Legal
Privacy Policy
This Privacy Policy explains how DiamondHawk Command System (“DiamondHawk,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit diamond-hawk.com, use the hosted DiamondHawk application at app.diamond-hawk.com, or otherwise interact with our services (collectively, the “Services”).
DiamondHawk is mission operating software for mission-critical construction, commissioning, and data center operations. This policy describes our data practices; it does not create warranties, certifications, or service-level commitments beyond what is expressly stated in a signed customer agreement.
1. Information we collect
1.1 Information you provide
- Account and profile information when you register or are invited, such as name, work email, company name, job title or role, and authentication credentials.
- Contact and demo requests, information you submit through our contact forms or email (name, company, work email, message content).
- Customer operational data that authorized users enter, upload, or import into the Services, such as project schedules, mission plans, commissioning records, daily command records, equipment and systems data, meeting notes, integrations metadata, and related operational content.
- Billing information when you subscribe, payment and billing details are collected and processed by our payment processor (Stripe). We receive limited billing metadata (such as subscription status) needed to operate accounts.
- Communications, messages you send to support, security, or privacy teams, feedback, and other correspondence.
1.2 Information collected automatically
- Usage and activity data, features used, actions taken, timestamps, session duration, and operational audit records generated as part of providing the Services.
- Device and browser information, browser type, device type, operating system, IP address, and general location derived from IP (such as city or region level).
- Hosting and security logs, request paths, user agents, error logs, and security events needed to operate, monitor, and protect the Services.
1.3 Information from third parties
We may receive information from single sign-on or identity providers you connect, integration partners you authorize (such as schedule or field-system connectors), or business contact information from publicly available sources for sales and support purposes.
2. How we use information
We use information to:
- Provide, maintain, secure, and improve the Services
- Authenticate users and enforce role-based access controls
- Process subscriptions, invoices, and account administration
- Respond to support, security, and privacy requests
- Send administrative messages about accounts, security alerts, and policy updates
- Send marketing communications where permitted by law and with appropriate consent or opt-out mechanisms
- Monitor usage trends and product reliability
- Detect, investigate, and prevent fraud, abuse, or security incidents
- Comply with legal obligations and enforce our agreements
- Create de-identified or aggregated data for analytics and product improvement that cannot reasonably identify you or any individual
3. How we share information
We do not sell personal information. We share information only in the following circumstances:
3.1 Service providers (subprocessors)
We use third-party vendors to host, operate, monitor, bill, and support the Services. Current categories include cloud infrastructure and hosting, managed databases, payment processing, email delivery, and (when enabled) AI inference providers for optional product features. Representative providers include Railway (hosting), Stripe (payments when billing is enabled), and infrastructure partners required to deliver the Services. These providers process information only to perform services on our behalf under contractual confidentiality and security obligations. A current subprocessor list is available on request at [email protected].
3.2 Within your organization
If you use the Services under a company or project account, administrators and other authorized users in your organization may access information according to your project membership and role settings.
3.3 Business transfers
If DiamondHawk is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify affected customers of any material change in ownership or control.
3.4 Legal requirements
We may disclose information when required by law, subpoena, court order, or government request, or when we believe in good faith that disclosure is necessary to protect rights, safety, investigate fraud, or respond to lawful requests.
3.5 With your consent
We may share information for other purposes with your explicit consent.
4. Customer data ownership
Customer operational data remains the property of the customer. DiamondHawk receives only the rights reasonably necessary to host, process, transmit, display, back up, and operate the Services. We treat customer project information as confidential and use it only to operate, support, maintain, and improve the Services.
5. Your privacy rights
Regardless of your location, you may:
- Access and export your data through in-product tools or by contacting us
- Update inaccurate account information in your profile settings
- Request deletion of your account and associated personal information by contacting [email protected]
- Opt out of marketing email using the unsubscribe link in any marketing message or by contacting us
5.1 California residents (CCPA / CPRA)
If you are a California resident, you may have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Right to know, request disclosure of categories and specific pieces of personal information collected, sources, purposes, and third parties with whom it is shared
- Right to delete, request deletion of personal information, subject to legal and operational exceptions
- Right to correct, request correction of inaccurate personal information
- Right to opt out of sale/sharing, we do not sell personal information or share it for cross-context behavioral advertising
- Right to limit sensitive personal information, we do not use sensitive personal information beyond permitted business purposes
- Right to non-discrimination, we will not discriminate against you for exercising privacy rights
To submit a request, email [email protected]. We will verify your identity before processing requests. You may designate an authorized agent with proper verification. We respond to verifiable requests within 45 days and may extend up to an additional 45 days with notice when reasonably necessary.
5.2 Other U.S. state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and opt out. Contact [email protected] to exercise those rights.
5.3 International users
DiamondHawk is operated from the United States. If you access the Services from outside the U.S., your information may be transferred to and processed in the United States. Customers requiring additional safeguards (such as Standard Contractual Clauses for GDPR compliance) may request a Data Processing Addendum by contacting [email protected].
6. Data retention
We retain information for as long as your account is active or as needed to provide the Services. After account termination:
- Customer data is retained for 30 days to allow export (the “Retrieval Period”)
- Following the Retrieval Period, we delete or de-identify customer data within 60 days, except where retention is required by law, to resolve disputes, or enforce agreements
- Encrypted backup copies may persist for up to 90 days after deletion from production systems
Customers are responsible for maintaining independent copies of records required by contract, regulation, or internal policy (including commissioning, schedule, and operational evidence).
7. Security
We implement technical and organizational measures designed to protect information, including HTTPS encryption in transit, authenticated access, role-based permissions, project-scoped authorization, operational audit history, and managed cloud infrastructure. Additional detail is on our Security page.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact [email protected] immediately.
8. Cookies and similar technologies
8.1 Public website
The public marketing site at diamond-hawk.com does not use advertising pixels, third-party marketing trackers, or analytics cookies.
8.2 Application
The authenticated application uses strictly necessary cookies and local storage for session management, authentication tokens, and user preferences. These are required for the Services to function.
Most browsers allow you to control cookies through settings. Blocking required cookies may prevent you from signing in or using the application.
9. Third-party links and integrations
The Services may link to third-party websites or integrate with third-party systems you authorize. This Privacy Policy does not apply to those third parties. Review their privacy policies before providing information to them.
10. Children's privacy
The Services are not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, contact [email protected] immediately.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify account holders by email or through a prominent notice in the Services at least 30 days before changes take effect, when practicable. Continued use after the effective date constitutes acceptance of the updated policy unless a signed customer agreement provides otherwise.
12. Contact
Privacy requests and inquiries: [email protected]
General support: [email protected]
Security incidents: [email protected]
Demo and sales: [email protected] or the Contact page
Related: Terms of Service · Security