Hill EEP — Privacy Policy

Version 1.0 · Effective Date: August 26, 2026

Hill Project Services LLC ("Hill," "we," "us," or "our") operates Hill EEP — the Engineering Execution Platform.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information in connection with Hill EEP and related services.

Hill Project Services LLC

1795 Alysheba Way, Ste 7202 #577310

Lexington, KY 40509

[email protected]

Terms of Service: hillprojectservices.com/hill-eep/terms

1.Scope

This Privacy Policy applies to personal information processed through Hill EEP, including information associated with:

  • user accounts;
  • organizational users;
  • employees and resources;
  • clients and contacts;
  • vendors and vendor contacts;
  • project records;
  • timesheets;
  • meetings and actions;
  • procurement;
  • construction and quality records;
  • administrative activity;
  • support; and
  • optional AI functionality.

Hill EEP is intended primarily for U.S.-based business and professional users and is not intended for children or consumer use.

2.Our Role

Depending on the information involved, Hill may act in different privacy roles.

For account administration, Platform security, service operations, product administration, billing relationship information, and our own business records, Hill generally determines the purposes of processing.

For project, employee, client, vendor, document, construction, and other Customer-controlled information submitted to Hill EEP, Hill generally processes information on behalf of the Customer organization and according to that Customer's instructions.

Customers are responsible for determining whether they have an appropriate legal basis to collect, enter, and process information through Hill EEP.

Enterprise Customers may enter into a separate Data Processing Addendum with Hill.

3.Information We Collect

Account and Profile Information

Hill EEP may process information such as:

  • name;
  • email address;
  • profile image or avatar URL;
  • job title;
  • telephone number;
  • timezone;
  • authentication identifier;
  • organizational membership;
  • account roles and permissions; and
  • account activity information.

Passwords are currently managed by Hill EEP's external authentication provider and are not stored directly in the Hill EEP application database.

Employee and Resource Information

Customers may enter or maintain information concerning employees, contractors, or other resources, including:

  • first and last name;
  • employee identifier;
  • business email;
  • title;
  • location;
  • department;
  • supervisor relationships;
  • standard working hours;
  • resource assignments;
  • time information;
  • cost rates; and
  • billing rates.

Certain financial and compensation-related information is treated as confidential and subject to Platform permissions.

Client, Vendor, and Contact Information

Customers may enter business contact information about individuals who are not themselves users of Hill EEP, including:

  • name;
  • employer or organization;
  • title;
  • role;
  • business email;
  • business telephone number; and
  • project, client, or vendor relationships.

Customers are responsible for ensuring that they have appropriate authority to provide this information.

Business and Project Information

Hill EEP processes extensive business records that may contain personal information, including information related to:

  • projects;
  • opportunities and proposals;
  • estimates;
  • project teams;
  • schedules;
  • documents and document reviews;
  • engineering deliverables;
  • risks and changes;
  • procurement and purchase orders;
  • vendors and bids;
  • timesheets and labor transactions;
  • meetings, decisions, and action items;
  • construction activities;
  • inspections;
  • punch items;
  • safety observations;
  • quality deficiencies;
  • turnover records;
  • project financial controls; and
  • governance and quality records.

Much of this information is business information rather than personal information, but personal information may be contained within these records.

4.Authentication Information

Authentication is currently provided through Hercules Auth using OpenID Connect ("OIDC").

Hill EEP stores an authentication identifier used to associate an authenticated identity with the appropriate application user.

Passwords and primary authentication credentials are handled by the external authentication service rather than directly stored by Hill EEP.

5.Cookies and Local Storage

Hill EEP currently uses limited browser storage for functional purposes.

A functional cookie may be used to remember whether the application sidebar is open or closed. The current cookie duration is approximately seven days.

Local browser storage may be used to remember a user's appearance preference, such as light or dark mode.

Hill EEP currently does not use advertising cookies or third-party behavioral advertising trackers.

6.Analytics and Advertising

Hill EEP currently does not use third-party behavioral analytics platforms, advertising networks, tracking pixels, or session-replay services.

