Privacy Policy

Effective date: 1 June 2026  ·  Last updated: 30 July 2026

This Privacy Policy explains how Architectena ("we", "us", or "our") collects, uses, and protects your personal data when you use the Architectena platform at architectena.com. We are committed to protecting your privacy and handling your data in accordance with the General Data Protection Regulation (GDPR) and applicable Egyptian data-protection law.

1 Who we are

Architectena is operated by Architectena Co., based in Cairo, Egypt. As the data controller, we are responsible for deciding how and why your personal data is processed.

Data Controller

Architectena Co.

Cairo, Egypt

info@architectena.com

2 Data we collect

Data you provide directly

  • Account details — full name, email address, username, password (stored hashed)
  • Profile information — birthdate, nationality, phone number, profession, bio, location, website
  • Media — profile avatar, cover photo, portfolio images, project files, and other uploads
  • Content you create — posts, comments, project descriptions, group messages, job listings, résumé data
  • Communications — messages sent through the platform, contact-form submissions

Data collected automatically

  • Log data — IP address, browser type, operating system, pages visited, and timestamps, retained in server logs for security and abuse-prevention purposes
  • Session data — a session cookie required to keep you signed in
  • Error and diagnostic data — when a technical error occurs, limited diagnostic information (which may include your IP address and the page you were viewing) is recorded so we can diagnose and fix the problem

We do not use advertising networks, third-party analytics services (such as Google Analytics), or tracking pixels of any kind. Our own first-party, aggregate usage measurement is described in the Cookies section below.

3 How we use your data

We use your personal data to:

  • Create and manage your account and public profile
  • Provide platform features — feed, groups, jobs, projects, messaging, and search
  • Send transactional emails — account verification, password reset, follow and job notifications
  • Detect and prevent fraud, abuse, and unauthorised access
  • Comply with legal obligations

We do not use your data for advertising or for profiling for marketing purposes. We do use automated systems for safety: images you upload are scanned for explicit content, and text is checked against keyword rules. A positive match can result in the file being deleted, a post being unpublished, or — after repeated matches on the same account — an automatic suspension, which can escalate to a permanent ban. You are notified whenever we act against your account, and you can appeal; those notices cannot be switched off. Every other enforcement decision, including action on a report from another member, is reviewed by a person.

4 Legal basis for processing (GDPR)

  • Contract — processing your account, profile, and content data is necessary to provide the service you signed up for.
  • Legitimate interests — security logging and abuse prevention, where our interest in protecting the platform does not override your rights.
  • Legal obligation — where processing is required by applicable law.
  • Consent — for non-essential cookies, if we ever set any. We do not set them today, and we would ask you first. You could withdraw that consent at any time.

5 Data sharing and third parties

We do not sell, rent, or trade your personal data. We share data only with the service providers we rely on to operate the platform, each acting as a data processor on our behalf:

