Privacy Policy
How DatumPilot collects, uses, shares, and protects personal data, and the rights you have over it.
This Privacy Policy explains how DatumPilot (operated by IngeniVue Engineering Services Inc., “DatumPilot”, “we”, “us”) handles personal data when you use the DatumPilot application and website. DatumPilot is built for global availability. We aim to meet the baselines of Canadian privacy law (PIPEDA), United States state privacy law (California CCPA/CPRA), and the EU/UK General Data Protection Regulation (GDPR and UK GDPR) together with ePrivacy cookie/consent requirements.
Who we are and how to contact us
IngeniVue Engineering Services Inc. is the controller of personal data processed through DatumPilot. For privacy questions, to exercise your rights, or to reach the person accountable for the protection of personal information, contact us at support@datumpilot.com. EU and UK users may use the same address to reach us about EU/UK data-protection matters; we will identify a designated representative for these regions where one is required.
Data we collect
We collect the following categories of personal data:
- Account and authentication data — account identifiers managed through our authentication provider, Clerk (for example, your user ID and the email address you sign in with).
- Billing data — subscription and payment information handled through our payment processor, Stripe. We do not store full card numbers; Stripe processes payment details. We retain non-sensitive billing references (for example, hashed subscription identifiers, plan, interval, and billing period) to manage entitlements.
- Image extraction compatibility data — DatumPilot does not currently expose image upload in the Interpret UI. If a future approved issue re-enables image extraction, the uploaded image and derived GD&T text would be processed to produce a result. See “Image extraction and OpenAI processing” below.
- Interpretation and recommendation reports — the feature control frame, design context, and validated output needed to provide the service. Successful AI outputs are automatically saved as reports visible only to your account. You can rename or delete each report. Short-lived recovery records become eligible for deletion after 24 hours and are removed by the next successful scheduled cleanup run. Until then, an interrupted save can be retried without running the AI again.
- Product analytics — if you opt in, we use PostHog to understand product usage. Analytics are consent-gated and off by default; they are not collected until you opt in through the cookie banner, and analytics are not yet enabled in production.
- Operational logs— technical logs needed to run the service securely and reliably (for example, request metadata and error diagnostics). We keep sensitive content such as raw or normalized GD&T callouts out of logs.
Why we use your data and our legal bases
We use personal data to provide and secure the service, authenticate you, process subscriptions and payments, deliver GD&T interpretation and recommendation features, respond to support requests, and, where you consent, improve the product through analytics.
Where the GDPR/UK GDPR applies, our legal bases are: performance of a contract (providing the service and processing your requests), legitimate interests (securing, maintaining, and improving the service in ways that do not override your rights), consent (analytics and non-essential cookies), and legal obligation (for example, tax and accounting records related to billing).
Sub-processors and service providers
We share personal data with vetted service providers who process it on our behalf, under contract and only as needed to deliver DatumPilot:
- Clerk — authentication and account management.
- Stripe — subscription billing and payment processing.
- OpenAI— AI processing for GD&T interpretation and recommendations, plus retained image-extraction compatibility if an approved future issue re-enables it (see below).
- Supabase — managed database and storage.
- Upstash — rate limiting and caching.
- Vercel — application hosting and content delivery.
- PostHog — product analytics (consent-gated; not yet enabled).
- Resend — transactional email delivery.
A current list of sub-processors is available at /legal/subprocessors, including each provider’s purpose, processing region, and the categories of data it handles. We keep it up to date as providers are added, removed, or materially changed.
Image extraction and OpenAI processing
DatumPilot does not currently expose image upload in the Interpret UI. If a future approved issue re-enables image extraction, DatumPilot does not store raw uploaded image snippets after extraction, and we send OpenAI requests with store=false. OpenAI processes the image and text as a sub-processor and may retain content under its API abuse-monitoring controls for up to 30 days, subject to its policies. Separately, OpenAI may retain content longer where required by law or its safety processes, including its child-safety (CSAM) safety exception. We rely on OpenAI’s enterprise/API data handling commitments for this processing.
Because OpenAI operates internationally, this processing may involve transfers of personal data outside your country, including to the United States. Where required, such transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
International data transfers
We and our sub-processors may process personal data in countries other than your own, including Canada, the United States, and the EU/UK. Where required, we use appropriate transfer safeguards (such as Standard Contractual Clauses and the UK Addendum) to protect personal data when it crosses borders.
How long we keep data
We keep personal data only as long as needed for the purposes described here or as required by law. As general guidance:
- Account data — kept while your account is active and for up to 90 days after closure, after which it is deleted or anonymized.
- Billing and tax records — kept for up to 7 years to meet tax and accounting record- keeping obligations.
- Operational logs — kept for up to 90 days for security and reliability, then rotated out.
- Saved interpretation and recommendation reports — kept while your account is active or until you delete them. A deleted report becomes unavailable immediately, becomes eligible for permanent deletion after 30 days, and is removed by the next successful scheduled cleanup run.
- Image extraction compatibility snippets — not currently collected through the Interpret UI; if re-enabled, raw snippets are not stored by DatumPilot after extraction (see “Image extraction and OpenAI processing”).
Your rights
Depending on where you live, you have rights over your personal data:
- GDPR / UK GDPR (EU/UK): access, rectification, erasure, restriction, portability, and objection, plus the right to lodge a complaint with a supervisory authority.
- CCPA / CPRA (California): the right to know, to delete, to correct, and to opt out of sale/sharing of personal information. We do not sell personal information.
- PIPEDA (Canada): the right to access your personal information and to challenge its accuracy.
- Withdrawing consent: where we rely on your consent (for example, analytics), you can withdraw it at any time. Withdrawal does not affect processing already carried out.
You can manage and delete your account, and download a versioned export of applicable owner-linked DatumPilot records from in-app account controls. The export documents security-ledger and legally retained provider-financial exclusions. You can also exercise any of these rights by contacting support@datumpilot.com. We will respond within the timeframes required by applicable law.
Quebec residents (Law 25)
If you are in Quebec, Quebec’s Law 25 (the Act respecting the protection of personal information in the private sector) applies to your personal information. The person accountable for the protection of personal information at IngeniVue Engineering Services Inc. can be reached at support@datumpilot.com. In addition to the rights above, you may access and correct your personal information, withdraw consent, and request a copy of the computerized personal information you provided to us in a structured, commonly used technological format (data portability). We will also inform you, on request, of the personal information we hold and how it is used.
Automated processing
DatumPilot’s GD&T interpretation and recommendation features are decision-support tools. DatumPilot does not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Its outputs are intended to be reviewed by you and a qualified engineer, not applied automatically.
If there is a data breach
If a security incident affecting your personal information creates a real risk of significant harm, we will notify affected users and the appropriate authorities as required by applicable law, including PIPEDA, Quebec’s Law 25, and, where it applies, the GDPR/UK GDPR (which require notice to a supervisory authority, generally within 72 hours of becoming aware). We keep records of breaches as required.
Cookies
We use necessary cookies and similar storage to run DatumPilot and preserve preferences. Only analytics cookies require consent and remain off until you opt in. See our Cookie Policy for details and how to change your choices.
Changes to this policy
We may update this policy as the product and our legal obligations evolve. We will update the “Last updated” date above and, where appropriate, provide additional notice.