Stralos

How we handle personal information

1. Who we are

Stralos is operated by Stralos Limited (company number 9442335, NZBN 9429053795076), a New Zealand company with its registered office at 105 Verona Place, RD 2, Ohoka 7692, New Zealand ("Stralos", "we", "us").

This policy explains how we collect, use, store, disclose and protect personal information when you visit our website (stralos.app and stralos.co.nz) or use the Stralos platform, our software service for estimating, scheduling and managing civil construction work (the "Service").

We comply with the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs). We handle the personal information of everyone who uses Stralos, including people in Australia, in the same way, consistently with the New Zealand Privacy Act.

Our two roles

2. What we collect

2.1 Website visitors and people who register interest

2.2 Account holders (users of the Service)

2.3 Billing contacts

When your organisation subscribes we collect the billing email address, organisation name, country and billing address. Card details are entered directly into Stripe's hosted payment pages and are never received or stored by Stralos. We store the subscription status and the Stripe customer reference.

2.4 Information customers put into the Service

Customers use Stralos to run their construction business, so the Service holds information about people connected to that business, including:

Sensitive information. The Service is not designed to hold health, medical or other sensitive information. Customers should not record health details in free-text fields such as unavailability notes; record "leave" or "unavailable" instead.

3. How we use personal information

We do not sell personal information, and we do not use customer data from the Service for advertising. We do not use customer data, whether identifiable, de-identified or aggregated, for benchmarking or to train or improve AI models.

4. Service providers and where your information goes

We use the following service providers (sub-processors) to run Stralos. They act on our instructions and are bound by contract to protect the information. Some are outside New Zealand; see section 6. This table is our current sub-processor list.

We may also disclose information to our professional advisers, to a buyer or successor if our business is sold or restructured (subject to this policy), or where required or permitted by law, for example to a court or regulator.

We will give customers at least 30 days' notice, by email or in the app, before we add or replace a sub-processor, and update this list when we do.

5. AI features

Stralos includes AI features: the in-app assistant, automatic summaries and classification of uploaded documents, area take-off from drawings, and reading supplier rate sheets when you import them. When these features run, we send the model provider named in section 4:

We remove sign-in tokens before anything is sent. We use AI providers under terms that do not allow them to train their models on your data. We use Google's paid Gemini API tier. Google does not use our prompts, files or responses to train or improve its products. Google retains prompts and responses for up to 55 days, solely to detect and prevent misuse of its service. We do not log model outputs.

AI output can be wrong. Check anything the assistant produces before relying on it. The assistant proposes changes as drafts for you to confirm.

Assistant conversations are kept for 12 months and the record of assistant actions for 24 months, then deleted by a scheduled deletion job that runs weekly.

6. Storage and overseas disclosure

The Service's data, including customer data, documents and backups, is stored in Amazon Web Services' Sydney, Australia region. Our website's register-interest data is held by Cloudflare in its Oceania location.

Some service providers in section 4 process information in the United States, the European Union or elsewhere. Those providers hold and process information only on our behalf, to provide the Service to us, and not for their own purposes. Under section 11 of the Privacy Act 2020 this is not a disclosure to them for the purposes of IPP 12 (cross-border disclosure): we remain responsible for the information, and we use contracts that require each provider to protect it.

7. Cookies and similar technologies

Your choice on our website. When you first visit, we ask whether you accept analytics cookies. PostHog is not loaded and nothing is captured unless you accept. You can change your choice at any time with (also in the footer of every page); if you withdraw, we remove PostHog's cookies and local storage from your browser.

You can also block or delete cookies in your browser settings. Blocking the strictly necessary items will stop you signing in.

8. How we protect information

Privacy breaches. If we have a privacy breach that it is reasonable to believe has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable, as required by Part 6 of the Privacy Act 2020. Where the breach affects customer data we hold on a customer's behalf, we will tell the customer within 72 hours of becoming aware of it and help them meet their own obligations.

9. How long we keep information

How deletion works

When a user deletes something in Stralos, it is first removed from view and kept so it can be restored and so project history stays accurate (for example, records referenced by a submitted estimate). Projects are archived rather than deleted. This means an in-app "delete" does not immediately erase the information.

If you ask us to erase personal information, or a customer asks us to erase its data when it leaves, we will permanently delete or de-identify it from our live systems within 30 days of confirming the request, except where we must keep it by law. Confirmed erasure requests are carried out by our team within 30 days. Scheduled deletion jobs run weekly to enforce the retention periods above. Copies in backups are overwritten as the 30-day backup cycle runs.

10. Your rights

You have the right to ask for access to the personal information we hold about you (IPP 6) and to ask us to correct it (IPP 7). You can also ask us to delete it or to stop sending you marketing. Email [email protected]. We will respond within 20 working days, as the Privacy Act requires. We may need to verify your identity. There is no charge for most requests.

If your information is held in a customer's Stralos account (for example you are an employee or a contact of one of our customers), please contact that organisation. If you contact us, we will pass your request to them and help them respond.

If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).

11. Children

Stralos is a business service and the website is not directed at children. We do not knowingly collect personal information from anyone under 16.

12. Changes to this policy

We may update this policy. We will post the new version here with a new effective date and, for material changes, tell account holders by email or in the app before the change takes effect.

13. Contact our Privacy Officer

Privacy Officer: Graeme Ainsworth, Director
Email: [email protected]
Post: Privacy Officer, Stralos Limited (company number 9442335, NZBN 9429053795076), 105 Verona Place, RD 2, Ohoka 7692, New Zealand

To report a security concern or suspected unauthorised access, email [email protected].