Privacy Policy
This policy explains how Strucent handles personal information. It is structured around the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
Last updated: 2026-07-08
Who we are
Strucent is a quality management system (QMS) for fabrication workshops, operated by [STRUCENT LEGAL ENTITY NAME + ABN] (“Strucent”, “we”, “us”). You can contact us about privacy at privacy@strucent.com.
Two roles matter in this policy. Where we collect information about you directly (for example when you create an account), we handle it as described here. Where your employer or another Strucent customer stores information about you inside their Strucent workspace (for example welder qualification records), that customer controls the information and we process it on their behalf under our agreement with them.
What we collect
Information we collect directly:
- Account details — your name and email address.
- Sign-in and security records — sign-in events, IP addresses and device/browser information, kept for account security and fraud prevention.
- Support communications — emails and messages you send us.
- Billing details — subscription and payment records. Card payments are processed by Stripe; we do not store card numbers.
Information our customers store in their workspace (which may include your personal information if you work for or with a Strucent customer):
- Quality records — weld registers, inspection and test records, non-conformance reports, material records and similar QMS data.
- Personnel records — names, roles, qualifications, competency evaluations and signatures of workshop personnel.
- Uploaded files — documents, drawings and photos.
How we collect it (APP 3 and 5)
We collect information directly from you when you sign up, sign in, use the service or contact us. We collect workspace data because a customer enters it. We do not buy personal information from third parties and we do not collect it covertly.
How we use it (APP 6)
- To provide, operate and secure the service.
- To authenticate you and protect accounts (including optional multi-factor authentication).
- To respond to support requests.
- To bill for subscriptions.
- To send service emails (sign-in links, notifications you or your workspace admin have configured, and important service announcements).
We do not sell personal information, and we do not use customer workspace data for advertising or to train AI models.
Who we disclose it to (APP 6)
We disclose personal information only to the third-party service providers (sub-processors) we use to run Strucent — for example cloud hosting, email delivery and payment processing. The current list, including each provider’s purpose and location, is published at /legal/subprocessors. We may also disclose information where required by law.
Overseas disclosure (APP 8)
Customer data is hosted in Australia (AWS Sydney region, ap-southeast-2). Some of our sub-processors operate from, or process limited data in, other countries — for example payment processing and email delivery. The sub-processor list linked above states each provider’s location and the categories of data it handles.
How we keep it secure (APP 11)
- Encryption in transit (TLS) and at rest.
- Tenant isolation — each customer’s data is segregated at the database layer using row-level security.
- Optional multi-factor authentication (authenticator-app codes) for all users.
- Audit logging of security-relevant actions, including any access by Strucent staff.
- Virus scanning of uploaded files.
- Backups — automated database backups, including weekly encrypted backup copies stored separately, supporting point-in-time recovery.
If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
Cookies and analytics
Strucent uses only essential cookies — session cookies that keep you signed in and security cookies that protect against request forgery. We do not use advertising cookies or third-party analytics trackers. When our error-tracking service is enabled, it may capture technical details about an error (such as browser type and the page involved) so we can fix faults; it is used for service reliability only.
Access and correction (APP 12 and 13)
You can view and update your own account details in the app. For information held in a customer’s workspace (for example your qualification records held by your employer), ask that customer first — they control the record. You can also contact us at privacy@strucent.com to request access to or correction of personal information we hold; we will respond within 30 days.
Retention and deletion
We keep customer workspace data for the life of the subscription. When a subscription ends, the customer may export their data within 30 days of termination; the workspace is then deleted — a 30-day soft-delete window followed by permanent deletion from our databases and file storage. Some records (such as billing records and security logs) are retained longer where the law requires or for legitimate security purposes.
Complaints (APP 1)
If you have a privacy concern or complaint, contact us at privacy@strucent.com and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): online at www.oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
Changes to this policy
We may update this policy from time to time. Material changes will be notified to workspace administrators by email, and the “Last updated” date above will change.
See also: Terms of Service · Sub-processors