Privacy Policy

Bold Technology Pty Ltd (ABN 52 114 807 395)

Effective date: 25 August 2026 · Last updated: 25 August 2026

This Privacy Policy applies to Strata Hub, the building portfolio management platform available at https://strata-hub.com and through our mobile apps, operated by Bold Technology Pty Ltd.

1. Who We Are

Bold Technology Pty Ltd (ABN 52 114 807 395) ("Bold Technology," "we," "us," or "our") is a company registered in Queensland, Australia. We design, develop, and publish Strata Hub (the "App"), a building portfolio management platform available at https://strata-hub.com and through our mobile apps (together, the "Services").

Contact: support@strata-hub.com — Bold Technology Pty Ltd, Queensland, Australia.

This Privacy Policy explains what personal information we collect, how we use and protect it, who we share it with, where it is stored, and what rights you have, wherever in the world you use the Services.

2. Scope of This Policy

This Policy applies to personal information collected through:

  • The Strata Hub web app and any mobile app builds distributed via the Apple App Store or Google Play Store;
  • Our website(s), including account, billing, and support pages;
  • Customer support communications (email, in-app tickets, feedback and bug report forms).

It does not cover third-party websites, apps, or services that we link to but do not control, including the App Store and Google Play platforms themselves, which have their own privacy policies.

3. Information We Collect

3.1 Information you provide

  • Account information: name, email address, password (stored as a salted hash), phone number, preferred language, emergency contact details, and profile details you choose to add.
  • Building and community information: the organisation, portfolio level, building and unit records you or your administrators create, resident and occupancy details, committee and staff roles, vendor contacts, meetings, bookings, support tickets, announcements, marketplace listings, chat messages, and financial records.
  • User content: documents, images, and files you upload or store within the App ("User Content"), including documents submitted for AI analysis.
  • Payment-related information: where you purchase a subscription, payment is processed by Stripe or by Apple/Google for in-app purchases (see Section 9); we do not receive or store your full card details, only transaction confirmations, plan identifiers, and entitlement status.
  • Communications: messages you send us for support, feedback, or bug reports, including inputs you submit to any AI-powered feature (see Section 5).

3.2 Information collected automatically

  • Device and technical data: device model, operating system and version, IP address, app version, crash logs, and diagnostic data.
  • Usage data: features used, in-app actions, session length, timestamps, and general interaction data used to understand and improve the Services.
  • Approximate location derived from IP address, where relevant. We do not collect precise GPS location.
  • Cookies and similar technologies on our website(s) for authentication, preferences, and analytics — see Section 12.

3.3 Information from third parties

  • Stripe, Apple App Store and Google Play: purchase confirmations, subscription status, and aggregated analytics made available to developers.
  • Analytics and crash-reporting providers: technical and usage data as described above.
  • AI/LLM service providers: outputs generated when you use an AI-powered feature — see Section 5.
  • Identity providers: if you sign in using a third-party account (for example Google, Microsoft or Apple), we receive the limited profile information that provider authorises — typically name, email address, and a unique account identifier. We never see or store your third-party password.

3.4 Authentication. You may sign in with an email address and password (optionally protected by two-factor authentication) or a supported third-party sign-in method. Password hashes and 2FA/TOTP secrets are encrypted at rest.

4. How We Use Your Information

We use personal information to:

  • Provide, operate, maintain, and secure the Services;
  • Create and manage your account, memberships, roles, and access to the buildings and portfolios you are entitled to see;
  • Store, sync, and display your User Content, including at the storage location selected for your organisation where that option is offered;
  • Power AI features such as document analysis, meeting summaries, and assistive suggestions, as described in Section 5;
  • Respond to support requests, tickets, and feedback, and communicate with you about the Services;
  • Monitor, debug, and improve performance, stability, and features;
  • Detect, prevent, and investigate fraud, abuse, and security incidents;
  • Comply with legal obligations and enforce our Terms & Conditions;
  • Send service-related notices — including changes to free-tier features — and, where you have opted in, marketing communications you can withdraw at any time.

We do not use your User Content to train third-party AI/ML models without your consent, and we do not sell your personal information to third parties for their own marketing purposes — see Section 10.

5. AI Features, Recommendations, and AI Agents

Strata Hub uses third-party large language models and AI-driven agents to generate content, summarise documents and meetings, answer questions, and provide recommendations ("AI Features"). This section applies in addition to the rest of this Policy.

