Privacy Policy
This Privacy Policy explains what information Mission Critical Engineers (“MCE”, “we”, “us”) collects through the MCX Commissioning Platform — the website at mccommissioning.com and the application at platform.mccommissioning.com (together, the “Service”) — and how we use and protect it.
1. Information We Collect
- Waitlist email. If you join the launch waitlist on our website, we collect the email address you submit.
- Account information. When an account is created for you: name, email address, company, and role.
- Project content. Information you or your organization enter while using the application: commissioning records, test results, deficiencies, schedules, uploaded documents, comments, and electronic signatures. This content may include names and contact details of project participants.
- Technical data. Standard server logs (IP address, timestamps, requests) generated when you use the Service, used for security and operations.
We use browser storage (such as a session token and interface preferences like theme and panel sizes) strictly to operate the application. We do not use advertising or cross-site tracking cookies.
2. How We Use Information
- To provide and operate the Service — hosting, displaying, and backing up your data.
- To send service email: account verification, password and security messages, and notifications generated by your project (for example, an assignment or a review request).
- To notify the waitlist about availability of the product (the only use of waitlist emails).
- To secure, troubleshoot, and improve the Service.
We do not sell personal information, and we do not use your project content for advertising.
3. Sharing and location
The application and its database run on Amazon Web Services in Canada (ca-central-1). Uploaded documents and photographs are stored on that same server.
Exactly three service providers are involved, and no others:
- Amazon Web Services — hosting.
- Google Workspace — outbound email only (verification, password reset, and notifications generated by your project). Message content and the recipient address pass through it.
- Google — only if you choose to sign in with a Google workspace account. Google confirms your identity; we never receive your Google password.
Beyond that we share information with members of your own project or organization according to the access controls in the application, and where required by law. We do not sell personal information and we do not share project content between customers.
4. Security
All traffic to the Service is encrypted in transit (HTTPS/TLS). Passwords are stored only as one-way hashes and cannot be recovered from what we hold.
Separation between organizations is enforced by the database, through row-level security, and not only by the application: the account the application connects with cannot read another organization's projects even if the application asks it to.
The verification trail — every state change on every checklist, with its actor, timestamp and signature — is append-only at the database level. Permission to update or delete those rows is revoked from the application's database account, so the application is not merely instructed not to alter a signed record; it is incapable of it.
The database is backed up nightly, each backup is verified as readable before it is kept, and backups are retained for 30 days. We hold no SOC 2 or ISO 27001 attestation: the controls described here are real and can be demonstrated, but they have not been audited by a third party. No system can be guaranteed absolutely secure.
5. Retention
A commissioning record is evidence that a critical or life-safety system was tested and signed off, and may be needed years later by a building owner, an insurer or a court. Retention follows from that:
- Commissioning records — the life of the project, and 10 years after project completion.
- Account information — while the account is active, then deleted or pseudonymized within 30 days of closure, subject to section 6.
- Audit log — 7 years.
- Server logs — 90 days.
- Database backups — 30 days, rolling.
- Waitlist emails — until launch outreach is complete, or you ask to be removed.
6. Your Rights
Erasure has a limit here, and we would rather you learn it now than at the point of asking. When you ask us to erase your data we remove everything that is not part of a verification record: your profile, contact details, notes and preferences. On the signed records themselves your name is replaced with an opaque identifier, while the signature and timestamp remain — so the record stays verifiable and attributable to a person, but stops naming you. We do this under the exemption for the establishment, exercise or defence of legal claims, we record the erasure in the audit log, and we will tell you exactly what was kept.
You may request access to, correction of, or deletion of your personal information, and you may unsubscribe from the waitlist at any time, by contacting info@missioncriticalengineers.com. If your data was entered by an organization you work with, we may direct the request to that organization as the controller of its project records.
7. Children
The Service is a professional tool and is not directed to children under 16. We do not knowingly collect information from children.
8. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by updating the date above, and where practical by additional notice in the Service.
9. Contact
Privacy questions or requests: info@missioncriticalengineers.com.