CivilQuants — Privacy Policy
Effective date: 2026-05-31
Version: v1.2 (twice-iterated cross-LLM review: v1.0 → v1.1 → v1.2; final round GPT-5.5 Thinking + Gemini 3 Flash 2026-05-17)
Last updated: 2026-05-22 (EU + UK Representative details substituted from DataRep documentation pack; see [[wiki/entities/datarep]])
Quick summary (this is non-binding; the detailed sections below are authoritative)
- Who we are: Ember Forge Pte Ltd (UEN 202617538C), Singapore-incorporated. We run CivilQuants.
- What we collect: your email + account info, payment details (handled by Stripe — we never see your card number), your project inputs and outputs (so we can deliver the Service), basic usage and technical data, and — only with your explicit consent — your marketing-tip preferences.
- Why: to deliver the Service you bought, to bill you, to keep the Service running and secure, and (with consent) to send you occasional product updates.
- Who we share with: the third-party service providers we use to run CivilQuants — Stripe, Resend, Clerk, Cloudflare, Sentry, PostHog, Google Ads (advertising-conversion measurement, only with Marketing consent), Fly.io — plus tax authorities (HMRC in the UK, IRAS in Singapore, the EU Non-Union OSS scheme via our member-state portal, ATO in Australia, IRD in New Zealand, CRA in Canada, LHDN in Malaysia) and our professional advisors (accountant + legal counsel) where required. Each commercial provider is bound by a Data Processing Agreement.
- International transfers: some of those processors are US-based or operate globally. We rely on Standard Contractual Clauses + their compliance frameworks.
- When you use the MCP server with your own LLM client (Claude Desktop, Cursor, ChatGPT, Gemini): data you send to that LLM client is handled by that LLM provider under its own terms. CivilQuants only receives the MCP requests actually sent to our server.
- Your rights: you can access, correct, export, or delete your data any time. Email
dpo@emberforge.sg. - Marketing: opt-in only. Easy unsubscribe in every email.
The detailed sections below are the authoritative privacy notice; this summary is a non-binding plain-English overview.
1. Who we are and our role under data-protection law
This privacy policy is published by Ember Forge Pte Ltd ("we", "us", "our"), a private limited company incorporated in Singapore (Unique Entity Number 202617538C), with its registered office at 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051.
We operate the CivilQuants quantity take-off and parametric estimating service at civilquants.com and its associated surfaces (REST API, MCP server, CLI, Python SDK).
1.1 Our role — controller vs processor
The role we play under data-protection law depends on the type of personal data we are processing:
- Ember Forge Pte Ltd is the data controller for personal data we process in our own right — account data, billing data, your direct communications with us, security and audit logs, the computational audit log of paid renders (see §6), our marketing communications to you, and any aggregate analytics derived from your own use of the Service. This is most of what is covered by this Privacy Policy.
- Ember Forge Pte Ltd acts as a data processor / service provider for personal data that a business customer (typically a Studio or Practice account) uploads as part of their project inputs where that data contains personal data about third parties (for example: employee names in a project file, contractor names in a tender pack, or personal-data references inside a customer-supplied document). In that processing relationship, the business customer is the controller and we process that data only on the customer's documented instructions set out in our Customer Data Processing Addendum (Customer DPA) — including any documented instruction the customer gives us to irreversibly anonymise that data for the purpose of producing aggregate Service-improvement statistics (see §2.3). We do not determine our own purposes or means for processing third-party personal data uploaded by a business customer. Customer DPA available on request to
dpo@emberforge.sg; standard template available pre-launch.
1.2 Data Protection Officer
Our Data Protection Officer (DPO) is the person primarily responsible for our data protection compliance:
- Name: Dave Irvine, Director, Ember Forge Pte Ltd
- Email:
dpo@emberforge.sg - Postal address: as registered office above
Dave Irvine is registered with the Singapore Personal Data Protection Commission (PDPC) as Ember Forge Pte Ltd's data protection officer.
You can contact the DPO directly for any data protection question, request, or complaint.
