Legal
Privacy policy
Last updated: 31 August 2026
Draft. The highlighted entries below are placeholders that have not been filled in yet. This policy is not final until every one of them carries a real value.
Who we are
ProjectoFolio is operated by Invest At Will CommV, registered at Treurenborg 9, 2030 Antwerp, Belgium, company number 0843.200.313, VAT BE 0843.200.313. We are the data controller for the personal data described here.
For anything in this policy, write to privacy@projectofolio.com. No Data Protection Officer is appointed; privacy questions go to the contact address above.
What this covers
The ProjectoFolio web application at projectofolio.com and the ProjectoFolio Android app. The app is a mobile front end for the same service and the same account — everything below applies equally to both.
In short
- You need an account. We collect what an account needs and what you put into your projects, and nothing else.
- We do not run advertising, we do not profile you, and we do not sell or rent your data to anyone.
- There are no analytics or tracking SDKs in the Android app and no analytics cookies on the website. The only cookie we set is the one that keeps you signed in. The email-and-password sign-up form also runs Google reCAPTCHA, a spam check that can set one security cookie of its own. See Sign-up spam check.
- Your project content is private to the people invited to that project. The one exception is the supplier portal, and only you can open it: on the Business plan you can let staff of one of your subcontractor companies see that company’s own jobs, work orders, invoices, payment statements, and the hours of its own people. See The supplier portal.
- On the Business plan you can give another Business user full access to your whole account. While they are in it they see everything you see, including any workforce pay data. See Sharing your whole account.
- If your account has the optional Workforce & hours area, it holds details and pay rates of people who work for you and who are not users of this service, and what your subcontractor companies cost you per project. What that means, and what it makes you responsible for, is set out under People who work for you.
- One exception, and you have to switch it on yourself: if you link your own Anthropic (Claude) API key, the documents you ask the AI assistant about are sent to Anthropic to answer you. Nothing is sent unless you have linked a key, agreed to it, and the project’s owner has turned the assistant on for that project. See The AI assistant.
What we collect, and why
Account information
| What | Why | Where it comes from |
|---|---|---|
| Email address | Identifies your account, receives invitations, and carries verification, password-reset and task-assignment messages | You, or your Google account when you sign in with Google |
| Name | Shown to the other people on your projects next to your uploads and comments. Optional — leave it blank and they see your email address | You, or your Google account |
| Profile picture | Shown in the app header and on member lists. We store only the web address of the picture held by Google; we never copy the image itself | Your Google account |
| Password | Only for accounts created with an email address and a password. Stored as a one-way hash — we cannot read it, and neither can anyone who obtains a copy of our database | You |
| An internal account identifier, and the identifier your sign-in provider gives us | Links your sign-ins to your account | Generated by us / your provider |
We do not ask for your postal address, phone number, date of birth or any special category of data. (Phone numbers do appear in one place in the service — not yours, but those of the people recorded in Workforce & hours, if your account has that feature. See People who work for you.)
What you put into your projects
Everything you and your collaborators create inside ProjectoFolio: project names and descriptions, uploaded files, photos and video, task titles and descriptions, quality-control checkpoints and sign-off comments, category names, and messages in project, document and task chats.
We hold this to provide the service. It is visible to the members of that project and to nobody else. We do not read it, mine it, or use it to train anything, and it stays on our own infrastructure — with one exception you control yourself: the AI assistant, which sends the document you ask about to Anthropic, and only once you have switched it on.
The credentials vault
Each project can store logins for third-party systems the job depends on. This is the most sensitive thing we hold, so it is worth being precise about:
- The username, password and notes on each entry are encrypted before they are stored, using an encryption key kept outside the database. A copy of the database on its own does not reveal them.
- They are decrypted only at the moment a project member presses “Reveal”.
- Every reveal is recorded — which entry, which person, the network (IP) address they used, and when.
- Any member of a project who can see that project’s content can reveal any credential in it. Only owners and editors can add, change or delete them.
- Deleting an entry removes it immediately and permanently.
