StratFlow Privacy Policy

Version 2026-05-v2 Effective 2026-05-19

StratFlow Privacy Policy

ThreePoints Solutions is committed to safeguarding your personal information. This Privacy Policy outlines how we manage personal data collected through the StratFlow platform in strict compliance with the New Zealand Privacy Act 2020.

1. Scope and Privacy Officer Details
• Platform Operator: StratFlow is operated by ThreePoints Solutions.
• Privacy Officer Contact: For all privacy-related matters, including exercising your statutory rights to access, correct, export, delete, or restrict your data, please contact our Privacy Officer directly at stratflow@threepointssolutions.com.

2. Information We Collect (IPPs 1, 2, and 3)
To provide a secure and functional strategy-to-delivery workspace, StratFlow collects personal information directly from you or your organisation's administrators :
• Account Details: Basic identity data collected from account creators, administrators, and general platform users.
• User Management Data: Information relating to invited users, administrators, and support contact details.
• Security & Session Data: Technical logs, authentication state, multi-factor authentication (MFA) parameters, CSRF tokens, IP sessions, and system audit events to protect accounts against unauthorised access.
• Customer Content: Information processed directly within your workflow, which may include strategy documents, meeting notes, backlog artefacts, project summaries, diagrams, OKRs, work items, user stories, documented risks, and sprint data.
• Integration Metadata: Technical configurations and transactional tokens from connected systems such as Jira, GitHub, GitLab, Xero, or Stripe-backed billing systems.
• Communications: Explicit contents of structured support requests, bug reports, and consented diagnostic metadata.

3. Purpose of Processing (IPP 4)
We process your personal data and customer content strictly for the following necessary operational needs:
• Enabling platform authentication and secure tenant-scoped account access.
• Delivering core strategy-to-delivery features, workflow tools, and reporting dashboards.
• Facilitating requested integrations (such as syncing with Jira and Git data streams).
• Fueling AI-assisted summaries, evaluations, and generation features when enabled by your organisation.
• Executing technical security monitoring, diagnostic tracing, rate-limiting, and platform abuse prevention.
• Processing billing infrastructure updates, package states, and general system administration.
• Managing structured support queues and conducting compliance audits.

4. Third-Party Disclosures and Cross-Border Transfers (IPP 11 and 12)
We do not sell your personal data. Limited information is shared with external sub-processors only under strict data-handling terms, categorised beneath the following operational domains:
• Infrastructure & Hosting: Core cloud environments hosting application servers and databases.
• Communication Pipelines: Email transactional routing and customer support ticketing engines.
• Financial Services: Subscription billing, transactional accounting platforms, and Stripe payment gateways.
• AI Service Providers: Configured commercial artificial intelligence models powering automated summaries or persona critiques.
• Connected Integrations: Explicit external services authorised by the user, such as Jira, GitHub, GitLab, Azure DevOps, and Xero.
• Operational Security: Automated threat-mitigation tools, vulnerability scanners, and performance monitoring suites.
Cross-Border Transfer Compliance (IPP 12): Where personal data is transferred outside of New Zealand to global cloud providers or AI services, ThreePoints Solutions ensures that such sub-processors are subject to privacy safeguards comparable to those under the New Zealand Privacy Act 2020, or that your organisation has explicitly authorised the integration data-flow.
Data Minimisation Rule: Users are strongly advised to avoid submitting unnecessary sensitive personal details, unprotected system secrets, API access tokens, or raw source credentials that are not required by standard workflows.

5. Artificial Intelligence Data Safeguards & Google Terms
To ensure complete isolation of your corporate data, StratFlow interfaces exclusively with the paid developer and enterprise tiers of our AI sub-processors (specifically, Google Gemini API and Google Cloud Vertex AI platforms, as well as OpenAI and Anthropic).
• Gemini API Paid Services Tier: In alignment with the Gemini API Additional Terms of Service, when utilising StratFlow’s paid infrastructure, customer prompts and generated outputs are logged for a limited period of time solely for detecting and preventing violations of prohibited use policies. Google will not use your content to train or improve its machine learning products and services.
• Google Cloud Vertex AI Tier: For enterprise environments scaled onto Vertex AI infrastructure, strict data governance policies apply. In accordance with Section 17 ("Training Restriction") of the Google Cloud Service Specific Terms, Google will not use customer data to train or fine-tune any AI/ML foundation models without prior permission or explicit instruction.
• Data Separation: StratFlow separates system-usage accounting metadata from the underlying raw text prompts and provider responses to enforce strict tenant-scoping boundaries.
• Human Oversight: All final, publicly accessible help or structural policies remain strictly human-authored and reviewed; AI is only utilised to support triage and summary processes for internal administrative staff.

6. Storage, Security, and Retention (IPPs 5 and 9)
• Security Controls(IPP 5): StratFlow enforces strict defensive protocols, including mandatory session tokens, cross-site request forgery (CSRF) protections, multi-factor authentication (MFA) readiness, comprehensive audit trails, and strict tenant isolation boundaries to prevent cross-tenant data exposure.
• Retention Boundaries (IPP 9): Personal data is retained only for as long as required to fulfil the operational purposes detailed in Section 3, or to comply with statutory financial audit and legal obligations under New Zealand law.

7. Your Statutory Privacy Rights (IPPs 6 and 7)
Under the New Zealand Privacy Act 2020, you hold explicit rights regarding your personal information:
• The Right to Access (IPP 6): You have the right to request a copy of the personal information we hold about you.
• The Right to Correction (IPP 7): You have the right to request correction of any inaccurate or outdated personal data.
• Self-Service Controls: Users can execute an automated, self-service account export at any time via the internal application settings path (/app/account/export-data).
• Data Retrieval and Export: To retrieve or export your data, your organisation's account administrators may utilise the self-service export tools within the application settings path (/app/account/export-data) when available. Alternatively, you can submit a formal access request at any time directly to our Privacy Officer at stratflow@threepointssolutions.com. Manual requests will be verified and fulfilled by our team in accordance with the statutory timeframes prescribed under the Privacy Act 2020.

8. Notifiable Privacy Breaches
• Response Policy: Security incidents and privacy breaches are managed under our structured internal incident response framework.
• Statutory Notification Obligations: In accordance with the mandatory reporting rules of the New Zealand Privacy Act 2020, if a privacy breach occurs that results in, or is likely to result in, serious harm to affected individuals, ThreePoints Solutions will notify the affected individuals and the Office of the Privacy Commissioner as soon as practically possible.

9. Policy Acknowledgement and Material Changes
• Consent at Signup: All creating or joining users must explicitly accept this Privacy Policy during the account registration or invitation-acceptance flow before access is granted.
• Audit Trails: Acceptance details (including version numbers, active locale data, and canonical content cryptographic hashes) are recorded as tamper-evident audit evidence.
• Material Notifications: When significant changes occur in how we utilise your personal data, clear alerts will be communicated in-app or sent directly to your designated account contact.