Privacy notice
Last updated: August 10, 2026
Matterial is the platform where a construction company runs its jobs: the budget, purchasing, attendance, machinery and money. To do that, we process personal data about you and about people you register in the platform.
This notice is written to the strictest standard that applies to us, and that same standard governs all three languages, wherever you are. We do not keep a short version for some countries and a long one for others.
Who answers for your data
Matterial is a product of Darwwwin Experience, S.A. de C.V. ("Darwwwin"), tax ID DEX201009DP4. Darwwwin is the controller of the personal data described in this notice; Matterial is the brand the service is offered under.
For any privacy matter — including exercising your rights — write to privacidad@matterial.ai. We answer every request, even if only to say we need more information to identify you.
Two different roles, and it pays not to mix them up
Matterial processes personal data in two very different capacities, and who is responsible for what depends on which one applies.
For YOU, who opens the account and uses the platform, Matterial is the controller: we decide what we use your email, your name and your activity for, and we answer for it.
For the people YOU register — your crew in attendance, your clients, your subcontractors — Matterial is only the processor. Your company is the controller: you decide what you capture, what for and for how long; we store and process it following your instructions, and we use it for nothing else.
This has a practical consequence worth stating plainly: informing your crew about the processing of their data, and obtaining their consent where required, is your company's responsibility, not Matterial's. We give you the tools to delete, export and scope access; the notice to them comes from you.
What data we process
We do not ask for data we do not need. This is all of it.
- About your account: name, email address, encrypted password, preferred language, and a record of your activity in the platform (what you opened and when), which we use for security and support.
- About your company: legal name, country and currency, contracted plan and AI credit consumption.
- About your crew, if you use attendance: name, trade, crew, phone, photograph, daily rate, certifications and hire date.
- About your clients and subcontractors: name, company, tax ID, phone and contact email.
- For billing: if you subscribe to a paid plan, payment is processed by Stripe. Matterial NEVER sees or stores card numbers.
- Content you upload: job photos, drawings, receipts, invoices, voice notes and documents. These may contain personal data that you choose to include.
Two data points that deserve a separate mention
The worker PHOTOGRAPH in attendance is used as visual evidence of presence and so that whoever takes the roll call recognises who they are marking. We do not use it for biometric identification: we do not extract facial features, we do not generate biometric templates and we do not match faces automatically. Were we to add facial recognition in the future, it would be a separate, optional feature with express consent, and this notice would say so first.
The DAILY RATE is financial data and we treat it as such: only roles with cost permission inside your organisation can see it, and it is out of reach for anyone holding a site or field role.
What we use them for, and on what basis
We use the data to provide the service: give you access, store your job, compute your numbers, warn you about what is due, charge your plan and support you. The lawful basis here is performance of the contract you accept when you open the account.
We also use them to keep the platform secure and working: detect abuse, diagnose errors and measure in aggregate what is used and what is not. The basis here is our legitimate interest in running a secure service, and it goes no further than that.
For commercial communications that are not strictly about the service, the basis is your consent, and you can withdraw it at any time without losing anything in the platform. Operational alerts — a task went past due, your credits are running out, someone assigned you something — are not marketing and cannot be switched off entirely, though you can choose which channel they reach you on.
We never sell personal data. We never hand it to third parties for their own advertising.
What happens with artificial intelligence
Some Matterial features use third-party AI models: dictating a task or a daily log, reading a receipt with the camera, summarising bid documents, describing a finding from a photo. Only the content of that specific operation is sent — the audio you dictated, the image of the receipt — at the moment you ask for it.
Your data is NOT used to train those providers' models. We work with them under enterprise terms that expressly exclude it.
AI in Matterial proposes; it does not decide. No feature makes an automated decision with legal or similarly significant effects on a person: what the AI extracts from a receipt or a dictation is presented to you in an editable form and is not saved until you confirm it. The features that touch critical money are deterministic on purpose.
If you would rather not use these features, simply do not: typing the task or entering the receipt by hand does exactly the same thing without sending anything to a third party.
Who we share them with
Running the service requires infrastructure providers. This is the complete list, with what each one does. We keep it current: if we add or change a provider, we change this table.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication and storage of the files you upload | United States |
| Netlify | Hosting and delivery of the application | United States |
| Stripe | Payment processing for paid plans | United States and Ireland |
| OpenAI | AI models: speech transcription and document reading | United States |
| Anthropic | AI models: copilot and text analysis | United States |
| Sending platform emails and measuring site usage | United States | |
| Open-Meteo | Weather by job coordinates (receives no personal data) | Germany |
International transfers
As the table above shows, most of our providers are outside Mexico. That means your data is transferred to and stored in other countries, mainly the United States.
Those transfers are necessary to provide the service you contracted and are covered by the data processing agreements we have signed with each provider, which bind them to standards equivalent to those in this notice. They do not require your additional consent because they are indispensable to the contractual relationship, but we would rather you knew in writing and by name.
How long we keep them
We keep nothing "just in case". These are the periods.
| What | How long |
|---|---|
| Your account and job data | While the account is active |
| After you cancel the account | 90 days so you can recover it or export; then deleted |
| Billing records | 5 years, under Mexican tax obligations |
| Access and security logs | 12 months |
| Technical errors reported by the application | 30 days |
| Data you delete inside the platform | Removed immediately; up to 30 days in backups |
Your rights, and how to exercise them
You have the right to know what data of yours we hold and where it came from (access); to correct it if it is wrong (rectification); to have it deleted when we should no longer hold it (erasure); and to object to our using it for specific purposes (objection). You can also ask us to hand it over in a format you can take to another system (portability), and to restrict processing while we resolve a request.
If you gave consent for something, you can withdraw it whenever you like. Withdrawing it does not affect what we did before you withdrew it.
To exercise any of these rights, write to privacidad@matterial.ai from your account email, saying what you want and about which data. We answer within a maximum of 20 business days and, where applicable, act within the following 15 business days. If we need more information to identify you, we ask for it within the first 5 days.
A good part of this needs no writing at all: from the platform you can edit your data, export your information and delete records yourself, and it is faster.
If you believe we did not handle your request properly, you may turn to the data protection authority that applies to you.
How we protect them
Everything travels encrypted and is stored encrypted. Access is isolated per organisation in the database itself — not only in the interface — so one company cannot read another's data, not even through a programming mistake.
Inside your organisation, access is scoped by role and by job: you can add a site engineer who sees their job and not the prices, or a subcontractor who sees only their own contract. That restriction also lives in the database.
No system is infallible and we are not going to claim ours is. What we do is limit the possible damage: fewer people with access, less data per access, and a trail of who did what.
Minors
Matterial is a work tool and is not directed at minors. We do not create accounts for people under 18.
If your company registers a legally employed minor in attendance, that data sits under your responsibility as the employer and under whatever labour rules apply to you.
If something goes wrong
If a security breach occurs that significantly affects your personal data, we tell you without undue delay and at the latest within 72 hours of becoming aware of it.
We will tell you what happened, what data was involved, what we are doing and what we recommend you do. We are not going to wait until we have every answer before telling you there is a problem.
Changes to this notice
When we change this notice, we update the date in the header. If the change is substantial — a new provider, a new purpose, a different period — we tell you inside the platform and by email before it takes effect.
The version in force is always the one published on this page.