1. About this policy
ScopeCycle is a change-order tracking and approval application operated by Onni Contracting Ltd., a member of the Onni Group of Companies (“Onni”, “we”, “us”, “our”). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use the application, whether through the internal staff dashboard or the external contractor portal.
This policy supplements, and is to be read together with, the corporate Onni Privacy Policy published at onni.com/privacy, which describes Onni’s handling of personal information across the Onni Group of Companies as a whole. Where the two documents address the same topic, this ScopeCycle-specific policy adds detail about the application and does not reduce any rights or commitments made in the corporate policy.
We have prepared this policy in accordance with the Personal Information Protection and Electronic Documents Act(Canada) (“PIPEDA”), the Personal Information Protection Act(British Columbia) (“BC PIPA”), the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (together, the “CCPA”), and, where they apply, the comprehensive consumer privacy laws of other US states. Your rights under each of these laws are described in Section 11.
2. At a glance
- We collect only the information we need to operate the change-order workflow: your account profile, the content of change orders you submit or approve, digital signatures, file attachments, and audit records of actions taken in the application.
- We do not sell, rent, or share personal information for targeted advertising. We do not use advertising cookies.
- We use a small set of US-hosted service providers (Supabase, Postmark, Railway) to operate the application. This means personal information is transferred to and processed in the United States.
- You can request access to, correction of, or deletion of your personal information at any time by contacting [email protected].
3. Definitions
- Application
- The ScopeCycle web application, including the internal dashboard at scopecycle.onni.com (or any successor URL) and the external contractor portal served under the same domain.
- Change Order
- A request by a contractor to amend the scope, price, or schedule of work under a prime contract with Onni, and the record of Onni’s review, approval, and execution of that request.
- Personal Information
- Information about an identifiable individual, as that term is defined in PIPEDA and BC PIPA. Where you are a California resident, it also means “personal information” as defined in the CCPA.
- Contractor User
- An individual who accesses the Application on behalf of a contractor, subcontractor, consultant, or other counterparty to Onni.
- Internal User
- An Onni employee or authorised internal worker who accesses the Application through the dashboard.
4. Information we collect
4.1 Information you provide
- Account profile. Your email address, full name, job title, company name (for Contractor Users), assigned role, and email-notification preference.
- Authentication credentials. A password or, where single sign-on is used, an authenticated session issued by the identity provider. We never receive or store your corporate SSO password.
- Change-order content. Scope descriptions, pricing, cost-code allocations, schedule impact, comments, review decisions, and any other data you type into the Application while submitting or reviewing a change order.
- File uploads. Supporting documents, site photos, drawings, quotes, and other attachments you add to a change order, along with the associated file name, size, and MIME type.
- Digital signatures. Bitmap images (PNG) of the signature you draw when approving or executing a change order, together with the associated approval tier and timestamp.
4.2 Information generated by your use of the Application
- Audit records.An entry is recorded each time you take a material action (submission, revision, approval, rejection, execution, profile change). Each entry includes the actor’s user id, the affected record, a timestamp, and the source IP address of the request.
- Session and security records. A short-lived authentication cookie, a cross-site-request-forgery token, and basic server-side logs of request URLs, response codes, and timestamps for operational diagnostics.
- Email delivery records. For each notification we send on your behalf, our email provider records the recipient address, subject line, and delivery status.
4.3 Information we receive from third parties
- From our identity provider (Supabase Auth). The authenticated user id and email address associated with your session, and (for Contractor Users who signed up via an email-token link) confirmation that you received and clicked the link.
- From Onni colleagues. When a project manager or administrator adds you as a user, assigns you to a project, or invites you to a change order, that information is recorded against your profile.
5. How we use information
We use personal information for the following limited purposes.
5.1 To operate the change-order workflow
- Route change orders through the correct approval tiers for your project.
- Record approvals, rejections, revisions, and executions as the system of record.