1.3 EU and UK Data Protection Representatives
Because Ember Forge Pte Ltd is established outside the European Union and the United Kingdom but offers the Service to data subjects in the EU and the UK, we have appointed Data Protection Representatives in both regions under Article 27 of the UK GDPR and Article 27 of the EU GDPR. Data subjects in the EU or the UK may contact the relevant Representative in their region as an alternative to contacting our Data Protection Officer in Singapore.
Our appointed Representative in both regions is Data Protection Representative Limited (trading as DataRep) ("DataRep"), a company registered in the Republic of Ireland.
EU Representative (for data subjects in the European Union / EEA):
- Entity: Data Protection Representative Limited (trading as DataRep)
- Postal address: The Cube, Monahan Road, Cork T12 H1XY, Ireland
- Email: datarequest@datarep.com (please include "CivilQuants" in the subject line)
- Web form: www.datarep.com/data-request
- DataRep also maintains additional local contact addresses across all 27 EU/EEA member states. For your local-country contact address, see DataRep's published contact-locations document or contact us via the email/web form above and we will route accordingly.
UK Representative (for data subjects in the United Kingdom):
- Entity: Data Protection Representative Limited (trading as DataRep)
- Postal address: 107-111 Fleet Street, London EC4A 2AB, United Kingdom
- Email: datarequest@datarep.com (please include "CivilQuants" in the subject line)
- Web form: www.datarep.com/data-request
You may contact the relevant Representative for any matter relating to the processing of your personal data under the UK GDPR or EU GDPR, including data-subject rights requests, complaints, and requests for information. The Representative will, on receipt of your contact, route the matter to our DPO and ensure a response within the statutory timelines. You may also contact us directly via dpo@emberforge.sg, or your local supervisory authority (see §8).
The appointment of a Representative does not change the controller / processor relationship as set out in §1.1; we remain the controller (or where applicable, processor) of the personal data described in this Privacy Policy.
1.4 Use of the Service with your own LLM client (MCP)
CivilQuants is available via the Model Context Protocol (MCP) at api.civilquants.com/mcp. This lets you call CivilQuants from your own LLM client — Claude Desktop, Cursor, ChatGPT, Gemini, or another supported MCP client. It is important to understand how data flows in this mode:
- Data you send to your LLM client (project parameters you type into a chat, files you attach to a conversation, follow-up questions you ask) is handled by your LLM client's provider (Anthropic, OpenAI, Google, etc.) under that provider's own terms and privacy policy. CivilQuants does not see that data unless and until your LLM client makes an MCP call to our server with that data attached.
- CivilQuants only receives the actual MCP requests sent to our server: the structured tool-call arguments (project parameters), the resource-read URIs, and the authentication headers. We do not see your wider conversation, your other files, or the contents of your LLM client's chat history.
- When CivilQuants serves skill prompts (paid-tier feature, see ToS §8.5) via MCP, the skill prompt text passes through your LLM client's conversation context as part of normal MCP operation. Your LLM provider may retain that prompt in conversation history or include it in data exports per its own data-retention policy. CivilQuants has no technical control over that retention.
If you care about which provider sees what, choose your LLM client (and configure its privacy settings) accordingly. CivilQuants' direct privacy responsibilities cover the data you send to our servers; we cannot extend those responsibilities to data handled solely inside your chosen LLM client.
2. What personal data we collect, and why
2.1 Account data (lawful basis: contract)
When you create an account, we collect:
- Your email address
- Authentication credentials (password hash, or — if you use passwordless login — magic-link tokens)
- Optional profile information you choose to provide (name, organisation, role)
We use this to identify you, secure your account, and deliver the Service.
2.2 Payment data (lawful basis: contract; payment processor: Stripe)
When you purchase any tier (module credits, 7-day pass, or subscription), Stripe, through its Managed Payments (merchant-of-record) service, is the seller of record (see Terms of Service §6.3). Stripe collects and processes your payment information directly and accounts for applicable taxes. We never see your full card number, CVV, or other sensitive cardholder data. Stripe shares with us only:
- A masked card identifier (last 4 digits, brand, expiry) so we can show your default payment method in your account
- Your billing address and country (used for tax determination and to populate your invoice)
- Your VAT/GST number, where you provide one
- Transaction outcomes (success / failure / refund / chargeback)
Stripe's data-protection role is mixed. Stripe acts as our processor / service provider for the payment-processing services we use it for (charging your card, recording the transaction). Stripe also acts as an independent controller in its own right for some processing it performs for its own purposes — including fraud prevention and detection, compliance with payment-network rules, anti-money-laundering checks, and Stripe's own legal-obligation processing. Stripe's own privacy notice describes its independent-controller processing: https://stripe.com/privacy. Stripe Tax additionally calculates and reports applicable indirect taxes in real time at checkout.
