Privacy Policy

Your Data, Your Control

Last updated: January 2025. BuildForce is committed to protecting your privacy and handling your data with transparency and care.

Information we collect

BuildForce collects information necessary to provide our AI-native consulting platform services:

  • Account Information: Name, email address, company name, and billing details when you create an account.
  • Platform Connection Data: OAuth tokens, API credentials, and metadata from connected SaaS platforms (Salesforce, ServiceNow, HubSpot) to perform health checks and automation.
  • Usage Data: How you interact with BuildForce features, including health check results, deployment history, and AI consultant queries.
  • Technical Data: IP address, browser type, device information, and log data to maintain security and improve our services.

How we use your information

We use collected information to:

  • Provide our core services: health checks, CI/CD automation, data management, and AI consulting.
  • Monitor your SaaS platforms for configuration drift, security risks, and performance issues.
  • Train and improve our AI models to provide better recommendations and automation.
  • Communicate with you about your account, service updates, and support requests.
  • Maintain security, prevent fraud, and comply with legal obligations.

Data security and protection

BuildForce implements enterprise-grade security measures:

  • Encryption: All data encrypted at rest (AES-256) and in transit (TLS 1.3+).
  • Access Controls: Role-based access control with least-privilege principles and multi-factor authentication.
  • Infrastructure: Data hosted on secure cloud infrastructure (Supabase/AWS) with regular security audits.
  • Monitoring: Continuous vulnerability scanning and automated threat detection.
  • Compliance: Architecture designed to support SOC 2 and FedRAMP compliance paths.

Data sharing and third parties

We do not sell your personal data. We share data only in these limited circumstances:

  • Service Providers: Trusted partners (hosting, analytics, payment processing) under strict data protection agreements.
  • Connected Platforms: Data shared with your connected SaaS platforms (Salesforce, ServiceNow, HubSpot) as necessary to provide automation services.
  • Legal Requirements: When required by law, court order, or to protect our rights and safety.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets (with advance notice).

Your rights and choices

You have control over your data:

  • Access: Request a copy of your personal data at any time.
  • Correction: Update or correct inaccurate information in your account settings.
  • Deletion: Request deletion of your account and associated data (some data retained for legal compliance).
  • Opt-Out: Unsubscribe from marketing communications (service notifications will continue).
  • Data Portability: Request your data in a machine-readable format.

Data retention

We retain your data as long as your account is active or as needed to provide services. After account deletion, we retain certain data for legal compliance (typically 90 days for backups, up to 7 years for financial records).

Children's privacy

BuildForce is not intended for users under the age of 16 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact privacy@buildforce.io and we will promptly delete such information from our systems.

International data transfers

BuildForce is based in the United States and processes data on servers located in the United States and other regions. By using our services, you consent to the transfer of your data to countries outside your residence, which may have different data protection laws.

  • For EU/EEA users: We rely on Standard Contractual Clauses and other appropriate safeguards to transfer data outside the EU/EEA in compliance with GDPR Article 46.
  • Contact privacy@buildforce.io for information about our data transfer mechanisms and to request a copy of relevant safeguards.

U.S. state privacy rights

Residents of California, Virginia, Colorado, Connecticut, and other states with comprehensive privacy laws have additional rights:

  • California (CCPA/CPRA): Right to know what personal information is collected, right to delete, right to opt-out of sale/sharing (we do not sell personal information), right to correct inaccurate information.
  • Virginia, Colorado, Connecticut: Right to confirm we're processing your data, right to access, right to delete, right to correct, right to opt-out of targeted advertising and profiling.
  • To exercise these rights, contact privacy@buildforce.io. We will respond within 45 days as required by applicable law.

Contact us about privacy

For privacy questions, data requests, or concerns, contact us at privacy@buildforce.io or through our support channels. We respond to all privacy requests within 30 days.