Legal

Privacy Policy.

This policy explains what personal data Architectt holds, why, who else touches it, how long we keep it and what you can demand from us. It covers members, firm and studio teams, their invited clients, verified reviewers and readers of our editorial pages.

Last updated
20 September 2026
Version
3.1
Applies to
architectt.com and all Architectt subdomains

In plain language

  • We collect what is needed to run your account, your projects and your payments — nothing for advertising.
  • Your project material is never used to train AI models and is never sold.
  • Your database records and files are stored in the EU; some processors are in the US under Standard Contractual Clauses.
  • You can export, correct or delete your data, and we answer requests within one month.

This summary is for orientation only. The numbered sections below are the binding text.

01Who is responsible

Controller: Architectt, Bredgade 45 B, 1260 København K, Kingdom of Denmark, VAT 45438031. Privacy contact: hello@architectt.com.

Where a firm or studio invites you into a project, that firm is the controller of the project data it uploads and we act as its processor under our Data Processing Agreement. For your own account and billing data we are always the controller.

02What we collect

  • Account data: email address, display name, password hash held by our authentication provider, role and tier, verification status, notification preferences.
  • Project data you submit: briefs, site descriptions, uploaded photographs and drawings, floorplans, room and budget records, materials, messages, comments and files.
  • Generated outputs: renders, floorplan suggestions, written summaries, and the prompts and quality assessments behind them.
  • Reviewer data: professional registration details, portfolio links, verification decisions, delivered reviews and payout records.
  • Payment data: billing name, address, VAT number, invoice and subscription status, token ledger entries. Card numbers are handled by Stripe and never reach us.
  • Communications: emails we send you and your replies, enquiry forms, support messages, and delivery outcomes such as bounces and unsubscribes.
  • Technical and usage data: IP address, device and browser information, pages viewed, errors, security events and administrative audit entries.
  • Consented analytics: aggregate measurement of site and funnel usage, only after you accept it.

04AI processing

When you ask for a render, a floorplan or written output, the relevant prompt and reference material are sent through our AI gateway to the model provider needed to produce it. Providers act as our processors, are contractually barred from training on your material, and are named in the subprocessor list. We do not use your project content to train models of our own. Editorial AI use and ownership of outputs are described in AI & Ownership.

05Who we share data with

We share personal data only with the processors listed in our subprocessor list — hosting, database, email, payments, AI generation and consented analytics — and:

  • reviewers, who see the project material submitted for review;
  • people you invite into a project, portal or share link, limited to what their role allows;
  • authorities or advisers, where we must comply with law or defend a legal claim.

We never sell personal data and run no advertising trackers.

06Where data is stored and transferred

Your account records, project data and files are stored in the European Union. Some processors — including payment, AI and edge-delivery providers — are established in the United States. Those transfers rely on the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, and encryption in transit and at rest. You can request a copy of the transfer mechanism applying to a specific provider.

07How long we keep it

DataRetention
Account and project dataWhile the account is open; 30 days after closure, then deleted
Database backupsRolling encrypted backups, overwritten on our hosting provider's cycle and in no case held longer than 35 days
Guest trial sessionsUp to 30 days
Invoices, payout and tax recordsAs required by Danish accounting law (5 years plus the current year)
Email delivery logs and suppression records24 months (suppression kept while needed to avoid mailing you again)
Security and admin audit logs24 months
Consented analyticsUp to 14 months

08How we protect it

Data is encrypted in transit and at rest. Access is enforced at the database level so each account and project role reaches only its own records; privileged operations are restricted to service credentials and recorded in an audit log. Share links are token-based and expiring, secrets are held outside the codebase, and we run automated security and dependency scanning. No system is perfectly secure — if a breach affects your data we will tell you and the supervisory authority as required.

09Your rights

Under the GDPR you may request access to your data, its correction, deletion, restriction or portability, and you may object to processing based on legitimate interests or withdraw consent for analytics at any time. You are not subject to any decision made solely by automated means that has legal effect on you.

Account deletion can be requested from your account settings; requests are reviewed by an administrator, which cancels any subscription, removes your files and notifies you when it is done. Or write to hello@architectt.com — we reply within one month.

If you are unhappy with our answer, you may complain to the Danish Data Protection Agency (Datatilsynet) or to the supervisory authority where you live.

10Cookies and site storage

The storage we set, what each item does and how consent works are itemised in the Cookie Policy.

11Children

The Service is for adults. We do not knowingly collect data from children under 18. If you believe a child has created an account, write to us and we will remove it.

12Changes to this policy

We update this policy when our processing changes. Material changes are notified by email or in-app notice at least 14 days before they take effect; the version and date at the top identify the text in force.

Privacy requests: hello@architectt.com. All documents are listed in the legal centre.