Privacy Policy
1. Who we are
1.1 This Privacy Policy explains how [Company Legal Name], a company registered in [Jurisdiction] under company number [Number] with its registered office at [Registered Address] (we, us, our), collects and uses personal data.
1.2 We are the data controller for the personal data described in this policy, except where we act as a processor on your behalf as described in section 5.
1.3 You can contact us about anything in this policy at [privacy@domain].
2. What this policy covers
2.1 This policy covers personal data we handle when you visit [Website URL], download or trial RoundTrips, buy or use a Subscription, contact our support team, or receive marketing from us.
2.2 It does not cover the practices of third parties whose services you connect to RoundTrips, such as Autodesk Construction Cloud, Microsoft OneDrive or Dropbox. Those services handle your data under their own privacy policies.
2.3 This policy forms part of our Terms of Service.
3. What we do not collect
3.1 We think this is the most important section, so it comes first.
3.2 We do not collect or store the contents of your models, drawings or documents. RoundTrips processes files locally on your machine. When a Task moves or builds files, the contents travel directly between your machine and the storage locations you have authorised. They do not pass through our servers and we keep no copies.
3.3 We do not have access to your project files in a Connected Service. We hold an access token that lets the Software act on your instructions from your machine; we do not use it to browse, read or retrieve your files ourselves.
3.4 We do not sell personal data, and we do not share it with advertisers or data brokers.
4. Personal data we collect
4.1 Account and billing data. Your name, work email address, company name, job role, country, billing address, VAT or tax number, and purchase history. Payment card details are collected and stored by our payment processor, not by us.
4.2 Licence and activation data. Your licence key, the number of Seats assigned, the individuals assigned to them, activation records, machine identifiers used to enforce Seat limits, and the software version installed.
4.3 Operational data from the Software. Task configuration metadata such as Task names, project names, folder paths, file names, file types and file counts; Run outcomes, timings and stage durations; data volumes moved; error diagnostics; and application logs. Folder paths and file names can contain personal data if you name files after people, so we treat this category as personal data.
4.4 Connected Service authorisation data. Access and refresh tokens issued when you authorise a Connected Service, the account identifier associated with that authorisation, and the scopes granted.
4.5 Support data. The content of emails and support tickets you send us, and any logs or files you choose to attach.
4.6 Website data. IP address, browser and device type, pages viewed, referring site, and the contents of forms you submit, including trial download requests.
5. Where we act as a processor
5.1 Some of the data the Software handles is personal data belonging to your own clients, staff or project participants. Where that is the case you are the controller and we act as a processor, handling it only on your documented instructions.
5.2 If you require a data processing agreement, ours is available at [DPA URL]. Where we act as processor, our commitments in that agreement take precedence over this policy for the data it covers.
6. Why we use your data, and our legal basis
6.1 To provide the Software and your Subscription — creating your account, issuing and validating licence keys, enforcing Seat and tier limits, and running the Tasks you configure. Legal basis: performance of a contract.
6.2 To provide support — investigating problems you report, reproducing errors, and responding to you. Legal basis: performance of a contract, and our legitimate interest in supporting our customers.
6.3 To keep the Software secure and working — detecting failures, diagnosing errors, preventing abuse of licence keys, and protecting our systems. Legal basis: our legitimate interest in the security and integrity of our service.
6.4 To improve the product — understanding which Tasks fail, how long Runs take, and where performance problems occur, so we can fix and improve them. Legal basis: our legitimate interest in improving a product our customers rely on. We use aggregated data for this wherever it is sufficient.
6.5 To take payment and meet our accounting obligations — invoicing, collecting payment, and keeping financial records. Legal basis: performance of a contract, and compliance with a legal obligation.
6.6 To send you service messages — trial expiry, renewal, security and availability notices, and material changes to our terms. Legal basis: performance of a contract. You cannot opt out of these while you hold a Subscription.
6.7 To send you marketing — product updates and occasional announcements, where you have opted in or where you are an existing customer and we are permitted to contact you about similar products. Legal basis: consent, or our legitimate interest in marketing to existing customers. You can unsubscribe from any marketing email, at any time, using the link in it.
