Política de Privacidade
Esta página está disponível apenas em inglês por enquanto. A versão em português, adaptada à LGPD, está em preparação.
Tempus 7 is a software-as-a-service platform for construction bid management, CRM, and field operations. This policy describes what data we collect, why, and how we use and protect it.
Última atualização: 2026-08-04 (substitui a versão de 2026-08-03; acrescenta a seção sobre importação de dados assistida por IA). Alterações relevantes serão comunicadas aos usuários ativos por e-mail com pelo menos 14 dias de antecedência.
1. Quem somos
The Tempus 7 service is provided by Lloyd Consulting Services (“we,” “us”). For privacy questions, contact privacy@tempus7.com.
2. Nosso papel em relação aos seus dados
For account and billing data, we decide how data is processed. For the business data inside a tenant — including data about a tenant's employees and field crews — the tenant organization is in charge of the data and we process it on their behalf and at their direction. If you are an employee of a company that uses Tempus 7, your employer controls that data; privacy requests about it should go to your employer first, and we will support them in fulfilling it.
3. Dados que coletamos
- Account data: name, email, role, the tenant organization you belong to, and authentication credentials (password hashes, not plaintext).
- Business data you create: customers, bids, projects, RFIs, submittals, drawings, daily logs, change orders, files, and other operational records you enter or upload.
- Time and location data: where a tenant uses the time-tracking module, we record clock-in and clock-out events, which may include precise device location captured at those moments (not continuous tracking). This data is visible to the worker and their employer and is used for timekeeping and payroll purposes.
- Files and photos: documents and photos you upload, which may contain embedded metadata (such as capture time or location) from the device that created them.
- External collaborator data: when a tenant shares an item (for example, a submittal review link) with someone outside their organization, we process that person's name, email, and access events for the shared item.
- Demo visitors: the public demo is an anonymous, shared sandbox. We set session cookies to make it work and apply rate limiting by IP address. Anything typed into the demo may be seen by other visitors and is deleted on a recurring schedule — don't put real data there.
- Usage data: request logs, IP addresses, user agent, timestamps, feature interactions, in-product feedback you submit, and training progress (which guided walkthroughs a user has completed).
- Email metadata: delivery, bounce, and complaint events from our transactional email provider. Used to maintain sender reputation and suppression lists.
- Billing data: subscription billing is handled by Stripe. Payment details (card numbers, bank account numbers) go directly to Stripe and never touch our servers; we hold the billing contact, plan, and invoice status.
4. Conexão com o QuickBooks Online
Tenants can optionally connect their QuickBooks Online account. When connected:
- What we access: accounting data needed for the sync features the tenant enables — such as customers, vendors, invoices, bills, and payments — exchanged in both directions at the tenant's direction.
- Why: solely to keep the tenant's Tempus 7 records and QuickBooks records consistent. We do not use QuickBooks data for any other purpose, do not sell it, and do not use it to train AI models.
- How it's protected: the OAuth tokens that authorize the connection are encrypted at rest with an application-level key, on top of infrastructure encryption. A per-tenant sync log records what moved and when, visible to the tenant.
- Disconnecting: tenants can disconnect at any time from Settings, which revokes the connection and deletes the stored tokens. Synced business records the tenant chose to import remain part of their tenant data.
- Intuit's handling of data on their side is governed by Intuit's privacy statement. Tempus 7 is not affiliated with or endorsed by Intuit Inc.
5. Importação de dados assistida por IA (opcional)
Three optional features use Anthropic's Claude AI to read files you upload. Each runs only when you use it, and nothing it produces is saved until you review and approve it. Every feature also has a manual path that uses no AI.
- Spreadsheet import wizard (Settings): only your file's structure is sent — sheet names, column headers, row counts, and up to five sample rows per sheet with emails, phone numbers, and street addresses masked before sending. The rest of the file is parsed on our servers and not sent.
- Supplier quote import (Cost book): the vendor quote PDF you upload is sent in full so the AI can read its line items and prices. We don't keep the PDF; the extracted lines are kept for you to review.
- Proposal layout import (Brand): the proposal PDF you upload is sent in full so the AI can suggest a matching layout and pull out your standing terms. Nothing is saved until you approve it. A blank template or a sample without real customer details works just as well, and we recommend it.
- Anthropic's handling: requests are made under Anthropic's commercial terms — inputs and outputs are not used to train their models.
- No content logging: we log only metadata about each request (which feature, counts, timing), never the contents. Uploaded files are processed in memory and are not stored by these features.
- Scope: the wizard imports customers, cost book items, and scope lists. It never handles employee time, GPS, or login data.
6. Como usamos os dados
- To operate the service: authenticate you, store and serve your data, process subscriptions, send transactional emails (invitations, password resets, notifications, review links).
- To support you: respond to questions, diagnose issues you report.
- To secure the platform: detect abuse, fraud, and integrity events.
- To improve the product: aggregate usage analytics. We do not sell your data and we do not use your business data to train AI models.
7. Quem tem acesso
- Within your tenant: users in your organization see the data your role and tenant settings allow them to.
- Cross-tenant isolation: users in other tenants cannot see your data. This is enforced at multiple layers (application authorization + database row-level security).
- People you share with: external collaborators see only the specific items shared with them, through expiring, revocable links.
- Sub-processors we rely on: Amazon Web Services (hosting, database, file storage), Microsoft (transactional email during our SES transition), GoDaddy (DNS), Stripe (subscription billing), and Anthropic (AI-assisted import suggestions — structure and masked samples only, as described above). See the full list with purposes and data categories at /sub-processors.
- We do not sell or rent your data to any third party.
8. Localização e segurança dos dados
Data is stored in Amazon Web Services data centers in the United States (currently us-east-1). Connections use TLS 1.2+. Data at rest is encrypted via AWS-managed encryption; integration credentials (such as QuickBooks tokens) carry an additional application-level encryption layer. Passwords are hashed with bcrypt; we never store plaintext passwords. Access inside the platform is governed by role-based permissions, and write operations to business records are captured in an append-only audit log.
9. Retenção
We retain account and business data for the duration of your subscription plus a wind-down period (typically 30 days after termination) for export, recovery, and dispute purposes. Audit logs and request logs are retained for up to 90 days. Demo-sandbox data is deleted on a recurring schedule. You may request earlier deletion under section 10.
10. Cookies e rastreamento
We use first-party cookies strictly to keep you signed in (session cookies, including in the public demo) and to remember user-interface preferences (e.g., light/dark mode). We do not use third-party analytics or advertising cookies. We do not embed third-party trackers on application pages.
11. Seus direitos
- Access and export the data we hold about you
- Correct inaccurate data
- Delete your account and associated personal data
- Object to or restrict certain processing
Email privacy@tempus7.com with your request; we respond within 30 days. If your data is controlled by your employer's tenant (section 2), we may route the request through them, as required.
12. Crianças
Tempus 7 is a workplace tool and is not directed to children. We do not knowingly collect data from anyone under 16.
13. Contato
Privacy questions: privacy@tempus7.com
Security disclosures: security@tempus7.com