SIC Civil
Privacy policy
What SIC Civil reads, what it stores, where it is kept, for how long, and how to reach us.
This policy explains how Applied Ontologies ("we", "us") handles personal information in SIC Civil, the app that connects ChatGPT and other AI assistants to AIPE (SIC, Super Intelligence Civil) projects. It covers the sign-in service at auth.sicivil.com and the app server at mcp.sicivil.com. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What SIC Civil reads
When you ask a question, SIC Civil reads the records of the projects you are appointed to, within your role: project status, documents, inspection and test plans with their hold and witness points, lots, the programme, milestones and the risk register. These are your company's project records. Some of them carry the names and roles of people on the project. Commercial records are read only for the roles that hold them.
What we store about you
| Your login | Your email address, your name as it appears on the login, and your password as an argon2id hash. We never store or see your password itself. |
|---|---|
| Second step | For directors, project managers and Superintendents: the authenticator secret, encrypted, and your recovery codes as one-way hashes. |
| Your appointments | Your role on each project, the party you act for, who appointed you and when. |
| Sign-in records | Each sign-in, sign-in failure and token event, with the time, the application (for example ChatGPT) and the network address it came from. |
| Audit log of tool calls | Each request the AI assistant makes on your behalf: the time, your login and role, the project, the tool, the request details (up to 600 characters, plus a fingerprint of the whole request), whether it was answered, and the size and time of the answer. |
| Draft comments | Comments you ask SIC Civil to draft, with the item they are about. |
| Access tokens | The tokens your AI assistant uses to call SIC Civil, stored as one-way hashes. |
We collect only what SIC Civil needs to sign you in, answer your requests and keep the service secure. We do not ask for payment card details, health information or government identifiers.
Why we use it
- To sign you in and apply your role on each project.
- To answer your requests from the project records.
- To keep the service secure: detecting repeated failed sign-ins, limiting request rates and investigating misuse.
- To trace any answer back to the records it read, and to fix faults.
We do not sell personal information, we show no advertising, and we do not use your data or your project records to train AI models.
Who receives it
- The AI assistant you connect. Answers to your requests go back to the assistant you use, for example ChatGPT, and become part of your conversation there. OpenAI handles that conversation under its own privacy policy and your settings in ChatGPT. SIC Civil receives only the requests the assistant sends to its tools.
- Hetzner Online GmbH, which provides the server SIC Civil and AIPE run on, in Nuremberg, Germany.
- Cloudflare, Inc., which carries all traffic to SIC Civil over encrypted connections and protects the service from attacks. Cloudflare processes network addresses and request details to do this.
- People in your company with the right role, who can see draft comments you file for the team once filing is available.
- Authorities, where Australian law requires it.
Where it is kept
Everything SIC Civil stores, and the AIPE project records it reads, are held on a dedicated server in Germany (Hetzner, Nuremberg). Because we are based in Australia and the server is in Germany, your information is held outside Australia. Germany is subject to the EU General Data Protection Regulation. Access to the server is limited to Applied Ontologies.
How long we keep it
- Sign-in records and the audit log of tool calls: 12 months, then deleted automatically.
- Access tokens: deleted 30 days after they expire.
- Your login, appointments, second-step records and draft comments: while your login is active. When you or your company ask us to close the login, we delete them within 30 days.
- Project records belong to your company and are kept under our agreement with it.
Your choices and rights
- Disconnect SIC Civil in ChatGPT at any time. Email us to sign your login out of every application.
- Ask to see the personal information we hold about you, to correct it, or to delete it, by emailing [email protected]. We reply within 30 days. Deleting your login ends your access to SIC Civil.
- If you are unhappy with how we handled a request, tell us first. You can also complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Security
SIC Civil is reachable only through Cloudflare's encrypted tunnel. Passwords are hashed with argon2id, tokens are stored as hashes, sign-in codes are single-use and short-lived, and logins lock after repeated wrong passwords. Directors, project managers and Superintendents sign in with a second step. Every tool call is recorded in the audit log.
Who SIC Civil is for
SIC Civil is a business service for people working on civil-construction projects. It is intended for adults and is not directed at children.
Changes
When this policy changes, we update it on this page with a new effective date, and tell login holders by email of any significant change.
Contact
Applied Ontologies, Queensland, Australia. Privacy questions and requests: [email protected].