We may introduce operational analytics or telemetry in the future to improve security, reliability, performance, or product functionality. If future technology materially changes our privacy practices, this Privacy Policy will be updated and consent mechanisms will be implemented where legally required.

Hill EEP does not currently sell advertising or use personal information for targeted advertising.

7.How We Use Information

We use information to:

  • provide Hill EEP;
  • authenticate users;
  • administer Customer organizations;
  • enforce roles and permissions;
  • maintain tenant isolation;
  • provide project and engineering workflows;
  • process Customer instructions;
  • maintain project records;
  • support collaboration;
  • provide optional AI functionality;
  • troubleshoot and provide support;
  • secure the Platform;
  • investigate errors or misuse;
  • maintain audit history;
  • develop and improve the Service;
  • comply with contractual and legal obligations;
  • protect Hill, Customers, users, and third parties; and
  • generate de-identified or aggregated statistics.

8.Artificial Intelligence Processing

Hill EEP currently includes an optional Portfolio Intelligence Agent and may introduce additional AI-assisted functionality.

When AI functionality is used, Hill EEP may send:

  • the user's question or prompt;
  • relevant bounded project or organizational context;
  • system instructions necessary to perform the requested function; and
  • related contextual information

to an AI service provider.

Current AI processing is routed through Hercules AI Gateway, which in turn uses an OpenAI model.

Hill EEP applies technical filtering intended to exclude designated sensitive fields before organizational data is sent to AI processing. Current filtering includes protections for authentication information and certain personal, compensation, banking, tax, and other sensitive fields.

AI interaction logs may contain:

  • the user's submitted message;
  • the AI response;
  • processing status;
  • token usage;
  • processing duration; and
  • error information.

These logs may be retained for security, troubleshooting, auditability, service improvement, and Platform operations.

Hill does not authorize AI subprocessors to use Customer information for purposes beyond providing applicable services where such restrictions are supported by applicable contractual arrangements.

Because the specific data-processing and model-training terms applicable to upstream providers may change, Customers with specific AI confidentiality or data-residency requirements should contact us before enabling AI capabilities.

AI features may be disabled or restricted based on Customer configuration where supported.

AI recommendations do not independently create authoritative project actions without applicable user confirmation and governed workflows.

9.Audit Logs and Activity History

Hill EEP is designed to maintain extensive auditability.

Governed data changes may generate immutable activity records containing information such as:

  • the affected record;
  • action performed;
  • before and after state;
  • fields changed;
  • user performing the action;
  • timestamp;
  • source context;
  • correlation identifier; and
  • criticality.

Access and permission changes may also be separately audited.

Some audit history is intentionally designed not to be altered or deleted because it supports data integrity, security, financial controls, accountability, and legal or contractual recordkeeping.

10.Tenant Isolation and Access Controls

Hill EEP uses a multi-tenant architecture in which multiple Customer organizations may use common hosted infrastructure.

Customer data is logically separated using organizational identifiers and server-side authorization controls.

The Platform uses role-based, scope-based, and permission-based access controls to limit access within Customer organizations.

Customers are responsible for determining which of their users may access particular projects, records, or confidential information.

11.Customer Administrators

Authorized Customer administrators may have broad access to information within their own organization, depending on their permissions.

This may include:

  • users;
  • project records;
  • audit history;
  • operational information;
  • timesheets;
  • documents;
  • procurement information;
  • financial/project-control information;
  • AI execution records; and
  • organizational configuration.

Customer administrators cannot access another Customer organization's information through ordinary tenant access.

12.Hill Administrative Access

Hill's authorized Platform administrators have technical capabilities that may permit access across Customer environments.

During initial beta, demonstration, testing, and stabilization activities, administrative access may be used where reasonably necessary to validate, troubleshoot, secure, and improve the Platform.

