ArdaroBack to signup
Recorded version 2026.08.13

Ardaro Privacy Policy

Effective version: 2026.08.13

Scope and roles

This Privacy Policy explains how Ardaro collects, uses, discloses, retains, and protects personal information associated with getardaro.com, workspace requests, accounts, support, and the Ardaro construction operations service.

For account administration, service security, billing, product operations, and direct communications with Ardaro, Ardaro determines the purposes of processing. For customer, worker, subcontractor, property, project, and other information a subscribing business places in its workspace, that business generally determines why the information is processed and Ardaro processes it to provide the service. Individuals seeking rights concerning workspace content should ordinarily contact the subscribing business first.

This Policy does not cover a subscriber's own privacy practices, third-party websites, or integrations that Customer independently controls.

Information collected

Ardaro may collect the following categories:

Sources

Information comes from subscribers and users; people who submit lead, portal, onboarding, or support forms; files and systems they choose to connect or import; payment and email providers; the browser or device used to access the service; and Ardaro's security, audit, and infrastructure systems.

Optional voice input

On supported browsers, an authenticated workspace user may choose browser speech recognition instead of typing certain job details. The user's browser or operating-system speech provider may process microphone audio under that provider's own terms and privacy practices. Ardaro does not receive or store microphone audio in the current implementation.

Recognized transcript text remains editable. Text reaches Ardaro when the user submits it for in-memory analysis that produces structured suggestions or guided briefing questions, or when the user saves it through an ordinary workspace form. Guided answers are not retained as a server-side conversation, and proposed values do not become workspace records until the user reviews and applies or saves them. Users may type instead and should not dictate passwords, payment-card data, access codes, private credentials, or other unnecessary sensitive information.

Uses

Ardaro uses information to:

Ardaro does not sell personal information or Customer Content. Ardaro does not share personal information for cross-context behavioral advertising and does not use Customer Content for unrelated advertising.

Ardaro Intelligence

The current Ardaro Intelligence capability uses deterministic application rules over authorized workspace data. It does not send workspace data to a third-party general-purpose artificial-intelligence model as part of that capability. If Ardaro later introduces an external model provider or materially different use of Customer Content, Ardaro will update the applicable product, contract, and privacy disclosures before that use.

Intelligence results and associated quality metadata may be stored with the workspace or service logs as needed to provide, secure, and troubleshoot the capability.

Service providers and recipients

Ardaro may provide limited information to service providers acting for Ardaro, including:

Providers receive information only for the services they perform and operate under their own contracts, privacy terms, retention practices, and legal obligations. Ardaro may replace a provider with a functionally similar provider and will update this Policy when the change materially affects personal-information processing.

Ardaro may also disclose information to authorized Customer users and recipients; at Customer's direction through an integration or public portal; to professional advisers bound by confidentiality; in a corporate transaction subject to appropriate safeguards; or when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or secure the service.

Ardaro does not disclose one tenant's protected workspace content to another tenant.

Direct file uploads

In the hosted service, an authorized browser may upload file bytes directly to private Amazon S3 storage through a short-lived, narrowly scoped upload capability. Ardaro authorizes the tenant and job scope before issuing the capability and verifies file metadata before creating the final workspace record. The file is not intended to be public, and downloads remain subject to Ardaro authorization.

Abandoned pending uploads in the current hosted configuration are scheduled to expire after one day. Replaced or deleted object versions may remain as noncurrent private versions for up to ninety days. These storage controls do not replace Customer's responsibility to upload only authorized and necessary information.

Cookies and browser storage

Ardaro uses cookies and browser storage that are necessary for authentication, security, preferences, partially completed forms, and service workflows. Authentication cookies are configured for server-side access and protected transport in the hosted service. Ardaro does not require third-party advertising cookies for the core workspace service.

Anonymous workspace login pages do not intentionally prefill a stored workspace email on a new or untrusted device. A browser may still offer information saved by the user's own password manager or browser settings, which Ardaro does not control.

