Privacy Policy
Last updated: 26 August 2026
This Privacy Policy explains how Mufaddal Maimoon, trading as Projexa (a sole trader, no company number), of Rutland House, 23-25 Friar Lane, Leicester, LE1 5QQ ("Projexa", "we", "us") collects, uses, and protects personal data in connection with the Projexa application (app.getprojexa.com) and website (getprojexa.com) (together, the "Service").
Projexa is a project management platform for engineering, architecture, surveying, and similar professional-services firms. Depending on which data is at issue, we act either as a Data Controller or a Data Processor — see "Our role" below.
1. Our role: Controller vs Processor
- Where you are a subscribing firm (a "Customer"), and you enter data about your own clients, staff, contacts, projects, or files into Projexa, you are the Data Controller of that data and Projexa is your Data Processor. Our processing of that data on your behalf is governed by our Data Processing Addendum, not this Policy — this Policy still describes the technical/organisational picture, but the legal terms live in the DPA.
- Where we collect data about you directly — your name and work email when you sign up, billing contact details, support correspondence, and how you use the Service — Projexa is the Data Controller. This Policy is the primary document governing that data.
- If you are a client of one of our Customers and use the Projexa client portal to view project progress or download documents, the Customer who invited you is the Data Controller of your data, and Projexa is their Data Processor, in the same way as above.
2. What we collect
| Category | Examples | Collected from |
|---|---|---|
| Account data | Name, work email, password (hashed), role | You, at signup/invite |
| Company data | Company name, disciplines, settings | Your Customer's admin |
| Client & contact data | Names, emails, phone numbers of a Customer's clients | Entered by the Customer |
| Project & financial data | Project details, budgets, fees, deliverables, time logs | Entered by the Customer's team |
| Documents | Files uploaded and issued to clients | Entered by the Customer's team |
| Audit data | Who did what, and when, within the app | Generated automatically |
| Client portal accounts | Name, email, login activity of a Customer's own clients | The Customer, when inviting a client |
| Technical data | IP address, browser type, timestamps (server logs) | Automatically, from your use of the Service |
We do not currently use analytics, advertising, or marketing cookies/trackers. See "Cookies" below.
3. How we use data
- To provide, operate, and secure the Service (authentication, storing your data, sending the emails you or your Customer trigger — e.g. invites, progress reports).
- To provide customer support.
- To maintain security and audit logs, and to investigate misuse.
- To communicate essential service notices (e.g. planned downtime, security incidents).
- With your consent, or your Customer's, for anything else.
We do not sell personal data, and we do not use Customer data to train any AI/ML model or for our own marketing purposes.
4. Legal basis (UK GDPR)
Where Projexa is the Controller, we rely on:
- Contract — processing needed to provide the Service you signed up for.
- Legitimate interests — securing the Service, preventing abuse, improving the product.
- Consent — for anything optional (e.g. marketing emails, if we ever add them).
Where Projexa is the Processor, the Customer determines the legal basis for their own data.
5. Cookies
Projexa currently sets only strictly necessary cookies required to keep you signed in (issued by our authentication provider, Supabase). These do not require consent under UK PECR. We do not currently use analytics or advertising cookies. If that changes, this section and a dedicated Cookie Policy/consent banner will be added first.
6. Who we share data with
We share data only with the subprocessors needed to run the Service — see our Sub-processor list for the current list, their purpose, and where they process data. We do not sell or rent personal data to third parties.
7. International transfers
Our core infrastructure (database, authentication, file storage, and application hosting) runs in the EU (Ireland). Where any subprocessor processes data outside the UK/EEA, we ensure an appropriate transfer mechanism is in place (e.g. the UK International Data Transfer Addendum, or reliance on an adequacy regulation) — see the Sub-processor list for specifics per provider.
8. Data retention
- Active data is retained for as long as your account/Customer relationship is active.
- Deleted records are held in a recoverable "trash" state for 30 days, after which they are permanently purged.
- On termination of a Customer's subscription, data is retained for 30 days to allow export, then deleted. See the DPA for the Customer-facing commitment.
9. Security
We use industry-standard measures including encryption in transit (TLS) and at rest, role-based access control enforced at the database level (not just in the app), and audit logging of key actions. See the Data Processing Addendum for the full security commitment.
10. Your rights
Subject to UK GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. If your data was entered into Projexa by a Customer (e.g. your employer or a firm you're a client of), please contact that Customer directly first — they are the Controller and best placed to action your request. If we are the Controller (see Section 1), contact us at privacy@getprojexa.com.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
11. Children
The Service is intended for business use and is not directed at children. We do not knowingly collect data from anyone under 18.
12. Changes to this policy
We'll post updates here and, for material changes, notify Customers by email.
13. Contact
Mufaddal Maimoon, trading as Projexa Rutland House, 23-25 Friar Lane, Leicester, LE1 5QQ privacy@getprojexa.com