PLAT Privacy Policy
Last updated: August 27, 2026
1. Who We Are and What This Policy Covers
This Privacy Policy describes how Cemented Solutions ("we", "us", or "our") collects, uses, and protects personal information in connection with the PLAT platform (the "Service"). PLAT is business software used by trade contractor companies ("Customers"). Much of the information in the Service is entered and controlled by the Customer whose tenant you use; for that information, we act on the Customer's behalf and the Customer's own policies also apply.
2. Information We Collect
- Account information: name, email address, company, country, password (stored hashed), and optional profile photo.
- Customer content: information your company enters into the Service, such as estimates, job records, contacts, documents, plans, and time tracking entries about its workforce.
- Usage and device information: IP address, browser and device details (user agent), pages and actions within the Service, and timestamps.
- Authentication information: multi-factor authentication enrollment details and, if you sign in with Google or Microsoft, the basic profile information those providers share with us.
- Billing information: subscription and payment records. Card details are collected and processed by our payment processor; we do not store full card numbers.
- Support communications: messages you send us, such as email to our support address.
3. How We Use Information
- Provide, operate, and maintain the Service for your company's tenant;
- Authenticate users, enforce permissions, and secure accounts (including multi-factor authentication);
- Process subscriptions and payments;
- Maintain audit trails of meaningful actions for security, accountability, and Customer compliance needs;
- Monitor performance, troubleshoot issues, and improve the Service;
- Communicate with you about the Service, including transactional emails such as invitations, password resets, and notifications;
- Comply with legal obligations and enforce our Terms and Conditions.
We do not sell personal information, and we do not use Customer content for advertising.
4. Audit Logs
The Service keeps detailed, append-only audit logs of meaningful user and system actions. Audit entries include the acting user, timestamp, IP address, user agent, and before-and-after change context. Sensitive values such as credentials are redacted from logs. Audit logs exist to protect Customers and their data, are retained for a minimum of seven (7) years by default, and are accessible to authorized administrators of your company's tenant.
5. Cookies and Local Storage
The Service uses cookies and similar technologies that are necessary for it to function: a session cookie to keep you signed in, a CSRF token to protect forms, and browser local storage for interface preferences such as light or dark theme and unsaved drafts. We do not use third-party advertising or cross-site tracking cookies.
6. How We Share Information
We share personal information only with:
- Service providers (subprocessors) that help us run the Service, such as cloud hosting and file storage (Amazon Web Services), payment processing (Stripe), real-time messaging infrastructure, and email delivery. These providers process data only on our instructions.
- Your company: administrators of the tenant you belong to control your account there and can see the content and activity within that tenant, including audit logs.
- Identity providers you choose, such as Google or Microsoft, when you use single sign-on.
- Legal and safety recipients, where disclosure is required by law or necessary to protect rights, safety, or the integrity of the Service.
- A successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.
7. Security
We maintain safeguards designed to protect personal information, including isolation between customer tenants, encryption of data in transit, hashed password storage, support for multi-factor authentication, role-based access controls, and comprehensive audit logging. No system is perfectly secure; please use a strong, unique password and protect your credentials.
8. Data Retention
- Account information and Customer content are retained for the life of the Customer's subscription and for a limited export window after termination, as described in our Terms and Conditions.
- Audit logs are retained for a minimum of seven (7) years by default to meet security and compliance objectives.
- Billing records are retained as required by tax and accounting law.
- Archived files may be stored in long-term archival storage during the subscription.
9. Your Choices and Rights
You can view and update your profile information within the Service. Because tenants are administered by Customers, requests to access, correct, export, or delete information held in a company's tenant should first go to that company's administrator. Depending on where you live, you may have legal rights regarding your personal information, such as access, correction, deletion, and portability. You can contact us directly using the details below and we will respond consistent with applicable law, working with the relevant Customer where we process information on its behalf.
10. International Transfers
The Service is hosted on cloud infrastructure that may store and process information in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers of personal information.
11. Children
The Service is business software and is not directed to children under 16. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If a change is material, we will provide reasonable notice, for example by email or an in-product notice. The "Last updated" date above reflects the current version.
13. Contact
Privacy questions and requests can be sent to [email protected].