Support and administrative access

Authorized Ardaro personnel may access account and workspace information when reasonably necessary to operate the service, investigate a security or reliability event, comply with law, or fulfill an authorized support request. Ardaro's support workflow is designed to record the reason, scope, status, and time limit for controlled support access where applicable. Ardaro does not provide an unrestricted tenant-impersonation route.

Subscribers control their own administrators and should review workspace access regularly.

Retention, archival, and deletion

Ardaro retains information while an account is active and as reasonably needed to provide and secure the service, maintain financial and audit records, resolve disputes, enforce agreements, and comply with law. Different records have different retention needs.

Workspace archival blocks normal access but does not physically delete tenant records. Operational records, security events, legal acceptance evidence, billing records, and audit logs may be retained after cancellation when needed for legitimate business or legal purposes. Deleted information may remain in restricted backups or noncurrent object versions until the applicable backup or lifecycle period expires.

An authorized workspace owner may initiate an export, correction, or deletion review through Ardaro's authenticated support channel or at privacy@getardaro.com. Ardaro verifies identity and authority before acting. A request may be limited by another person's rights, Customer instructions, technical dependencies, fraud prevention, legal holds, tax or accounting duties, backup cycles, and applicable law. Ardaro will communicate the applicable scope and outcome rather than representing archival as deletion.

Security

Ardaro uses safeguards designed for the nature of the service, including tenant-scoped authorization, role controls, password hashing, protected sessions, encryption in transit, private database and object storage, restricted infrastructure access, audit logging, backups, deployment controls, and monitored service events. No security program eliminates all risk.

Users must protect credentials and devices, use unique passwords, grant minimum necessary access, verify recipients before sharing, and promptly report suspected unauthorized activity. Customers should not use Ardaro for data types or regulated workloads prohibited by the Acceptable Use Policy or not covered by a written agreement.

If a security incident affects personal information, Ardaro will investigate and provide notice as required by applicable law and agreements.

International processing

Ardaro's current hosted application infrastructure is located in the United States. Service providers may process limited information from other locations under their applicable safeguards. Customer is responsible for determining whether the service and its instructions are appropriate for data subject to international transfer or localization requirements unless a signed agreement states otherwise.

Individual choices and requests

Depending on location and applicable law, an individual may have rights to request access, correction, deletion, or a copy of personal information, or to object to or restrict certain processing. Ardaro may need to verify identity, authority, and jurisdiction before responding.

For information in a subscriber workspace, contact that subscriber first because it controls the business record and user access. For Ardaro-controlled account, direct-marketing, or personal-information requests, contact privacy@getardaro.com. For account access, billing, or security support, contact support@getardaro.com. Ardaro may require identity, authority, and jurisdiction verification before responding.

Ardaro may send service, account, security, billing, and legal communications that are necessary for the relationship. Promotional email, if introduced, will use an applicable preference or unsubscribe process. Transactional messages may continue when necessary to operate or secure an account.

Sensitive information and children

Ardaro is a business service and is not directed to children under 13. Users must not knowingly submit children's personal information without a lawful business need, appropriate authority, and any required consent.

Do not submit complete payment-card data, account passwords, medical records, biometric templates, classified information, or other specially regulated information unless Ardaro has expressly agreed in writing to process it. Minimize and restrict access to taxpayer identifiers or similar information contained in business records.

Changes

Ardaro may update this Policy prospectively as the service, providers, or law changes. A material update will use a new version and reasonable notice. When required, Ardaro will request a new acknowledgement or consent. Ardaro will not materially expand use of previously collected identifiable Customer Content without appropriate notice and authority.

The version acknowledged during public signup is recorded with a cryptographic document fingerprint.

Contact

Privacy questions and personal-information requests may be initiated at privacy@getardaro.com. Account access, billing, and technical-support requests may be initiated at support@getardaro.com. Do not email passwords, session credentials, complete payment-card data, private keys, or unnecessary Customer Content. Ardaro may move a request into an authenticated channel before disclosing information or changing an account.