Privacy Policy
Last Updated: September 1, 2026
1. Who We Are
DataDrivenAEC (“we”, “us”, “our”) operates datadrivenaec.com, the AEC market-intelligence platform for architects, engineers, and contractors. We are based in Berlin, Germany.
Controller for GDPR purposes: DataDrivenAEC, Berlin, Germany Contact: [email protected]
2. Information We Collect
2.1 Information You Provide Directly
| Data | Collected When | Purpose |
|---|---|---|
| Email address | Newsletter signup | Send newsletter and product updates |
| Email address | Paid service checkout | Deliver your report; send receipt |
| Uploaded files (drawings, PDFs, specs) | Paid agent services | Run the analysis you purchased |
| Project information (location, type, brief) | Opportunity / product research | Generate your research report |
2.2 Information Collected Automatically
When you visit the site, we collect anonymised usage data via Plausible Analytics, a cookie-free analytics tool we self-host. It records pages visited, referral source, browser/device type, and country-level location (derived from IP; raw IP is never stored). Plausible does not track you across other websites and does not share data with advertising networks.
2.2.1 Cold-Outreach Link Tracking
Links in our cold-outreach emails may be individualized so we can see whether our outreach is relevant to you (e.g. whether it was opened or a link was clicked). This is used to gauge outreach relevance and avoid re-sending irrelevant follow-ups — not for advertising or resale. See Section 3 for the legal basis this is processed under.
2.3 Information from Third Parties
We do not receive personal data from third-party data brokers or advertising networks. We do not offer social login.
When you pay via Stripe, Stripe may share basic transaction metadata (amount, currency, timestamp) with us for order confirmation. Your full payment details remain with Stripe.
2.4 Cookies
We use essential first-party cookies for signed-in sessions, and a local-storage preference for theme setting. On the opportunity map we also set one first-party identifier cookie (ddaec_vid, 30 days, HttpOnly) used to enforce daily usage limits and to understand which listings and source documents are used; it is never shared with third parties or combined with advertising data. Our analytics (Plausible) is cookie-free. We do not use advertising or marketing cookies.
3. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Deliver paid agent reports | Uploaded files, email, project info | Contract performance (Art. 6(1)(b)) |
| Send newsletter | Email address | Consent (Art. 6(1)(a)) |
| Send transactional emails (receipts, report delivery) | Email address | Contract performance (Art. 6(1)(b)) |
| Analyse site traffic and improve the Service | Anonymised usage data | Legitimate interest (Art. 6(1)(f)) |
| Respond to support requests | Email, context you provide | Legitimate interest (Art. 6(1)(f)) |
| Cold outreach to business contacts sourced from public sources | Name, business email, role | Legitimate interest (Art. 6(1)(f)) — B2B outreach; you may object/unsubscribe at any time |
| Process payments | Payment data (via Stripe) | Contract performance (Art. 6(1)(b)) |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
Cold outreach: We may email business contacts (name, business email address, role) sourced from public professional information for B2B outreach relevant to their role in the AEC industry. Every outreach email includes an unsubscribe path; once you unsubscribe or object, we honour that permanently — we keep a minimal suppression record specifically so we do not contact you again. To object outside of an email’s unsubscribe link, email [email protected].
We do not use your data for automated decision-making or profiling.
4. How We Share Your Information
We do not sell, rent, or share personal data with third parties for advertising or marketing purposes.
We share personal data only with service providers who process it on our behalf, under a data processing agreement, and only to the extent needed to run the Service. These fall into the following categories:
- Hosting, storage, and job execution — Cloudflare R2 stores uploaded files; Supabase stores job and account metadata; Amazon Web Services runs report-processing workloads
- AI processing — depending on the service and processing route, submitted content may be processed through the OpenAI API or Anthropic API. DataDrivenAEC does not use submitted files or briefs to train models. Provider retention depends on the endpoint, feature, account controls, and applicable legal or safety exceptions; we do not claim zero data retention unless a separate approved control or agreement is verified
- Payment processing — handled by Stripe at checkout; we never see or store your card details
- Email delivery — transactional email and receipts via Resend; newsletter delivery and subscription management via Beehiiv
A full, current list of subprocessors is available on request at [email protected].
Legal Requirements
We may disclose your information if required by law, court order, or government request. Where permitted, we will notify you before complying.
Business Transfers
If DataDrivenAEC is acquired, merged, or sells assets, your data may be transferred to the new entity, which will be bound by this Privacy Policy.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Newsletter email subscriptions | Until you unsubscribe |
| Uploaded files (drawings, PDFs) | Operational policy: remove within 30 days after report delivery; earlier deletion can be requested. Automatic lifecycle enforcement is not represented as verified |
| Report content | Kept as needed for delivery and support; deletion can be requested, subject to legal obligations |
| Transaction and business records | 6–10 years depending on record type and applicable law; invoices and accounting vouchers are generally retained for 8 years |
| Anonymised analytics | Rolling 24 months |
| Support email correspondence | 2 years |
We keep personal data only as long as necessary for the purpose it was collected for, or as required by law.
6. Data Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit and at rest, and access controls limiting data access to authorised personnel. See our Security page for more detail on how uploaded files are handled.
7. Your Rights Under GDPR (EEA/UK Residents)
If you are in the EEA or UK, you have the right to:
- Access — Request a copy of personal data we hold about you
- Rectification — Correct inaccurate or incomplete data
- Erasure — Request deletion of your data (“right to be forgotten”). For business contacts reached via cold outreach, our erasure process redacts your record and records a permanent suppression entry so you are not contacted again
- Restriction — Ask us to pause processing in certain circumstances
- Portability — Receive your data in a portable, machine-readable format
- Object — Object to processing based on legitimate interests
- Withdraw consent — At any time, for processing based on consent (e.g., newsletter)
To exercise any right, email [email protected]. We will respond without undue delay and normally within one month, subject to the extensions permitted by applicable law.
You also have the right to lodge a complaint with the Berlin data protection supervisory authority:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstr. 219, 10969 Berlin datenschutz-berlin.de
8. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the right to know what personal information we collect, request its deletion or correction, opt out of sale or sharing (we do not sell or share personal information), and not be discriminated against for exercising these rights.
To exercise your rights, email [email protected].
9. International Data Transfers
Some service providers process data outside the EEA. Where required, we use an applicable transfer mechanism and contractual safeguards, which may include Standard Contractual Clauses and data processing agreements. Contact us for the current safeguards applicable to a particular service.
10. Children’s Privacy
The Service is not directed at children under 16 (the GDPR minimum in Germany). We do not knowingly collect personal data from children. If you believe a child has submitted data to us, contact [email protected] and we will delete it promptly.
11. Changes to This Policy
We will update this page when our data practices change. Material changes will be noted at the top of this page and communicated to newsletter subscribers by email. The “Last Updated” date reflects the most recent revision. Continued use of the Service after changes constitutes acceptance.
12. Contact
DataDrivenAEC Berlin, Germany 📧 [email protected]
For GDPR complaints, you may also contact the Berliner Beauftragte für Datenschutz und Informationsfreiheit (see Section 7).