LEVRTEK / DOCUMENTS
Privacy policy
This master policy explains how LEVRTEK handles personal information across its websites, product families and services. Each product schedule describes the additional data flows for that product.
Last updated 5 September 2026
Business identity
LEVRTEK is a registered Australian business name, ABN 62 127 504 482. Privacy enquiries, access or correction requests, deletion requests and complaints may be sent to privacy@levrtek.com.
Scope and responsibility
LEVRTEK determines why and how information is handled for the parent website and its own services. A customer organisation may control information it puts into a LEVRTEK workspace; in that case LEVRTEK processes the information to provide the service and may refer an individual’s request to that customer.
Information we may collect
Depending on the service, LEVRTEK may handle account and authentication details; organisation membership and permissions; contact, waitlist and communication choices; billing and entitlement records; uploaded CAD, drawings, spreadsheets and engineering packages; job, stock, material, supplier, costing, quote, approval and delivery records; generated analyses and reports; support requests; consent records; and technical, security and audit events. A product schedule identifies which categories apply to that product.
How information is collected and used
Information may come from you, an authorised organisation, a connected service, a selected supplier or recipient, and hosting, payment, security or analytics providers. LEVRTEK uses it to provide and secure services, authenticate users, isolate workspaces, process files and payments, produce requested outputs, deliver communications, support customers, prevent misuse, diagnose faults, improve consented product performance, comply with law and establish or defend claims. LEVRTEK does not sell personal information.
Customer engineering content and AI
Customer files, geometry, dimensions, costs, quotes, supplier information and workspace content are product data, not advertising data. LEVRTEK does not use customer engineering content or personal information to train shared or third-party AI models. An optional AI or voice feature may send only the disclosed input to the named provider after a separate just-in-time notice and any required agreement; a non-AI path must remain available where the product schedule promises one.
Providers and their roles
Cloudflare may provide DNS, TLS, CDN, WAF, Access, Workers, D1, private R2, request security and rate limiting. Supabase may provide waitlist and contact-lifecycle data services and, where a later product release enables it, identity, organisation data and row-level security. PostHog may receive consented allow-listed product events. Sentry may receive scrubbed operational errors. Resend may deliver application email; cPanel mail supports human correspondence. Paddle may act as merchant of record for self-service subscriptions. Stripe may process payments only for a product or order that expressly identifies Stripe. OpenAI may process optional AI or voice requests where separately enabled. Google Search Console supplies aggregate search-performance information. Not every provider is used by every product; the product schedule and in-product notice identify the enabled roles.
Disclosure and overseas processing
LEVRTEK discloses information only to authorised workspace users and recipients, contracted providers, professional advisers, transaction counterparties, regulators or others where needed to follow instructions, operate the service, comply with law, or protect rights and safety. Providers may process limited information in Australia, the United States and other locations in their current service and subprocessor material. LEVRTEK assesses material providers and uses reasonable contractual, technical and organisational safeguards for overseas processing.
Cookies, storage and analytics
The master cookie and storage notice sets the portfolio rules. Each application may use host-specific essential storage for security, sessions, recovery, drafts and preferences. Optional analytics remains off until valid consent is obtained where required, and may be withdrawn locally. A website choice does not automatically enable analytics on another app or authorise marketing, AI, voice, diagnostics, benchmark contribution or acceptance of service terms.
Retention and deletion
LEVRTEK retains information only while needed for the disclosed purpose, an active service, security, dispute resolution or law. Exact periods depend on the product: temporary analysis files may be deleted when a job finishes; local drafts may remain only on the user’s device; product records may remain until user deletion or workspace closure; provider telemetry follows its configured retention; and billing, security and audit evidence may be kept longer. Encrypted backups may age out under a protected schedule rather than being deleted immediately. The applicable product schedule states the verified periods or release gate.
Security and data breaches
LEVRTEK uses measures designed for the applicable risk, including encrypted transport, access controls, tenant isolation, restricted server-side secrets, private object storage, input validation, rate limiting, monitoring, audit records, environment separation, backups and incident response. No system can guarantee absolute security. Suspected eligible breaches enter the Australian Notifiable Data Breaches assessment process where applicable.
Your rights and choices
You may request access to or correction of personal information LEVRTEK holds, request deletion where applicable, obtain available exports, withdraw optional consent, unsubscribe from marketing, object to certain processing, or complain. LEVRTEK may verify identity and authority. If information belongs to a customer-controlled workspace, LEVRTEK may refer the request to that customer or assist it. If a complaint remains unresolved, you may contact the Office of the Australian Information Commissioner or another regulator with jurisdiction.
Children, communications and changes
LEVRTEK services are business tools and are not directed to children. Commercial email requires the applicable consent, identifies the sender and includes a working unsubscribe facility; necessary account, billing and security messages remain separate. LEVRTEK updates this policy and the relevant schedule before materially changing data categories, purposes, providers, countries or retention, and provides additional notice where required.