- Generate final change-order PDF documents for your and Onni’s records.
- Send transactional email notifications about actions that concern you.
5.2 To operate the Application
- Authenticate you and maintain your session.
- Prevent, detect, and respond to fraud, abuse, and security incidents.
- Diagnose errors, measure reliability, and improve performance.
- Produce internal dashboards and reports on change-order activity, cost, throughput, and workload distribution.
5.3 To meet legal and compliance obligations
- Maintain audit logs sufficient to satisfy accounting, tax, and audit requirements.
- Respond to lawful requests from regulators, auditors, or courts, and enforce our legal rights in connection with the Application.
6. How we share information
We share personal information only as described below.
- Within the Onni Group of Companies. With Onni employees whose role grants them access to the project or change order in question. Access is scoped through role-based access control and row-level database security.
- With counterparties to a change order.Information you submit in a change order is visible to the contractor or Onni staff who are on the other side of that change order. A contractor cannot see another contractor’s change orders.
- With service providers who process information on our behalf and under written contract. See Section 7.
- In response to legal process. We may disclose information to regulators, auditors, or law-enforcement authorities where required by applicable law, subpoena, court order, or to establish or defend legal claims.
- In a business transaction. In connection with a merger, acquisition, reorganisation, or sale of assets involving Onni Contracting Ltd. or its affiliates, subject to the acquirer agreeing to treat information consistently with this policy.
We do not sell or rent personal information, and we do not use it for targeted advertising. For California residents, we do not “sell” or “share” personal information as those terms are defined in the CCPA.
7. Service providers
The following service providers process personal information on our behalf to operate the Application. Each is bound by a written agreement that restricts their use of the information to the services they provide to us.
| Provider | Role | Hosting region |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Postmark | Transactional email delivery | United States |
| Railway | Application hosting | United States |
8. Cross-border processing
Because the Application is hosted in the United States, using the Application results in your personal information being transferred to, stored in, and processed in the United States. While your information is in the United States it is subject to US law, including lawful requests by government authorities.
This notice is provided in satisfaction of our obligations under PIPEDA Principle 4.8 (openness) and under BC PIPA section 30.1 (notification of outside-Canada storage). We have contractual, organisational, and technical safeguards in place with each service provider to protect your information during and after the transfer.
9. Retention
We only retain your personal information for as long as necessary to fulfill the purposes for which it was collected, except where otherwise required or permitted by law. Once your personal information is no longer required, it will be securely destroyed, erased, or anonymised so it no longer identifies you.
Where a statute, audit, tax, or dispute obligation requires us to retain information for a longer period, we retain it for the longer period. Change-order records, including associated signatures, attachments, and audit log entries, are retained for the duration of the underlying project and for the period afterwards required to meet construction, accounting, tax, and limitations-of-action obligations.
10. Security safeguards
We use reasonable administrative, technical, and physical safeguards to protect personal information against loss, theft, and unauthorised access, copying, use, modification, or disclosure. Our current safeguards include:
- Encryption of data in transit (TLS) and at rest in the database and object storage.
- Role-based access control and row-level security in the database, so users can access only the records their role entitles them to.
- Cross-site-request-forgery protection on every state-changing request.
- Signature attachments validated by file-type magic-byte checks and size limits.
- Automated audit logging of material actions.
- Service-provider agreements that impose equivalent safeguards on our processors.
No safeguard is perfect. We work continuously to improve our security, and we will notify affected individuals and the applicable regulator if a breach creates a real risk of significant harm (see Section 16).
11. Your rights
11.1 All users
You may at any time:
- ask us what personal information we hold about you;
- ask us to correct personal information that is inaccurate or incomplete;
- ask us to delete personal information that we no longer need;
- withdraw your consent to a particular use, subject to legal or contractual restrictions.
11.2 Canadian users (PIPEDA / BC PIPA)
Canadian users have the rights described above as a matter of federal law under PIPEDA and, in British Columbia, under BC PIPA. You also have the right to complain to the applicable regulator (see Section 13).
