What we collect, why we collect it, how long we keep it, and what you can ask us to do with it.
Engineering projects involve two sensitive categories of information: personal data about the people involved, and technical data about the asset being engineered. We treat both carefully, and we treat them differently, because the risks are different.
This policy covers personal data. Project documents and technical content are governed by the confidentiality controls described in the terms of service and by any NDA executed for a project.
Account data — name, email, password hash, country, time zone, language. Profile data — discipline, specialisations, experience, education, certifications, registrations, software, standards, industries, rates, availability and portfolio content that you choose to publish.
Verification data — identity documents, qualification records and registration details submitted for checking. Transaction data — contracts, milestones, invoices and payment records. Communication data — messages, proposals, RFIs and comments exchanged through the platform.
Technical data — IP address, device and browser type, pages viewed, and search queries. We use this for security, abuse prevention and understanding which parts of the product work.
To operate your account and provide the service you asked for; to match projects to engineers using the structured fields you have supplied; to process payments and hold funds in escrow; to verify credentials where you have asked us to; to prevent fraud, credential falsification and abuse; to comply with legal obligations including tax and anti-money-laundering requirements; and to improve the product.
We do not sell personal data. We do not use your project content to train third-party models.
Where the GDPR or a comparable regime applies, we rely on: performance of a contract for account, matching, contracting and payment functions; legitimate interests for security, fraud prevention and product improvement; legal obligation for tax, accounting and regulatory reporting; and consent for optional marketing communications, which you can withdraw at any time.
Identity documents and qualification records submitted for verification are held separately from your public profile, encrypted at rest, and accessible only to the verification team. They are never shown to other users. What other users see is the outcome — verified or not verified — and not the underlying document.
Where a verification provider or issuing institution is involved in the check, we share only what that check requires. We retain identity documents for the period required by anti-money-laundering rules and delete them after that.
This is a global marketplace, so data moves across borders by design. Where data is transferred out of the EEA or UK, we rely on adequacy decisions where they exist and on standard contractual clauses where they do not, together with technical measures appropriate to the sensitivity of the data.
Account and profile data is kept while your account is open and for 12 months after closure. Contract, invoice and payment records are kept for seven years to meet tax and accounting obligations. Identity verification documents are kept for the period anti-money-laundering rules require, then deleted.
Project files are retained while the contract is active and for 24 months after completion, so that either party can retrieve the authoritative revision if a question arises later. After that they are deleted unless you have asked us to keep them.
Subject to your jurisdiction, you may request access to the personal data we hold about you, correction of inaccurate data, deletion, restriction of processing, a portable copy, and objection to processing based on legitimate interests. You may also withdraw consent for marketing at any time.
Some data cannot be deleted on request — contract and payment records we are legally required to retain, and content that forms part of another party's contractual record. We will tell you when that applies and why.
Requests go through the contact form. We respond within 30 days.
Data is encrypted in transit and at rest. Access to production systems is restricted, logged and reviewed. File access within a project is recorded in an audit log against the named user, including opens, downloads and shares.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.
The platform is not intended for anyone under 18 and we do not knowingly collect data from children. If we learn that we have, we delete it.
Questions about this policy, or requests to exercise your rights, can be raised through the contact form. If you are in the EEA or UK and are unhappy with our response, you may complain to your local supervisory authority.