Projects Library
PricingSign in

Projects Library - Privacy Policy

Version 1.0
Last updated: September 2026

1. Introduction

This Privacy Policy explains how EU Systems Ltd processes personal data in connection with Projects Library.

EU Systems Ltd
Suite RA01, 195-197 Wood Street
London, E17 3NU
United Kingdom
Company number: 06956313
VAT number: GB 528 1369 81

Privacy contact: privacy@myprojectslibrary.com

2. Our Role Under Data Protection Law

EU Systems may act in different data-protection roles depending on the information and processing involved.

EU Systems generally acts as a controller for personal data used for account administration, security, contractual administration, service operations, subscription administration, communications and similar purposes for which EU Systems determines the purposes and means of processing.

Where a business Customer determines why and how personal data contained in its Workspace Content is processed, the Customer is normally the controller and EU Systems acts as processor in providing Projects Library.

Where applicable, that processor relationship is further governed by our Data Processing Agreement.

3. Personal Data We Process

Depending on how the Service is used, we may process:

  • account information, such as name and email address;
  • authentication and sign-in information;
  • Google sign-in linkage where used;
  • Workspace membership, role and administrative information;
  • Workspace Content including projects, links, to-dos, discussions, documents, notes, prompts and Collections;
  • uploaded files and attachments;
  • Resource/contact information about users and non-users;
  • subscription/tool records;
  • Vault information, including encrypted secrets, wrapped encryption keys, salts and security/lockout information;
  • guest-sharing configuration;
  • Chat Analysis content submitted for AI processing;
  • search/indexing information and embeddings;
  • AI usage information such as token usage, timing and cost estimates;
  • service and security logs;
  • trial, plan and usage information;
  • support communications; and
  • payment/subscription information received from our Merchant of Record.

We do not store Vault PINs or passphrases in plaintext.

4. How We Use Personal Data

We may use personal data to:

  • provide and operate Projects Library;
  • authenticate Users;
  • create and administer Workspaces;
  • provide storage, search, sharing and Vault functionality;
  • process user-requested Chat Analysis;
  • provide AI-assisted search;
  • manage trials and subscriptions;
  • process or administer payments through our Merchant of Record;
  • send service and transactional communications;
  • provide customer support;
  • maintain security and prevent abuse;
  • diagnose faults and improve reliability;
  • understand limited service usage;
  • comply with legal obligations; and
  • establish, exercise or defend legal rights.

Where EU Systems acts as processor, processing is performed on the Customer's documented instructions and as necessary to provide the Service.

5. Legal Bases

Where EU Systems acts as controller and UK/EU data-protection law applies, legal bases may include:

  • performance of a contract;
  • steps taken at your request before entering a contract;
  • legitimate interests in operating, securing, supporting and improving the Service;
  • compliance with legal obligations; and
  • consent where required for a particular activity.

Where legitimate interests are relied upon, we consider the nature of the processing and the interests and rights of affected individuals.

6. Customer Responsibility for Third-Party Personal Data

Customers may store information about people who are not Projects Library Users, including Resources, clients, suppliers, contacts, family members and people mentioned in documents or conversations.

The Customer is responsible for determining whether it has a lawful basis and appropriate authority to collect and process that information.

Where EU Systems processes that information solely to provide the Service on the Customer's instructions, EU Systems acts as processor.

7. Payments and Creem

Creem acts as Merchant of Record for applicable Projects Library purchases.

Creem may collect and process payment information, billing details, tax information and transaction information under its own applicable terms and privacy arrangements.

EU Systems may receive information needed to administer the Customer's subscription, such as transaction status, plan, billing period, renewal status and relevant customer identifiers.

Projects Library does not require complete payment-card details to be stored in the Workspace for subscription checkout.

8. AI Processing

Projects Library currently uses artificial intelligence for Chat Analysis and AI-assisted search.

Chat Analysis

When a User submits text to Chat Analysis, the content is processed through the Lovable AI gateway using Google Gemini 2.5 Pro to generate the requested analysis.

AI-assisted search

Projects Library uses Google Gemini Embedding 2 through the Lovable AI gateway to generate embeddings used for search and retrieval.

Content submitted to these services may include personal data contained in Workspace Content.

Use of Customer Content for AI Training

Projects Library does not use Workspace Content submitted through the Service to train AI models.

AI features such as Chat Analysis and AI-assisted search use paid AI services through the Lovable AI gateway. Under applicable service arrangements, content submitted through these features is not used to train or improve the underlying AI models.

EU Systems has also configured available Lovable model-training controls consistently with this commitment.

AI providers may temporarily retain limited processing information or content for security, abuse-prevention or service-protection purposes in accordance with applicable terms. Such retention is separate from model training.

9. Automated Decision-Making

Projects Library's current AI features assist with extraction, organisation, search and retrieval.

They are not intended to make legally significant or similarly consequential automated decisions about individuals on behalf of Customers.

Users remain responsible for reviewing AI-generated information and deciding what actions to take.

10. Vault Privacy and Security

The Vault provides additional encrypted protection for credentials and similar information.

Vault items use additional cryptographic controls and controlled access. Decryption occurs as part of server-side Service processing when authorised access is requested.

The Vault is not a zero-knowledge or end-to-end encrypted service.

Workspace Administrators have recovery capabilities that can enable them to recover and access Vault information within their Workspace.

EU Systems does not routinely access Vault contents, and ordinary platform administration does not provide a general interface for browsing Customer Workspace Content.

11. File Storage and Security

Uploaded files are stored in private cloud storage and protected by application access controls and provider-level encryption at rest.

Temporary signed links may be used to provide authorised access to files.

Ordinary attachments are not encrypted using the same per-item Vault encryption model.

Supported document text may be extracted and indexed to provide search functionality.