Please do not store personal logins here. It is a shared facility for the project’s own accounts.
The AI assistant, and your own Anthropic key
This is optional, off by default, and costs you nothing here — you bring your own Anthropic account and pay Anthropic directly. It is also the one place where your project content leaves our infrastructure and reaches a company that is not our hosting, payment or sign-in provider, so it is set out here in full.
What we store
- Your Anthropic (Claude) API key, if you link one in Your account → AI assistant. It is encrypted before it is written to the database, with libsodium’s
secretbox, using an encryption key held in AWS Secrets Manager and injected into the running application — never in our source code. After you save it we never show it back to you: the page displays the last four characters only, so that you can tell which key is linked. There is deliberately no “reveal” function. Anthropic is the only provider supported. - Your conversations with the assistant — your questions and its answers — so that you can read your own history. Each message is deleted 90 days after it is written. You can delete a conversation yourself before then, and one goes with the document, the project or the account it belongs to.
- How many tokens each request used, and when, for the usage figures we show you and for rate limiting, and so that a project owner can see whose questions spent their Anthropic budget. We do not write your questions or the assistant’s answers into our server logs. These records are kept for 13 months and then purged.
- The fact that you agreed to document contents being sent to Anthropic, and when.
What is sent to Anthropic, and when
Nothing is sent unless all three of these are true: you have linked a key, you have agreed to this processing, and the project’s owner has switched the assistant on for that project.
When those conditions are met and you ask the assistant about a document, the contents of that document and the question you typed are sent to Anthropic — the text of the PDF, or the image itself, as stored in the project. Anthropic returns an answer and we show it to you.
Anthropic acts as a processor on your instruction for that request, under the terms of the Anthropic account whose key is used. Your relationship with Anthropic is yours: we do not hold your Anthropic account, we do not see what it is billed, and we add no charge of our own. Anthropic’s privacy policy is at anthropic.com/legal/privacy and its commercial terms at anthropic.com/legal/commercial-terms. Anthropic processes outside the European Economic Area; see Where your data is held.
Who runs on whose key
The assistant on a project runs on the project owner’s key. By default only the owner can use it. The owner can grant individual members of that project permission to use it — and when they do, those members’ use is charged to the owner’s Anthropic account.
What stays private
Your conversation with the assistant is yours alone. It is not added to the shared project, document or task chats that the other members of the project can read. Someone you have shared your whole account with has their own conversations, stored under their name; the questions they ask while in your account are charged to your key, and their usage appears under their name on your AI assistant page. They cannot change, remove or test your key or change your consent. See Sharing your whole account.
Turning it off
Remove your key in Your account → AI assistant and the encrypted key is deleted from our database; nothing further can be sent to Anthropic from your account. A project owner can switch the assistant off for a project, or withdraw an individual member’s permission, at any time. Material already sent to Anthropic is then governed by the retention settings of your own Anthropic account, not by ours.
People who work for you — Workforce & hours
This section is different from every other one, and it is worth reading even if it does not apply to you.
Workforce & hours is an optional area that is switched off for every account by default and is only enabled on request. If it has been enabled for your account, you can record the people who work for you, the subcontractor companies they work for, what each person is paid per hour, and the hours they worked each day. It produces cost totals and a CSV export.
This means the service holds personal data about people who are not users of ProjectoFolio. Those people have no account here, never agreed to our terms and may not know this application exists. We are setting that out plainly rather than leaving it to be discovered.
What is recorded about a worker
| What | Required? |
|---|---|
| First and last name | Yes — a person cannot be recorded without one |
| Email address, phone number, job title | Optional |
| A reference number you use for them internally | Optional |
| The subcontractor company they work for, with that company’s name, VAT number and a contact name, email and phone | Optional |
| Free-form notes | Optional |
| Their hourly rate, with the period it applies to | Optional, but needed for cost figures |
| The hours they worked on each date, and a description of the work | This is the point of the feature |
What we do with it
Nothing beyond storing it, adding it up and showing it back to you. It is not sent to any third party, not used for advertising, analytics or profiling, not used to train anything, and not sold. It stays in our own database in Frankfurt. We never contact the individual people you record. No worker is emailed, invited or given an account because you recorded them. A worker’s email address and phone number are stored as contact details for you, and we do not use them to reach the worker.
