Strova ("Strova", "we", "us") provides a project intelligence and document control platform for construction and infrastructure projects, available at strovapi.com and app.strovapi.com (the "Platform").
This policy explains how we handle personal information, and is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
Strova holds two different kinds of personal information, and your rights differ between them.
| Category | What it is | Our role |
|---|---|---|
| Account data | Information about the people who sign up for and administer a Strova account — name, work email, company, role, billing contact. | We are the controller. We decide how it is used. |
| Project data | Everything a customer puts into the Platform — defects, RFIs, drawings, photographs, site diaries, inductions, worker competency records, correspondence. | We are the processor. The customer (your employer or principal contractor) is the controller and decides what goes in, who sees it, and how long it is kept. |
If you are a worker or subcontractor whose details appear in a project because a head contractor put them there, your first point of contact is that organisation, not Strova. We will help them respond, and we will act on their instructions, but we cannot delete or change their project records on your say-so alone. See §11.
We do not use third-party analytics, advertising trackers, or behavioural profiling tools.
Construction site records can contain sensitive information as defined by the Privacy Act — for example an incident report describing an injury, or a medical restriction recorded against a worker's induction.
Strova does not require this information and does not ask for it. Where a customer chooses to record it, they are responsible for obtaining the consent the Privacy Act requires. We process it only to provide the Platform, and it inherits the same access controls as the rest of that project's data.
If you are a customer configuring an induction or incident form, only collect what you actually need. Every field you add is a field you become responsible for.
We do not sell personal information. We never have and we will not.
We disclose it to the following categories of recipient, and to no others:
| Recipient | Purpose | Location |
|---|---|---|
| Other users on the same project | The Platform's core function. Visibility is controlled by the customer through project roles and company scoping. | As configured |
| Google Cloud / Firebase | Hosting, database, file storage, authentication. | Australia (australia-southeast1/2) |
| SendGrid (Twilio) | Transactional email delivery and inbound mail routing. | United States |
| Anthropic | AI features — see §7. | United States |
| xAI | Secondary verification on some AI answers — see §7. | United States |
| CloudConvert | Document format conversion where required. | Germany |
| Professional advisers, or a lawful authority | Where required by law, or to establish or defend a legal claim. | — |
If Strova is ever acquired or merged, personal information would transfer as part of that transaction. We would tell customers before it took effect.
The Platform includes an AI assistant ("Stella") and several AI-assisted features such as document review and drafting help. You should understand precisely what this means for your data.
If your organisation cannot send project data to a US-based AI provider, tell us — AI features can be disabled at the workspace level.
Your project data is stored in Australia. Firestore, Cloud Storage and our Cloud Functions all run in Google Cloud's Australian regions.
Some processing necessarily happens overseas: email delivery (United States), AI features when you use them (United States), and document conversion (Germany). We take reasonable steps to ensure these recipients handle the information consistently with the APPs, but you should be aware that overseas providers are subject to their own local laws.
No system is perfectly secure, and we would rather say so than imply otherwise. Our current security posture, including known limitations, is described at /security.html.
| Data | Retention |
|---|---|
| Project data | For as long as the customer's account is active. Construction records often must be retained for years after practical completion; the customer decides. |
| After cancellation | Retained for 90 days so the account can be reinstated or the data exported, then eligible for deletion. |
| Account data | While the account exists, plus any period required for tax and corporate records. |
| Backups | 90 days, then automatically deleted. |
| Error reports | Retained while diagnostically useful. |
Under APP 12 and APP 13 you may ask to access the personal information we hold about you, and to have it corrected.
Email support@strovapi.com. We will respond within 30 days. There is no charge for a reasonable request.
Contact that organisation first — they control the record and they are the ones who can change or remove it. If you cannot identify or reach them, write to us and we will pass the request on and tell you who we passed it to. We will not alter a customer's project records without their instruction, because those records are frequently contractual or safety documents where unilateral alteration would cause real harm.
We use only what the Platform needs to work:
There are no advertising cookies and no third-party trackers. Blocking the authentication cookie will prevent sign-in.
We maintain a data breach response plan. If a breach is likely to result in serious harm, we will notify the affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where Strova is the processor, we will notify the customer promptly so they can meet their own obligations.
We will post any change here and update the version and effective date. For a change that materially reduces your privacy protections, we will give account holders reasonable notice by email before it takes effect.
Privacy enquiries and complaints: support@strovapi.com.
We will acknowledge a complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.