Privacy Policy
Last updated: 23 July 2026
Who we are
Tech Box d.o.o. ("we", "us") provides TerenIQ construction field operations software at tereniq.com, app.tereniq.com and through our iPhone and Android apps. This policy explains what personal data we handle and why. For any privacy question, write to hello@tereniq.com.
Our role and legal basis
Tech Box d.o.o. is the controller for account administration, billing, security and direct support data. Your company decides what workplace and project content its users enter into TerenIQ; for that content, your company is the controller and Tech Box d.o.o. acts as its processor to provide the service.
The terms on which we process that content for your company are set out in our Data Processing Agreement.
Our legal basis depends on the purpose: we process account, project and subscription data to perform the service agreement; protect accounts and comply with financial or other legal obligations where required by law; and rely on legitimate interests for service security, fraud prevention and essential operational communications. Features that use your device's camera, microphone, location or notifications remain under your device control and are used only when you choose or enable them.
What we collect
Account data (your name, work email, company name and password hash), optional profile and directory details (profile photo, phone number, role and trade), the records your company creates in the product (projects, tasks, comments, inspections, issues, RFIs, daily reports, permits, safety briefs and directory entries), and the media you attach to them (photos, videos, voice notes, documents, drawings and signatures). Field records can include precise GPS coordinates and timestamps because that is what makes them useful as evidence. We only request location while you use a feature that needs it; TerenIQ does not track your location continuously in the background.
If you enable notifications, we store the push-notification token needed to deliver them. Android uses Firebase Cloud Messaging and iPhone uses the Apple Push Notification service. The Android app also uses a per-installation Firebase identifier for reliable notification delivery. If your company buys a plan through the App Store, we store the subscription product, transaction identifier, status and expiry details needed to activate and maintain that plan. Apple processes the payment details; TerenIQ does not receive your full card or bank-account information.
What we do not do
We do not sell your data, we do not run advertising, and we do not use your project records for anything except operating the service. We do not use cross-app tracking. The marketing site you are reading sets no analytics cookies.
International transfers
Some service providers may process data outside your country. Where an international transfer of personal data requires safeguards, we use an adequacy decision, approved standard contractual clauses or another lawful transfer mechanism and require the recipient to protect the data consistently with this policy.
Where data lives
Application records are stored in Cloudflare D1 and file attachments in Cloudflare R2. Traffic is encrypted in transit with TLS. Access inside the product is controlled by your company's roles, from owner down to guest.
Service providers
We use Cloudflare to host and protect the service, Apple to process App Store purchases and deliver iPhone push notifications, Google Firebase to deliver Android push notifications, Mapbox to render maps and location pins when you use mapping features, and transactional-email providers to send account and service messages. They may process only the data needed to provide those services and must protect it consistently with their agreements and applicable law. Mapbox may receive device, network and location information when its map is displayed and location access has been authorized. We do not use advertising networks or cross-app tracking SDKs.
Each provider is named, with what it processes and where, on our sub-processors page.
Notifications
If you enable push notifications, we store a device token to deliver assignment, overdue and mention alerts. You can disable push at any time in iOS or Android system settings; email notifications can be managed in the product.
Retention and deletion
Your records stay available while your company account is active. To control storage, each workspace has a data-retention setting (chosen by the owner or an admin): completed work — tasks and, optionally, closed issues, RFIs, inspections and signed handovers — is automatically and permanently deleted after a chosen period (90 days by default, or never), including its photos, videos and comments. You can change or disable this in Settings → Data retention.
Trials that are never activated are removed: if a workspace does not move to a paid plan within 90 days after its free trial ends, the account and all of its data are permanently deleted. We email the workspace owners beforehand. You can also ask us to delete your company data at any time. In the iPhone or Android app, an individual user can permanently delete their account from Settings → Legal → Delete account. You may also request account deletion by emailing hello@tereniq.com with the subject “TerenIQ account deletion”; we will verify the request before deleting the account and associated personal data, except records we must retain by law or that belong to a company workspace under its retention instructions. If that user is the only owner of a workspace that still has other members, ownership must be transferred or those members must be removed first so the workspace is not orphaned.
How long we keep each kind of data
Workspace content follows your company's retention setting, described above. Beyond that: account and profile data are kept while the account exists and deleted with it; invoices and the accounting records behind them are kept for eleven years from the end of the business year they relate to, because Croatian accounting law requires it; audit records of administrative actions on accounts are kept for two years; sign-in sessions and device records are kept until they expire or you revoke them, and expired rows are swept away; notification history is deleted after six months; scheduled-job records are kept for thirty days; aggregate delivery counters hold no personal data and are kept indefinitely.
Backups are overwritten on their ordinary cycle, so a record you delete may persist in a backup for a short period before it is cycled out. It is not restored into the live service.
Automated decisions
We do not make decisions about you based solely on automated processing, and we do not profile you. Features that score or flag work — an inspection pass threshold, an overdue marker, a weather advisory — evaluate records, not people, and produce no legal or similarly significant effect on any individual.
Sensitive information
TerenIQ does not ask for special categories of personal data. Some fields are free text — safety briefs, incident notes, daily reports — and a user could type health information into them, for example about an injury on site. Where that happens, the company running the workspace is the controller for it and is responsible for having a lawful basis under article 9 of the GDPR. We ask that such details be kept to what the record genuinely requires.
Age
TerenIQ is a workplace tool for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, write to hello@tereniq.com and we will delete it.
Getting a copy of your data
You do not have to ask us. In the product, Settings → Privacy lets any user download their own personal data, and a workspace owner or administrator can download the whole workspace data set. Both arrive as a JSON file. Files stored in the workspace are downloaded from the app itself; the export carries their details, not the files.
Your rights
You can request access to, correction of, deletion of, restriction of, or a portable copy of your personal data, and object to processing based on legitimate interests, by writing to hello@tereniq.com. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. These rights can be limited where the law permits. If you are in the EU or EEA, you may also lodge a complaint with your local supervisory authority.
Changes
If this policy changes in a way that matters, we will notify company owners by email before the change takes effect.