Privacy Policy
Manufacturing PLM holds the definition of your product — the thing your business is. This page states what we collect, why we are allowed to, how long we keep it, and the two commitments that matter most: your product data is yours, and it is never used to train a model.
Who this applies to, and the two roles involved
Manufacturing PLM is operated by dev.co. This policy covers the marketing site at manufacturing.co/plm and the application at plm.erp.io.
There are two distinct relationships and they carry different obligations. For account data — the name and work email of the person who signs in, billing contacts, support correspondence — we are the controller, and this policy governs it.
For tenant content — your parts, structures, documents, changes, suppliers and everything else you put into the product — we are a processor acting on your instructions. Your own privacy notice governs that data, and the terms under which we process it are set by the data processing agreement, not by this page. Where the two disagree, the agreement wins.
What we collect
Deliberately little, and nothing whose purpose we cannot state in a sentence.
- Account data — name, work email, organisation, role and authentication identifiers. Necessary to give you an account and to tell two users apart.
- Tenant content — everything you or your colleagues create in the product. We hold it, index it and back it up. We do not mine it.
- Operational telemetry — request timing, error traces, job outcomes and feature usage counts, attributed to a tenant and a user id. Used to keep the service up and to find out which screens are slow.
- AI usage records — which agent ran, at which permission tier, which tools it called, how many tokens it consumed and what it cited. Kept because you are billed for it and because an agent action has to be auditable.
- Billing data — plan, seat counts and invoices. Card details are handled by our payment processor and never reach our servers.
- Support correspondence — what you write to us, and what we write back.
What we do not collect
There are no advertising, analytics or session-replay trackers on either the marketing site or the application. Site analytics are server-side and aggregate, derived from request logs rather than from anything stored in your browser.
That is why there is no cookie banner. The only cookies set are the session cookie that keeps you signed in and, on this site, the single localStorage entry recording whether you chose the dark theme. Neither is used to build a profile, and neither is shared.
We do not buy personal data, enrich your account from third-party data brokers, or sell anything to anyone. There is no version of this business in which that would be a good trade.
Your product data is yours
You retain all rights in your tenant content. Our licence to it exists solely to run the service for you — to store it, index it, resolve it, back it up, and show it to the people you have authorised.
We do not access tenant content except in three narrow circumstances, each of which leaves an audit record: when you ask us to, in the course of support; when it is necessary to investigate an incident affecting service integrity; and where we are compelled by law, in which case we will tell you unless legally prohibited from doing so.
Nothing is shared between tenants. Isolation is enforced as a predicate at the data layer rather than as a check in application code, and external supplier sessions narrow a second time. This is described in more detail, with the specific mechanism, on the tenant isolation page.
AI processing, and the training commitment
This is the section most buyers turn to first, so it is stated plainly. We do not use your tenant content to train, fine-tune or improve any model, ours or anybody else's. Not with anonymisation, not with aggregation, not on an opt-out basis.
When an agent runs, the relevant objects are sent to a model provider under a zero-retention arrangement to produce that answer, and that is the end of it. Prompts and completions are not retained by the provider for training. Where you bring your own key, requests go to your own account under your own contract and we never see the content at all.
You control what agents may do. Each agent holds one of four permission tiers per tool per tenant — Observe, Recommend, Prepare, Execute — and agents cannot exceed the permissions of the user they act for. Every agent action is recorded in a hash-chained audit trail naming the agent, its tier, the tools it called and the object revisions it cited.
Agents can be disabled entirely at tenant level. Doing so removes agent features; it does not degrade anything else in the product.
Why we are allowed to process it
For account data, our lawful bases under the UK and EU GDPR are: performance of a contract, for anything necessary to provide the service you have subscribed to; legitimate interests, for keeping the service secure, preventing abuse and understanding which features are used, balanced against your interests and documented; and legal obligation, for tax and accounting records.
We do not rely on consent for anything in the product, because a service you cannot use without agreeing is not a free choice. Marketing email is the exception and is opt-in, with a working unsubscribe link in every message.
For tenant content we act on your documented instructions as processor. The lawful basis for that data is yours to determine, and your data processing agreement records it.
Sub-processors and where data is held
We use a small number of sub-processors, each under a written agreement with confidentiality and security obligations at least as protective as those we owe you. The current list, what each one does and where it is located is published on the sub-processors page and maintained as a living document.
Production data is held in the European Union by default. Where a sub-processor operates outside the UK or EEA, transfers are made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, with a transfer risk assessment on file.
Regional data residency — pinning a tenant's data to a named jurisdiction — is not yet offered. It is a tracked commitment for the first customer whose contract genuinely requires it, and we would rather say so here than discover it during your procurement review.
How long we keep it
Tenant content is kept for as long as your subscription is active. On termination it remains available for export for thirty days, is then deleted from live systems within a further thirty days, and expires from encrypted backups within ninety days of that.
Account data is kept for the life of the account and for one year afterwards, so that a returning customer is not a stranger and so that an access request can still be answered. Billing records are kept for seven years, which tax law requires and we do not get to choose.
Operational telemetry is retained for ninety days. Audit trail records are retained for the life of the tenant, because an audit trail with a rolling window is not an audit trail — the entries you most need are always the old ones.
Your rights
If you are in the UK or EEA you may request access to the personal data we hold about you, correction of anything inaccurate, erasure, restriction of processing, portability in a machine-readable format, and you may object to processing carried out under legitimate interests. If you are in California you have equivalent rights of access, deletion, correction and portability, and a right not to be discriminated against for exercising them.
Write to the address below and we will respond within thirty days. There is no charge, and no requirement to explain why you are asking.
Where the request concerns tenant content rather than your own account data, we will refer you to the customer who controls that tenant — we are not permitted to act on their data without their instruction, and a processor that honoured such requests directly would be a poor one to trust with yours.
You may complain to a supervisory authority at any time. In the UK that is the Information Commissioner's Office. We would appreciate the chance to fix it first, but that is a preference and not a precondition.
Security, breaches and changes to this policy
Data is encrypted in transit and at rest. Access to production is limited to named engineers, requires multi-factor authentication, and is logged. The security review pack sets out the isolation design, the audit chain and the access control model in full, and it is published rather than gated behind a sales call.
In the event of a personal data breach affecting tenant content we will notify the affected customer without undue delay and in any case within seventy-two hours of becoming aware, with what we know, what we do not yet know, and what we are doing about it.
When this policy changes materially we will tell account administrators by email at least thirty days before it takes effect, and the previous version will remain available. Questions, requests and complaints: privacy@dev.co.