Effective date: 1 May 2025 · Last updated: 28 May 2026 · Version 1.3
1. Who we are
GRAFTIX is a trading name of Echo Thirteen Capital Ltd, a company registered in England and Wales under company number 15053443, with its registered office at 128 City Road, London, EC1V 2NX ("we", "us", "our").
We are the data controller in respect of personal data collected through the GRAFTIX platform and website. We are registered with the Information Commissioner's Office (ICO) under registration number ZC139440.
2. Personal data we collect
We collect the following categories of personal data:
Account data — your name, email address, company name, job title and password (stored in hashed form).
Profile data — your trade type, qualifications, professional certifications and any photograph you choose to upload.
Usage data — pages and features accessed, actions performed (e.g. tasks created, plans viewed), timestamps and session information.
Device and technical data — IP address, browser type and version, operating system, device identifiers, and time zone.
Communications data — messages sent through the GRAFTIX in-app chat; form responses submitted via eForms.
Vault data — credentials and other sensitive project information you store in the Vault are encrypted in your browser before they reach us, using AES-256-GCM under a key derived locally from your passphrase (Argon2id at 64 MiB and 3 iterations, falling back to PBKDF2-HMAC-SHA256 at 600,000 iterations where WebAssembly is unavailable). We store only ciphertext and wrapped keys. We hold no master key, no organisation key and no recovery key, and we are not able to decrypt, read or disclose Vault contents — including in response to a legal request. Your Vault PIN is verified server-side to enforce rate limiting; only a bcrypt hash of it is stored, never the PIN itself. Organisation recovery is performed using a recovery key your organisation generates and controls, to which Graftix has no access. Vault access events are recorded in an append-only audit log.
Payment data — we do not collect or store payment card data directly. All payment data is processed by our payment processor. We receive only summary transaction information (plan type, payment status, invoice amounts).
Third-party sign-in data — if you sign in using Google, we receive your name and email address from Google as part of the authentication process.
Location data
GRAFTIX captures GPS coordinates in the following specific circumstances:
Attendance sign-in and geofenced check-in — if your project has a geofence configured, your device's GPS position is checked at sign-in to verify you are on site. The coordinate captured at sign-in is retained as part of your attendance record and is visible to your project's admins, project managers and supervisors. No continuous location tracking occurs — only a single point at the moment of sign-in. Legal basis: legitimate interests (site safety and attendance verification).
Task photo uploads — photographs taken on a GPS-enabled device may contain location coordinates in their EXIF metadata. GRAFTIX extracts and stores this coordinate alongside the attachment so work can be geographically referenced. This data is visible to anyone with access to the task. You can disable EXIF location extraction in Profile Settings, under Location on photos — when disabled, no coordinate is stored. Legal basis: your own action in uploading the photo, with the ability to opt out in Settings at any time.
Chat location sharing — you can voluntarily share your current location in an in-app conversation (as a static pin or a live-updating share). The coordinate is stored for the duration of the share and is visible only to participants in that conversation. Live shares expire after the duration you choose; static pins remain until you delete them. Legal basis: your own action in initiating the share.
SOS alert — when you trigger an SOS, your GPS coordinates (if location permission has been granted on your device) are captured and sent to all admins and supervisors in your organisation. The location is retained in the SOS Log for audit and safety review purposes and is not automatically deleted when the alert is resolved. Legal basis: legitimate interests (safety of workers).
3. How we use your personal data
We use your personal data for the following purposes, under the legal bases shown:
To provide and maintain the GRAFTIX service — including account creation, authentication, project management features and customer support. Legal basis: performance of a contract (Article 6(1)(b) UK GDPR).
To send service communications — such as password reset emails, subscription notifications and invitation emails. Legal basis: performance of a contract or legitimate interests.
To improve the platform — analysing usage patterns to understand how the platform is used and to identify areas for improvement. Legal basis: legitimate interests (Article 6(1)(f) UK GDPR) — we have balanced our interest in improving the service against your rights and found that this processing does not unduly prejudice you.
To ensure security and prevent fraud — monitoring for suspicious activity, unauthorised access or misuse of the platform. Legal basis: legitimate interests.
To comply with legal obligations — such as responding to lawful requests from public authorities or retaining financial records. Legal basis: legal obligation (Article 6(1)(c) UK GDPR).
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share your data with
We may share your personal data with the following categories of third-party recipient:
Infrastructure providers — your data is stored in regional cloud infrastructure depending on the data residency region of your organisation. EU organisations: data is stored in the United Kingdom (AWS eu-west-2, London). The UK benefits from an EU adequacy decision, permitting the free flow of personal data between the UK and EU/EEA member states. US organisations: data is stored in our US-region infrastructure managed by our hosting provider, AWS, in compliance with US data handling standards. Global organisations: data is distributed across UK and US infrastructure according to each project's designated region and each user's home region, set at the time of joining.
Payment processor — to handle subscription payments and invoicing. We share only the minimum data necessary (e.g. email address for receipt delivery).
Email service provider — to send transactional emails (invitation links, password resets, subscription notifications).
AI service provider — project data is submitted to an AI processing service to power the Dave AI Assistant and AI Symbol Takeoff features. For EU organisations, inference is performed via AWS Bedrock in the United Kingdom (eu-west-2, London); no EU organisation data leaves the UK for AI processing. For US organisations, inference runs through the direct Anthropic API; training on commercial API data is disabled by default. In neither case is your data used to train AI models. Data submitted is processed only to fulfil your request.
