Legal
Privacy Policy
How Keplerworks agents — principally the Carbon agent — collect, anchor and delete IFC-derived data across UK, EU and global projects.
Last updated: 4 May 2026
1. Who we are and what this covers
For personal data tied to workspaces (names, billing contacts, telemetry rows with user or firm identifiers), Keplerworks operates as data controller.
For BIM deliverables uploaded solely to fulfil embodied carbon workflows, Keplerworks predominantly acts under your instructions (processor role in EU law terms) although we jointly determine analytical methodology.
This policy applies to browsers visiting keplerworks.io plus registered firms using IFC upload, embodied carbon routing, dashboards and CSV/PDF/JSON artefacts.
2. Data we collect
- Account & billing metadata: work email, hashed password, firm label, Stripe customer linkage, tier/allowances, optional team seat manifests.
- Carbon workflow artefacts: IFC binaries during ingestion, BIM metadata, embodied carbon aggregates, methodological labels, hotspots, summaries, persisted export bundles.
- Analysis geography signals: ISO country anchor you confirm, whether you accepted an auto-suggestion or overrode it.
- Session & security telemetry: signed session cookies, CSRF tokens, coarse IP/User-Agent metadata for rate limiting.
- Product analytics (server-side): firm-scoped events such as sign-ins, analysis runs, exports, subscription changes — not shared with ad networks.
3. Storage and isolation
Structured state lives in managed PostgreSQL with firm-scoped access controls. IFC blobs are written to application disk only for the parse/analyse window described in §5. Production hosting is currently provisioned in EU regions (for example Frankfurt) via providers such as Render and Neon.
4. Lawful bases (UK GDPR / GDPR)
- Contract (Art. 6(1)(b)) — running accounts, parsing IFC, computing embodied carbon, enforcing quotas, delivering upgrades and invoices.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, debugging outages, and firm-scoped product analytics.
- Legal obligation (Art. 6(1)(c)) — retaining purchase records and meeting tax/accounting duties.
We do not use optional marketing cookies at this revision; only essential authentication cookies are set without a consent banner.
5. Retention & deletion
- IFC files: after a successful Carbon analysis the platform deletes the uploaded IFC blob while retaining derived numeric results.
- Analysis history: kept for active paid subscriptions until you delete an analysis or close the account (subject to legal holds).
- Free tier: analyses older than 30 days may be removed automatically (see Pricing).
- Backups & logs: may persist for a limited period for disaster recovery and security investigations.
6. Cookies & similar technologies
- Session cookie (
keplerworks.sid): httpOnly session identifier; Secure and SameSite=Lax in production. - CSRF token: supplied for authenticated mutating API calls.
- No behavioural advertising stack runs on the marketing site or app shell at this policy date.
7. Third-party processors & factor catalogues
- Stripe — cardholder data tokenisation, subscriptions, invoices.
- Hosting & database vendors (e.g. Render, Neon) — compute, storage, backups.
- Transactional email providers — password resets and operational notices.
- Embodied carbon data services — EC3, ECO Portal, Ökobaudat and national EPD programmes; ICE v3.0 ships inside the application for default coverage.
Factor API calls send material search metadata, not your IFC geometry. Your model never leaves Keplerworks for those lookups.
8. International transfers
Some subprocessors process data outside the UK or EEA. Where required we rely on UK IDTA / EU Standard Contractual Clauses, adequacy regulations or vendor accreditation schemes. Request a summary via info@keplerworks.io.
9. Security
We apply tiered controls: password hashing, scoped database access, HTTPS, session hardening, rate limits and operational monitoring. No online service is perfectly secure — protect credentials and locally cached IFC copies within your own IT policies.
10. Data subject rights
Where UK GDPR or GDPR applies you may request access, rectification, erasure, restriction, portability and may object to legitimate-interest processing. Email info@keplerworks.io from your registered address with subject line GDPR REQUEST.
For complaints, UK users may contact the ICO (ico.org.uk).
11. Children
Keplerworks is aimed at organisational users and is not directed at anyone under 16. If you believe we collected a child's data in error contact info@keplerworks.io.