2.3 Project inputs and outputs (lawful basis: contract — for Service delivery; see anonymisation note for aggregate analytics)
The whole point of CivilQuants is to take your project parameters in, compute, and return outputs. For Service delivery, we process the following on a contract basis (UK/EU GDPR Art 6(1)(b)):
- Project parameters you input (geometries, dimensions, material specifications, depths, etc.)
- The Bills of Quantities, drawings, Excel workbooks, and other deliverables we generate from those inputs
- Project metadata (name, revision, date)
- Any file metadata associated with outputs delivered through the Service
We use this data only to deliver the Service to you. We do not:
- Sell your project data to third parties
- Use your project data to train any machine-learning model in a way that would allow your specific project content to be recovered or attributed
- Share your project data with anyone other than the processors strictly required to deliver the Service (see §4)
Aggregate, anonymised statistics — how this works and on what basis. We may produce irreversibly anonymised aggregate statistics from project data — for example, "the average number of assemblies per project" or "the most common drainage standard chosen" — for product analytics and public communication. The lawful basis for the anonymisation step itself depends on whose personal data is being anonymised:
- Where the project data is your own personal data (you uploaded it as an individual customer; the personal data in the file relates to you), the anonymisation step is performed on the basis of our legitimate interest in improving the Service and understanding how it is used (UK/EU GDPR Art 6(1)(f)). We have assessed this against your rights and freedoms and consider the interests balanced: the data is irreversibly anonymised before any analytics or public use; no individual customer or project is identifiable in the output; the processing supports product quality which benefits all customers. You may object under §8 ("Objection" right); on receipt of objection we will exclude your data from future aggregations and replace prior aggregate snapshots at the next scheduled rebuild.
- Where the project data contains personal data about third parties (typically uploaded by a business customer — see §1.1), we act as a processor and may only anonymise that data on the documented instruction of the business customer (controller) set out in our Customer DPA. We do not anonymise third-party personal data on our own initiative or on the basis of our own legitimate interest. Where the Customer DPA does not authorise anonymisation, that data flows only through Service-delivery processing and is not used in any aggregate analytics dataset.
After irreversible anonymisation, the resulting aggregate statistics are no longer personal data under UK/EU GDPR, PDPA, or equivalent regimes, and may be used by us for ongoing Service-improvement and public communication without further restriction under data-protection law.
2.4 Service usage and technical data (lawful basis: legitimate interests)
When you use the Service, we automatically collect:
- IP address and approximate location (country, city)
- Browser type and version, operating system
- Pages and features used, the time and duration of those interactions
- Performance and error data (so we can fix bugs)
- Audit log of significant actions (login, payment, output generation, account changes)
We use this for:
- Securing the Service against fraud and abuse
- Ensuring the Service works correctly and is performant
- Understanding how the Service is used, in aggregate, to improve it
- Compliance with our own legal obligations (e.g. tax records)
Some of this data is collected via cookies and similar technologies. See our Cookie Policy for the full list.
2.5 Marketing preferences (lawful basis: consent)
If — and only if — you check the marketing opt-in box at signup, at PPC email-capture, or in your account settings, we will add you to one of our Resend marketing audiences and send you occasional product updates and QS productivity tips.
You can withdraw consent at any time:
- Click the unsubscribe link in any marketing email
- Update your preferences in your account settings → Privacy
- Email
dpo@emberforge.sg
Withdrawing marketing consent does not affect the lawfulness of any processing we did before withdrawal, and it does not stop us sending you operational emails (receipts, security notifications, billing) — those are required to deliver the Service.