5.1 How AI Features process your information. When you use an AI Feature, the inputs you provide — for example a document you ask us to analyse, a prompt, or the relevant account and building data needed to personalise a response — are sent to our AI provider(s) to generate a response. These providers process your inputs under data processing terms with us that include confidentiality and security obligations. We do not authorise our AI providers to use your data to train their general-purpose models. AI outputs may be logged for a limited period for quality assurance, abuse prevention, and debugging, consistent with Section 11. Where an AI agent takes actions on your behalf, it acts only within the permissions of your account and the scope of that feature.

5.2 Accuracy and limitations. AI Features use predictive models that can produce inaccurate, incomplete, or inappropriate output. AI-generated content — including document analyses, risk findings, and suggested action items — is provided for informational purposes only and is not professional, legal, engineering, or financial advice. You are responsible for reviewing and verifying AI output before relying on it.

5.3 Your choices. Where an AI Feature is optional you can choose not to use it, and declining will not affect your access to the core, non-AI functionality of the Services. If we materially change which AI provider processes your data, we will update this Policy and, where required, seek your consent.

6. Legal Bases for Processing (EEA/UK Users)

If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:

  • Contract — processing necessary to provide the Services you or your organisation signed up for (Art. 6(1)(b));
  • Legitimate interests — security, fraud prevention, analytics, and service improvement, balanced against your rights (Art. 6(1)(f));
  • Consent — optional features such as marketing communications or optional analytics cookies (Art. 6(1)(a)); you may withdraw consent at any time;
  • Legal obligation — where we must retain or disclose information to comply with law (Art. 6(1)(c)).

7. Where Your Data Is Stored

Account data and databases are hosted in data centres located in the United States, operated by our infrastructure providers.

Where your organisation can choose a storage location or region for uploaded documents and object storage, that choice determines only where the underlying file is physically stored; the account database, authentication records, and associated metadata remain hosted in the United States regardless of the region selected. We disclose this so you can make an informed choice where data residency matters for your own regulatory obligations.

This means personal information is transferred to and processed in the United States, which may not have data protection laws equivalent to those in your own country. Where an AI Feature is used, your inputs may also be processed by our AI provider(s).

8. International Data Transfers

8.1 EEA / UK. Where we transfer personal information from the EEA or UK to the United States we rely on appropriate safeguards recognised under GDPR / UK GDPR, which currently include the EU-U.S. Data Privacy Framework and the UK Extension (where our provider is a certified participant) and/or Standard Contractual Clauses with the UK International Data Transfer Addendum. You can request a copy of the relevant safeguard by contacting us.

8.2 Australia. As an Australian company we take reasonable steps to ensure overseas recipients of your personal information do not breach the Australian Privacy Principles, consistent with APP 8. By using the Services you understand your data will be handled in the United States as described in Section 7.

8.3 Other regions. We apply comparable contractual and technical safeguards with our infrastructure and AI providers regardless of where you are located, and rely on the transfer mechanisms available under applicable law, including your consent where required.

9. Payments and Subscriptions

Subscriptions purchased through our website are billed and processed by our third-party payment processor, Stripe, Inc. ("Stripe"), under Stripe's privacy policy at https://stripe.com/privacy. Payment details you enter (card number, expiry, CVC, and billing address) are collected and processed directly by Stripe; they pass through our checkout interface but are not transmitted to or retained on our servers.

Purchases made through a mobile app build are billed by Apple (https://www.apple.com/legal/privacy/) or Google (https://policies.google.com/privacy) under their own terms.

Across all channels we receive only limited information sufficient to grant access to purchased features and maintain your billing history — purchase confirmation, plan identifier, transaction amount and date, and subscription status. Neither Bold Technology nor Strata Hub retains your full card number, CVC, or bank account details.

You can view your billing and subscription status at any time from the Billing section of the App.

10. Who We Share Information With

10.1 We do not sell personal information. We do not sell, and have not in the preceding 12 months sold, any personal information that identifies, relates to, or could reasonably be linked with you as an individual, as "personal information" and "sale" are defined under the CCPA/CPRA and equivalent laws. We do not share personal information for cross-context behavioural advertising.

10.2 Service providers. We share personal information with providers who process it on our behalf under contract — hosting and infrastructure, object storage, email delivery, analytics and crash reporting, payment processing, and AI/LLM providers — only to the extent needed to deliver the Services.

