Privacy policy

Effective date: 7 August 2026
Last updated: 7 August 2026
Entity: BuildFoundry Limited (trading as TakeoffQS)
Contacts: support@takeoffqs.com, privacy@takeoffqs.com

01 Information we collect

We collect the following categories of information:

  • Account information: Name, email address, organisation, and trade or role.
  • Plan data: PDF files you upload, together with any corrections, annotations, comments, or adjustments you make within the Service. This may include data used to generate prenail, foundations, painting, balance of house, roofing, and similar estimating outputs.
  • Usage data: Processing events, edits, activity history, action logs, error logs, and related service telemetry.
  • Billing information: Billing and payment-related information processed through our payment providers. We do not store full payment card numbers.
  • Artificial intelligence review artifacts: Where applicable, we may collect screenshots, replay clips, review states, and similar workflow records generated to support quality assurance, output review, support, security, dispute resolution, and service improvement.

02 How we use information

We use information for the following purposes:

  • To provide the Service: To extract quantities, generate estimates, manage projects, support account administration, process payments, and provide customer support.
  • To operate, secure, and improve the Service: To maintain system performance, troubleshoot issues, monitor reliability, prevent misuse, investigate incidents, enforce our terms, and comply with legal obligations.
  • To train, test, evaluate and improve our models and workflows: We may use uploaded drawings and representations or portions of them—including rasterised pages, image crops and technical features extracted from drawings—together with annotations, corrections, confirmations and feedback provided by users. Our focus is the technical content of drawings, including geometry, dimensions, spatial relationships, structures, symbols, annotations, layouts, material types and descriptions, specifications, brands and product references, quantities, measurements, relationships between those items and user corrections—not the identity of the customer or anyone named in a drawing. Personal information may be processed incidentally where it appears within a drawing, but we do not intentionally select or label personal information for training purposes or use it to identify or profile individuals. We do not make one customer’s original plan files available to another customer or use training data to recreate another customer’s project.
  • To facilitate transactions: If you request quotes, supplier connections, pricing, availability, or ordering support, we use relevant project information to help facilitate those requests.
  • To communicate with you: To send service updates, account notices, support communications, and other service-related messages.

We may also use technical, product and quantitative information contained in or derived from Customer Data—including material descriptions, specifications, product references, quantities, measurements and user corrections—to operate, evaluate, develop and improve the Service and related features. We may create de-identified datasets and aggregated insights from this information, but those datasets and insights will not reasonably identify the Customer, a project, a site or any individual.

Customer-specific commercial information—such as price books, rates, costs, margins, discounts, supplier terms and quoted prices—may be processed where necessary to provide the Service or where it appears within Customer Data. We do not intentionally use that information to train models used across customers unless the Customer agrees, or the use is clearly disclosed as part of a feature the Customer chooses to use.

Contractual basis: Model development is one of the purposes for which eligible plan-derived information and user corrections are collected and used. The Customer separately grants the contractual data licences described in clause 8 of the Terms of Service. Where personal information relates to someone other than an account user, TakeoffQS handles it in accordance with applicable privacy law. Contractual acceptance by an organisation does not waive an individual’s privacy rights.

If an organisation has a separate written agreement with TakeoffQS that restricts this use, that agreement prevails to the extent of the inconsistency.

03 Data sharing and commercial connections

We share information only as reasonably necessary for the purposes described in this Privacy Policy.

  • Service providers: Hosting, infrastructure, analytics, customer support, security, and payment providers under contract. These providers may access information only on a need-to-know basis.
  • Integration partners and suppliers: If you use features that request quotes, pricing, availability, or material orders, we may share relevant project data with suppliers or integration partners to facilitate that transaction.
  • Subsidised or sponsored accounts: If your account is sponsored by a commercial partner, we may share usage statistics and limited project metadata with that partner to administer that arrangement.
  • AI processing providers: We may use third-party AI providers to help process data.

Overseas processing: Some of our service providers process information outside New Zealand or Australia, including in the United States and Singapore. This may include AI processing, model evaluation, infrastructure, analytics, communications, monitoring and support. We require appropriate confidentiality, security and privacy protections from our service providers. Where an overseas transfer is legally treated as a disclosure, we use an appropriate lawful transfer mechanism.

