Scope
Who we are and when this policy applies
Oporo is a commercial software platform operated under the Built4.Construction name (referred to as “Oporo”, “we”, “us”, or “our”). The contracting legal entity, company number, and registered postal address must be confirmed before this draft is published. That legal entity will be the controller for Oporo's business, website, account, security, and service-administration processing. This policy explains how we handle personal data when you visit our public website, contact us, use the Oporo platform, or interact with us in a business capacity.
For account administration, service security, product operations, and our own sales relationships, Oporo acts as a controller. When a customer uploads project information or manages its workforce, consultants, suppliers, and other project contacts in Oporo, the customer normally acts as controller and Oporo acts as its processor. In that situation, the customer’s privacy notice and its agreement with Oporo also apply.
- Privacy contact: contact@oporo.net.
- We have not appointed a data protection officer because we do not currently consider the statutory appointment criteria to apply. We keep that assessment under review. No ICO registration number is currently stated in this draft.
- If your request concerns information entered by an Oporo customer, contact that customer first where practical. We will assist the customer with verified requests as required by our contract and data protection law.
- This policy applies to the Oporo public website, web portal, API, notifications, and related support and business communications.
Personal data
The information we process
The information we process depends on how you interact with Oporo. Customer-controlled files and free-text fields can contain personal data beyond the examples below. Please do not provide special category data, criminal offence data, or personal data that is not needed for the relevant project or request.
- Identity and account data: name, display name, work email address, internal and federated identity identifiers, username, password hash, account status, email-confirmation status, roles, permissions, project memberships, invitation details, and account creation dates.
- Professional and directory data: organisation, job or project role, company, postal or site address, telephone number, email address, point of contact, professional titles, membership status, and authorisation scopes.
- Sales and enquiry data: name, company, work email, role, project stage, enquiry or project details, and readiness-assessment answers, score, and outcome.
- Project and collaboration data: documents, drawings, images, BIM and IFC models, asset metadata, filenames, descriptions, comments, issues, assignments, approvals, review decisions, transmittals, notifications, and any names, contact details, signatures, images, or other personal data contained in them.
- Activity and audit data: uploads, downloads, changes, invitations, approvals, login or upload failures, who performed an action, timestamps, resource identifiers, before-and-after values, request and correlation identifiers, and notification history.
- Technical and security data: IP address used to create a refresh token, authentication tokens and session identifiers, browser or device request information, service logs, error details, and hosting and application telemetry.
- Preferences and device data: selected project, display and navigation preferences, user settings, notification groups, cached inbox messages, document comments or review state, and queued audit events stored in the browser.
Sources
Where information comes from
We receive personal data directly from you, from the organisation that gives you access to Oporo, from authorised project users, and from your organisation's identity provider when you use federated sign-in. We also generate service, security, audit, and workflow information as the platform is used.
Customers and authorised users may add information about other people, including project participants and document authors. They are responsible for having a lawful basis and providing any notice required before doing so.
Purposes and bases
Why we use personal data
Under UK data protection law, we must have a lawful basis for each use of personal data. The bases below apply according to the context. Where Oporo acts only on a customer’s instructions, the customer determines the purpose and lawful basis.
- Contract: to create and administer accounts, authenticate users, provide project workspaces, process files, support collaboration workflows, deliver notifications, provide support, and meet our customer agreements.
- Legitimate interests: to respond to business enquiries, arrange demonstrations, manage professional relationships, operate and improve the service, maintain audit trails, prevent misuse, investigate failures, secure accounts and infrastructure, and establish or defend legal claims. We balance these interests against the rights of affected people.
- Legal obligation: to meet applicable accounting, tax, regulatory, law-enforcement, and data protection requirements.
- Consent: where we specifically ask for consent, including any optional electronic marketing or non-essential cookies introduced in the future. Consent can be withdrawn at any time without affecting earlier lawful processing.
Locations and transfers
Where information is processed
Oporo and its providers may process personal data in the United Kingdom and in other countries used to deliver hosting, identity, communications, monitoring, support, and optional platform features. The current provider and service locations are maintained in our Sub-Processor Register. A customer-specific data-residency commitment applies only where it is expressly stated in the applicable customer agreement.
Where personal data is transferred from the United Kingdom to a country not covered by UK adequacy regulations, we use an approved transfer safeguard where required, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organisational measures and a transfer risk assessment where required. Contact us for information about the safeguard relevant to a particular transfer. Contractual commitments about a customer's selected data region are set out in the applicable customer agreement.