2.6 Support correspondence (lawful basis: contract + legitimate interests)
If you contact us for support (support@civilquants.com), we will keep a record of your messages and our replies, including any personal data you choose to include. We use this to provide support and to improve our help content.
2.7 Cookies and similar technologies
Cookies and similar storage technologies are used per your choice in our cookie banner. Essential / strictly-necessary storage is always on (the site needs it). We do not use marketing cookies in v1. Optional product analytics fires only with your explicit consent. Full details in our Cookie Policy.
3. Lawful basis for processing (UK GDPR Art 6 / EU GDPR Art 6 / PDPA equivalents)
| Activity | Lawful basis | Notes |
|---|---|---|
| Creating and maintaining your account | Contract (Art 6(1)(b)) | Necessary to deliver the Service to you |
| Processing your payment | Contract (Art 6(1)(b)) — for our processing | Stripe acts as our processor for payment processing and as an independent controller for its own fraud / compliance / tax processing (see §2.2) |
| Generating and delivering Service outputs from your inputs | Contract (Art 6(1)(b)) | The Service we have agreed to provide |
| Anonymisation of project data into aggregate statistics — where the data is your own personal data | Legitimate interests (Art 6(1)(f)) | See §2.3; you may object |
| Anonymisation of project data into aggregate statistics — where the data contains third-party personal data uploaded by a business customer | Documented controller instruction under our Customer DPA (Art 28(3)(a)) | We act as processor; see §1.1 and §2.3 |
| Use of aggregate statistics that have been irreversibly anonymised | Out of scope of UK/EU GDPR (no longer personal data) | See §2.3 |
| Strictly-essential operational telemetry (uptime, error detection, security logging) | Legitimate interests (Art 6(1)(f)) | Necessary to keep the Service running, secure, and accountable; minimised data scope |
| Optional product analytics (PostHog) — page views, feature usage, funnels | Consent (Art 6(1)(a)) — for non-essential analytics cookies / similar storage | Per ePrivacy / PECR; consent collected via cookie banner; opt-out at any time |
| Advertising-conversion measurement (Google Ads) — confirming whether an ad click led to a purchase | Consent (Art 6(1)(a)) — for marketing cookies / similar storage | Per ePrivacy / PECR; collected via the separate Marketing category of the cookie banner; opt-out at any time |
| Sending operational emails (receipts, security alerts, billing notifications) | Contract (Art 6(1)(b)) + legitimate interests (Art 6(1)(f)) | Necessary to deliver the Service and to keep your account secure |
| Sending marketing communications | Consent (Art 6(1)(a)) | Withdrawable at any time; one-click unsubscribe in every email |
| Fraud prevention, security monitoring, abuse handling | Legitimate interests (Art 6(1)(f)) | Necessary to protect the Service and other users |
| Tax and accounting records | Legal obligation (Art 6(1)(c)) | UK HMRC, Singapore IRAS, EU OSS, and equivalents — retention periods in §6 |
| Defending or enforcing legal claims | Legitimate interests (Art 6(1)(f)) | Where reasonably necessary |
| Responding to data subject requests | Legal obligation (Art 6(1)(c)) | Statutory obligation under UK/EU GDPR, PDPA, etc. |
4. Who we share your data with
We share data only with the third-party service providers strictly required to deliver and run CivilQuants, plus tax authorities and professional advisors where required. Each commercial provider is bound by a Data Processing Agreement (DPA) restricting their use of your data to providing services to us, except where a provider acts as an independent controller in its own right (see Stripe note in §2.2).
