of the platform. Legal basis: legitimate interests.
To comply with legal obligations — such as responding to lawful requests from public authorities or retaining financial records. Legal basis: legal obligation (Article 6(1)(c) UK GDPR).
To process content on your organisation’s instructions — storing and returning the projects, records, recordings and transcripts it puts into the platform, and running the AI features it asks for. We act on the organisation’s documented instructions; the legal basis for that content is the organisation’s to establish as controller.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share your data with
We may share your personal data with the following categories of third-party recipient:
Infrastructure providers — all customer data is stored in the United Kingdom. The application runs on Northflank, hosted on Google Cloud europe-west2 (London). The database is hosted by Neon on AWS eu-west-2 (London), and files, drawings and photographs are stored in Amazon Web Services S3 in London (eu-west-2) with encryption at rest. We do not currently operate any other storage region. Should we introduce one, we will update this notice and notify affected customers before any data is moved.
Payment processor — to handle subscription payments and invoicing. We share only the minimum data necessary (e.g. email address for receipt delivery).
Email service provider — to send transactional emails (invitation links, password resets, subscription notifications).
AI service provider — project data submitted to the Dave AI Assistant and AI Symbol Takeoff is processed by Anthropic's Claude models via AWS Bedrock in the United Kingdom (eu-west-2, London). Your data does not leave the United Kingdom for AI processing, and it is not used to train AI models. Data submitted is processed only to fulfil your request.
Analytics and monitoring tools — aggregate and anonymised usage data may be processed by error monitoring and performance tools to help us maintain a reliable service.
Other members of your organisation — your name, role, avatar and any project data you create or contribute to is visible to other members of your GRAFTIX organisation.
Push notification providers — where you enable notifications, Apple, Google or Expo receive a device token and the text of the notification in order to deliver it to your device. No other project data is sent this way.
Address lookup — where a customer site address is placed on a map, that address is sent to the OpenStreetMap Nominatim service to obtain coordinates. The coordinates are stored against the site so the lookup is not repeated.
Text message delivery — where your organisation has configured a messaging provider and switched on customer notifications, the recipient's telephone number and the message text are passed to that provider. With no provider configured, nothing is sent and the attempt is recorded as skipped.
A Data Processing Addendum (DPA) is available on request for business customers who require one for their own compliance purposes. Please contact support@graftix.io.
We do not sell your personal data to any third party. We do not share your personal data with advertisers.
5. Sub-processors
We use the following sub-processors to deliver the GRAFTIX service. Each is subject to a data processing agreement with us:
Sub-processor
Role
Processing location
DPA
Northflank
Application hosting and compute
United Kingdom — Google Cloud europe-west2 (London)
northflank.com/legal
Neon
Managed PostgreSQL database hosting
United Kingdom — AWS eu-west-2 (London)
neon.tech/dpa
Amazon Web Services (AWS)
Object storage (S3) and AI inference routing (Bedrock)
United Kingdom — eu-west-2 (London)
aws.amazon.com/service-terms
Anthropic (via AWS Bedrock)
AI inference — Dave AI Assistant and Symbol Takeoff
United Kingdom — eu-west-2 (London)
anthropic.com/legal/dpa
Cloudflare
DNS resolution only — no proxying of traffic or content
Global (US-headquartered; SCCs in place)
cloudflare.com/cloudflare-customer-dpa
Clerk
User authentication and identity management
United States (SCCs in place)
clerk.com/legal/dpa
Stripe
Subscription billing and payment processing
United States (SCCs in place)
stripe.com/legal/dpa
Resend
Transactional email delivery
Ireland (EU)
DPA available on request from Resend
Apple Push Notification service
Push notification delivery to iOS devices
Global (US-headquartered; SCCs in place)
apple.com/legal/privacy
Expo
Push notification delivery to the GRAFTIX Engineer app
United States (SCCs in place)
expo.dev/privacy
Firebase Cloud Messaging (Google)
Push notification delivery to Android and web devices
Global (US-headquartered; SCCs in place)
firebase.google.com/support/privacy
OpenStreetMap Foundation (Nominatim)
Address lookup for customer site mapping
Global (EU-headquartered foundation)
osmfoundation.org/wiki/Privacy_Policy
Twilio
Text message delivery, only where your organisation configures it
United States (SCCs in place)
twilio.com/legal/privacy-notice
We will notify you of any changes to this list that materially affect how your data is processed.
