← Back to Projectoolbox

GDPR & Cookie Policy

Last updated: 1 April 2026

1. Our GDPR Commitment

Projectoolbox is committed to complying with the UK General Data Protection Regulation (UK GDPR) and, where applicable, the EU General Data Protection Regulation (EU GDPR). This page explains our key commitments and how to exercise your rights.

For full details on how we collect and use your personal data, please read our Privacy Policy.

2. Data Controller

PMGT Solutions Ltd is the data controller for personal data collected through the Projectoolbox platform. Where you upload project data, we act as a data processor on your behalf — you remain the controller of that content.

3. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right of Access

Request a copy of all personal data we hold about you (Subject Access Request).

Right to Rectification

Ask us to correct inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten"). Some data may be retained for legal reasons.

Right to Restriction

Ask us to restrict processing of your data in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format (JSON or CSV).

Right to Object

Object to processing based on our legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on consent.

Right Not to Be Subject to Automated Decisions

Request human review of any significant automated decisions.

To exercise any right, email privacy@projectoolbox.com. We will respond within 30 days (extendable to 90 days for complex requests, with notice).

4. International Data Transfers

We use sub-processors located outside the UK/EEA. Where personal data is transferred internationally, we ensure adequate protections through:

  • UK adequacy regulations or EU Commission adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the ICO or European Commission
  • The UK International Data Transfer Agreement (IDTA) where applicable

5. Sub-Processors

We use the following sub-processors to deliver the Service:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageUS (AWS)
AnthropicAI model processingUS
StripePayment processingUS
VercelHosting, CDN, edge functionsUS / Global
Recall.aiMeeting bot transcriptionUS
Google AnalyticsUsage analyticsUS

6. Cookie Policy

We use the following categories of cookies:

Strictly Necessary Cookies

Required for the platform to function. These include session tokens, CSRF protection, and authentication state. They cannot be disabled.

Examples: next-auth.session-token, __Host-next-auth.csrf-token

Analytics Cookies

We use Google Analytics 4 to understand how the platform is used. These cookies collect anonymised data about page visits, feature usage, and navigation.

Examples: _ga, _ga_*

You can opt out of analytics cookies at any time via our cookie banner or by installing the Google Analytics Opt-out Browser Add-on.

Preference Cookies

Store your preferences such as theme (light/dark mode) and UI settings.

Examples: theme

7. Complaints

If you are unhappy with how we handle your data, you have the right to lodge a complaint with:

We would appreciate the opportunity to address your concerns first — please contact us at privacy@projectoolbox.com before escalating to a supervisory authority.