  • Cloudflare — network, content delivery, and file storage. All traffic to the platform passes through Cloudflare, which terminates the connection and therefore sees every request, including your IP address; it also tells us the country your request came from. Files you upload are stored on Cloudflare R2 — public files such as avatars, cover photos, portfolio images and project files in one bucket, and sensitive documents such as CVs, cover letters and office verification documents in a separate private bucket that is never served publicly. Cloudflare acts as a data processor; it is based in the United States and relies on Standard Contractual Clauses for GDPR-compliant transfers.
  • Hetzner — our hosting provider. The platform's servers and database run on Hetzner infrastructure located in Germany, within the European Economic Area (EEA).
  • Resend — our transactional email provider. Your email address and the content of system-generated emails (e.g. verification links, notifications) are transmitted to Resend solely to deliver those messages. Resend acts as a data processor under a Data Processing Agreement and does not use your data for its own purposes. Resend is based in the United States and relies on Standard Contractual Clauses for GDPR-compliant international transfers.
  • AI provider — the writing, translation and alt-text tools send the text — and, for alt-text and cover suggestions, the image — to a third-party AI provider to generate the result. This happens only when you use one of those tools, never in the background, and it is our provider's terms rather than ours that govern what they do with it. We do not use your content to train any model of our own.
  • Dodo Payments — our payment processor, acting as Merchant of Record for paid plans. If you subscribe, Dodo collects and processes your payment details and billing information directly — we never see or store your card number. We receive and keep a record of the transaction, including the payment identifiers Dodo returns to us. Dodo's own privacy policy governs what it does with your payment data.
  • Google — two separate roles. If you choose "Sign in with Google", Google confirms your identity to us and we receive your name and email address. Separately, the fonts used across the platform are served by Google Fonts, which means your browser contacts Google on page load and Google receives your IP address as a result. We do not use Google Analytics or any Google advertising product.
  • OpenStreetMap — maps and address lookup. When a map is shown, or when you pin a location on a job or project, your browser requests map tiles and address lookups from OpenStreetMap and its Nominatim service. Those requests include the coordinates being looked up and your IP address.
  • Content delivery networks — some scripts and stylesheets are served from public CDNs (jsDelivr, code.jquery.com, unpkg). Your browser contacts them on page load, and they receive your IP address as a result.
  • Sentry — error monitoring. When the platform encounters a technical error, diagnostic data about the failure is sent to Sentry so we can diagnose and fix it. We have configured Sentry not to attach personal data to these reports — it does not receive your IP address, cookies, or the contents of your request. Sentry acts as a data processor and is based in the United States.

We may also disclose your data if required by law, court order, or to protect the rights and safety of Architectena or its users.

6 International data transfers

Architectena Co. is based in Cairo, Egypt, and runs its primary servers and database with Hetzner in Germany, within the European Economic Area (EEA). Some of your data is also processed outside the EEA — including by Cloudflare, Resend, Sentry, Dodo Payments and Google, which operate in the United States. Where those providers offer Standard Contractual Clauses approved by the European Commission, our agreements with them rely on those clauses. As an Egyptian company we are subject to the Personal Data Protection Law No. 151 of 2020, and we comply with it. We are not established in the European Union and have not appointed a representative there under Article 27 of the GDPR. We describe the rights below in GDPR terms because they are a good standard and we intend to honour them for everyone, wherever you live — not as a claim to be established in the EU or supervised by an EU authority. Nothing here affects rights you have under the law of your own country.

7 How long we keep your data

  • Active accounts — data is kept for as long as your account remains open.
  • After account deletion — deletion happens immediately when you confirm it, not on a delay. Your profile, your posts and projects, and the files you uploaded are removed as part of the request. There is no recovery period.
  • Kept after deletion — a small number of records outlive the account, and we would rather tell you than let you assume otherwise. Payment records, including the transaction data our payment processor returns to us, are kept for tax and accounting purposes and to defend a chargeback or dispute. Moderation and security audit records — what action was taken and why — are kept so decisions remain reviewable. Analytics and search records are kept for the windows listed above, with your account detached from them, which means they can no longer be traced back to you. If you want any of these reviewed, email us and we will look at whether we still need them.
  • Searches, and who looked at your profile — when you search we store the query text together with the filters you applied, so we can improve results and see what people cannot find. When someone views your profile we store the fact and the date, but not who they are: the viewer is recorded as a one-way cryptographic hash, so we can tell you how many people looked and we cannot tell you — or ourselves — which people they were. That is a deliberate design choice, and it is why no "who viewed your profile" feature exists.
  • Your own activity log — significant actions on your account — sign-ins, changes to your email or password, publishing, moderation actions taken against you — are recorded and shown back to you in your account activity page. Failed sign-in attempts are recorded too: five failures within an hour lock the account for an hour, which is there to protect you.
  • Usage and analytics records — page-visit records are kept for 365 days, search records and profile-view records for 180 days, and activity records for 365 days. Each of these is deleted automatically on a nightly schedule.
  • Sessions — your sign-in session lasts one week; the record is deleted automatically once it expires.
  • Notifications — read notifications are deleted after 90 days.
  • Backups — we take a nightly backup of the database so we can recover from a failure. Backups are stored in Cloudflare R2, kept for 30 days and then deleted automatically, so data you delete may persist in a backup for up to that long before it ages out.
  • Server logs — retained for up to 90 days for security purposes, then deleted.