6. How long we keep your data
Operational data (projects, tasks, files, messages) — retained for the lifetime of your organisation's subscription plus 6 years following termination, in line with the UK contractual limitation period under the Limitation Act 1980.
Audit logs — the immutable compliance audit trail is retained for 6 years from the date of the logged event.
Operational logs — high-volume technical logs are pruned automatically on shorter cycles: security and access logs are kept for 1 year, AI-assistant usage records for 1 year, and push-notification delivery logs for 90 days.
Account data — deleted on account closure, subject to any statutory retention obligations (e.g. financial records retained for 7 years to meet HMRC requirements).
Deleted member data — personal identifiers (name, email) are anonymised or deleted within 30 days of a deletion request. Project contributions are retained to preserve the integrity of the project record for other organisation members.
Post-cancellation grace period — organisation data is retained for 90 days after subscription cancellation to allow for export, then permanently deleted.
Voice recordings and transcripts — held as operational data for as long as the member keeps the note. Deleting the note removes the audio and the transcript with it; they are not retained separately.
Working time records — retained with the organisation’s operational data, and for at least the period payroll and HMRC obligations require.
Vault audit records — kept with the compliance audit trail for 6 years from the logged event.
Backup copies — overwritten within 30 days of the corresponding primary data being deleted.
7. Your rights under UK GDPR
You have the following rights regarding your personal data:
Right of access — to request a copy of the personal data we hold about you.
Right to rectification — to correct any inaccurate or incomplete personal data.
Right to erasure ("right to be forgotten") — to request deletion of your personal data in certain circumstances.
Right to restriction — to request that we limit the processing of your data in certain circumstances.
Right to data portability — under Article 20 UK GDPR, where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller. To request a data export, contact support@graftix.io.
Right to object — to object to processing based on legitimate interests.
Right to withdraw consent — where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at support@graftix.io. We will respond within one calendar month. There is no charge for exercising your rights unless your request is manifestly unfounded or excessive.
See also Your privacy controls — a step-by-step guide to toggling location on photos, removing a shared location pin, managing SOS permissions, requesting a data export, and requesting account deletion.
8. Cookies
GRAFTIX uses essential cookies and similar local storage technologies to maintain your session, remember your preferences (e.g. dark mode) and support the offline capability of the Progressive Web App. We do not use third-party advertising or tracking cookies.
9. International transfers
All customer project data is stored and processed in the United Kingdom. This includes drawings, tasks, photographs, certificates, RAMS, qualification records and Vault contents. This data is not transferred outside the UK.
Three categories of personal data are processed outside the UK. Authentication data — your name, email address and credentials are processed by Clerk in the United States, as Clerk does not currently offer a UK or EU-resident option. Payment data — subscription and billing records are processed by Stripe in the United States; we do not receive or store payment card details. Push notification tokens — where you enable notifications, the device token and the notification content are handled by Apple, Google or Expo to deliver the message to your device. No project data is sent this way beyond the text of the notification itself.
In addition, Cloudflare provides DNS resolution on a global anycast network. Cloudflare resolves the domain name only; it does not proxy, cache or otherwise handle your data or the contents of your session.
For each of these transfers we rely on the International Data Transfer Addendum to the EU Standard Contractual Clauses, as issued by the Information Commissioner's Office. Copies are available on request. Where a customer's own compliance requirements make US-resident authentication unacceptable, contact us at support@graftix.io and we will discuss the options available.
10. How to complain
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first at support@graftix.io.
11. Changes to this notice
We may update this Privacy Notice from time to time. When we make material changes, we will notify you by email and update the "Last updated" date above. Continued use of GRAFTIX after such notification constitutes acceptance of the updated notice.
12. Contact us
Data Controller: Echo Thirteen Capital Ltd t/a GRAFTIX
Address: 128 City Road, London, EC1V 2NX
Email: support@graftix.io