Privacy Policy
Last updated: 7/4/2026
1. Introduction
Engsitetools ("we", "us", or "our") operates the Project Scheduler web application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
Engsitetools is an individual business operating from Perth, Western Australia. This policy applies to the Service and any related communications. Where we rely on your consent to process personal information (for example, marketing communications or optional integrations), we will ask for it separately and you can withdraw it at any time. For all other processing, we rely on the lawful bases described in Section 3.
2. Information We Collect
a) Authentication and Account Information
We use Supabase Auth for user authentication. When you create an account, we collect:
• Email address
• Name and profile information you provide
• Authentication tokens and session data
b) Project and Service Data
To provide our scheduling service, we collect and store:
• Project details, activities, and relationships
• Schedules, baselines, and resource assignments
• Documents and files you upload
• Risk assessments and mitigation plans
• Comments and collaboration data
c) Usage and Analytics Data
We monitor service usage to optimize performance:
• AI usage metrics (requests, tokens consumed)
• Storage usage and project counts
• Feature usage patterns
• Performance and error data
d) Billing Information
Payment processing is handled by Stripe:
• Stripe customer IDs (stored securely)
• Subscription status and plan information
• Billing history (via Stripe)
e) Integration Data
When you connect third-party services:
• OAuth tokens for Microsoft Graph and Google Drive
• Access permissions you authorize
• Metadata from linked files and resources
f) Technical Information Collected Automatically
When you use the Service, we automatically collect:
• IP address and approximate location derived from it
• Browser type, operating system, and device identifiers
• Pages and features accessed, timestamps, and referring URLs
• Error and performance data
We use cookies and similar technologies for authentication (keeping you logged in), security, and basic usage analytics. We do not use third-party advertising cookies or cross-site tracking.
3. How We Use Your Information
We use your information for the following purposes:
• To provide and maintain the Service - including authentication, storing your projects, enabling collaboration, and delivering features you request (performance of contract)
• To process subscriptions and manage billing (performance of contract; legal obligation)
• To enable AI features and chat functionality - see Section 4 for detail (performance of contract)
• To facilitate integrations with third-party services you authorise (performance of contract; consent)
• To monitor service usage, diagnose issues, and improve performance (legitimate interests)
• To respond to support requests and feedback (performance of contract; legitimate interests)
• To send service-related notifications (security alerts, billing notices, material changes to terms) - you cannot opt out of these while you have an active account (performance of contract; legal obligation)
• To send optional product updates or marketing - only with your consent, which you can withdraw at any time (consent)
• To comply with legal obligations including tax, accounting, and lawful requests from authorities (legal obligation)
• To detect, prevent, and respond to fraud, abuse, or security incidents (legitimate interests; legal obligation)
About our marketing emails
If you opt in to marketing emails, we may use tracking pixels to measure opens and click-throughs so we can gauge the effectiveness of our communications. You can unsubscribe at any time using the link in any marketing email or by emailing [email protected]. Unsubscribing from marketing does not stop service-related emails (security alerts, billing notices, material changes to terms) - those continue while you have an active account.
4. AI Data Handling
Some Service features (AI chat, automated reports, document analysis) are powered by third-party AI providers. When you use these features, we send your prompts and the minimum project data necessary to generate a response.
Our AI providers
We currently use APIs from OpenAI, Anthropic (Claude), and Google (Gemini). These providers are primarily based in the United States. We deliberately select providers based on data protection practices, reliability, and suitability for commercial work - not lowest cost.
Our commitments
• We use enterprise or API tiers with each provider under terms that prohibit the use of your prompts or outputs to train their models
• We do not sell your AI interaction data
• We send only the project data necessary to fulfil your request
• We track aggregate metrics (request counts, tokens) to enforce plan limits, not to profile individual users
Our own use of AI metadata
We log basic metadata about AI feature usage - timestamp, which user triggered which feature, and the type of object (project, task, document) it was used on - to monitor performance, enforce plan limits, and improve the Service. We do not use the contents of your prompts or AI outputs to train any model, ours or a third party's.
What we cannot guarantee
Because processing occurs on third-party infrastructure, providers may temporarily retain prompts for abuse monitoring under their own terms. Current retention windows for the API tiers we use range from zero to thirty days. We review provider terms periodically and will update this policy if our arrangements change materially.
Enterprise options
If you need stricter controls - such as restricting AI processing to a specific provider, region, or your own API keys - contact us at [email protected] to discuss enterprise configuration.
5. Our Role: Data Controller and Data Processor
Privacy laws generally distinguish between the "data controller" (who decides why and how data is processed) and the "data processor" (who processes data on behalf of the controller).
Engsitetools acts as data controller for:
• Account and billing information about you as our customer
• Usage analytics and service logs
• Support communications and feedback
Engsitetools acts as data processor for:
• Project data, schedules, activities, documents, risk assessments, and any personal information about your employees, contractors, or third parties that you upload to the Service
When we act as processor, we only process this data on your documented instructions and in accordance with our Data Processing Addendum (available on request at [email protected]). You are responsible for ensuring you have a lawful basis to upload personal information about others to the Service, and for handling any data subject requests from those individuals.