We do not sell your personal contact information to unrelated third-party advertisers. We may, however, use, analyse, and commercialise de-identified and aggregated information for product improvement, benchmarking, market intelligence, and related commercial purposes.

04 Retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy.

  • Active account data: For the life of the account, unless you delete the data earlier.
  • Deleted account data: Removed from user-facing systems promptly and generally within 14 days. Residual backup copies may persist for a limited period.
  • Logs and operational records: Generally retained for up to 12 months.
  • Training and evaluation data: Approved Training Data, Derived Data and associated evaluation records may be retained on an ongoing basis where permitted by our Terms, any applicable separate agreement and applicable law. Retention does not itself mean that information has been de-identified.
  • AI review artifacts: Generally retained for up to 90 days, unless a longer period is required.

What deletion means: When you request deletion, we remove Customer Data from active, customer-facing systems within 14 days, subject to legal, security and dispute-related retention requirements. Isolated backup copies may remain until they expire under our backup-retention schedule and are not restored except for recovery or legal purposes.

Deleting source Customer Data does not ordinarily require TakeoffQS to retrain models that were completed before the deletion request. We may retain Derived Data, Business Intelligence and model improvements created before the request where they no longer reasonably identify the Customer, a project, a site or an individual and do not reproduce the Customer Data in substantially its original form.

Where Approved Training Data, a training record, a model or an output contains or can reproduce personal information, we will assess and respond to access, correction and deletion requests as required by applicable law. Depending on the circumstances, this may include deleting or suppressing a training record or output, attaching a correction, updating a model or taking another reasonable technical measure.

A contractual licence does not limit an individual’s rights under applicable privacy law.

05 Security

We use reasonable technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration, or disclosure. Measures include industry-standard encryption for data in transit and at rest, role-based access controls, authentication controls, audit logging, monitoring, incident response processes, and contractual requirements for subprocessors.

No method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a privacy breach that has caused or is likely to cause serious harm, we will promptly take steps to contain and investigate the breach, and will notify the Office of the Privacy Commissioner and affected individuals where required.

06 Your rights and choices

Subject to applicable law, you may request access to, correction of, or deletion of personal information we hold about you. Contact privacy@takeoffqs.com or support@takeoffqs.com. We aim to respond within 20 business days.

Access and correction requests may cover retrievable personal information contained in source plans, training or evaluation records, AI review artifacts and model outputs. Depending on the circumstances, applicable law may require us to provide access, make a correction, attach a statement of correction or take another reasonable step, rather than to delete the information, and we will respond as the law requires.

Our Service is not directed to children under 16. We do not knowingly collect personal information from children under 16.

If you believe we have interfered with your privacy, you may complain to the Office of the Privacy Commissioner (New Zealand) or the Office of the Australian Information Commissioner.

07 Automated processing and human review

Our Service uses automated tools, including machine learning and AI-assisted processing, to help generate estimating outputs and related workflow suggestions. These tools are intended to support human review, not replace professional judgment.

To the extent applicable, we do not use solely automated processing to make legally significant decisions about individuals without meaningful human involvement.

08 Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, the Service or applicable law.

If we make a material change, we will take reasonable steps to notify account administrators and affected users before the change takes effect, unless an earlier change is reasonably required by law or to address an urgent security risk.

Changes apply from their stated effective date and do not retrospectively authorise a materially different use of personal information. Where applicable law requires consent or authorisation for a new use or disclosure, we will obtain it.

09 Cookies and tracking

We use cookies and similar technologies to operate, secure, analyse, and improve the Service, and to support marketing.

  • Strictly necessary: Essential for core functions (authentication, session management, security).
  • Performance and analytics: Help us understand usage patterns. Data is commonly aggregated or de-identified.
  • Functionality: Remember your choices and preferences.
  • Targeting and advertising: Deliver relevant adverts and measure campaign effectiveness.

Most browsers allow you to block or delete cookies. If you decline non-essential cookies, some features may be limited.

10 Contact and further information

If you have questions about this Privacy Policy or our privacy practices, contact privacy@takeoffqs.com or support@takeoffqs.com.