A subcontractor company’s stored email addresses are different. We send to them only when you tell us to: a payment statement, a work order or a tool-hire contract you send, or an invitation to the supplier portal. Each of these goes only to the addresses stored on that company. Nobody can type in a different address.
Who can see the pay
You can share hours-logging with another ProjectoFolio user, so a foreman can enter the day’s hours. A person you share with can see the people and the hours and can never see a rate or a cost figure — pay is left out of what our servers send them, not merely hidden on screen. Only you can see rates, run cost reports or export the CSV — you, and anyone you have shared your whole account with on the Business plan, because while they are in your account they act as you, on your behalf and on your instructions (see Sharing your whole account). Hours-logging sharing never gives that access; account sharing always does.
Subcontractor costs and invoices
The same area also lets you record what a subcontractor company costs you on a particular project: an agreed cost cap, the jobs agreed with that company and their prices, any extra work you approve, and the invoices the company has sent — invoice number, date, amount excluding VAT, a status such as received or paid, and how the amount is split across your projects. These are commercial terms and financial records about a company, not further personal data about a worker, and they are kept for the same reason the rest of the feature is: so the figures add up.
Only you can see any of it — you, and anyone you have shared your whole account with. No project member sees these figures, whatever their role, and neither does anyone you have shared hours-logging with; the figures are left out of what our servers send them rather than hidden on their screen. The subcontractor sees only what you send it, and, if you invite its staff to the supplier portal, the part of your records that concerns that company. They never see your cost caps, hourly rates or cost figures. See The supplier portal.
If you attach a scanned invoice to one of these records, the file itself is an ordinary project document and is held and erased as any other document is; the record that points at it is not the file. All of it — allocations, agreed prices, approved extras and invoice records — is erased when you delete your account, in the same sweep as the rest of Workforce & hours.
What is kept about changes
Every change to an hours entry is recorded — the previous and new number of minutes, who changed it and when — and each CSV export of pay data is recorded with who ran it, the period covered and the network (IP) address it was run from. An hours record that can be altered without a trace is not worth having.
If you use this feature, this part is your responsibility
For the people you record, you decide what is held and why, so you — not we — are the one those people can hold to account for it. You must have a lawful basis for recording them, and you must tell them that you do, what you record and who processes it for you. Record only what you actually need: this is not the place for anything sensitive, and the notes field is not a personnel file.
If you have been recorded in someone else’s workforce
You will not have an account here and cannot sign in to see your entry. The business that recorded you is the one to ask — they decide what is held and they can correct or remove it. If you cannot identify them or get no response, write to privacy@projectofolio.com with what you can tell us and we will pass the request to the account holder and help them act on it.
If you work for a subcontractor company and the business you work for has been given supplier-portal access, staff of your company can see your name and the hours recorded for you. That includes the description of the work typed for each day. See the next section.
The supplier portal (Business plan)
The supplier portal is a read-only view for a subcontractor company you work with. Only an account holder on the Business plan who has Workforce & hours switched on can open it. You invite that company’s staff to see the part of your records that concerns their company, and nothing else.
Who can be invited, and how
- An invitation can only go to an email address already stored on that company’s record: its contact, billing or contracts address. You cannot type in another address.
- We email the invitation to that address. To accept it, the person has to be signed in to their own ProjectoFolio account, and the account’s email address must match the invited one.
- An invitation that is not accepted expires after 14 days.
- You can withdraw access at any time. Access also ends automatically if you remove that address from the company’s record.
- Each account holder invites separately. One person can have portal access to several account holders’ records, and each account holder’s records stay separate from the others.