11.3 California residents (CCPA / CPRA)
This section is provided to California consumers in compliance with the CCPA. Terms used in this section have the meanings given to them in the CCPA. We collect, use, and disclose personal information of California consumers as described in this Privacy Policy. We do not sell your personal information, and we do not “share” personal information for cross-context behavioural advertising as that term is defined in the CCPA. We may disclose categories of personal information to our service providers for a business purpose, as described in Section 6.
If you are a California resident, you have the following rights, upon submitting a verifiable request:
- Right to access: request access to the categories and specific pieces of personal information we have collected about you.
- Right to know: request that we disclose the categories and specific pieces of personal information we have collected about you in the last 12 months, the sources from which we collected it, the business and commercial purposes for collecting it, the categories of third parties with whom we have shared it, and the categories of personal information disclosed for a business purpose in the last 12 months.
- Right to data portability: request to receive your personal information, when provided electronically, in a readily-useable format.
- Right to correction: request correction of inaccurate personal information.
- Right to deletion: request that we delete personal information we have collected about you, subject to the exceptions provided by the CCPA.
- Right to be free from discrimination: exercise any of these rights without fear of being denied goods or services.
California residents may submit a request through any of the methods in Section 12. In compliance with the CCPA, we may require identifying information to verify your request. We will honour verified requests in compliance with the CCPA but may be required to continue to retain or share portions of your personal information to comply with regulatory or legal obligations.
11.4 Residents of other US states
A growing number of US states — including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others — have enacted comprehensive consumer privacy laws. These laws differ in detail. Most contain exemptions for personal information processed in an employment or business-to-business context, and most apply only to organisations that meet specified processing thresholds. Because ScopeCycle is a workforce and business-to-business application, a given state law may or may not apply to you and to the information we process about you. Where a comprehensive state privacy law does apply to you, you have, to the extent that law grants them, the following rights:
- Right to confirm and access: confirm whether we process your personal information and obtain a copy of it;
- Right to correct: correct inaccuracies in your personal information;
- Right to delete: delete personal information we hold about you, subject to the exceptions permitted by the applicable law;
- Right to data portability: obtain your personal information in a portable and, to the extent technically feasible, readily-useable format;
- Right to opt out: opt out of the sale of personal information, targeted advertising, and profiling that produces legal or similarly significant effects. As described in Sections 5, 6, and 15, we do not sell personal information, conduct targeted advertising, or carry out such profiling, so there is nothing to opt out of; you may still contact us to confirm this;
- Right to non-retaliation: exercise these rights without being subjected to unlawful discrimination or retaliation;
- Right to appeal: appeal a refusal to act on your request, as described in Section 13.
Some state laws require your affirmative consent before certain categories of sensitive personal information are processed. We do not request sensitive personal information through the Application, and you should not submit it. Residents of Nevada may submit a verified request directing a business not to sell certain covered personal information; we do not sell personal information as defined under Nevada law. To exercise any of these rights, use the methods in Section 12.
12. How to exercise your rights
To exercise any of the rights in Section 11:
- Send a request to [email protected] with the subject line “ScopeCycle privacy request”.
- Include enough information for us to identify you and the records you are asking about. We may ask for additional information to verify your identity; we will not use that verification information for any other purpose.
- We will acknowledge receipt within seven (7) days and respond substantively within the time required by applicable law (thirty (30) days under PIPEDA and BC PIPA, and forty-five (45) days under the CCPA and the comprehensive US state privacy laws, each extendable once where permitted).
- You may use an authorised agent to submit a request on your behalf where applicable law permits. We may require the agent to provide proof of authorisation, and we may still verify your identity directly.
California residents may additionally submit a CCPA request by calling Onni’s toll-free line at 1-800-495-2210 or through the corporate privacy page at onni.com/privacy. Those channels reach the Chief Privacy Officer identified in Section 21 and cover the Application.
