AcervasAcervas
Solutions
IndustriesAbout
Integrations
BlogROI CalculatorContact
Log inStart my 90-day free pilot

Acervas — Privacy Policy

Last updated: 10 July 2026

Acervas Limited (NZ company number 9416841) (Acervas, we, us, our) is committed to protecting personal information in accordance with the Privacy Act 2020 (New Zealand), the Australian Privacy Principles under the Privacy Act 1988 (Australia), and applicable United States state privacy laws.

This Privacy Policy explains what personal information we collect, how we use and share it, where it lives, how we protect it, and the choices you have. It applies to our website at acervas.com and our software platform (the Service). Acervas serves manufacturing customers in New Zealand, Australia, and the United States; the Service is not directed at the European Union.

If you have questions about this Privacy Policy or your personal information, contact us at info@acervas.com.


1. About the personal information we handle

Acervas's Service is designed primarily to handle industrial maintenance data — information about machines, equipment, fixes, procedures, and operational events. Most of the data flowing through the Service is not personal information.

However, we do collect and process some personal information, particularly about:

  • the people who set up and administer customer accounts;
  • the engineers and operators who use the Service on behalf of our customers;
  • visitors to our website; and
  • prospective customers we communicate with.

This Privacy Policy explains how we handle that personal information.


2. Where your information lives

  • Customer data is stored onshore in Australia. Our production database, file storage, and authentication run in Sydney (Supabase, AWS region ap-southeast-2), and our application compute is routed via Sydney (Vercel, syd1).
  • AI features are processed in the United States. When you use voice transcription, search, or the AI assistant, the relevant text, queries, or audio are sent to OpenAI in the US for processing, and the results returned. OpenAI does not use data submitted through its API to train its models.
  • Some supporting services process limited data in the United States — transactional email, analytics, and rate limiting, as set out in the sub-processor table in section 5.

This is the same residency position described in our Security & Trust Overview, available to customers on request.


3. The personal information we collect

3.1 Information you give us

We collect personal information you provide directly, including:

  • Account information — name, email address, job title, phone number, and the name of the company or plant you represent
  • Communications — the content of emails, support requests, and other communications you send us
  • Marketing and sales information — information you provide when you request a demo, sign up for our newsletter, or interact with our sales team
  • Recordings of your voice — when you use the voice input feature, we capture and process audio recordings of you and your personnel speaking. These recordings are transcribed using automated speech recognition technology

We do not collect or store passwords. Sign-in to the Service is passwordless, by emailed magic link or one-time code.

3.2 Information generated through your use of the Service

  • Usage data — records of your interactions with the Service, including features used, queries submitted, and entries created
  • Device and technical information — IP address, browser type and version, operating system, device identifiers, and approximate location derived from your IP address
  • Diagnostic and log information — error logs, performance data, and similar technical information

3.3 Information from third parties

We may receive limited information about you from:

  • Your employer or plant operator — when they arrange an account for you on the Service
  • Our analytics providers — aggregated usage analytics about how people interact with the Service and our website (see sections 5.1 and 10)
  • Public sources — for example, LinkedIn profiles when we research prospective customers

3.4 Information we do not seek

We do not knowingly collect personal information from children. The Service is intended for use by adult professionals in industrial workplaces. We do not deliberately collect sensitive personal information (for example, health information, racial or ethnic origin, religious beliefs, or political opinions). If such information is included in customer-uploaded content, we treat it as customer data and process it only as a service provider to the customer.


4. How we use personal information

We use personal information for the following purposes, and only where collection is necessary for those purposes (Information Privacy Principle 1, Privacy Act 2020 (NZ); Australian Privacy Principle 3).

4.1 To provide the Service

  • Authenticate users and provide access to the Service
  • Process voice, text, and photo inputs and return AI-generated outputs
  • Display knowledge entries to authorised users within your plant and (subject to the anonymisation described in section 5.2) across the cross-plant network
  • Provide customer support

4.2 To operate and improve Acervas's business

  • Communicate with you about your account, billing, and changes to the Service
  • Respond to your enquiries
  • Send transactional emails (for example, sign-in links, billing notices)
  • Send marketing communications, where you have consented or where permitted by law (you can opt out at any time)
  • Monitor and improve the performance, security, and reliability of the Service
  • Operate, evaluate, and improve the Service — including its machine-learning components — using anonymised and aggregated data only. We do not use identifiable personal information for model training, and we do not permit third-party AI providers to train their models on customer data.

