Last updated 1 July 2026. In this document, Projexio, “we”, “us” and “our” mean the provider of the Projexio service, and “you” means the customer or visitor.
1. Who this notice covers
This notice explains how we handle personal data when you visit this website, when you use the Projexio service, and when you contact us. It applies wherever you are located.
There are two distinct relationships to keep separate, because your rights differ between them.
- Account data: information about you as a customer, prospective customer or website visitor. For this, we are the data controller and this notice governs our handling of it.
- Project content: the tasks, files, comments, time entries and personal data your team and your clients put into a workspace. For this we act as a processor on your instructions, and our Data Processing Addendum governs it rather than this notice.
If you are an employee or client of one of our customers and you want to exercise rights over project content held in their workspace, contact that customer directly. We will assist them, but we cannot act on their data without their instruction.
2. What we collect and where it comes from
We collect only what we need to run the service, bill for it and support you. We do not buy personal data from brokers and we do not enrich your record from third-party datasets.
Information you give us directly:
- Account details: name, work email address, password (stored only as a hash), and optionally a display picture and job title.
- Workspace details: workspace name, your role, and the region you select for hosting.
- Billing details: billing contact, billing address, tax registration number where you supply one, and a payment token from our payment processor. We never receive or store full card numbers.
- Correspondence: the content of support tickets, sales enquiries and any messages you send us.
Information generated by your use of the service:
- Authentication and security events: sign-in times, IP address, and changes to permissions or sharing settings.
- Product usage: which features are used and how often, recorded pseudonymously and excluding the content of your projects.
- Technical diagnostics: browser and device type, error reports and performance traces.
Information from third parties:
- Identity confirmation from your single sign-on provider, if your organisation uses SAML.
- Payment and subscription status from our payment processor.
- Metadata from a connected integration where you have authorised the connection, limited to what that integration requires.
3. Why we use it, and our legal basis
Where the GDPR or UK GDPR applies, the relevant legal basis is given in brackets. Where the PDPO or PDPA applies, we collect for the purposes described below and no other purpose without telling you first.
- To provide the service, including creating workspaces, authenticating you and enforcing permissions (performance of a contract).
- To bill you and keep accounting records (performance of a contract, and compliance with a legal obligation for retention).
- To provide support and respond to your enquiries (performance of a contract, or legitimate interests where you are not yet a customer).
- To keep the service secure, investigate abuse and prevent fraud (legitimate interests, and compliance with a legal obligation).
- To understand which features are useful so we can improve the product (legitimate interests, using pseudonymous aggregate data).
- To send service and security notices you cannot opt out of while holding an account, such as breach notifications or material changes to terms (performance of a contract, and legal obligation).
- To send product update emails, which are optional and which you can unsubscribe from at any time (consent).
We do not use your data for automated decision-making that produces legal effects, and we do not profile you for advertising.
4. We do not train models on your content
Your project content is not used to train machine learning models, ours or anyone else's. It is not sold, rented or shared with advertisers, data brokers or any other customer.
Where a specific feature needs to send content to a third-party processor in order to function, that processor is named on our sub-processor list, is contractually barred from using your content for its own purposes, and is barred from retaining it beyond what the feature requires.
6. International transfers
We operate across Asia-Pacific, the Americas and other regions, so personal data may be transferred across borders. Your workspace's primary hosting region is one you select at creation, from the United States, Singapore or Hong Kong SAR.
Where a transfer leaves a jurisdiction that restricts onward transfer, we rely on an appropriate safeguard: standard contractual clauses approved by the relevant authority, an adequacy decision where one exists, or your explicit consent where neither applies. The specific mechanisms for each sub-processor are set out in our Data Processing Addendum.
Support and engineering personnel may access production data only where necessary to resolve an issue you have raised, under access that is logged and time-limited.
7. How long we keep it
We keep personal data only as long as we need it for the purpose it was collected for, then delete or irreversibly anonymise it.
- Account and workspace data: for the life of the account. After cancellation the workspace becomes read-only for 90 days so you can export, then is scheduled for irreversible deletion.
- Project content: deleted with the workspace, subject to the same 90-day export window. Individual items you delete are removed from backups within 35 days.
- Billing and accounting records: retained for seven years after the transaction, because tax law in our operating jurisdictions requires it.
- Support correspondence: three years from the last message, so we can understand the history of a recurring issue.
- Security and audit logs: as set out on the security page, ranging from 90 days to configurable retention depending on plan.
- Marketing consent records: for as long as the consent stands, plus three years after withdrawal so we can evidence that we honoured it.
8. Your rights, and how to use them
Depending on where you are, you have some or all of the following rights over personal data we hold as controller.
- Access: ask what we hold about you and receive a copy.
- Correction: have inaccurate data corrected.
- Deletion: have data erased where we have no continuing lawful basis to keep it.
- Portability: receive your data in a structured, machine-readable format.
- Restriction and objection: ask us to pause processing, or object where we rely on legitimate interests.
- Withdraw consent: for anything we do on the basis of consent, including product update emails.
- Opt out of sale or sharing: we do not sell or share personal information for advertising, so there is nothing to opt out of, but the right exists and we honour it.
- Non-discrimination: exercising any of these rights will not affect your service or pricing.
To exercise a right, email support@projexio.org from the address on your account. We respond within 30 days, and will tell you if we need longer and why. We may ask you to confirm your identity, but only to the extent necessary to avoid disclosing your data to someone else.
If you are unhappy with how we have handled a request, you may complain to your local supervisory authority. In Hong Kong SAR that is the Office of the Privacy Commissioner for Personal Data. In Singapore it is the Personal Data Protection Commission. In the European Economic Area or the United Kingdom it is your national data protection authority. We would prefer you raise it with us first at support@projexio.org so we have a chance to fix it.
9. How we protect it
Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest, including backups. Access to production systems requires multi-factor authentication, is limited to named personnel and is logged.
Our security page sets out the specific controls across encryption, authentication, authorisation, tenancy isolation, infrastructure, backups, audit logging, incident response and secure development. It also states plainly which third-party certifications we do not hold.
If a personal data breach affects you, we will notify you without undue delay and, where we are your processor, within 72 hours of confirming it, so you can meet your own notification obligations.
10. Children
Projexio is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, email support@projexio.org and we will delete it.
12. Changes to this notice
We update this notice when our practices change. The date at the top of the page always reflects the current version.
If a change materially reduces your rights or expands how we use your data, we will notify account owners by email at least 30 days before it takes effect, so you have time to object or to leave.
Questions about this document
Email support@projexio.org, or use the contact page.