What a portal user sees (for your account and that one company only)
| What | Detail |
|---|---|
| The projects the company is allocated to | Project name, and each job’s reference, title, agreed amount, type and status |
| Work orders you sent them | The PDF of each work order you sent |
| The company’s own people and their hours | Each person’s name, and the hours recorded for them by day, together with the description of the work typed on your side. Only hours from the date that person joined that company are shown. |
| Invoices and payment statements | Amounts, VAT, status, the lines per project, statement PDFs, and the notes on self-billed statements |
What a portal user never sees: hourly rates, costs, cost caps, and any other project content: documents, photos, tasks, quality checks, chats, credentials or the list of members. We do not send these to their browser at all, so hiding them on screen is not what keeps them private. They also see nothing about any other subcontractor company, and nothing about people you have recorded as working for another company or for you directly.
What we store: the invitation (the address it was sent to, the company, who sent it, and when it was sent, expires, is accepted or is withdrawn) and, once accepted, which ProjectoFolio account it is linked to. The invitation email is sent through our email provider (Amazon Web Services, listed under Who we share it with). We use the invited address only to deliver the invitation and to check it against the account that accepts it.
Your responsibility. The portal shows the company data you recorded about its own people: their names, the days they worked, how long, and what you wrote about the work. Deciding to show it is your decision. You are responsible for what you record about a subcontractor’s people, and for having a reason to share it with their employer. Write hour descriptions knowing that the company can read them. As with the rest of Workforce & hours, record only what you need.
If you are a portal user, what you see belongs to the account holder who invited you. Use it for your dealings with them. To have something corrected, ask them. Ending your access does not delete their records.
Sharing your whole account (Business plan)
If both you and another person are on the Business plan, you can give them full access to your account under Your account → Account sharing. They then switch into your account from the top bar and work as you, with access to your work: every project you own, and Workforce & hours including the pay rates and costs of the people you record. They can use the AI assistant in your projects, on your key. They cannot delete your account, change its issuing identity, change who it is shared with, change your plan or payment details, or replace, remove or test your AI key or change your AI consent.
What we store: who you have shared your account with, when, and who added them, and when the person you shared with accepted the terms of that access and which version of the wording they accepted. If you remove someone and add them again, their earlier acceptance does not carry over. We also record, in the security records described below, each time someone switches into or out of an account shared with them — against their own account, with the network address and browser identification of the request and which account they switched into.
Who it is recorded against: what they do in your account is recorded under their own name — their messages, uploads, checkpoint sign-offs, credential reveals, hours changes, exports, documents sent and AI usage. You can therefore tell their actions from yours. What belongs to the account stays yours: the projects, the plan, the Workforce & hours records, the billing customer and the AI key, so AI questions they ask in your account are charged to your key.
Your responsibility. Giving someone this access means they can see personal data you hold about other people — including the names, hours and pay of the people in your Workforce & hours records. For that data you are the controller: you decide who gets access, as you decide what to record in the first place. The person you share with works with it on your behalf and on your instructions, not for their own purposes, and must confirm that before they can switch into your account for the first time. Until they do, your sharing list shows them as Not yet accepted. Share only with people you trust with your own sign-in, and remove them when they no longer need it.
Ending it: remove the person under Account sharing at any time; if they are in your account at that moment, their next click takes them back to their own. Access also stops if either of you leaves the Business plan. The record of the share is deleted when either account is deleted.
Billing information
If you subscribe to a paid plan, payment is taken by Stripe. Card numbers and payment details are entered on Stripe’s own pages and never reach our servers or our database. What we store is your plan, the date it started, and the customer and subscription identifiers Stripe gives us, so we know what you are entitled to.
Stripe processes your payment data as an independent controller under its own privacy policy: stripe.com/privacy.
Security records
We record sign-ins, failed sign-ins and sign-outs, and each switch into or out of an account someone has shared with you, each with the network (IP) address and the browser or app identification string (User-Agent) that made the request. We also record every reveal from the credentials vault. This exists to detect and investigate unauthorised access to accounts.
We do not use your IP address to work out or store where you are, and we collect no location data of any kind.