4.3 To comply with law and protect rights

  • Comply with legal obligations, including responding to lawful requests from public authorities
  • Enforce our Terms of Service
  • Detect, prevent, and respond to fraud, security incidents, or unlawful activity
  • Protect the rights, property, or safety of Acervas, our customers, or others

5. How we share personal information

We do not sell personal information. We share personal information only as described below.

5.1 With our service providers (sub-processors)

We use trusted third-party service providers to operate the Service and our website. These providers process information on our behalf, subject to agreements requiring them to protect it and use it only for the purposes we authorise.

Our current sub-processors are:

ProviderPurposeData exposedLocation of processing
SupabaseDatabase, authentication, file storageAll customer application dataAustralia (Sydney, ap-southeast-2)
VercelApplication hosting, content deliveryRequest data, app trafficCompute routed via Sydney; global CDN (US company)
OpenAISpeech-to-text, text embeddings, AI chatKnowledge text, queries, voice audioUnited States
UpstashRate limiting, background job queueRate-limit counters, job metadataUnited States
ResendTransactional email deliveryRecipient email addressesUnited States
PostHogProduct analyticsUsage events, device informationUnited States
Google AnalyticsMarketing website analytics onlyWebsite visit dataUnited States
Microsoft ClarityMarketing website session analytics onlyWebsite visit dataUnited States

Google Analytics and Microsoft Clarity run only on our public marketing website — they are not loaded inside the authenticated Service. We may update this list from time to time; material changes will be communicated through this Privacy Policy or by direct notice.

5.2 With other customers (cross-network knowledge sharing)

The Service enables anonymised cross-plant knowledge sharing as described in our Terms of Service. Knowledge surfaces to another organisation only where both the contributing and the receiving organisation have enabled network sharing, and only after it is stripped of organisational identifiers, plant names, personnel names, and customer-specific identifiers (such as work order numbers or internal asset tags). Shared knowledge is keyed to equipment make and model, not to any organisation, and cross-network results are designed to be incapable of identifying the plant they came from. Photographs are not shared cross-network unless the customer opts in to photo sharing.

5.3 In connection with business transactions

If Acervas is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honour this Privacy Policy or notify you of any material changes.

5.4 To comply with law or protect rights

We may disclose personal information when we believe in good faith that disclosure is necessary to:

  • Comply with a legal obligation, court order, or lawful request from a public authority
  • Enforce our Terms of Service
  • Protect the rights, property, or safety of Acervas, our customers, or others
  • Investigate fraud or security incidents

5.5 With your consent

We may share personal information for other purposes with your explicit consent.


6. International data transfers

Customer data is stored in Australia (section 2). Some processing — AI features, transactional email, analytics, and rate limiting — takes place in the United States through the sub-processors listed in section 5.1.

When information is transferred outside New Zealand or Australia, we take steps to ensure it remains protected to a comparable standard:

  • For disclosures from New Zealand, we comply with Information Privacy Principle 12 (Privacy Act 2020), ensuring the receiving party is subject to comparable safeguards.
  • For disclosures from Australia, we take reasonable steps as required by Australian Privacy Principle 8.
  • Each sub-processor is bound by data-processing terms restricting its use of the information, and each maintains independent security certification (SOC 2 or equivalent).

7. How long we keep personal information

We keep personal information only for as long as needed for the purposes set out in this Privacy Policy, and in any event:

CategoryRetention period
Account and authentication informationFor the duration of your account, plus 7 years for tax and legal compliance
Customer content (knowledge entries, voice recordings, photos)For the duration of your account. On termination, exportable for 30 days, then deleted
Deleted recordsSoft-deleted records are permanently purged within 30 days; residual copies in database backups age out on a rolling ~7-day cycle
Anonymised and aggregated dataIndefinitely, as set out in our Terms of Service
Sales and marketing communicationsUntil you opt out, plus 12 months
Website analyticsUp to 13 months
Diagnostic and log informationUp to 12 months
Billing and financial records7 years (NZ tax law requirement)

We may retain information for longer where required by law, where needed to defend legal claims, or where the information has been irreversibly anonymised.