7. Who we share data with
7.1 We share personal data only with service providers who help us operate, and only as far as they need it. Our sub-processors are:
• [Payment Processor] — payment processing and invoicing
• [Cloud Host] — hosting our licensing and web infrastructure
• [Email Provider] — transactional and marketing email
• [Support Tool] — support ticketing
• [Analytics Provider] — website analytics
7.2 A current list of sub-processors is maintained at [Sub-processors URL]. Where we act as processor, we will give you notice of changes to this list as set out in our data processing agreement.
7.3 We may also disclose personal data where we are legally required to, to establish or defend legal claims, or to a buyer or successor in connection with a merger, acquisition or sale of assets — in which case we will notify you before your data becomes subject to a different privacy policy.
8. International transfers
8.1 We are based in [Jurisdiction] and some of our service providers are located outside it, including in the United States.
8.2 Where we transfer personal data outside the UK or the European Economic Area, we rely on an adequacy decision where one applies, or otherwise on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, together with any additional safeguards the transfer requires.
8.3 You can request a copy of the safeguards we rely on by writing to [privacy@domain].
9. How long we keep data
9.1 Account and billing data — for the life of your account, and then for [7] years to meet accounting and tax obligations.
9.2 Licence and activation data — for the life of your Subscription, and then for [24] months to handle renewals, disputes and licence misuse.
9.3 Operational data and application logs — for [12] months, after which it is deleted or irreversibly aggregated.
9.4 Connected Service tokens — until you disconnect the service, revoke access from within that service, or your Subscription ends. Tokens are then deleted.
9.5 Support correspondence — for [24] months after the ticket is closed.
9.6 Website analytics — for [14] months.
9.7 We may keep data for longer where we are legally required to, or where it is needed for a legal claim that is active or reasonably anticipated.
10. How we protect data
10.1 We use encryption in transit for all connections between the Software, our services and Connected Services, and encryption at rest for stored credentials and tokens.
10.2 Access to personal data within our organisation is restricted to staff who need it, and is logged.
10.3 We keep the fact that model and document contents never reach our systems as a deliberate design decision — it is the strongest protection we can offer for the data you care most about.
10.4 No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the risk is high.
11. Your rights
11.1 Depending on where you live, you have some or all of the following rights over your personal data: to access it; to have it corrected; to have it erased; to restrict or object to our use of it; to receive it in a portable format; and to withdraw consent where our use relies on consent.
11.2 Where we rely on legitimate interests, you may object at any time and we will stop unless we have compelling grounds to continue.
11.3 To exercise any right, write to [privacy@domain]. We will respond within one month, and will tell you if we need longer because the request is complex.
11.4 We will not charge you for exercising your rights, or treat you differently for doing so.
11.5 If you are unhappy with how we have handled your data you may complain to your local supervisory authority. In the UK this is the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to address your concern first.
12. Cookies and website analytics
12.1 Our website uses cookies that are strictly necessary for it to function, and analytics cookies that help us understand how the site is used.
12.2 Analytics cookies are set only with your consent, which you give through our cookie banner and can change at any time via [Cookie Settings link].
12.3 We do not use advertising or cross-site tracking cookies.
12.4 Details of each cookie we set, its purpose and its lifetime are listed at [Cookie Policy URL].
13. Children
14. Changes to this policy
14.1 We may update this policy. When we make a material change we will update the effective date at the top, and where the change affects how we use data you have already given us we will notify you by email or in the Software before it takes effect.
14.2 Previous versions are available on request.
14. Changes to this policy
14.1 We may update this policy. When we make a material change we will update the effective date at the top, and where the change affects how we use data you have already given us we will notify you by email or in the Software before it takes effect.
14.2 Previous versions are available on request.
15. Contact us
15.1 For any question about this policy, or to exercise your rights:
• [Company Legal Name]
• [Registered Address]
• [privacy@domain]
15.2 Our data protection representative is [Representative name and contact, if you are required to appoint one].