See the Sub-Processor Register for the current service-level location information.
Retention
How long we keep information
We keep personal data only for as long as reasonably necessary for the relevant purpose. The applicable period depends on the customer agreement, customer instructions, project lifecycle, account status, legal limitation periods, security requirements, and any statutory record-keeping obligation.
Account data is normally retained for the contract term and up to 90 days after closure. Customer project content is normally retained for the customer contract term and up to 90 days after termination or an authorised deletion request. Deleted information may remain in isolated, access-controlled backups for up to 35 days before routine overwrite.
Security and audit logs are normally retained for 12 months, support records for three years after closure, and sales enquiries or unsuccessful prospect records for 24 months after the last meaningful contact unless the person objects sooner. Contracts, billing records, and material business correspondence may be kept for up to seven years after the relationship ends for tax, accounting, contractual, or legal-claims purposes. Data may be retained longer where needed for a legal hold, dispute, investigation, fraud prevention, or statutory obligation.
- The Oporo session cookie has an eight-hour sliding lifetime. Oporo access tokens normally last 15 minutes and refresh tokens normally expire after 30 days; a token may be revoked sooner.
- Some portal information is stored in browser local storage until you sign out, clear site data, or overwrite or remove the relevant item. Session storage normally lasts until the browser tab is closed.
- IFC retention settings can be configured per project. The current platform default marks models for archive after 30 days and for purge after 90 days, while preserving selected audit information. A purge status does not necessarily remove every related backup, audit entry, or customer record immediately.
- Deletion from live systems may not immediately remove copies held in backups, which are isolated and expire under the applicable backup schedule.
Cookies and storage
Cookies and browser storage
The authenticated Oporo platform uses a strictly necessary HTTP-only cookie named oporo.session to maintain a signed-in session. It also uses browser local storage and session storage for account context, project selection, permissions, preferences, cached workflow information, and temporary operational queues. These technologies are necessary to provide requested platform functions and are not used for advertising.
With your permission, the public Oporo website uses Microsoft Clarity to measure site usage and improve the visitor experience. Clarity may process page interactions, clicks, scrolling, device and browser details, approximate location, IP address, and session recordings, and may set first-party analytics cookies. Clarity does not load until you accept analytics, and you can withdraw your choice through Cookie settings in the website footer. Hosting providers still process request information needed to deliver and secure the site.
Security
How we protect information
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, or access. These include authenticated access, project and role-based permissions, password hashing, account lockout controls, short-lived access tokens, hashed refresh tokens, HTTP-only session cookies, encrypted network transport, cloud access controls, audit logging, and restricted file-download routes.
No service can guarantee absolute security. Customers and users must protect their credentials, assign access on a least-privilege basis, avoid uploading unnecessary personal data, and tell us promptly about suspected unauthorised access.
Your rights
UK data protection rights
Depending on the circumstances, you may have the right to ask for access to your personal data, correction of inaccurate data, erasure, restriction of processing, data portability, or to object to processing based on legitimate interests or for direct marketing. Where processing relies on consent, you may withdraw it at any time.
Email contact@oporo.net to exercise a right. Please describe your relationship with Oporo and the relevant customer or project. We may need to verify your identity and may refer a request concerning customer-controlled project data to the relevant customer. We normally respond within one month, subject to the extensions and exemptions allowed by law. There is usually no charge, although the law permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
- You may object at any time to direct marketing. Oporo does not currently use personal data for third-party advertising.
- You may complain to the UK Information Commissioner’s Office at ico.org.uk or by calling 0303 123 1113. We would appreciate the opportunity to address your concern first.
Automated decisions
Automated processing and children
Oporo may calculate a business readiness-assessment score from the answers submitted on the public website. This is used to provide an indicative result and does not produce a legal or similarly significant decision about an individual. We do not otherwise use personal data for solely automated decisions that have legal or similarly significant effects.
Oporo is a business service and is not directed to children. Users must be authorised by a business customer and able to enter into the relevant arrangements under applicable law.
Changes
Changes to this policy
We may update this policy when our services, suppliers, or legal obligations change. We will publish the revised version here and change the effective date. Where a change materially affects how we use personal data, we will provide additional notice where appropriate.
Contact
Questions, concerns, and rights requests
Contact contact@oporo.net about this policy or personal data handled by Oporo.