Access and correction requests are free. Where a request is manifestly unfounded, excessive, or repetitive, we may charge a reasonable fee or decline to act, and we will tell you why.
13. Complaints and appeals
If you are not satisfied with our response to a privacy request, you may appeal by replying to our response within a reasonable time, including the additional information you would like us to consider. We will review the appeal and inform you in writing of the outcome and the reasons for it, within the period required by applicable law (for example, sixty (60) days under the Virginia, Colorado, and Connecticut state privacy laws). If you remain dissatisfied, you may also complain to:
- the Office of the Privacy Commissioner of Canada (priv.gc.ca) in respect of PIPEDA;
- the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca) in respect of BC PIPA;
- the California Privacy Protection Agency (cppa.ca.gov) and the California Attorney General (oag.ca.gov) in respect of the CCPA;
- the Attorney General of your US state of residence, where a state privacy law grants you the right to do so.
14. Accuracy and correction
We rely on you to keep your personal information accurate and up to date. You can review and update your profile from the settings page in the Application, or request correction by contacting us at the address in Section 21. Where correction is requested and information is demonstrably inaccurate, we will correct it and, where appropriate, notify any third party to whom we have disclosed the information.
15. Automated decision-making
The Application routes change orders through pre-configured approval tiers based on each project’s configured assignees. Every decision with legal or financial effect is made by a human approver in the Application. We do not use automated decision-making or profiling to produce legal or similarly significant effects on you without human review.
16. Breach notification
If a breach of security safeguards involving personal information in the Application creates a real risk of significant harm to you, we will notify you and the applicable regulator as required by law (including PIPEDA’s mandatory breach reporting obligations and BC PIPA where applicable). We maintain internal records of all breaches, whether or not notification is required.
17. Cookies and similar technologies
The Application uses cookies only for the purposes of keeping you signed in and protecting requests against cross-site-request forgery. We do not use advertising cookies, tracking pixels, third-party analytics, session-replay tools, or behavioural profiling. The cookies we set are:
- a first-party authentication cookie issued by Supabase Auth (expiring with your session or after a fixed period, whichever comes first);
- a first-party CSRF token (session-lifetime, not readable by JavaScript).
18. Third-party links
The Application may occasionally link to websites operated by third parties (for example, in a change-order attachment or comment). We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy notices before providing personal information to them.
19. Changes to this policy
This Privacy Policy may be updated from time to time, and the new version will become effective immediately once posted to the Application. It is your responsibility to ensure that you have read and understood the latest version.
Onni will update this Privacy Policy as required to keep current with applicable laws and regulations, new technologies, industry standards, and user concerns. Changes take effect when a modified version is posted here and the “Last updated” date above is revised. If we make significant changes, we will post a more prominent notice in the Application and, where the change affects your rights in a material way, we will notify active users by email through the same channel used for workflow notifications. By continuing to use the Application after a modified version has been posted, you accept the changes, subject to any additional consent requirement that may apply under law.
We will not materially change this Privacy Policy in a way that makes it less protective of personal information we have previously collected from you without first notifying you. Prior versions are retained in our change history and can be requested at the address in Section 21.
20. Accountability
Onni Contracting Ltd. is accountable for personal information in its custody or control, including information handled by service providers on our behalf. Our privacy designate for ScopeCycle is reachable at [email protected]; corporate privacy matters across the Onni Group of Companies are handled under the policy published at onni.com/privacy.
21. Contact
For any question, concern, complaint, or rights request concerning this policy, the personal information Onni holds about you, or personal information Onni may have shared with third parties in connection with the Application, please contact:
Chief Privacy Officer
Onni Group of Companies
- By mail: 200 – 1010 Seymour Street, Vancouver, BC V6B 3M6, Canada
- By phone: 604-602-7711
- By email: [email protected] (subject: “ScopeCycle privacy request”)