8 Cookies

We group cookies and similar storage into three categories. Today we set only the strictly-necessary ones, so no cookie-consent banner is shown. If we ever add analytics or advertising cookies, we will ask for your consent through a banner before any non-essential cookie is set.

1. Strictly necessary — always active

  • The full list — we set six cookies at most, and none of them track you across other sites: sessionid keeps you signed in (one week), csrftoken protects forms against cross-site submission, django_language remembers your interface language (one year), theme remembers light or dark (one year, and readable by the page's own scripts because that is how the theme is applied before the page paints), arch_consent records your answer to a consent banner, and arch_vid is a two-hour visit identifier we only set if you consent to it — today nobody has, because consent defaults to no.
  • Session cookie — keeps you signed in. It lasts one week, or until you sign out. The matching server-side session record is deleted when it expires.
  • CSRF token — a security token that prevents cross-site request forgery attacks on forms.
  • Language preference — remembers whether you chose English or Arabic.
  • Theme preference — remembers your chosen light or dark theme.
  • Consent choice — if you are ever asked about cookies, this remembers your answer so we don't ask again.

2. Analytics — We measure aggregate site usage — pages viewed, the site you arrived from, your approximate country (from your IP address), and device type — to understand traffic and improve Architectena. This measurement is first-party and recorded on our own servers under our legitimate interest; we do not sell or share it, and raw records are kept for up to 12 months. We do not currently set any analytics cookie on your device.

3. Advertising — We do not show ads and set no advertising or tracking cookies. If that changes, we will request your consent through a cookie banner before any advertising cookie is set, and you will be able to withdraw it at any time.

9 Your rights

Under GDPR, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your data ("right to be forgotten"). One exception: if you manage an office, you cannot delete the account until that office is transferred to someone else or removed, because deleting it would take the office and everything published under it with you. Contact us and we will help you transfer it.
  • Restriction — ask us to pause processing of your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw consent — where processing relies on your consent, you may withdraw it at any time without affecting prior processing.

Many of these rights can be exercised directly through your account Settings page. For requests that cannot be completed there, contact us at info@architectena.com. We will respond within 30 days. If a request is complex or you have made several, we may extend that by a further 60 days — we will tell you within the first 30 days if we need to, and why. We may ask you to confirm your identity before we act on a request about an account, so that nobody else can use these rights against you.

You also have the right to lodge a complaint with your local data-protection supervisory authority. EU residents may contact their national authority; other users may contact the relevant authority in their jurisdiction.

10 Security

We implement technical and organisational measures to protect your data against unauthorised access, loss, or disclosure — including HTTPS encryption in transit, hashed password storage, and restricted database access. No transmission over the internet is completely secure; we will notify you promptly if a breach affecting your data occurs.

End-to-end encryption for direct messages. One-to-one direct messages are end-to-end encrypted by default: their text and attachments are encrypted in your browser and can be read only by you and the recipient. Our servers store and relay the ciphertext but cannot read it, and it is never used for search, previews, or link fetching. Group, job, and office conversations are server-managed (so moderation, safety scanning, and content search can run) — protected in transit and at rest, but not end-to-end encrypted. So are the conversations attached to a post, a project, a project team or a client liaison: end-to-end encryption applies to one-to-one direct messages only.

Three things to know about it. It applies to threads created after the feature shipped, not retrospectively to an older thread. Either participant can switch it off for a thread, and the other is told. And because we hold only ciphertext, a data export of an encrypted thread contains ciphertext — we cannot decrypt it for you, which is the same property that stops us reading it. If you lose both your password and your recovery code, the message history in your encrypted threads cannot be recovered by anyone, including us. That is the design, not a fault.

11 Children

Architectena is intended for users who are 16 years of age or older. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has registered, please contact us and we will delete the account.

12 Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, notify you by email or an in-platform notice. Continued use of Architectena after changes take effect constitutes acceptance of the revised policy.

13 Contact us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your data, please contact us:

Privacy enquiries

info@architectena.com