| Provider | What they process | Region of processing | Transfer mechanism (for UK/EU personal data) | Role | Reason |
|---|---|---|---|---|---|
| Stripe | Payment data, billing address, VAT number, transaction outcomes | Global (Stripe has UK/EU/SG entities; specific routing depends on Stripe's configuration) | Stripe's own SCC framework + adequacy where available | Mixed: processor for the payments we engage them to process; independent controller for fraud/compliance/tax processing they perform for their own purposes (see §2.2) | Payment processing, tax calculation/collection, fraud screening |
| Resend | Email address, send/open/click events, unsubscribe state | US (EU region pending GA) | UK ICO IDTA + EU SCCs + supplementary measures | Processor | Sending transactional and (with consent) marketing email |
| Clerk | Email address, password hash, auth session, MFA factors | US | UK ICO IDTA + EU SCCs + supplementary measures | Processor | Authentication |
| Cloudflare | IP address, request metadata, edge logs (short retention) | Global edge network; data processed at the edge closest to user | UK ICO IDTA + EU SCCs (for any data egress to US backbones) | Processor | DNS, CDN, DDoS protection, R2 object storage |
| Sentry | Error events, stack traces, user identifier (hashed) | EU region (we configure EU; verified at deployment) | None required for EU-to-EU; SCC fallback if any sub-processor is outside EU | Processor | Error monitoring |
| PostHog | Usage events, page views, session metadata, IP, anonymised user identifier | EU region (we configure EU; verified at deployment) | None required for EU-to-UK and EU-to-EU; SCC fallback if any sub-processor is outside EU | Processor | Product analytics (consent-gated) |
| Google Ads (Google Ireland Limited) | Conversion event, advertising click identifier, IP — only for users who opt into Marketing consent | Global (Google has EU/US entities; routing depends on Google's configuration) | Google's own SCC framework + adequacy where available | Processor | Advertising-conversion measurement (Marketing-consent-gated; fires only on post-purchase confirmation pages) |
| Fly.io | All application + database data hosted on our compute and Postgres | London (LHR) region for v1 | None required for LHR-to-UK and LHR-to-EU; SCC fallback if Fly's US control-plane processes any data | Processor | Hosting infrastructure |
| HMRC (UK), IRAS (SG), EU Non-Union OSS scheme via to be confirmed at EU OSS registration; see [[wiki/spin-outs/civilquants-privacy-policy-v1]] for the current version (member state of identification — Ember Forge is a non-EU established supplier registering under the Non-Union OSS scheme per Council Directive 2006/112/EC Title XII Chapter 6 Section 2), ATO (AU), IRD (NZ), CRA (CA), LHDN (MY) | Tax records as required by applicable law | Respective national tax authorities; for the Non-Union OSS scheme, the chosen member-state portal acts as the single point of identification and reporting for EU consumer indirect tax | Statutory legal obligation (no transfer mechanism needed) | Independent controllers acting under statutory authority | Tax compliance |
| Our accountant | Books and records as required for accounting and tax | Singapore | Statutory confidentiality + professional duty | Processor | Professional accounting services |
| Our legal counsel | Contracts, correspondence as required for legal advice | Singapore + UK | Legal privilege + professional duty | Independent controllers acting under professional duty | Professional legal services |
We do not sell, rent, or trade your personal data to anyone.
We may disclose your data if required by law, in response to a valid legal request (subpoena, court order, government request), or to protect rights, property, or safety where reasonably necessary. Where lawful, we will give you prompt notice and an opportunity to seek a protective order.
If we are involved in a corporate transaction (merger, acquisition, asset sale), your data may be transferred as part of that transaction — but the recipient remains bound by this Privacy Policy or by a notice giving you a chance to opt out before any materially different processing.
Sub-processor change notice. Where we engage a new sub-processor or change the role of an existing one, we will update this table at the same time the change becomes effective. Material changes affecting customers (for example, a change in region of processing for a primary sub-processor) will be notified to active accounts by email at least 30 days in advance where reasonably practicable.
Customer DPA. Business customers (Studio / Practice tiers; or any customer whose project data may contain personal data about third parties — for example, employee names on a project file) may request our Customer Data Processing Addendum to govern the processor-relationship the customer-as-controller has with us. Email dpo@emberforge.sg.
5. International transfers
Ember Forge Pte Ltd is in Singapore. Some of our processors are in the United States or operate globally. The transfer mechanisms we rely on depend on the country of residence of the data subject and the country of processing of the recipient.
5.1 UK personal data transferred outside the UK
For personal data of UK residents transferred outside the UK, we rely on:
- UK Adequacy: transfers to recipients in countries the UK has determined provide adequate protection (the UK adequacy list is broadly aligned with the EU adequacy list and includes, among others, the EEA and several non-EU jurisdictions).
