Privacy Policy
ProjectNexus Enterprise is a cloud-based project management and collaboration platform used by organizations, project teams, consultants, contractors, clients and other authorized users. This policy explains what information we process and why.
Last updated: 17 August 2026
This document is provided for information about how the platform operates. It is not legal advice, and it has not been certified by an external legal adviser. It may be revised as the service and applicable regulation evolve.
1. Who we are
ProjectNexus Enterprise (“ProjectNexus”, “we”, “us”) provides a multi-tenant workspace for contract administration, programme management, document control and project communication. The service is operated by ProjectNexus Enterprise, based in Arusha, Tanzania.
Where an organization subscribes to ProjectNexus and invites its members, that organization is generally the controller of the project data in its workspace, and ProjectNexus acts as a processor on its instructions. For individual accounts and platform-level account data, ProjectNexus is the controller.
2. Account information
- Account identifiers: email address, hashed password credentials, account status and verification state.
- Profile information: full name, job title, professional discipline, organization membership, avatar image and any biography or contact details you choose to add.
- Role and permission assignments within each organization and project you belong to.
- Invitations you send or accept, and organization registration details submitted during onboarding.
3. Google and Apple authentication data
If you sign in with Google or Apple, we receive a limited set of identity information from the provider so that we can create and secure your ProjectNexus account:
- Your email address and email verification status.
- Your basic profile: name and, where provided, profile picture.
- A stable provider account identifier used to link the sign-in to your ProjectNexus account.
We never receive or store your Google or Apple password. We request only the minimum scopes needed for authentication, and we do not read your Gmail, Drive, Calendar, Contacts or iCloud data.
Google user data handling. ProjectNexus’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google sign-in data is used solely to authenticate you, create or match your account, and display your identity to collaborators in your workspace. It is not sold, not used for advertising or ad profiling, not used to train generalized AI models, and not disclosed to third parties except to service providers acting on our instructions, or where required by law. You can disconnect ProjectNexus at any time from your Google Account permissions page; your ProjectNexus account remains available via email sign-in.
4. Project and organization data
- Organization records: legal and trading name, addresses, branding assets, membership lists and approval structures.
- Project records: project metadata, participants, contracts, programmes and schedules, bills of quantities, interim payment certificates, variations, extension-of-time claims, RFIs, site instructions, inspections and reports.
- Workflow data: submissions, reviews, approvals, signatures, statuses and the audit history of each record.
5. Documents, communications and files you upload
You and your collaborators may upload drawings, specifications, photographs, spreadsheets, contract documents and other files, and may exchange messages, comments, meeting minutes and correspondence through the platform. We store this content to provide the service to you and your organization. We do not review it for commercial purposes and do not use it for advertising.
Where you use AI-assisted features, the relevant content is processed to generate the output you requested. AI outputs are advisory only and remain subject to your professional review.
6. Usage and security information
- Technical logs: IP address, browser and device type, operating system, timestamps and pages or actions requested.
- Security events: sign-in attempts, password resets, permission changes, impersonation or administrative access events, and audit trail entries.
- Diagnostics: error reports and performance data used to keep the platform reliable.
7. Cookies and session data
We use strictly necessary cookies and browser storage to keep you signed in, maintain your session securely, remember your selected organization or project context, and store interface preferences such as theme. We do not use advertising cookies or third-party ad tracking. Blocking essential cookies will prevent authentication from working.
8. How we use information
- To create, authenticate and secure accounts and sessions.
- To deliver core functionality: projects, contracts, documents, approvals, messaging and reporting.
- To apply role-based access control and maintain audit trails required for project governance.
- To send transactional email such as verification, password reset, invitations and notifications.
- To provide support, investigate incidents, prevent abuse and enforce our Terms of Service.
- To maintain, troubleshoot and improve platform reliability, performance and security.
- To comply with legal, regulatory and contractual obligations.
Depending on your location, our legal bases include performance of a contract, legitimate interests in operating and securing the platform, compliance with legal obligations, and consent where required.
9. How information is stored and protected
- Encryption in transit using TLS, and encryption at rest for stored data and file storage.
- Row-level security and tenant isolation so each organization sees only the records its roles permit.
- Least-privilege administrative access, with privileged actions recorded in the audit trail.
- Managed, regularly backed-up infrastructure with monitoring and logging.
No system can be guaranteed absolutely secure. You are responsible for keeping your credentials confidential and for managing the permissions you grant to collaborators. Data is hosted with managed cloud providers whose data centres are located outside Tanzania. International transfers are covered in section 12.
10. When information may be shared
- With other authorized users of your organization and of projects you participate in, according to your role and the permissions configured by your administrators.
- With service providers who host, secure, email, or otherwise support the platform, under contract and only to provide those services.
- With your organization's administrators, who may access, export or remove workspace data.
- Where required by law, regulation, court order, or to protect rights, safety and platform integrity.
- In connection with a merger, acquisition or asset transfer, subject to this policy continuing to apply.
We do not sell personal information and we do not share it with advertisers.
11. Third-party service providers
We use a limited set of providers to operate the platform. Each acts on our instructions under contract, may only process data to deliver its service, and may not use it for its own purposes:
- Cloud hosting, managed database and file storage for the application and your uploaded documents.
- Authentication services, including Google and Apple sign-in where you choose to use them.
- Email delivery for verification, password reset, invitations and notifications.
- AI processing providers used only to generate the output you request from AI-assisted features.
- Monitoring, logging and error-reporting services used to keep the platform reliable and secure.
12. International data transfers
ProjectNexus Enterprise is operated from Arusha, Tanzania, while our infrastructure providers operate data centres outside Tanzania. Your information may therefore be stored or processed in other countries. Where personal data is transferred internationally, we rely on appropriate safeguards, such as contractual data-protection commitments with our providers, including standard contractual clauses where required by applicable law. Transfers are limited to what is necessary to operate, secure and support the service.
13. Data retention
We retain account and profile data for as long as your account is active. Project, contract and document records are retained for as long as the owning organization keeps its workspace, because construction and engineering records commonly need to be preserved for contractual, statutory and dispute-resolution purposes. Security and audit logs are retained for a limited period appropriate to their purpose. Backups are cycled and expire on a rolling schedule. Where a specific statutory retention period applies to your jurisdiction or contract, that period governs.
14. Your rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of or objection to certain processing, a portable copy of data you provided, and withdrawal of consent where processing relies on it. You may also lodge a complaint with your local data protection authority.
If the data sits within an organization’s workspace, we will normally refer your request to that organization as controller and assist them in responding.
15. Account deletion
You may request deletion of your individual account at any time by contacting support from your registered email address. On deletion we remove your profile and personal identifiers and revoke your access. Records you contributed to an organization’s projects — such as approvals, certificates and audit entries — may be retained by that organization for contractual and legal reasons, and may remain attributed for audit integrity. Residual copies in backups expire on our normal backup cycle.
16. Children
ProjectNexus is a business platform and is not intended for individuals under 18. We do not knowingly collect data from children.
17. Changes to this policy
We may update this policy as the platform evolves. Material changes will be notified in-app or by email, and the “last updated” date above will change. Continued use after the effective date constitutes acceptance.
18. Contact and support
Privacy enquiries and data requests: privacy@projectnexusenterprise.com. Security reports: security@projectnexusenterprise.com. General support: support@projectnexusenterprise.com. Location: Arusha, Tanzania. Correspondence is handled by email; we do not publish a street address or telephone number.