/ Data processing

How we handle project data on deployments

These commitments apply to the Hecato platform when deployed for a customer. Website enquiries are governed by the privacy policy.

Last updated

July 2026

Roles

For project data processed on a deployment, the customer is the controller and Hecato AI is the processor, acting on documented instructions under the agreement. For enquiries made through this website, Hecato AI is the controller and the privacy policy applies.

Categories of data

Deployments process the project record: contracts and amendments, programmes, instructions, correspondence, site records and cost data. Construction records incidentally contain personal data, typically the names, roles and communications of project, site and commercial staff, and it is handled under the same terms as the rest of the record.

Instructions and use

Hecato processes project data only on the customer's documented instructions and for the purposes set out in the agreement. Specifically:

  • Project data is not used to train models for other customers.
  • Project data is not accessed by Hecato staff except as needed to provide support under agreed procedures.
  • Outputs are generated only for the customer whose data is being processed.

Sub-processors

We use a small number of infrastructure sub-processors. The current list, with purpose and location for each, is provided during procurement and on request at hello@hecato.ai, and the agreement sets the notice period for changes. Where flow-down restrictions on a project limit which sub-processors may touch the data, the deployment is scoped to comply before any record is shared.

Location and residency

Hosting region is agreed at deployment against the restrictions that flow down the main contract. Where data classification prohibits an external processor entirely, Hecato is deployed inside the customer's own environment.

Security

Access is permissioned by role and by project. Output is source linked, so every figure traces to the document, revision and clause it came from. Technical and organisational measures are set out in the agreement, and the security page on this site describes the posture in plain terms, including what we do not claim.

Deletion and exit

On termination, project data is returned in an agreed format and then deleted on the timescale set in the agreement, with deletion confirmed in writing on request.

Contact

Procurement and data protection questions go to hello@hecato.ai.