8. How we protect personal information

We take reasonable steps to protect personal information against loss, unauthorised access, disclosure, alteration, and misuse. These include:

  • Encryption in transit — TLS for all connections, with HTTP Strict Transport Security
  • Encryption at rest — AES-256 for data stored in our database and file storage, with additional field-level encryption for integration credentials
  • Passwordless authentication — sign-in by emailed magic link or one-time code; there are no passwords to steal, and accounts are provisioned invite-only
  • Row-level security enforced in the database — strict separation between customer organisations, applied even to our own application code
  • Cross-network query architecture designed so that cross-plant queries are structurally incapable of identifying source plants
  • Access controls — role-based access, with administrative actions rate-limited and audit-logged
  • A CI-gated development process — code and database changes pass automated linting, type checks, and a full test suite before deployment
  • Regular security review of our systems, dependencies, and sub-processors, with a formal incident-response plan being documented as part of our SOC 2 programme

Full detail — including what is verified today versus on our roadmap — is in our Security & Trust Overview, available to customers on request.

No system is completely secure. If you believe your account or any personal information has been compromised, contact us immediately at security@acervas.com.


9. Your privacy rights

9.1 Rights under New Zealand law (Privacy Act 2020)

  • Access — you can request a copy of the personal information we hold about you
  • Correction — you can request that we correct personal information that is inaccurate, incomplete, or out of date
  • Complaint — you can complain to us or to the Office of the Privacy Commissioner (privacy.org.nz) if you believe we have breached your privacy

9.2 Rights under Australian law (Privacy Act 1988)

If you are in Australia, you have equivalent rights of access and correction under the Australian Privacy Principles, and you may complain to us or to the Office of the Australian Information Commissioner (oaic.gov.au).

9.3 Rights under United States state laws

Depending on your state of residence, you may have rights to access, correct, or delete personal information, and to know how it is shared. We honour verified requests to the extent required by the law that applies to you.

Whatever your location, we will act in good faith on any reasonable request to access, correct, or delete your personal information — email us and we will help.

9.4 How to exercise your rights

To exercise any of these rights, contact us at info@acervas.com. We will respond within the timeframes required by applicable law (in New Zealand, within 20 working days of receiving your request).

We may need to verify your identity before responding. In some cases, applicable law allows or requires us to refuse a request or charge a reasonable fee. We will explain if this is the case.

9.5 Note on customer data

If you are an end user of the Service (for example, an engineer using the Service on behalf of your employer), Acervas processes most of your personal information on behalf of your employer, who controls that information. To exercise rights in relation to that information, please contact your employer in the first instance.


10. Cookies and similar technologies

Our website and Service use cookies and similar technologies to:

  • Keep you signed in to your account (essential cookies)
  • Remember your preferences (preference cookies)
  • Understand how the Service is used (analytics — PostHog)
  • Understand how our public marketing website is used (analytics — Google Analytics and Microsoft Clarity, marketing website only)

Essential cookies are required for the Service to function. You can disable other cookies through your browser settings, though some features may not work correctly.

We do not use third-party advertising cookies.


11. Marketing communications

We may send you marketing communications about Acervas products and services, where you have consented or where permitted by law.

You can opt out of marketing communications at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Emailing info@acervas.com

Opting out of marketing communications does not affect transactional communications relating to your account or use of the Service.


12. Children

The Service is not directed to children under 18 and we do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us at info@acervas.com and we will delete it.


13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you in advance by email (where we have your email address) or by prominent notice on the Service or our website.

The "Last updated" date at the top of this Privacy Policy shows when it was last revised. Your continued use of the Service after the effective date of a change constitutes your acceptance of the change.


14. Contact us

For privacy and general enquiries, contact info@acervas.com. For security matters, including suspected vulnerabilities, contact security@acervas.com.

Acervas Limited 23 Wilding Avenue, Epsom, Auckland 1023, New Zealand NZ company number: 9416841

If you are not satisfied with our response to a privacy enquiry or complaint, you can contact the Office of the Privacy Commissioner (New Zealand):

  • Website: privacy.org.nz
  • Phone: 0800 803 909
  • Email: enquiries@privacy.org.nz

In Australia, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

AcervasAcervas

Fix it once. Know it everywhere. The cross-plant knowledge network for maintenance teams.

Product

SolutionsIndustriesHow it worksNetworkFeaturesIntegrationsBlogROI CalculatorPricing

Company

AboutFAQContactPrivacy PolicyTerms of Service

© 2026 Acervas. All rights reserved.