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs: for transfers to non-adequate countries (including the United States, where applicable).
- Supplementary measures (encryption in transit, encryption at rest, access controls, transfer impact assessments) where required.
5.2 EU/EEA personal data transferred outside the EEA
For personal data of EU/EEA residents, we rely on:
- EU Adequacy decisions for recipients in countries the European Commission has determined provide adequate protection.
- EU Standard Contractual Clauses (Module 2: Controller-to-Processor; Module 3: Processor-to-Processor) for transfers to non-adequate countries.
- Supplementary measures as above.
5.3 Singapore personal data transfers
Singapore has its own data-protection regime under the Personal Data Protection Act 2012 (PDPA). Singapore is not an EU adequacy country. For personal data subject to the PDPA transferred outside Singapore, we comply with PDPA Section 26 (transfer limitation) by taking reasonable steps to ensure the receiving recipient is bound by legally enforceable obligations to provide a standard of protection at least comparable to the PDPA. For UK/EU personal data transferred to Singapore or onward to other jurisdictions, we rely on the UK IDTA / EU SCCs and supplementary measures as set out above.
5.4 Country-specific notes
- Australia (APP 8 — Cross-border disclosure of personal information). Where we disclose personal information about Australian residents to overseas recipients, we take reasonable steps to ensure that recipient does not breach the Australian Privacy Principles. For our US-based processors, we rely on contractual arrangements (DPAs incorporating relevant data-protection obligations). Australian residents may complain to the Office of the Australian Information Commissioner (OAIC) if they believe their personal information has been mishandled in connection with a cross-border disclosure.
- New Zealand (Privacy Act 2020, IPP 12 — Disclosure outside New Zealand). Where we disclose personal information about New Zealand residents to overseas recipients, we take reasonable steps to ensure the recipient is required to protect the information in a way that, overall, provides comparable safeguards to those in the Privacy Act 2020. New Zealand residents may complain to the Office of the Privacy Commissioner if they believe their personal information has been mishandled.
- Canada (PIPEDA — Accountability principle). Where personal information about Canadian residents is transferred to a third party for processing (including outside Canada), we remain accountable for the information and require the recipient to provide a comparable level of protection through contractual or other means. Canadian residents may complain to the Office of the Privacy Commissioner of Canada (OPC). Quebec residents have additional rights under the Loi 25 (formerly Bill 64) modernising Quebec's privacy regime.
- Malaysia (PDPA 2010, Section 129 — Transfer of personal data outside Malaysia). Where personal data about Malaysian residents is transferred to a place outside Malaysia, we comply with PDPA Section 129 requirements, either by relying on a transfer-place gazetted by the Minister or by satisfying one of the statutory exceptions (data subject consent, necessity for contract performance, etc.). Malaysian residents may complain to the Jabatan Perlindungan Data Peribadi (JPDP).
You can request a copy of the relevant transfer mechanism documentation (SCCs, IDTA, etc.) by emailing dpo@emberforge.sg.
6. How long we keep your data
| Category | Retention period |
|---|---|
| Active account data | For as long as your account is active |
| Account data after closure | 90 days from closure (in case you wish to reopen), then deleted |
| Project inputs and outputs you save | For as long as your account is active; deleted with your account 90 days after closure (or earlier on your request) |
| Payment and tax records | 7 years from the relevant tax year, per HMRC, IRAS, and EU member-state requirements |
| Security and access audit logs (login events, admin actions, security-relevant events) | 24 months |
| Computational audit log of paid renders (parameters submitted, output hash, engine version, software version, warranty-policy version in force, warranty-acknowledgment timestamp, account/API-token identity, render timestamp — see ToS §8.4) | 7 years from render date. Retained on the basis of legitimate interest in the establishment, exercise, or defence of legal claims (UK/EU GDPR Art 6(1)(f) and the corresponding retention exemption from the right of erasure under Art 17(3)(e); equivalent provisions in Singapore PDPA 2012, Canada PIPEDA, Australia APP 3 & 12, New Zealand Privacy Act 2020 IPP 9, Malaysia PDPA 2010). This retention is necessary so that we (and you) can reconstruct any paid output for the duration of the typical commercial limitation period for construction-sector disputes. See §8 for how this interacts with the right of erasure. |
| Analytics data (consent-gated) | 12 months at user-identifiable granularity; aggregated, anonymised retention thereafter |
| Marketing audience records (when you have consented) | Until you unsubscribe, plus 90 days of suppression-list retention to honour the unsubscribe |
| Support correspondence | 24 months from last contact |
| Anonymised, aggregated statistics | Indefinitely (no longer personal data) |
You can request earlier deletion of any data not subject to a legal retention requirement (see §8). For data we are legally required to retain (tax records etc.), we will retain only what is necessary and delete any non-required associated data.