These records are not kept indefinitely: they are erased from our database after 90 days, and the archived copy expires 365 days after the event. See How long we keep it.
The record we keep of each Workforce & hours export, which also includes a network address, is not covered by this 90-day window — it is kept with the workforce records it belongs to. See People who work for you.
Sign-up spam check (Google reCAPTCHA)
The email-and-password sign-up form uses Google reCAPTCHA (the “I’m not a robot” box) to stop automated account creation and abuse. When you open that form, your browser — or the Android app — loads the check from Google, which looks at your IP address, browser and device characteristics, and how you interact with the page, and may set a security cookie (see Cookies). When you submit, our server sends Google the result of the check together with your IP address, and Google tells us whether it looks like a person.
Google does this as our processor, only to provide the check, under the Google Cloud Data Processing Addendum: cloud.google.com/terms/data-processing-addendum. Google Cloud’s privacy notice: cloud.google.com/terms/cloud-privacy-notice.
It applies only to that form. Signing in, and signing up or in with Google or Microsoft, do not load reCAPTCHA.
What we do not collect
No advertising identifier. No device identifier or fingerprint, other than the browser and device characteristics the sign-up spam check reads, above. No location. No contacts — the suggestions on the invite form come only from people you already share a ProjectoFolio project with, never from your phone’s address book. No calendar. No browsing history. No analytics, behavioural or crash-reporting data from your device.
Cookies
We set one cookie, PROJECTOFOLIO_SESSION. It keeps you signed in, contains no personal information itself, is marked Secure and HttpOnly so it cannot be read by scripts or sent over an unencrypted connection, and it expires when you close your browser or sign out.
It is strictly necessary for the service to work, so it does not require consent. We set no advertising, analytics or tracking cookies, so there is nothing here to consent to.
The sign-up form is the one exception to “one cookie”: Google reCAPTCHA can set a cookie called _GRECAPTCHA on Google’s own domain while it runs its check. It is used only for that security check, not for advertising. See Sign-up spam check.
The Android app holds the same session in its own storage rather than as a browser cookie. Signing out clears it.
Android app permissions
| Permission | What it is for |
|---|---|
| Camera | Taking photos and video of the job from inside the app. Only asked for when you first use the camera; refuse it and the rest of the app works normally |
| Microphone | Only so that video you record has sound. No audio is recorded, uploaded or stored on its own |
| Internet / network state | The app is a front end for an online service |
The app requests no other permissions. It does not need storage permission — when you download a file it asks you where to save it and writes only there.
Who we share it with
We do not sell your data and we do not share it for anyone else’s marketing.
We use a small number of service providers who process data on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage and outbound email | eu-central-1, Frankfurt, Germany |
| Stripe | Payment processing for paid plans | Ireland / United States |
| Google Sign-In, if you use it; distribution and updates of the Android app through Google Play; the reCAPTCHA spam check on the email-and-password sign-up form, which receives your IP address and browser and device characteristics | Global | |
| Anthropic | The AI assistant, only if you have linked your own Anthropic API key and the project’s owner has switched the assistant on. Receives the contents of the documents you ask about and the questions you type | United States |
Anthropic is different from the others in the table: it is engaged by you, with your API key, and it receives nothing at all until you switch the feature on. Everyone else in the table processes data for every account by default. See The AI assistant.
The other people on a project see the content of that project, and each other’s names, email addresses and profile pictures. That is what a shared project is.
If you share your whole account with someone on the Business plan, they see everything in it, as described under Sharing your whole account. That is a disclosure you make, to a person you choose; it is not us sharing your data with a third party.
Workforce & hours data goes to none of the providers in the table above beyond the hosting that stores it and the email service that delivers what you send. If you share hours-logging with a colleague they see the people and the hours; they never see anyone’s pay rate or cost. If you share your whole account with someone, they see all of it, pay included.
