Privacy Policy
Last updated: July 12, 2026
At ProjexaOne we are committed to protecting your privacy. This Policy describes how we collect, use, store and protect your personal information when you use our platform.
1. Data Controller
- Controller: Piero Cimule Troise
- Platform: ProjexaOne
- Contact email: admin@projexaai.com
- Website: projexaone.com
2. Personal Data We Collect
2.1 Data provided by the user
| Category | Data | Source |
|---|---|---|
| Identification | Full name, email, phone, identity document | Registration / Import |
| Organization | Company name, PH name, country, number of units | Registration |
| Residents | Name, email, phone, document, unit number, role (owner/tenant) | Bulk import / Form |
| Payments | Payment receipts (images), amounts, dates | Resident portal |
| Credentials | Password (Argon2id hash, never plain text) | Registration / Change |
2.2 Automatically collected data
- IP address and user agent (browser/device).
- Push notification token (mobile app).
- Audit log of actions within the platform.
- Session and preference cookies (see section 8).
- Error and diagnostic data (Sentry, anonymized).
3. Purpose and Legal Basis of Processing
| Purpose | Legal basis |
|---|---|
| Provide the PH management service | Contract performance |
| Manage user accounts and authentication | Contract performance |
| Send billing notifications and announcements | Legitimate interest / Consent |
| Generate account statements and receipts | Contract performance / Legal obligation |
| Security, fraud prevention and audit | Legitimate interest / Legal obligation |
| Improve the platform (anonymous analytics) | Legitimate interest |
| Technical support and customer service | Contract performance |
4. Data Recipients
We share data only with:
| Provider | Service | Country |
|---|---|---|
| Render | Cloud infrastructure (API and web hosting) | USA |
| Neon / PostgreSQL | Serverless PostgreSQL database | USA |
| Sentry | Error monitoring (anonymous data) | USA |
| Expo / FCM / APNs | Mobile push notifications | USA |
All providers are subject to data processing agreements and have adequate security certifications. We do not sell, rent or transfer your personal data to third parties for commercial purposes.
5. International Transfers
Some of our infrastructure providers are located in the United States. Data transfers to such providers are made under adequate safeguards, including EU Standard Contractual Clauses (SCCs) where applicable, complying with GDPR and equivalent regulations.
6. Data Retention
| Data type | Retention period |
|---|---|
| Active user account | While the account is active |
| Financial data (charges, payments, receipts) | 7 years (legal obligation) |
| Audit logs | 2 years |
| JWT session tokens | Until expiration or logout |
| Data post-account cancellation | 30 days (then permanent deletion) |
7. Your Rights
Depending on your jurisdiction (GDPR, CCPA, local law), you may exercise the following rights:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): delete your data when no longer necessary.
- Portability: receive your data in a structured, readable format.
- Objection: object to processing based on legitimate interest.
- Restriction: restrict processing in specific cases.
- Withdrawal of consent: withdraw consent when processing is based on it.
To exercise any of these rights, send an email to admin@projexaai.com with the subject "Data Rights Request" indicating the right you wish to exercise. We will respond within a maximum of 30 days.
California residents (CCPA): you also have the right not to be discriminated against for exercising your privacy rights.
8. Cookies and Similar Technologies
| Type | Purpose | Duration |
|---|---|---|
| Essential | Maintain authenticated session, language and theme preferences | Session / 30 days |
| Functional | Remember user settings (language, dark mode) | 1 year |
| Analytics | Aggregated anonymous usage metrics (no PII) | 90 days |
You can control cookies from your browser settings. Disabling essential cookies may affect service functionality.
9. Data Security
We implement the following technical and organizational measures:
- Encryption in transit via TLS 1.2+ (mandatory HTTPS).
- Passwords stored with Argon2id hashing (never plain text).
- Authentication via JWT with refresh token rotation.
- Two-factor authentication (MFA/TOTP) available.
- Data isolation per tenant (secure multi-tenant architecture).
- Complete audit log of administrative actions.
- Automatic database backups.
- Production access restricted through strict access controls.
Despite our measures, no system is 100% secure. We recommend using strong passwords and enabling MFA. Immediately report any security incident to admin@projexaai.com.
10. Minors
ProjexaOne is not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. If we detect that we have collected data from a minor without parental consent, we will delete it immediately.
11. Changes to This Policy
We may update this Policy periodically. Material changes will be notified at least 15 days in advance by email or prominent notice on the platform. The "Last updated" date at the top indicates when the current version took effect.
12. Contact and Complaints
For any inquiry, rights request or complaint related to your privacy:
- Email: admin@projexaai.com
- Recommended subject: "Privacy - [your request]"
- Response time: Maximum 30 business days
If you believe that the processing of your data violates applicable regulations, you have the right to file a complaint with the competent data protection authority in your country.