我們正在招募 Forward-Deployed Engineer查看職缺

Legal

Privacy Policy

Last updated

本頁目前僅提供英文版本。

This policy explains how Operon Solutions, Inc. ("Operon", "we", "us") collects, uses and protects personal information. It covers our website, operonsolutions.com, and our software services, including the Operon P&ID platform and the Operon HVAC takeoff application at hvac.operonsolutions.com (together, the "Services").

1. Who is responsible for your information

  • Your account and our website. Operon is responsible for the account and website information described here.
  • Content your company uploads. This means drawings, documents, takeoffs and similar work. We process it on behalf of the organization that holds the subscription (the "Customer"), following its instructions.
  • If you use the Services through your employer, your employer controls that content. Send requests about it to your workspace owner, and we will help them respond.

2. Information we collect

  • Account information. Your name, work email address and password. Passwords are stored only as a one-way salted hash, so we never see them. We also keep the workspaces you belong to and your role in each.

  • Sign-in with Google or Microsoft. If you choose this, the provider sends us:

    • your name and email address
    • whether the provider has verified that address
    • a unique identifier for your account (for Microsoft, also your organization's directory identifier)

    We never receive your Google or Microsoft password. We do not request access to your email, files, contacts or calendar.

  • Workspace content. The drawings and documents your organization uploads, such as PDF drawing sets. It also includes what you create in the Services: takeoff quantities, markups, review decisions, comments, templates and exported files.

  • License and administration records. These include:

    • your company's name, owner contacts, number of seats, license term and price
    • invitations, requests for more seats and requests to join a workspace
    • an audit record of license and access changes
  • Communications. Messages you send us, including in-app feedback. Feedback can include screenshots you choose to attach and an email address for our reply.

  • Security and technical information.

    • A session record while you are signed in.
    • Short-lived counters that limit repeated failed sign-in attempts. These are derived from your IP address and email address, and stored only as one-way hashes.
    • Standard request data, such as IP address and browser type, which our hosting and network providers may process in their operational logs.
  • What we don't collect: payment card details. Licenses are invoiced.

3. Cookies and browser storage

The Services use only the cookies needed to sign you in:

  • a session cookie that keeps you signed in for up to 7 days
  • a cookie that lasts 10 minutes and protects sign-in with Google or Microsoft

Your browser also stores display preferences on your device, such as the light or dark theme. It keeps your unsaved edits too, so they survive a dropped connection; these are cleared when you sign out.

The Services do not use advertising or analytics cookies.

Our website, operonsolutions.com, uses Arrivl, a website analytics service. Each time you load a page, our server sends Arrivl the page address, the page you arrived from, your browser's user-agent string and your IP address. Arrivl does not set cookies in your browser.

4. How we use information

We use personal information to:

  • provide and operate the Services, including:
    • signing you in
    • applying workspace permissions and license seat limits
    • storing and processing your organization's drawings
    • producing takeoffs and exports
  • run AI-assisted takeoff when it is enabled (see section 6)
  • send messages about the Services: invitations, password resets, seat and access notifications, and service or security notices
  • provide support, fix problems, and improve the reliability and usability of the Services
  • protect the Services and our customers, for example by detecting abuse, investigating incidents and keeping audit records
  • meet legal obligations and enforce our Terms of Service

What we don't do:

  • We do not sell personal information.
  • We do not use it for advertising.
  • We do not use your organization's content to train AI models, ours or anyone else's.

5. Google and Microsoft sign-in

When you sign in with Google, we request only the basic sign-in permissions: your identity, email address and basic profile. We use this information only to:

  • sign you in
  • match you to your Operon account or invitation
  • keep your account secure

We do not use it for advertising, do not sell it, and share it only with the service providers who host the Services (section 7).

Operon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft sign-in works the same way, with the same limits.

You can remove Operon's access:

  • Google: in your account's third-party connections
  • Microsoft: in your Microsoft account settings, or through your organization's administrator

6. AI processing

The HVAC takeoff application can prepare a draft takeoff with AI. When this feature is enabled for the Services, the following happens:

  • drawings uploaded to start a takeoff are sent automatically to our AI provider, OpenAI
  • relevant page images and extracted text go along with them
  • the result is a draft for your team to review and correct

Our requests to OpenAI are made with its response-storage option turned off. Under OpenAI's API policies:

  • data sent through its API is not used to train OpenAI's models
  • it may be kept for up to 30 days to detect abuse, then deleted

AI results are drafts. Your original drawings and your team's own work are kept separately, and your team decides what to keep.

If your organization does not want its drawings processed by AI, contact us before uploading.

7. How we share information

We share personal information only as follows:

  • Service providers that process data for us under contract, and only to run the Services:
    • Google Cloud: hosting, database and file storage, in the United States
    • Cloudflare: domain, network security and encrypted backup storage
    • OpenAI: AI processing, in the United States
    • Resend: sending service emails
  • Google and Microsoft, when you choose to sign in with them.
  • Within your organization.
    • Workspace owners can see members' names, email addresses, roles and invitations.
    • Members of a workspace can see the projects and work in it, according to their roles.
  • Legal reasons. When required by law, or to protect the rights, property or safety of Operon, our customers or others.
  • Business transfers. If Operon is involved in a merger, acquisition or sale of assets. We will tell you if your information becomes subject to a different privacy policy.
  • With your consent. In other cases you agree to.

8. Where information is stored

We store data in the United States, using Google Cloud in its Iowa region. Encrypted backups are kept with Cloudflare.

If you are outside the United States, including in Canada, your information will be transferred to and processed in the United States. While there, it may be accessible to authorities under that country's laws.

9. How long we keep information

  • Account information: kept while your account is active. Deleted when you ask, unless we need to keep some of it for legal, security or accounting reasons.
  • Workspace content: kept for the length of your organization's subscription.
    • When a subscription ends, the workspace stays available to view and export for the grace period in your organization's license.
    • We then delete workspace content within 30 days, or sooner if the Customer asks us in writing.
  • Backups: encrypted backups are kept for up to 90 days and then deleted automatically. Deleted information can remain in a backup until that backup expires.
  • License, access and audit records: kept as long as needed for legal, accounting and security purposes.
  • Feedback: kept for as long as we need it to respond and improve the Services.

10. Security

Our safeguards include:

  • encryption in transit (HTTPS) and encryption at rest by our hosting providers
  • passwords hashed with Argon2
  • database-level separation, so one company's workspace cannot read another's
  • sign-in protections against repeated failed attempts
  • an append-only audit log of license and access changes
  • regular encrypted backups

No system is perfectly secure. If a breach affects your personal information, we will notify you and the appropriate authorities as the law requires.

11. Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal information we hold about you
  • correct it
  • delete it
  • receive a copy of it
  • object to or limit certain uses
  • withdraw consent

To make a request, email privacy@operonsolutions.com. We will confirm your identity and respond within 30 days.

For workspace content controlled by your employer, we will forward your request to your organization or act on its instructions.

You may also complain to the data protection authority where you live.

12. Children

The Services are for businesses and are not directed to children under 16. We do not knowingly collect their information.

13. Changes to this policy

We will post any changes on this page and update the date at the top. If a change is significant, we will also notify workspace owners by email or in the Services before it takes effect.

14. Contact us

Operon Solutions, Inc.
131 Continental Dr, Suite 305
Newark, DE 19713, United States
Privacy questions and requests: privacy@operonsolutions.com