If you invite a subcontractor company’s staff to the supplier portal, they see that company’s jobs, work orders, invoices and statements, and the names and hours of that company’s own people. They never see rates or costs. As with account sharing, this is a disclosure you make to people you choose. We do not share your data with a third party.
We will disclose data where the law requires it, and to establish or defend legal claims.
Where your data is held
Our servers, database, uploaded files and outbound mail all run in Amazon Web Services’ eu-central-1 region in Frankfurt, Germany.
Stripe and Google process data outside the European Economic Area under their own transfer safeguards (Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework).
If you use the AI assistant, the document contents and questions you send go to Anthropic in the United States, under Anthropic’s own transfer safeguards. If your project holds material you may not transfer outside the EEA, do not switch the assistant on for it.
How long we keep it
| What | How long |
|---|---|
| A file you delete | Kept recoverable in the project’s trash, then permanently erased. 14 days on Free, 30 days on Starter and 180 days on Pro, Pro Extended and Business — the window is set by the project owner’s plan |
| A project you delete | The same window, then permanently erased with everything in it |
| A credentials-vault entry you delete | Erased immediately |
| Your account and its data | Kept while the account is open. After deletion the account is deactivated at once and permanently erased 30 days later. |
| Security records (sign-in and credential-reveal logs) | 90 days in full, including the IP address and the browser or app identification string. At 90 days the record is erased from our database, having first been copied to encrypted archive storage in the same Frankfurt region so that a security incident can still be investigated afterwards. That archived copy expires 365 days after the event, and from then on nothing about it remains anywhere. Deleting your account does not wait for either point — the purge strips the IP address, identification string, email address and event details out of every one of your security records the moment it runs, though a copy already archived by then still runs out its 365 days. |
| Workforce & hours records — people, subcontractors, rates, hours, the change history, the subcontractor cost records (caps, agreed job prices, approved extras and invoices) and the export log | For as long as the account exists. Nothing expires them on a timer: there is no job that deletes a workforce record after a set period, so they are kept until the account is deleted and are erased then. Marking a person inactive, or removing them, keeps their record and their hours, because the hours are what the figures were built from. The record of each CSV export, including the network (IP) address it was run from, is kept on the same basis — those addresses are not covered by the 90-day security-record window described above |
| Who you have shared your whole account with | Until you remove the person, or until either account is deleted. If either of you leaves the Business plan the share is paused, not deleted, and resumes if you both return to Business. Switches into and out of a shared account are security records and follow the window above |
| Supplier-portal invitations and access | An invitation that is not accepted stops working after 14 days. Access lasts until you withdraw it, the address is removed from the company, or either account is deleted. After that, the invitation and access record is kept for TO BE SUPPLIED: retention period for ended supplier-portal access records. The portal copies nothing: portal users see your live records, so what they see follows the Workforce & hours row above |
| Billing records | For as long as tax and accounting law requires — 7 years |
| Your Anthropic API key | Held, encrypted, until you remove it or your account is deleted. Removing it deletes the stored key outright |
| Your AI assistant conversations | 90 days from the date each message is written, then deleted automatically. You can also delete a conversation yourself at any time, and one goes immediately with the document, the project or the account it belongs to |
| AI usage records (token counts and timestamps, no message content) | 13 months, then purged. They exist for rate limiting and so that a project owner can see whose questions spent their Anthropic budget; 13 months covers a full billing year plus the month you are comparing against |
Your rights
If you are in the EEA or the UK, you have the right to:
- access the personal data we hold about you,
- have inaccurate data corrected,
- have your data erased,
- restrict or object to how we process it,
- receive your data in a portable form,
- withdraw consent where we relied on it, and
- complain to your data protection authority. In Belgium that is the Gegevensbeschermingsautoriteit / Autorité de protection des données, gegevensbeschermingsautoriteit.be.
Write to privacy@projectofolio.com and we will respond within one month.
A second practical note: if the only place you appear is somebody’s Workforce & hours records, we hold that data on their instructions and cannot change or delete it on our own initiative. See People who work for you for how to reach them. The same applies to what you see in the supplier portal: the account holder who invited you holds those records, so ask them to correct them.
