Privacy Policy
This Privacy Policy explains how Ventaara ("Ventaara," "we," "us") collects, uses, and protects information when you use the Ventaara platform — our construction and real-estate project-management service, including its web application, AI assistant (Tara), email and SMS intake, portals, and related services (together, the "Service"). By using the Service you agree to this Policy and to our Terms of Service.
The short version: your project data belongs to you and your company. We never sell it, and we never use it to train AI or large language models. We collect what we need to run the Service, keep it secure, and bill you — and this page spells out exactly what that means.
1. Information we collect
Account and workspace information
Your name, email address, password (stored only as a salted hash), company name, role, and the settings your workspace administrators configure (branding, modules, permissions).
Customer content
The material you and your team put into the Service: projects, budgets, invoices, contracts, drawings, photos, documents, RFIs, schedules, messages, meeting recordings and transcripts (when your team uses the Notetaker — recordings are transcribed by a speech-to-text subprocessor on our behalf, unlike browser dictation below), signatures on documents you sign electronically, and content you send in via your workspace's email or SMS intake addresses. Customer content belongs to your company; we process it only to provide the Service.
Voice dictation
Where your browser supports it, you can dictate to Tara instead of typing. Dictation uses the speech recognition built into your own browser, so the audio does not pass through Ventaara: your browser captures it and sends it to its vendor's speech service (Google for Chrome and Chromium browsers, Apple for Safari), which returns the text. Ventaara receives only the resulting text, and only once you choose to send the message — the transcript appears in the message box first so you can read and edit it. We never receive or store the audio recording. Your browser will ask for microphone permission the first time, the microphone is active only while you are dictating, and the feature is simply absent in browsers that don't offer speech recognition. Your browser vendor's handling of that audio is governed by its own privacy policy, not this one; if you would rather not use it, don't press the microphone — everything works by typing.
Usage and log data
Standard technical logs when you use the Service: IP address, browser and device type, pages and endpoints requested, timestamps, and error reports. This includes the security-event logs described in Section 4.
Payment information
Subscription payments are handled by a PCI-compliant payment processor. We receive your plan, billing status, and the last digits and brand of your card for display — full card numbers never touch our servers.
2. How we use information
- To provide the Service — hosting your workspace, syncing your projects, sending the notifications you and your admins configure.
- AI features — when you use Tara or an AI-assisted feature, the relevant content is processed by our AI model providers under agreements that prohibit them from using your data to train their models. AI features can be disabled per project by your admins.
- Billing and account management — subscriptions, credits, and usage metering.
- Support — responding when you contact us, including looking at the specific records you ask us to look at.
- Security — protecting your workspace and other customers' workspaces, as described in Section 4.
- Service improvement — aggregate, de-identified usage statistics (never your content) to understand which features matter.
3. What we never do
- We never sell your personal information or your customer content.
- We never use your customer content to train AI or large language models, and our AI subprocessors are contractually barred from doing so.
- We never read your messages, files, or records except to provide the Service, at your request for support, or as required by law.
4. Security monitoring and abuse prevention
To keep every workspace safe, the Service automatically logs security-relevant events — for example failed sign-in attempts and requests that were denied by the Service's permission system — together with the associated account, IP address, and timestamp.
- What is logged is metadata only. Security-event logs record that a request was denied and what kind of request it was. They do not capture the contents of your messages, files, or records, and no content monitoring is performed for this purpose.
- Automated flagging. Automated rules review these logs for patterns that suggest attempts to circumvent access controls and may flag an account for review.
- Human review. A small number of authorized Ventaara personnel may review flagged event logs to assess whether activity is malicious, mistaken, or benign. Access to these logs is restricted and itself audit-logged.
- Workspace administrator notification. If reviewed activity from an account in your workspace is confirmed as a concern, we may notify your workspace's administrators so they can follow up internally. These notices describe the pattern of denied requests — never any content.
- Enforcement. We may suspend or restrict accounts engaged in attempts to gain unauthorized access, as described in the Terms of Service.
5. When information is shared
- Within your workspace — according to the roles and permissions your admins set.
- With people you share with — when you invite a partner or share records with another company on the platform, the recipient sees exactly what the share grants and nothing more.
- Subprocessors — vendors that help us run the Service, limited to these categories: cloud hosting and infrastructure, database and file storage, AI model providers, speech-to-text for meeting recordings, transactional email and SMS delivery, payment processing, and any integrations you connect yourself. Each processes data only to provide its function to us; a current list of subprocessors is available on request at legal@ventaara.app.
- Legal requirements — if required by law, subpoena, or to protect the rights, safety, or property of Ventaara, our customers, or the public.
- Business transfers — if Ventaara is involved in a merger or acquisition, data may transfer with the business, subject to this Policy.
6. Data retention and deletion
Customer content is retained while your workspace is active. When a workspace is closed, its content is deleted or irreversibly de-identified within 90 days, except where a longer period is required by law or for billing records. Security-event logs are retained for up to 12 months. Workspace administrators can export their data at any time.
7. Security
Data is encrypted in transit (TLS) and at rest. Access inside Ventaara is role-based and audited. Workspaces can require two-factor authentication, and every account supports it. No system is perfectly secure — if we learn of a breach affecting your data, we will notify affected workspace administrators promptly and as required by law.
8. Your rights
Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, export, restrict, or delete your personal information, and to object to certain processing. Because most information in the Service is controlled by the company that owns your workspace, the fastest path is usually your workspace administrator; you can also contact us directly at legal@ventaara.app and we will respond within 30 days. We do not discriminate against anyone for exercising privacy rights, and we do not sell personal information, so there is nothing to opt out of selling.
9. Cookies and local storage
The Service uses browser local storage for your sign-in session and preferences. We do not use advertising cookies or third-party ad trackers.
10. Children
The Service is for business use and not directed to anyone under 16. We do not knowingly collect personal information from children.
11. Changes to this Policy
If we make material changes, we will notify workspace administrators by email or in-app notice before the changes take effect. The "Last updated" date above always reflects the current version.
12. Contact
Questions or requests: legal@ventaara.app.