Privacy
Last updated 8 August 2026
STRUCTURA is a portfolio management tool for engineering organisations. This page describes what data the service holds, why, and who else can reach it. It is written to be read rather than to be survived.
Who is responsible
STRUCTURA is operated by [LEGAL ENTITY, ADDRESS]. For anything on this page, including data access and deletion requests, contact jl@z23.dk.
Where you use STRUCTURA to manage your own organisation's portfolio, you are the data controller for the content you put in it, and we are your processor.
What we store
Account data, for every user:
- Name and email address.
- A hashed password — never the password itself.
- Your role and the organisation and department you belong to.
- Onboarding state, such as whether you have completed the product tour.
Portfolio content, which is whatever your organisation enters:
- Projects, schedules, statuses, risks and escalations.
- Resource rosters, allocations and forecasts, including named people and their capacity.
- A field-level change log recording who changed what and when. This is an audit trail and is retained deliberately.
If you submit the access-request form, we store the name, email, organisation and any details you provide, so we can reply. That is the only purpose it is used for.
What we do not do
- No third-party analytics, advertising or tracking scripts. The site sets no tracking cookies.
- No selling, renting or sharing of data with advertisers.
- No marketing email to addresses collected through the product.
The only cookie the application sets is the session cookie that keeps you signed in. It is required for the service to function.
Where it lives
Your data is stored in a SQLite database on a server in [HOSTING REGION], continuously replicated to encrypted object storage for backup. Each customer organisation is isolated at the row level — every query is scoped to your organisation.
Sub-processors
Three third parties can touch data, each for one job:
- Resend— transactional email only (invitations, password resets, email verification). Receives the recipient's name and email address.
- An AI provider (Anthropic by default) — powers Coach John and the in-app assistant. When an AI feature runs, relevant portfolio content is sent for processing: project names, statuses, risks, schedule and forecast figures. This happens only when an AI module is switched on for your organisation. It is off by default and enabled per tenant.
- Object storage for backups — encrypted database replicas held in [BACKUP PROVIDER AND REGION].
Retention and deletion
Portfolio content is kept for as long as your organisation has an account. Deleted items go to a recoverable trash before permanent removal. The change log is retained as an audit record for the life of the account.
You can ask for an export or the deletion of your organisation's data at any time by emailing jl@z23.dk. We will action it within [RESPONSE WINDOW].
Your rights
If you are in the EU or UK you have the right to access, correct, export, restrict or delete your personal data, and to object to processing. Contact us and we will handle it. If we get it wrong, you can complain to your national data protection authority.
Changes
If this page changes materially we will update the date at the top and tell account holders by email rather than changing it quietly.