← Back to independenttechnologies.io

Cross Link — Privacy Policy

Effective date: July 25, 2026 Independent Technologies Limited — info@independenttechnologies.io

This policy covers the Cross Link applications: the desktop viewer/editor for Windows, the Cross Link mobile viewer for Android, and the project web viewer (PWA). It describes what data the apps handle, what little of it ever reaches us, and your choices.

The short version

Data we collect

Sign-in and licensing

When you unlock the app with Microsoft sign-in or an activation code, the app sends your email address (and, for Microsoft sign-in, the signed identity token issued by Microsoft) to our licensing service to confirm your organization's seat entitlement. Because seats are bound to devices, activation also sends a device identity: the device name, the operating-system username on that device, a derived device identifier, and the platform type. We store the email address, seat assignment, device identity, activation records, and per-device last-seen timestamps needed to administer your organization's license, for the life of the seat. Authentication itself is performed by Microsoft; we never see or store your password.

Support requests (optional)

If you use Submit Bug or Feature Request or send a diagnostics log, we receive what you chose to send: your description, optionally your email address for follow-up, and — if a diagnostic log exists on your device from a session where you enabled logging — a redacted technical log. Diagnostic logging is off by default. Logs never include your drawings or their contents; they may include technical events plus project/file names and storage addresses (credentials and access tokens are removed). Support data is kept only as long as needed to resolve the issue.

Update checks

The desktop app — and the Android app when installed outside Google Play — checks for signed application updates by fetching version metadata. No personal data is included in update checks. On Google Play, app updates are delivered by Google Play itself.

Drawing submissions (Windows desktop, Admin seats only)

If an Admin uses Submit Drawings for Scanning, we receive the drawing files plus the submitting person's name, email address and phone number, and the company, project and notes attached to the pack, any PO number entered, the application version, and the identity of the signed-in Admin seat that authorised the upload (its account name and email address). This is the one path by which drawing content reaches us, it is never automatic, and it is not available in the Android app or the web viewer. Full detail in Drawings you send us for scanning, below.

Nothing else

The apps collect no location data, no contacts, no device identifiers for advertising, and no usage analytics. The mobile app uses the camera only to scan QR codes for opening projects; camera images are processed on your device and are never stored or transmitted. If you deny camera permission you can still open projects by other means — only QR-code scanning is affected.

Your projects stay in your storage

Cross Link is client-hosted by design. Project packages are stored in your organization's own SharePoint, Azure storage, or network drives, governed by your organization's permissions and policies. When an app opens a project, it talks directly to your organization's storage — that traffic never passes through Independent Technologies.

Packages may additionally be encrypted at rest with a company key (AES-256). Company keys are never transmitted to us; locked packages are decrypted entirely on your device.

Drawings you send us for scanning

A Cross Link project is produced by our scanning service, which means you send us the source drawings. This is a deliberate, admin-initiated action — the Submit Drawings for Scanning feature in the Windows desktop app, available only to holders of an Admin seat. The Android app cannot submit drawings at all, and neither can the web viewer.

When a drawing pack is submitted, we receive and store on infrastructure we control (Cloudflare):

That record is the whole of it. It is generated from the columns of the table it is stored in, so it is the complete list rather than a summary of one.

Three entries deserve a note. Pixel dimensions are recorded so we can flag a scan that is too low resolution to read before it reaches the scanning team. The email address of the Admin seat that authenticated the submission is recorded separately from the contact email above, because the person who submits a pack may legitimately be someone other than the contact for the job. The company name as typed is recorded on every submission, not only on the ones where it differs from the company that owns the authenticating seat: the pack is always filed under the seat's company, and the typed value is kept verbatim so that a division rename can be told apart from work queued in another company's name.

Scanning runs on offline models on our own workstations. Your drawings are never sent to a third-party or cloud AI service.

How long we keep the files. Submitted drawing files are retained until the pack has been scanned and the finished project has been accepted, or sooner on your written request. Closing out the job deletes those files from our storage. You do not have to do anything to accept a delivery. Where you have a signed services agreement, acceptance is as that agreement defines it. Under the current form that is a 30-day review period after each delivery, in which you can ask at no charge for correction or re-scan of ANY drawing in the package, so that you can satisfy yourself the processed data is right — you do not have to show that anything is wrong. If you ask for nothing in that window the package is deemed accepted, and corrections requested after it are billed at the per-drawing revision rate. A revision re-scan, or drawings added to an existing project, is itself a delivery and starts its own review period. There is no button to press. Two backstops apply automatically so that an unfinished job cannot hold drawings indefinitely: a delivered project that is never accepted has its source files deleted 90 days after the pack is downloaded — or 90 days after delivery for a pack that is never downloaded — and an upload that is interrupted and never completed is discarded after 7 days.

The submission record outlives the drawings. Closing out a job deletes the drawing files but not the record of the job. Every entry in the list above is kept, with no end date — closing out a job clears none of them, and nothing else deletes them on a clock. We keep it so a customer who loses their originals can be told exactly what to re-send, and so we can identify past work. It is a business record, not drawing content — the drawings themselves are gone. You can ask us to erase the record as well, and we will.

Using drawings to improve recognition

Our tag-recognition models are trained on drawings that have been through the scanning service.

Retention for model improvement is opt-in: no drawing is retained for model improvement unless you authorize it for your project, which matches Section 7.3(d) of the services agreement. Declining does not affect the quality of your own project, though we may decline work where retention is not permitted.

Two points are worth stating plainly rather than burying:

You may request deletion of your project's retained training material at any time by emailing us.

Sharing

We do not sell, rent, or trade personal data — ever. The limited data above is processed by the sub-processors we run on:

That list is maintained in full, with a 30-day change-notice commitment, in Sub-processors — see The documents this refers to below. We disclose data only if required by law.

Security

All traffic between the apps and our services uses HTTPS. Application updates are cryptographically signed and verified before install. Optional package-at-rest encryption uses AES-256-GCM. Licensing records are stored on Cloudflare's infrastructure with access limited to Independent Technologies.

Retention and deletion

Licensing records are kept for the life of your organization's license. Support submissions are deleted once resolved.

Submitted drawing files are kept until the pack is scanned and accepted, or until you ask for them in writing. Two backstops apply automatically so that an unfinished job cannot hold drawings indefinitely: a delivered project that is never accepted has its source files deleted 90 days after the pack is downloaded — or 90 days after delivery for a pack that is never downloaded — and an upload that is interrupted and never completed is discarded after 7 days. The submission record — the queue number, the company and project names, the submitting person's name, email address and telephone number, the notes, the list of file names and sizes, and 15 further fields, listed in full under "Drawings you send us for scanning" above — is kept after the drawings are deleted, with no end date, as the record of work performed. Retained training material is covered above and can be deleted on request.

To request access to or deletion of your data, email info@independenttechnologies.io — deletion requests are honored within 30 days, except records we must keep for license administration your organization has contracted for.

Two companion annexes carry the detail behind this section, and are versioned so you can see when they change: Sub-processors (SUBPROCESSORS.md) lists in full every third party that processes data on our behalf, with a 30-day change-notice commitment; Data Retention and Deletion (DATA_RETENTION.md) sets out how long each category of data is kept and what deletes it. Both are published as Sub-processors & Data Retention in the Cross Link documentation set, and are available on request from the address in "Contact" below.

Children

Cross Link is a professional/industrial tool and is not directed at children under 13. We do not knowingly collect data from children.

Changes

If this policy changes materially, we will update this page and the effective date above. Continued use after a change means acceptance of the updated policy.

Contact

Independent Technologies Limited info@independenttechnologies.io https://independenttechnologies.io