One practical note on erasure: a project you contributed to may belong to someone else, and other members may depend on what you uploaded. Where we cannot delete something without destroying another person’s records, we will tell you what we can and cannot remove, and why.
Deleting your account
You can delete your account yourself at any time, without asking us: sign in, open Your account from your name in the top bar, and choose Delete my account under Danger zone. The confirmation screen states, with real counts, how many projects, files and quality-control records will be destroyed and how many other people lose access, and it requires you to type a confirmation phrase. You can also request deletion without signing in — see Delete your account. Confirming deactivates the account immediately: you are signed out, sign-in is refused, any paid subscription is cancelled, and every project you own becomes unreachable for all of its members. Everything is then permanently erased, stored files included, after 30 days. Nothing is irreversible before that point.
Deleting your account is a cascade. Every project you own is destroyed with it — its documents, photos and video (including the stored files themselves), its tasks, its quality-control checkpoints and sign-offs, its stored credentials, its conversations, and every other member’s access to it. It is not limited to your own copy: the project stops existing for everybody in it. The confirmation screen tells you the exact numbers before you commit.
Projects owned by other people are not affected. You lose your membership of them. Messages, comments and quality-control sign-offs you left there stay in place, because they are the other members’ record of what happened; your name and email address are removed from them and they show as Deleted user.
Supplier-portal access ends with either account. If you invited a company’s staff to the supplier portal, their access ends when your account is deactivated. If you have portal access to someone else’s records, deleting your account ends that access. Their records about your company stay with them.
Billing and invoice records are kept for as long as tax and accounting law requires and cannot be deleted on request.
The publicly reachable deletion-request address, which needs no account and no app, is projectofolio.com/delete-account.php.
Legal bases for processing
| What | Basis |
|---|---|
| Running your account and providing the service | Performance of a contract |
| Verification, password-reset and task-assignment emails | Performance of a contract |
| Security logging and fraud prevention | Legitimate interests — keeping accounts and their contents secure |
| The reCAPTCHA spam check on the sign-up form | Legitimate interests — preventing automated account creation and abuse |
| Sending a supplier-portal invitation to a subcontractor company’s stored address, and checking it against the account that accepts | Performance of our contract with the account holder who asked us to send it. For the person receiving it: legitimate interests, which means delivering an invitation the account holder addressed to their company and making sure only that address can accept it |
| Showing a subcontractor’s portal users their company’s jobs, documents sent to them, invoices, and the names and hours of their own people | Performance of our contract with the account holder, on their instruction. The account holder decides to make this disclosure and needs their own lawful basis for it (see The supplier portal) |
| Billing and tax records | Legal obligation |
| Sending document contents and your questions to Anthropic for the AI assistant | Consent — recorded when you agree to it, and withdrawable at any time by removing your key |
Consent is the basis for exactly one thing: the AI assistant. Withdraw it by removing your key, and nothing further is sent. Nothing else we do relies on consent, because we do not process any of your data for advertising, analytics or profiling.
Security
- All traffic to and from ProjectoFolio is encrypted with TLS. The Android app refuses unencrypted connections.
- Passwords are stored as one-way hashes and are never recoverable.
- Credentials-vault secrets are encrypted at rest with a key held outside the database, and every access is logged.
- A linked Anthropic API key is encrypted at rest the same way, with a key held in AWS Secrets Manager, and is never displayed back to anyone — not to you, and not to us — after it is saved.
- Access to project content is checked on the server for every request; roles and per-file exclusions are enforced there, not in the browser.
No system is perfect. If you believe you have found a security problem, please tell us at privacy@projectofolio.com before telling anyone else.
Children
ProjectoFolio is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes to this policy
We will post any change here and update the date at the top. If a change materially affects how we handle your data, we will tell account holders by email before it takes effect.
Contact
privacy@projectofolio.com — Invest At Will CommV, Treurenborg 9, 2030 Antwerp, Belgium.
See also the terms of service and the help page.