Legal
Privacy Policy.
This policy explains what personal data Architectt holds, why, who else touches it, how long we keep it and what you can demand from us. It covers members, firm and studio teams, their invited clients, verified reviewers and readers of our editorial pages.
- Last updated
- 20 September 2026
- Version
- 3.1
- Applies to
- architectt.com and all Architectt subdomains
In plain language
- —We collect what is needed to run your account, your projects and your payments — nothing for advertising.
- —Your project material is never used to train AI models and is never sold.
- —Your database records and files are stored in the EU; some processors are in the US under Standard Contractual Clauses.
- —You can export, correct or delete your data, and we answer requests within one month.
This summary is for orientation only. The numbered sections below are the binding text.
01Who is responsible
Controller: Architectt, Bredgade 45 B, 1260 København K, Kingdom of Denmark, VAT 45438031. Privacy contact: hello@architectt.com.
Where a firm or studio invites you into a project, that firm is the controller of the project data it uploads and we act as its processor under our Data Processing Agreement. For your own account and billing data we are always the controller.
02What we collect
- Account data: email address, display name, password hash held by our authentication provider, role and tier, verification status, notification preferences.
- Project data you submit: briefs, site descriptions, uploaded photographs and drawings, floorplans, room and budget records, materials, messages, comments and files.
- Generated outputs: renders, floorplan suggestions, written summaries, and the prompts and quality assessments behind them.
- Reviewer data: professional registration details, portfolio links, verification decisions, delivered reviews and payout records.
- Payment data: billing name, address, VAT number, invoice and subscription status, token ledger entries. Card numbers are handled by Stripe and never reach us.
- Communications: emails we send you and your replies, enquiry forms, support messages, and delivery outcomes such as bounces and unsubscribes.
- Technical and usage data: IP address, device and browser information, pages viewed, errors, security events and administrative audit entries.
- Consented analytics: aggregate measurement of site and funnel usage, only after you accept it.
03Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account and providing Blueprints, projects and portals | Performance of a contract (Art. 6(1)(b)) |
| Generating the AI outputs you request | Performance of a contract |
| Taking payment, issuing invoices, paying reviewers | Contract and legal obligation (Art. 6(1)(b), (c)) |
| Service emails: welcome, notifications, reviewer and project updates | Contract |
| Security, abuse prevention, audit logging, debugging | Legitimate interests (Art. 6(1)(f)) |
| Verifying professional credentials | Contract and legitimate interests |
| Analytics and measurement of marketing performance | Consent (Art. 6(1)(a)) |
| Keeping accounting and tax records | Legal obligation |
04AI processing
When you ask for a render, a floorplan or written output, the relevant prompt and reference material are sent through our AI gateway to the model provider needed to produce it. Providers act as our processors, are contractually barred from training on your material, and are named in the subprocessor list. We do not use your project content to train models of our own. Editorial AI use and ownership of outputs are described in AI & Ownership.
06Where data is stored and transferred
Your account records, project data and files are stored in the European Union. Some processors — including payment, AI and edge-delivery providers — are established in the United States. Those transfers rely on the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, and encryption in transit and at rest. You can request a copy of the transfer mechanism applying to a specific provider.
07How long we keep it
| Data | Retention |
|---|---|
| Account and project data | While the account is open; 30 days after closure, then deleted |
| Database backups | Rolling encrypted backups, overwritten on our hosting provider's cycle and in no case held longer than 35 days |
| Guest trial sessions | Up to 30 days |
| Invoices, payout and tax records | As required by Danish accounting law (5 years plus the current year) |
| Email delivery logs and suppression records | 24 months (suppression kept while needed to avoid mailing you again) |
| Security and admin audit logs | 24 months |
| Consented analytics | Up to 14 months |
08How we protect it
Data is encrypted in transit and at rest. Access is enforced at the database level so each account and project role reaches only its own records; privileged operations are restricted to service credentials and recorded in an audit log. Share links are token-based and expiring, secrets are held outside the codebase, and we run automated security and dependency scanning. No system is perfectly secure — if a breach affects your data we will tell you and the supervisory authority as required.
09Your rights
Under the GDPR you may request access to your data, its correction, deletion, restriction or portability, and you may object to processing based on legitimate interests or withdraw consent for analytics at any time. You are not subject to any decision made solely by automated means that has legal effect on you.
Account deletion can be requested from your account settings; requests are reviewed by an administrator, which cancels any subscription, removes your files and notifies you when it is done. Or write to hello@architectt.com — we reply within one month.
If you are unhappy with our answer, you may complain to the Danish Data Protection Agency (Datatilsynet) or to the supervisory authority where you live.
11Children
The Service is for adults. We do not knowingly collect data from children under 18. If you believe a child has created an account, write to us and we will remove it.
12Changes to this policy
We update this policy when our processing changes. Material changes are notified by email or in-app notice at least 14 days before they take effect; the version and date at the top identify the text in force.
Privacy requests: hello@architectt.com. All documents are listed in the legal centre.