Projects Library restricts supported file types and file sizes for security and operational purposes.

Uploaded attachments are not currently scanned for viruses or malware. Acceptance of an upload does not mean the file has been certified as safe.

12. Guest Collection Access

Where a Workspace Administrator enables Guest Access, selected Collections may be accessible to people who do not have Projects Library accounts.

Guest access is protected by the configured guest-access controls, including a password and any applicable access window.

A guest link and password may potentially be forwarded to another person. Customers are responsible for deciding whether particular Workspace Content is suitable for Guest Access.

Where guest editing is enabled, information may be changed by a person using guest access without a named Projects Library account.

13. Who We Share Personal Data With

We may share or make personal data available to service providers where necessary to operate Projects Library.

The principal service platform is Lovable, which provides hosting/platform services and acts as a subprocessor where EU Systems acts as processor for Customer Personal Data.

Lovable may engage downstream providers supporting functions such as:

  • database and authentication services, including Supabase;
  • edge/runtime infrastructure, including Cloudflare;
  • AI processing, including Google Gemini;
  • email delivery;
  • search/indexing;
  • monitoring and security; and
  • other infrastructure required to provide the Service.

Our public website may also use limited operational/visitor-statistics infrastructure associated with Lovable where enabled.

Creem processes payment information in its role as Merchant of Record.

We may also disclose information where required by law, to protect legal rights or security, or in connection with a lawful corporate transaction.

We do not sell Workspace Content to advertisers.

14. International Data Transfers

The primary database and storage environment currently used for Projects Library is hosted in the European Union. The current project environment is hosted in AWS eu-west-1 (Ireland).

Some processing may nevertheless occur outside the United Kingdom or European Economic Area. For example, AI processing using Google Gemini may involve processing in the United States, and global edge, email, monitoring or other infrastructure may involve processing in other locations.

Where data-protection law requires safeguards for restricted international transfers, appropriate mechanisms will be used. These may include adequacy decisions, EU Standard Contractual Clauses, the UK Addendum, the UK International Data Transfer Agreement or another legally recognised mechanism.

15. Data Retention

We retain personal data for as long as reasonably necessary for the purposes for which it is processed, including provision of the Service, security, contractual administration and legal compliance.

Workspace Content is ordinarily retained while the Workspace is active.

Following trial expiry or the end of paid entitlement, the Workspace ordinarily enters a 30-day read-only/export period.

After that period, Workspace Content may be scheduled for deletion from active systems.

Information may remain temporarily within backups and disaster-recovery systems until removed through normal retention and backup-rotation processes.

Some records may be retained for longer where required for legal, tax, fraud-prevention, security or dispute-resolution purposes.

16. Data Export and Portability

Customers may use available download and export functionality to retrieve Workspace Content.

During the 30-day post-expiry/post-subscription period, authorised Users may continue to view and download information and use available export functionality.

Data-protection rights to portability may also apply in particular circumstances.

17. Data Deletion

Customers may delete information using available product functionality.

Following the applicable post-expiry period, Workspace Content may be deleted from active systems.

Deletion from active systems does not necessarily result in immediate removal from all backups. Backup copies are removed according to applicable backup-rotation and retention processes unless continued retention is legally required.

18. Security

We use technical and organisational measures designed to protect personal data.

Depending on the feature, these measures include:

  • authentication;
  • Workspace separation;
  • database row-level security;
  • private file storage;
  • temporary signed file links;
  • role and permission controls;
  • provider encryption at rest;
  • additional encryption for Vault items;
  • controlled Vault unlocking;
  • security and operational logging; and
  • restrictions on supported file types.

No internet-connected service can guarantee absolute security.

19. Data Protection Rights

Depending on your location and applicable law, you may have rights including:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent where processing is based on consent; and
  • complaint to a supervisory authority.

Where EU Systems processes personal data solely on behalf of a Customer, requests concerning that Customer's Workspace Content should normally be directed to the relevant Customer as controller.

We will assist Customers with applicable Data Subject requests where required.

Requests concerning personal data for which EU Systems acts as controller may be sent to privacy@myprojectslibrary.com.

20. UK Information Commissioner's Office

If UK data-protection law applies, you may have the right to complain to the UK Information Commissioner's Office.

We encourage you to contact us first where appropriate so we have an opportunity to address your concern.

21. Children

Projects Library accounts and Workspace ownership are intended for people aged 18 or over.

The Service is not directed at children.

Customers remain responsible for ensuring that any personal data about children placed within Workspace Content is processed lawfully and appropriately.

22. Cookies

Projects Library uses cookies and related storage technologies for purposes such as authentication, security, session management, application preferences and, where enabled, limited visitor statistics.

Further information is provided in our Cookies & Tracking Technologies Policy.

23. Marketing Communications

Where we send optional marketing communications, we will do so in accordance with applicable law.

You may opt out of marketing communications using the unsubscribe mechanism provided or by contacting us.

Service, security and contractual messages may still be sent where necessary.

24. Changes to This Policy

We may update this Privacy Policy as the Service, providers, legal requirements or processing practices change.

The current version will be published on myprojectslibrary.com with its latest revision date.

Where changes are material, we will provide appropriate notice where required.

25. Contact

Data controller for EU Systems-controlled processing:

EU Systems Ltd
Suite RA01, 195-197 Wood Street
London, E17 3NU
United Kingdom

Company number: 06956313
VAT number: GB 528 1369 81

Privacy: privacy@myprojectslibrary.com
Support: support@myprojectslibrary.com

Terms·Privacy·Cookies·Refunds·Acceptable Use·AI Disclaimer·DPA
HomeFeaturesPricing

© 2026 Projects Library. All rights reserved.
Projects Library is a product operated by EU Systems Ltd.