7. How we keep your data secure
We use industry-standard technical and organisational measures, including:
- TLS 1.3 encryption for all data in transit
- Encryption at rest for our primary database (Fly Postgres) and object storage (Cloudflare R2)
- Access controls based on the principle of least privilege; production access is restricted to named individuals (currently Dave Irvine as DPO + the engineering function)
- Multi-factor authentication required on all production-access accounts
- Audit logging of significant production actions
- Regular dependency scanning and security patching
- Backups encrypted and rotated
- Incident response playbook with notification timelines that meet UK GDPR (≤72 hours to ICO + affected individuals where likely high-risk), EU GDPR (≤72 hours to lead supervisory authority), and PDPA (≤72 hours to PDPC for "notifiable" breaches)
No system is completely secure, and we cannot guarantee absolute security. If you suspect your account has been compromised, contact us immediately at support@civilquants.com.
8. Your rights
You have the rights set out below under applicable data-protection law. Some rights are framed differently in different regimes; we provide each right to you to the extent the applicable statutory regime requires it. Where you would benefit from a more generous right under one of the regimes that applies to you, that regime's right applies.
| Right | What it means | How to exercise |
|---|---|---|
| Access | Get a copy of the personal data we hold about you | Email dpo@emberforge.sg. A self-service "Download my data" function in your account settings will become available post-launch (target Phase 3.6); until then we respond manually within the statutory 30-day window |
| Rectification / correction | Correct inaccurate or incomplete data | Edit basic profile information in your account settings, or email dpo@emberforge.sg for any field that's not user-editable |
| Erasure / deletion ("right to be forgotten" under UK/EU GDPR) | Request deletion of your data | Email dpo@emberforge.sg. A self-service "Delete my account" function will become available post-launch (target Phase 3.6); until then we respond manually within the statutory window. Some data may be retained for legal compliance (see §6) — specifically: (a) payment and tax records (7 years; legal obligation under Art 6(1)(c) / Art 17(3)(b)), and (b) the computational audit log of paid renders (7 years from render date; retained under Art 17(3)(e) for the establishment, exercise, or defence of legal claims — this allows us to reproduce any paid output for the duration of the typical commercial limitation period and is necessary to protect both you and us in any future dispute about a calculation). On erasure of your account, your name, email, billing information, and other personally identifying account data are removed from the audit log within 90 days; the technical render record (parameters, hash, engine version, timestamps) is retained for the full 7-year window in a form that is not linked to your identifying personal data outside the period necessary to substantiate the legal-claims basis. |
| Restriction of processing | Ask us to stop processing in certain circumstances | Email dpo@emberforge.sg |
| Portability | Receive your data in a machine-readable format and transfer it to another controller | Email dpo@emberforge.sg — output is JSON + CSV |
| Objection | Object to processing based on legitimate interests, or to direct marketing | Click unsubscribe in marketing emails (instant); for other objections, email dpo@emberforge.sg |
| Withdraw consent | Where processing is based on consent, withdraw it | Account settings (granular toggles) or email dpo@emberforge.sg |
| Not be subject to solely automated decision-making producing legal or similarly significant effects (UK/EU GDPR Art 22) | See §8.1 below | n/a — see explanatory text |
| Lodge a complaint with a supervisory authority | If you think we've handled your data wrongly | UK: ICO at https://ico.org.uk · EU: your lead supervisory authority (https://edpb.europa.eu/about-edpb/about-edpb/members_en) · Singapore: PDPC at https://www.pdpc.gov.sg · Australia: OAIC at https://www.oaic.gov.au · New Zealand: Privacy Commissioner at https://www.privacy.org.nz · Canada: OPC at https://www.priv.gc.ca · Malaysia: JPDP at https://www.pdp.gov.my |
We will respond to any valid request within 30 days (extendable by a further 60 days for complex requests, with notice). Where the request is manifestly unfounded, excessive, or repeated, we may charge a reasonable fee or refuse to act, with reasons.
