Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains what information Mission Critical Engineers (“MCE”, “we”, “us”) collects through the MCX Commissioning Platform — the website at mccommissioning.com and the application at platform.mccommissioning.com (together, the “Service”) — and how we use and protect it.

1. Information We Collect

We use browser storage (such as a session token and interface preferences like theme and panel sizes) strictly to operate the application. We do not use advertising or cross-site tracking cookies.

2. How We Use Information

We do not sell personal information, and we do not use your project content for advertising.

3. Sharing and location

The application and its database run on Amazon Web Services in Canada (ca-central-1). Uploaded documents and photographs are stored on that same server.

Exactly three service providers are involved, and no others:

Beyond that we share information with members of your own project or organization according to the access controls in the application, and where required by law. We do not sell personal information and we do not share project content between customers.

4. Security

All traffic to the Service is encrypted in transit (HTTPS/TLS). Passwords are stored only as one-way hashes and cannot be recovered from what we hold.

Separation between organizations is enforced by the database, through row-level security, and not only by the application: the account the application connects with cannot read another organization's projects even if the application asks it to.

The verification trail — every state change on every checklist, with its actor, timestamp and signature — is append-only at the database level. Permission to update or delete those rows is revoked from the application's database account, so the application is not merely instructed not to alter a signed record; it is incapable of it.

The database is backed up nightly, each backup is verified as readable before it is kept, and backups are retained for 30 days. We hold no SOC 2 or ISO 27001 attestation: the controls described here are real and can be demonstrated, but they have not been audited by a third party. No system can be guaranteed absolutely secure.

5. Retention

A commissioning record is evidence that a critical or life-safety system was tested and signed off, and may be needed years later by a building owner, an insurer or a court. Retention follows from that:

6. Your Rights

Erasure has a limit here, and we would rather you learn it now than at the point of asking. When you ask us to erase your data we remove everything that is not part of a verification record: your profile, contact details, notes and preferences. On the signed records themselves your name is replaced with an opaque identifier, while the signature and timestamp remain — so the record stays verifiable and attributable to a person, but stops naming you. We do this under the exemption for the establishment, exercise or defence of legal claims, we record the erasure in the audit log, and we will tell you exactly what was kept.

You may request access to, correction of, or deletion of your personal information, and you may unsubscribe from the waitlist at any time, by contacting info@missioncriticalengineers.com. If your data was entered by an organization you work with, we may direct the request to that organization as the controller of its project records.

7. Children

The Service is a professional tool and is not directed to children under 16. We do not knowingly collect information from children.

8. Changes to This Policy

We may update this Policy from time to time. Material changes will be indicated by updating the date above, and where practical by additional notice in the Service.

9. Contact

Privacy questions or requests: info@missioncriticalengineers.com.