| Data | Purpose | Basis |
|---|---|---|
| Work email address, organisation name, role in the workspace | Create and secure your account and workspace; invite teammates; contact you about the Service | Performance of the agreement |
| Sign-in events, IP address, browser details | Security, rate limiting, abuse prevention, the workspace audit trail | Legitimate interests (security) |
| Your workspace model (capabilities, systems, processes, business cases, uploaded workbooks) | Providing the Service — this is your Customer Data; it is designed to hold organisational, not personal, information | Performance of the agreement; you are the controller |
| Billing details (name, email, plan; card data is held by Stripe only) | Subscriptions, invoices, tax | Performance of the agreement; legal obligation |
| Support correspondence | Answering you and improving the Service | Legitimate interests |
We do not use analytics trackers or advertising cookies. The only cookie is a signed session cookie required to keep you signed in.
The Service runs on Cloudflare (Pages Functions and D1 database). Data is stored in Cloudflare's data-centre network; edge compute is global by design. Our subprocessors are listed in the DPA: Cloudflare (hosting, storage), Stripe (payments), [Clerk (identity), once enabled]. If you need data pinned to a specific region or a single-tenant deployment, ask us — a region-pinned hosted option and the offline zero-egress edition exist for that purpose.
AI assistance is off by default. When you enable it, text is sent to an endpoint you configure (your own provider or an in-network model); we show you the exact text first and redact identifying names by default. We do not train models on your data and we do not operate a shared default AI endpoint.
You can access and export your workspace data at any time from the workspace page or the app. You can ask us to correct or delete personal information, or complain about our handling of it, at [privacy contact email]. We will respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner (OAIC) or your local supervisory authority.
Encryption in transit (TLS) and at rest (platform-managed); tenant isolation enforced server-side; signed HttpOnly session cookies; least-privilege secrets management; an append-only audit trail per workspace; rate limiting and bot protection on sign-up. We hold no security certification yet; controls are being documented toward SOC 2 / ISO 27001. We notify affected customers of an eligible data breach without undue delay in accordance with the Notifiable Data Breaches scheme.
The Service is for organisations and is not directed at children under 16.
We will notify workspace administrators of material changes at least 30 days in advance. Contact: [Operator legal name], [postal address], [privacy contact email].