Analytics and monitoring tools — aggregate and anonymised usage data may be processed by error monitoring and performance tools to help us maintain a reliable service.
Other members of your organisation — your name, role, avatar and any project data you create or contribute to is visible to other members of your GRAFTIX organisation.
A Data Processing Addendum (DPA) is available on request for business customers who require one for their own compliance purposes. Please contact support@graftix.io.
We do not sell your personal data to any third party. We do not share your personal data with advertisers.
5. Sub-processors
We use the following sub-processors to deliver the GRAFTIX service. Each is subject to a data processing agreement with us:
Sub-processor
Role
Processing location
DPA
Anthropic (via AWS Bedrock for EU orgs; direct API for US orgs)
AI inference — Dave AI Assistant and Symbol Takeoff
United Kingdom (eu-west-2) for EU orgs; United States for US orgs
anthropic.com/legal/dpa
Amazon Web Services (AWS)
Cloud infrastructure, file storage, AI inference routing
United Kingdom (eu-west-2) for EU orgs; United States for US orgs
aws.amazon.com/service-terms
Neon
Managed PostgreSQL database hosting
United Kingdom for EU orgs; United States for US orgs
neon.tech/dpa
Clerk
User authentication and identity management
Global (US-headquartered; SCCs in place)
clerk.com/legal/dpa
Replit
Application hosting and US-region infrastructure
United States
replit.com/site/dpa
Stripe
Subscription billing and payment processing
Global (US-headquartered; SCCs in place)
stripe.com/legal/dpa
Resend
Transactional email delivery
Global (US-headquartered; SCCs in place)
DPA available on request from Resend
We will notify you of any changes to this list that materially affect how your data is processed.
6. How long we keep your data
Operational data (projects, tasks, files, messages) — retained for the lifetime of your organisation's subscription plus 6 years following termination, in line with the UK contractual limitation period under the Limitation Act 1980.
Audit logs — the immutable compliance audit trail is retained for 6 years from the date of the logged event.
Operational logs — high-volume technical logs are pruned automatically on shorter cycles: security and cross-region access logs are kept for 1 year, AI-assistant usage records for 1 year, and push-notification delivery logs for 90 days.
Account data — deleted on account closure, subject to any statutory retention obligations (e.g. financial records retained for 7 years to meet HMRC requirements).
Deleted member data — personal identifiers (name, email) are anonymised or deleted within 30 days of a deletion request. Project contributions are retained to preserve the integrity of the project record for other organisation members.
Post-cancellation grace period — organisation data is retained for 90 days after subscription cancellation to allow for export, then permanently deleted.
Backup copies — overwritten within 30 days of the corresponding primary data being deleted.
7. Your rights under UK GDPR
You have the following rights regarding your personal data:
Right of access — to request a copy of the personal data we hold about you.
Right to rectification — to correct any inaccurate or incomplete personal data.
Right to erasure ("right to be forgotten") — to request deletion of your personal data in certain circumstances.
Right to restriction — to request that we limit the processing of your data in certain circumstances.
Right to data portability — under Article 20 UK GDPR, where processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller. To request a data export, contact support@graftix.io.
Right to object — to object to processing based on legitimate interests.
Right to withdraw consent — where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us at support@graftix.io. We will respond within one calendar month. There is no charge for exercising your rights unless your request is manifestly unfounded or excessive.
See also Your privacy controls — a step-by-step guide to toggling location on photos, removing a shared location pin, managing SOS permissions, requesting a data export, and requesting account deletion.
8. Cookies
GRAFTIX uses essential cookies and similar local storage technologies to maintain your session, remember your preferences (e.g. dark mode) and support the offline capability of the Progressive Web App. We do not use third-party advertising or tracking cookies.
9. International transfers
EU organisations: your personal data is stored in the United Kingdom (AWS eu-west-2, London). The UK is not a member of the European Economic Area; however, the European Commission has granted the UK an adequacy decision under Article 45 UK GDPR, recognising that the UK provides an equivalent level of data protection to the EEA. Data may therefore flow freely between the UK and EU/EEA member states without additional transfer mechanisms.
AI processing for EU organisations is performed via AWS Bedrock in the United Kingdom (eu-west-2, London). No EU organisation data is transferred outside the United Kingdom for AI processing purposes.
US organisations: your data is stored in our US-region infrastructure. Authentication data (via Clerk) and payment data (via Stripe) may be processed in the United States; Standard Contractual Clauses (SCCs) approved by the ICO are in place for these transfers.
Where any third-party sub-processor processes data outside the UK, we ensure that appropriate safeguards are in place, including SCCs or reliance on an adequacy decision.
10. How to complain
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: ico.org.uk
Helpline: 0303 123 1113
Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We would, however, appreciate the opportunity to address your concerns before you contact the ICO. Please contact us first at support@graftix.io.
11. Changes to this notice
We may update this Privacy Notice from time to time. When we make material changes, we will notify you by email and update the "Last updated" date above. Continued use of GRAFTIX after such notification constitutes acceptance of the updated notice.
12. Contact us
Data Controller: Echo Thirteen Capital Ltd t/a GRAFTIX
Address: 128 City Road, London, EC1V 2NX
Email: support@graftix.io