10.3 Within your organisation. Strata Hub is a shared workspace. Information you enter is visible to other users of your organisation according to their role and permissions — for example building managers, committee members, staff, and assigned vendors. Your administrators control those permissions.

10.4 Legal and safety. We may disclose information where required by law, to enforce our Terms, or to protect the rights, property, or safety of users and the public.

10.5 Aggregated and de-identified data. We may compile aggregated, anonymised, or de-identified analytics that cannot reasonably be used to identify any individual. As at the "Last updated" date we do not license or sell such data; if this changes we will update this Policy and, where required, provide notice and an opt-out.

11. Data Retention

We retain personal information for as long as your account is active and as necessary to provide the Services. Following account deletion, we delete or de-identify personal information within 90 days, except where we are required to retain it longer to comply with legal, tax, accounting, dispute-resolution, or security obligations. Backups are cycled out over a similarly bounded period. AI Feature logs are retained only for the limited period necessary for the purposes described in Section 5.1.

Note that records created within a building or portfolio workspace (such as meeting minutes, financial records, or tickets) may be retained by the owning organisation after your individual account is deleted, as that organisation is responsible for its own record-keeping obligations.

12. Cookies and Similar Technologies

Our website and web app use cookies and similar technologies for:

  • Essential functions (authentication, security, session management);
  • Preferences (such as your selected theme and interface language);
  • Analytics (understanding aggregate usage).

Where required by law, we request your consent before setting non-essential cookies and you can change your preferences at any time through your browser settings. Mobile app builds do not use browser cookies but may use device-level identifiers for analytics and crash reporting as described in Section 3.2.

13. Your Privacy Rights

Depending on where you live you may have some or all the rights below. We honour valid requests regardless of your location as a matter of policy, subject to identity verification and applicable legal exceptions.

13.1 EEA / UK (GDPR, UK GDPR): the right to access, rectify, or erase your personal information; to restrict or object to processing (including automated decision-making such as AI-generated recommendations based on legitimate interests); to data portability; to withdraw consent at any time; and to lodge a complaint with your supervisory authority (in the UK, the ICO; in the EU, your national Data Protection Authority).

13.2 California and other US states (CCPA/CPRA and similar): the right to know and access the categories and specific pieces of personal information we hold; to delete and to correct personal information; to opt out of the sale or sharing of personal information (as noted above, we do not sell or share it); to limit use of sensitive personal information; and to non-discrimination for exercising these rights.

13.3 Australia (Privacy Act 1988, Australian Privacy Principles): the right to access the personal information we hold about you (APP 12); to request correction of inaccurate, out-of-date, or incomplete information (APP 13); and to make a complaint about a breach of the APPs — in the first instance to us, and if unresolved to the Office of the Australian Information Commissioner at www.oaic.gov.au.

13.4 Canada (PIPEDA): the right to access and request correction of your personal information, to withdraw consent subject to legal or contractual restrictions, and to complain to the Office of the Privacy Commissioner of Canada.

13.5 Brazil (LGPD), South Africa (POPIA) and other jurisdictions: you have broadly equivalent rights to access, correct, delete, and port your data, and to lodge complaints with your local regulator.

13.6 How to exercise your rights. Email support@strata-hub.com with your request and the email address associated with your account. We will respond within the time required by applicable law (for example one month under GDPR, or 45 days under CCPA, extendable in certain circumstances). You can also delete your account directly in the App under Profile.

14. Children's Privacy

The Services are intended for building residents, managers, and committee members and are not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under this age. If we become aware that we have inadvertently collected such information we will take reasonable steps to delete it promptly. If you believe a child has provided us with personal information, contact us at support@strata-hub.com.

15. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS), encryption at rest for sensitive fields (including password hashes and 2FA/TOTP secrets), row-level access controls that restrict records to the organisations and buildings you are entitled to see, and regular review of our infrastructure and AI vendor arrangements. No method of transmission or storage is completely secure and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and relevant regulators as required by applicable law, including the Notifiable Data Breaches scheme under the Australian Privacy Act.

16. Contact Us

Bold Technology Pty Ltd, Queensland, Australia.

Email: support@strata-hub.com

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology (including AI providers), or legal requirements. We will update the "Last updated" date above and, where changes are material, provide additional notice (such as an in-app notification or email) before the changes take effect. Continued use of the Services after the effective date of an update constitutes acceptance of the revised Policy.