Cadlyx/Legal/Privacy Policy

Privacy Policy

How Cadlyx collects, uses, and protects information.

Effective:

This Privacy Policy explains how Cadlyx, LLC collects, uses, and shares information about you when you visit cadlyx.com or use the Cadlyx platform (the "Service").

1. Information we collect

We collect the following categories of information, sourced directly from you, automatically as you use the Service, or from the third parties listed at /legal/subprocessors:

  • Account information: name, email, organization, role, profile preferences. Provided directly by you or your organization administrator.
  • Customer Content: CAD files (STEP, IGES, and other formats), drawings, technical specifications, quotes, supplier records, and other engineering data your organization uploads to the Service.
  • Usage telemetry: page views, feature interactions, performance metrics, and error reports, collected automatically when analytics cookies are accepted.
  • Support correspondence: emails, chat messages, and tickets you send to our support team.
  • Billing information: payment method tokens managed by Stripe; we do not store full card numbers on our systems. Invoice history is retained for accounting and legal compliance.
  • Authentication and security: hashed credentials, multi-factor authentication tokens, IP addresses of sign-in attempts, and audit logs of administrative actions.

2. How we use information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process CAD files and generate quotes via our analysis and AI features (see Section 3 below for AI processing details)
  • Authenticate users, secure accounts, and detect fraudulent or abusive activity
  • Bill and collect payment for the Service via our payment processor
  • Communicate with you about your account, the Service, and security or legal matters
  • Comply with legal obligations and respond to lawful requests from authorities
  • Measure aggregate usage trends and product performance, only when analytics cookies are accepted

We do not sell personal information or share it for cross-context behavioral advertising as defined under the California Consumer Privacy Act.

3. AI processing and model training

Cadlyx uses artificial intelligence to analyze CAD files, generate quotes, and provide engineering insights via the Bid Advisor agent and related features.

We do not use Customer Content to train, fine-tune, or improve any AI or machine learning model, whether ours or any third party's. This restriction is contractually committed in Section 1.6 of the Terms of Service.

Current Standard-service AI inference runs in Amazon Web Services Bedrock, region-pinned to us-east-2. Any separately contracted controlled-data deployment and its residency terms will be documented before use. Customer Content is not transmitted to AI model providers directly. AWS provides isolated model inference under contractual no-training terms (AWS Service Terms §50): foundation model providers (including Anthropic, Meta, and Amazon) do not see Bedrock traffic, and AWS operates its own copies of the model weights in the pinned region.

Custom models, if any, are encrypted with our AWS KMS keys and remain under our exclusive control. We do not export or share custom model weights with any third party.

Aggregated, fully de-identified Usage Data may be used to improve the Service, including to evaluate model accuracy and product performance, where it cannot reasonably be associated with you, any User, or any Customer Content.

4. How we share information

We share information only with the third-party subprocessors listed at /legal/subprocessors, with our affiliates, with your organization's administrators, and as required by law. We do not share Customer Content with any third party for their independent use, and Customer Content is not used by any subprocessor for purposes beyond delivering the Service to you.

5. Your rights and choices

Depending on your jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal information. Subject to verification, we honour these requests within the timelines required by applicable law.

6. Cookies and similar technologies

We use cookies and similar technologies for the following purposes, organized by category:

  • Strictly necessary: required to deliver the Service. Includes the Clerk session cookie (HttpOnly, Secure, SameSite=Lax), the CSRF token, and the cookie consent record. Set without consent.
  • Preferences: remembers UI choices like theme and recent workspaces. Set when you sign in.
  • Analytics: measures how the Service is used so we can improve it. Provided by PostHog. Off by default; only set when you opt in via the cookie banner shown on first visit or via /settings/privacy.

We do not use advertising cookies, third-party tracking pixels, or cross-site behavioral profiling. You can change your cookie preferences at any time at /settings/privacy.

7. Security

We implement technical and organizational measures designed to protect your information against unauthorized access, use, disclosure, alteration, or destruction. These include:

  • TLS 1.2+ for all connections, with HSTS enforced
  • AES-256 encryption at rest for data in S3 and RDS
  • Role-based access controls, multi-factor authentication for production access, and the principle of least privilege
  • Structured application logs and CloudWatch monitoring with retention of 90 days hot and 1 year cold
  • Background checks, confidentiality agreements, and security training for all personnel with production access
  • Inherited physical and infrastructure security from AWS (compliant with SOC 2, ISO 27001, and other frameworks)
  • A 72-hour notification commitment for confirmed personal data breaches affecting Customer Personal Data, as detailed in the Data Processing Addendum

No system can be guaranteed to be 100% secure. If you suspect a security issue, please contact [email protected].

8. International transfers

The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other jurisdictions where our subprocessors operate.

For transfers of Personal Data subject to the GDPR or UK GDPR, we rely on the European Commission's Standard Contractual Clauses (SCCs) — Module 2 (controller-to-processor) and Module 3 (processor-to-processor) — and the UK International Data Transfer Addendum, as applicable. These mechanisms are described in the Data Processing Addendum.

9. Retention

We retain information for as long as needed to provide the Service and for legitimate business or legal purposes after the Service relationship ends. Specific retention periods:

  • Account information: retained for the duration of the account, then deleted within 60 days of account closure unless retained longer for legal compliance.
  • Customer Content: retained for the duration of your subscription. Upon request following termination, deleted within 60 days. Backup copies are purged within 90 days under our standard backup rotation.
  • Usage telemetry: retained for up to 25 months when analytics consent is granted, then aggregated or deleted.
  • Audit logs: retained for at least 1 year for security and compliance purposes.
  • Billing records: retained for 7 years to comply with tax and accounting laws.

10. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children.

11. Changes to this policy

We will post changes to this policy on this page and update the Effective date. Material changes will be communicated via email to account administrators.

12. Contact

Questions about this policy or your data: [email protected].

Command Palette

Search for commands, pages, or recent jobs