EU and UK data subjects — alternative local contact. If you are a data subject in the European Union / EEA or the United Kingdom and would prefer to exercise your rights via a contact within your region rather than emailing our DPO in Singapore, you may contact our appointed Representative in your region — see §1.3 above for the relevant Representative's address and email. The Representative will route your request to our DPO and ensure a response within the same statutory timelines.
8.1 Automated decision-making and AI
The CivilQuants engine is deterministic parametric computation, not artificial intelligence in the machine-learning sense. When you input project parameters, the engine produces outputs through deterministic mathematical and rule-based computation. The engine does not "learn" from your inputs; the same parameters always produce the same outputs.
We do not currently make decisions about you, as a data subject, based solely on automated processing that produce legal effects or similarly significant effects concerning you (UK/EU GDPR Article 22). Specifically:
- The engine outputs are draft computational results based on the project parameters you supply. You (or your professional advisor) make the commercial or technical decision based on the output. The Service does not score, classify, profile, or take decisions about you as a data subject.
- We do not use automated decision-making in account approvals, pricing, fraud determinations, or any decision producing legal effects or similarly significant effects on you.
EU AI Act (Regulation 2024/1689) classification note. We believe the deterministic measurement engine itself is unlikely to be an AI system within the EU AI Act definition, because it does not infer outputs using an AI model — outputs are produced by deterministic mathematical and rule-based computation against the parameters you supply. However, MCP-connected LLM clients (your Claude Desktop, ChatGPT, Cursor, Gemini, etc.) that you choose to use to call the Service may themselves be AI systems within the AI Act definition, operated by their respective providers or by you as the deploying user; any AI Act compliance attaching to that client is the responsibility of its provider or its deployer, not of CivilQuants. We monitor the EU AI Act implementing acts, the European Commission's guidance on the AI-system definition, and any clarifications relevant to MCP-served deterministic services, and will update this classification if the regulatory position changes.
If we add LLM-mediated features in future (for example, a natural-language project-setup assistant), this section will be updated and you will be notified of any material change to automated decision-making processing per §12.
9. Children
CivilQuants is a professional tool not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data, contact dpo@emberforge.sg and we will delete it.
10. Marketing communications
We send marketing emails only when you have opted in:
- At signup (separate, unchecked-by-default checkbox)
- At PPC email capture (separate, unchecked-by-default checkbox)
- Via the newsletter sign-up form on the landing page (double opt-in: confirmation email after signup)
- Via account settings at any time
Every marketing email includes a one-click unsubscribe link compliant with RFC 8058. Unsubscribing takes effect immediately for new sends; emails already in flight may briefly continue to deliver.
We never sell your email address or share it with marketing third parties.
11. Cookies
See our Cookie Policy for full details on the cookies and similar storage technologies we use, why, and how to manage them.
In summary: essential / strictly-necessary storage is always on (the site needs it). Optional product analytics (PostHog) and advertising-conversion measurement (Google Ads) each fire only with your explicit consent, given via separate categories of our cookie banner — accepting Analytics does not enable Marketing, and vice versa. See the Cookie Policy for the full inventory.
12. Updates to this Privacy Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top records the most recent change. For material changes:
- We will notify active users by email at least 30 days before the change takes effect
- The previous version will remain accessible at
civilquants.com/legal/privacy/archivefor historical reference - Continued use of the Service after the effective date constitutes acceptance
13. Contact
For any privacy question, request, or complaint:
- DPO:
dpo@emberforge.sg - Postal address: Ember Forge Pte Ltd, 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051
You can also contact your local supervisory authority directly (see §8).