Following general commercial deployment, access to identifiable Customer project content will generally be limited to situations where:

  • the Customer requests and authorizes technical support;
  • access is reasonably necessary to address a security incident;
  • access is necessary to maintain service integrity;
  • access is required to comply with law; or
  • access is necessary to protect Hill, Customers, users, or the Platform.

Administrative access will be logged where technically practicable.

Hill does not currently provide administrators with functionality to impersonate a Customer user.

13.Service Providers and Subprocessors

We use third parties to operate Hill EEP.

Current providers and categories include:

Hercules Cloud / Convex — application hosting, backend compute, database, and file-storage infrastructure.

Hercules Auth — authentication and identity services.

Hercules AI Gateway — AI-processing gateway.

OpenAI — AI model inference through the Hercules AI Gateway.

Hercules CDN — delivery of certain application assets.

Google Fonts — web-font delivery. Standard requests to Google infrastructure may disclose technical information such as the user's IP address.

Additional subprocessors may be added as the Service evolves.

We expect to maintain a separate subprocessor listing as Hill EEP matures commercially.

14.External Enterprise Integrations

Hill EEP is architected to support integrations with systems such as Microsoft 365, Outlook, Teams, SharePoint, document management systems, scheduling platforms such as Primavera P6, ERP/accounting systems, payroll/timekeeping systems, and related enterprise applications.

Many of these integrations are currently architecture-ready rather than active production integrations.

If a Customer activates a third-party integration, information may be exchanged with that provider according to:

  • Customer configuration;
  • Customer permissions;
  • the applicable integration;
  • the external provider's terms; and
  • applicable data-processing arrangements.

This Privacy Policy may be updated as additional production integrations are activated.

15.Data Security

Hill EEP employs security controls intended to protect information, including:

  • authenticated access;
  • HTTPS encrypted communications;
  • server-side permission enforcement;
  • organization-level tenant isolation;
  • fine-grained permissions;
  • role and scope controls;
  • audit logging;
  • field restrictions for certain AI processing;
  • deletion protection for sensitive financial and audited records;
  • mutation idempotency controls;
  • secret management outside client-side application code; and
  • workflow health and operational monitoring.

No method of storage, transmission, or information security can guarantee absolute security.

Customers should maintain appropriate internal security practices, account controls, backups where required, and incident-response processes.

16.Data Location and International Processing

Hill EEP relies on third-party cloud and AI service providers.

Information may therefore be processed or stored in jurisdictions where those providers operate.

We do not currently make a contractual representation that all Hill EEP data is stored exclusively within the United States unless specifically agreed in writing.

Where legally required, appropriate contractual or legal safeguards may be used for international data transfers.

17.Data Retention

We retain information for as long as reasonably necessary to:

  • provide the Service;
  • fulfill Customer instructions;
  • maintain security;
  • preserve project and financial integrity;
  • satisfy contractual requirements;
  • resolve disputes;
  • enforce agreements;
  • comply with applicable law; and
  • maintain legitimate audit records.

Hill EEP does not currently apply a universal automated deletion period to every data category.

Different categories may require different retention periods.

18.Termination and Customer Data

Following termination of a Customer's Service, the Customer may request export of reasonably available Customer Data during a 30-day post-termination export period, unless another period is stated in an applicable agreement.

Following that period, Hill may delete or anonymize active Customer Data, generally within 90 days after expiration of the export period, subject to legal, technical, contractual, backup, and record-retention requirements.

Backups may persist until they age out under applicable infrastructure-provider retention schedules.

Certain records may be retained longer where necessary for:

  • audit integrity;
  • financial controls;
  • tax or accounting requirements;
  • construction or safety recordkeeping;
  • fraud prevention;
  • security;
  • legal obligations;
  • contractual enforcement; or
  • litigation or dispute preservation.

19.Account Deactivation and Privacy Requests

Hill EEP does not currently provide a self-service "Delete My Account" or comprehensive self-service data portability function.

Users may submit requests concerning their personal information to: [email protected]

We will evaluate requests according to applicable law and our contractual obligations to the Customer organization controlling the applicable account or records.

