Legal
All policies
Every policy in one place, including the ones that say what has not been done.
Last updated 21 August 2026
Everything that governs how the platform is run and used. Where a policy describes something not yet built, it says so rather than being written in the present tense.
- Terms of Service
- The terms on which the service is provided.
- Privacy Policy
- What personal data is held, why, and what is never done with it.
- Acceptable use
- No unlawful content, no attempts to reach another tenancy, no automated traffic that degrades the service for others. Security testing against your own tenancy is welcome — tell us first.
- Security disclosure
- Report a vulnerability to hello@construx.ai with SECURITY in the subject. We will not pursue anybody acting in good faith within their own tenancy, and we will credit you unless you ask us not to.
- Data retention
- The event chain is retained for the life of the tenancy. Notification delivery records are retained because "we told you on the 14th" must stay answerable. Bounded operational logs rotate and are never the source of a metric.
- Sub-processors
- The SMTP relay, and the AI providers named on each AI event with model class and cost. Any channel with no provider configured records as dispatched-not-transmitted.
- AI usage
- No agent mandate above PROPOSE. Governance decisions refuse AI authorship at the catalogue level. Costs are quoted before an action runs and charged against the wallet with a ledger entry.
- Accessibility
- Semantic markup and keyboard focus are in place. Neither has been audited against WCAG, and we will not claim conformance we have not tested.
This document describes how the platform behaves. Where it states a technical guarantee — chaining, redaction, tenancy isolation, notice handling — that behaviour is implemented and tested, and the corresponding test is the thing that keeps this page true.