What account administrators can see and do
If you use the Service through an organisation account, the account administrator (typically your employer or its appointed representative) can:
• Access projects, schedules, documents, and other content within the account, including content you create
• View activity logs showing actions taken within the account
• Add, suspend, or remove users
• Export data from the account
• Change account-wide settings, including AI features and integrations
If you have questions about how your administrator uses these capabilities, contact them directly. Engsitetools is not responsible for how administrators choose to configure or operate their accounts.
6. Data Sharing and Subprocessors
We share data only with the following categories of recipients, each bound by written agreements requiring confidentiality and data protection equivalent to Australian standards:
Subprocessors (engaged to deliver the Service):
• Supabase (United States / Singapore) - authentication and database hosting
• Stripe (United States / Australia) - payment processing
• OpenAI, Anthropic, Google (United States) - AI features
• Railway (Singapore, Southeast Asia) - backend infrastructure hosting
• Vercel (global CDN; primary processing in United States) - frontend hosting and content delivery
Authorised by you:
• Microsoft Graph, Google Drive - only when you connect these integrations
Other disclosures:
• Professional advisers (legal, accounting) under confidentiality obligations
• Law enforcement or regulators where legally compelled, where we believe in good faith disclosure is necessary to investigate fraud or illegal activity, or to protect the rights, property, or safety of Engsitetools, our users, or the public
• A successor entity in the event of a merger, acquisition, or sale of assets. Until any successor publishes its own privacy policy and gives you reasonable notice, your information will remain subject to this Privacy Policy.
A current list of subprocessors is available on request at [email protected]. We will give reasonable notice before adding or replacing a subprocessor that processes personal information.
7. Data Security
We implement security measures including:
• Encryption of data in transit and at rest
• Secure authentication and session management
• Regular security updates and monitoring
• Access controls and principle of least privilege
• Secure API key management
8. Your Rights
Under Australian Privacy Principles, you have the right to:
• Access the personal information we hold about you
• Request correction of inaccurate or out-of-date information
• Request deletion of your account and associated personal information, subject to legal retention requirements
• Withdraw consent for marketing communications at any time
• Receive a copy of your project data in a portable format (CSV or JSON)
• Make a complaint about how we have handled your personal information
Browser privacy signals: Where required by law, we honour Global Privacy Control (GPC) signals. We do not currently respond to Do Not Track (DNT) browser signals, as no industry consensus exists on how to interpret them.
How to exercise your rights
Email [email protected] from the email address associated with your account. We may ask you to confirm specific account details (such as your most recent project name or login activity) to verify your identity before acting on access, correction, or deletion requests. We will respond within 30 days. There is no charge for reasonable requests.
If a request is made on your behalf by a third party (such as a lawyer or family member), we will require written authorisation and may contact you directly to confirm.
If we cannot resolve your complaint
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
Note for users of customer accounts: If your employer or another organisation has uploaded your data to the Service, that organisation is the data controller. Please direct access, correction, and deletion requests to them in the first instance.
9. International Data Transfers
Your data may be stored or processed outside Australia, primarily in the United States, the European Union, and Singapore, depending on the subprocessor.
Under Australian Privacy Principle 8, we remain accountable for personal information disclosed to overseas recipients. We protect international transfers through:
• Written agreements with each subprocessor requiring data protection standards equivalent to the Australian Privacy Principles
• Reliance on EU Standard Contractual Clauses, the EU-US Data Privacy Framework, or equivalent transfer mechanisms where the subprocessor offers them
• Encryption of data in transit and at rest
If you require data residency in a specific region, contact us to discuss enterprise options.
10. Data Retention
We retain personal information only as long as necessary for the purposes it was collected, or as required by law:
• Account data: Retained while your account is active. After deletion, removed from production systems within 30 days and from encrypted backups within 90 days.
• Project data: Retained while your account is active. You can export or delete project data at any time. After account deletion, removed on the same schedule above.
• AI chat data: Cached up to 24 hours for performance; not retained beyond this on our systems (provider retention is governed separately - see Section 4).
• Billing records: Retained for seven years to comply with Australian tax and corporations law.
• Service and security logs: Retained for 90 days, then deleted.
• Support communications: Retained for two years from the date of last contact.
Where law requires longer retention (for example, in connection with a legal claim or regulatory investigation), we will retain only the data necessary for that purpose.
11. Children's Privacy
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided personal information to us, please contact [email protected] and we will delete the information promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version.
For minor changes (clarifications, formatting, or non-material updates), we will post the revised policy here.
For material changes - including new categories of data collection, new subprocessors, or new purposes of use - we will give you at least 14 days' advance notice by email and through the Service before the changes take effect. If you do not agree to the changes, you can close your account and export your data before they apply.
13. Contact Information
If you have questions about this Privacy Policy or your data rights, please contact:
Engsitetools
ABN: 49 868 421 517
Perth, Western Australia
Email: [email protected]
We will respond to your inquiry within 30 days.
