Privacy Policy
Privacy Policy
Last updated: 2026
What we collect
Account details (name, email, organization), and the project documents you upload for analysis — contracts, RFIs, emails, site instructions, meeting minutes, and similar records. We also keep an audit log of actions taken on your account (who reviewed or confirmed a variation, and when) for traceability.
How we use it
Uploaded documents are processed to identify potential variations, estimate recoverable value, and flag time-bar risk. Account data is used to authenticate you, enforce organization-level access control, and send notifications about your own analysis jobs. We don't sell your data, and we don't use your project documents to train models for other customers.
Where it's stored
Data is stored in Australian-region infrastructure. Access is scoped per organization — members of one company account cannot see another company's projects or documents.
Your rights
You can request a copy of your data or request deletion of your account and associated project data at any time by contacting us at hello@variationiq.com.
Data retention
We keep account and project data for as long as your organization has an active account, plus a limited period afterwards to allow account recovery and to meet our own record-keeping obligations. When you request deletion, we remove your account, project documents, and associated variation data from active systems; residual copies in backups are purged on our normal backup rotation cycle rather than instantly. Audit log entries (who reviewed or confirmed a variation, and when) may be retained for a longer period where needed for security, dispute-resolution, or accounting purposes, consistent with typical recordkeeping practice for commercial software — the specific retention period is still being finalized and will be confirmed here once set.
We're not aware of any Australian legal requirement that specifically mandates a minimum retention period for the kind of data VariationiQ holds, but if your organization's own contractual or regulatory obligations (e.g. under a head contract) require longer retention of project records, that is your responsibility to manage separately — we don't delete data against your organization's wishes while your account remains active.
Security & data handling
The controls described below are actively enforced in the current production system. This section reflects present-state functionality, not future intentions.
1. Authentication & session security
- Passwords are hashed using bcrypt before storage. Plaintext passwords are never stored, logged, or retrievable by VariationiQ personnel.
- Authentication is performed using signed JWT access tokens with short expiry, supported by rotating refresh tokens to limit the impact of a compromised token.
- Users may revoke sessions at any time, including signing out of all active devices, and sessions are automatically revoked on password reset.
2. Data isolation & access control
- Organizational data is isolated at the database query level — access is scoped so a user can retrieve only data belonging to their own organization.
- Role-based access control (RBAC) governs permissions within an organization: admins may manage members, roles, and organization-wide settings; members operate under restricted, role-appropriate permissions.
3. Audit logging
An audit log records key actions for traceability and accountability, including review, approval, or rejection of variation findings, together with the identity of the acting user and a timestamp for each recorded action. Audit records are immutable once created and are not editable through the application.
4. Transport & application security
- All traffic is encrypted in transit via HTTPS/TLS.
- HTTP Strict Transport Security (HSTS) is enforced in production.
- A restrictive Content Security Policy (CSP) is applied to reduce the risk of cross-site scripting (XSS) and related injection attacks.
5. Compliance status
VariationiQ does not currently hold formal third-party security certifications such as SOC 2 or ISO/IEC 27001, and no such claims are made. Our data handling practices are designed to operate consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) — including purpose limitation, data security, and access/correction rights — without representing formal certified compliance. Controls are proportionate to the current scale and sensitivity of data processed and are reviewed as the platform matures. This section will be updated if formal certifications are obtained.
6. Third-party service providers
We use a limited set of service providers necessary to operate VariationiQ. We do not sell personal information, and data is disclosed to these providers solely to the extent required for the functions described below.
- Anthropic— uploaded project documents are transmitted to Anthropic's API to perform variation detection, value estimation, and risk assessment. Data is processed for inference purposes only; Anthropic is not permitted to use customer data to train its models.
- Sentry — used for application error monitoring and debugging. May capture limited technical context (e.g. page URL, error stack trace); does not perform full session recording.
- Amazon Web Services (AWS) — uploaded documents are stored in Amazon S3, in the Sydney (ap-southeast-2) region.
- PostgreSQL — primary database for account, organization, and variation metadata.
- Email delivery — transactional email (invitations, password resets) is sent via SMTP. A named provider has not yet been finalized; this section will be updated once one is selected.
7. Cookies & authentication tokens
VariationiQ does not use advertising or behavioral tracking cookies. Authentication relies on JWT tokens rather than session cookies: stored in localStorageif "Remember me" is selected, or in sessionStorage otherwise (cleared when the browser session ends). Tokens are transmitted with each request solely to authenticate the user — not used for tracking, profiling, or analytics.
8. Data residency & international transfers
Account, project, and document data is primarily stored in AWS's Sydney (ap-southeast-2) region. Limited cross-border transfers occur as a function of the third-party services above: document content sent to Anthropic (a US-based provider) for AI-assisted analysis, and error-monitoring data sent to Sentry, processed in Sentry's EU data region. These transfers occur only as necessary to provide the service and are subject to each provider's own standard terms; we do not currently maintain bespoke data processing agreements beyond those terms. Organizations with specific data residency, regulatory, or contractual requirements should contact us before uploading sensitive project data, so we can advise whether current arrangements meet those requirements.
Note for enterprise users: VariationiQ supports operational analysis of construction project documents. It does not constitute legal, contractual, or financial advice, and outputs — including AI-generated variation candidates — should be independently reviewed by qualified personnel before being relied upon.