Legal
Data Handling
Last updated: 16 June 2026
This document explains how ProjectWorks.ai stores, processes, isolates, and deletes workspace data — including content you upload, AI-generated artifacts, and enterprise provisioning records. It complements our Privacy Policy and Security overview.
1. Data categories
Workspace and project data
- Project metadata, briefs, tenders, and uploaded source files (PDF, DOCX, etc.)
- Structured plans: WBS, schedules, budgets, resources, risks, deliverables
- Tasks, assignments, comments, and activity history
- Blueprint documents (charter, scope, governance, quality, procurement, and related types)
- Engine outputs: schedule baselines, budget line items, health scores, portfolio snapshots
Identity and organization data
- User profiles, roles, team membership, and workspace settings
- SSO attributes and SCIM provisioning records (enterprise)
- API keys and webhook configurations (where enabled)
Operational data
- Audit logs for governance actions (eligible plans)
- Usage metrics, error logs, and security events
- Billing and subscription records
2. Where data is processed
Primary application and database hosting use cloud infrastructure in regions selected by our providers. AI inference may occur in separate regions operated by AI subprocessors. Data location and transfer mechanisms for EEA/UK customers are described in our GDPR Information page.
3. AI processing flow
- You submit a brief, document, or prompt within an authenticated workspace.
- The application validates your access to the relevant project.
- Relevant content is sent to configured AI providers to generate the requested output (plan, document, insight, or action recommendation).
- Structured results are stored in your project and linked to delivery engines where applicable.
- Outputs remain in your workspace until you delete them or close your account.
We do not use your private workspace content to train public foundation models unless a feature explicitly states otherwise and you opt in.
4. Tenant isolation
- Production workspace data is scoped by user, organization, and project access controls
- Database row-level security enforces tenant boundaries on scoped tables
- Demo mode at /try/* uses in-browser sample data only — it never reads or writes production database records
- Service-role operations are limited to authenticated application logic, not end-user browsing
5. Engine synchronization
When you generate or update certain document types, ProjectWorks may synchronize structured data into delivery engines (schedule, budget, resources, health, governance, portfolio, actions). This processing occurs within your project boundary and triggers recalculation of dependent scores and recommendations.
6. Retention and deletion
- Active accounts: data retained while the account and projects remain active
- Deleted projects: removed from active systems; may persist in encrypted backups for a limited period
- Closed accounts: workspace data scheduled for deletion after a grace period unless legal hold applies
- Audit logs: retained per plan features and enterprise DPA terms
Request account or data deletion at privacy@projectworks.ai.
7. Export
Where available, in-app export features allow download of plans and reports. Enterprise customers may request bulk export assistance during migration or offboarding.
8. Enterprise controls
- SSO and SCIM for centralized identity lifecycle
- Role-based access and optional audit logging
- Custom DPA, subprocessor notification, and security questionnaire on request
- Dedicated support channel for data handling inquiries
Contact legal@projectworks.ai for enterprise agreements.
9. Subprocessors
We engage subprocessors for infrastructure, authentication, payments, email, and AI. A current list is available to enterprise customers upon request. Material additions will be notified per contractual terms.