In many cases, a user's employer or Customer organization may be the appropriate party to respond to requests concerning Customer-controlled project or employment information.

Deletion requests may not result in deletion of information that must reasonably be retained for security, financial integrity, auditability, legal compliance, regulatory requirements, contractual obligations, or other lawful purposes.

Where appropriate, personal identifiers may instead be restricted, anonymized, or separated from retained audit records.

20.Privacy Rights

Depending on applicable law and where an individual resides, an individual may have rights concerning personal information, which may include rights to:

  • request access;
  • request correction;
  • request deletion;
  • obtain information about processing;
  • request restriction;
  • object to certain processing; or
  • request a copy of certain information.

Hill EEP is initially offered primarily to U.S. business customers and does not currently represent that the Service has been fully localized for every international privacy regime.

We will respond to valid privacy requests as required by applicable law.

Requests may be submitted to [email protected].

We may need to verify identity and authority before responding.

21.Third-Party Business Contact Information

Customers may enter information about client contacts, vendor representatives, project stakeholders, contractors, and other business contacts who did not provide the information directly to Hill.

We process that information primarily to provide the Service on behalf of the applicable Customer.

Customers are responsible for determining the lawful basis for collecting and using such information and for providing notices where required.

22.Construction, Safety, and Quality Records

Hill EEP may process safety observations, inspections, quality deficiencies, punch records, site instructions, construction activities, and similar records.

These records may be subject to legal, regulatory, contractual, or litigation-related retention requirements.

Accordingly, such records may not always be eligible for deletion solely because an individual requests removal of associated personal information.

Hill EEP is a recordkeeping and workflow platform and does not independently determine regulatory retention requirements for Customer.

23.Financial and Employment Information

Hill EEP may process confidential business and employment-related information such as:

  • labor rates;
  • billing rates;
  • project costs;
  • budgets;
  • margins;
  • commitments;
  • procurement values; and
  • timesheet information.

Access to these records is controlled through Platform permissions.

Hill EEP's project financial functionality should not be interpreted as consumer financial services, banking, payroll processing, or payment-card processing.

Hill EEP currently does not process payment-card information for SaaS subscriptions directly.

24.Automated Decision-Making

Hill EEP does not currently use AI to make solely automated authoritative decisions concerning individuals.

AI functionality may provide recommendations, analysis, suggested actions, or summaries.

Authoritative actions remain subject to user confirmation and applicable workflows.

25.Marketing Communications

Hill EEP currently does not use personal information for behavioral advertising and does not currently operate an automated marketing-email system through the application.

We may send operational communications reasonably necessary to provide the Service, including messages concerning:

  • accounts;
  • security;
  • service changes;
  • support;
  • maintenance;
  • legal terms; or
  • Customer administration.

If marketing communications are introduced, we will provide legally required consent or opt-out mechanisms.

26.Children's Privacy

Hill EEP is intended for business and professional use by adults.

The Service is not intended for persons under eighteen (18) years of age, and we do not knowingly solicit accounts from children.

If we learn that a minor has improperly created or used an account, please contact us at [email protected].

27.Standards Alignment Information

Hill EEP may present information concerning alignment with frameworks such as ISO 9001, PMI/PMBOK, and CSIA Best Practices.

Such information describes Platform capabilities, configured controls, and available evidence.

It does not constitute certification, accreditation, formal compliance verification, or a guarantee of organizational conformity.

28.Changes to this Privacy Policy

We may update this Privacy Policy as Hill EEP evolves.

The current version will identify its Effective Date and version number.

If a change materially affects how personal information is processed, we will provide reasonable notice through the Platform, authentication process, website, email, or other reasonable method.

Where legally required, we will obtain appropriate consent.

The current Privacy Policy is available at: hillprojectservices.com/hill-eep/privacy

29.Contact Us

Questions, requests, or concerns regarding this Privacy Policy or Hill EEP privacy practices may be directed to:

Hill Project Services LLC

1795 Alysheba Way, Ste 7202 #577310

Lexington, KY 40509

United States

Email: [email protected]