the fine print

Supasite Privacy Policy

Last updated: August 24, 2026

1. Purpose and Scope of this Policy

BuildPass Pty Ltd (ACN 652 324 635), referred to in this policy as "we", "us" or "our", provides Supasite, a tool for capturing and organising phone calls, meetings, voice notes, photos and Photo + Voice walkthroughs. Supasite can process audio to create transcripts, notes, tasks and other requested outputs. This Privacy Policy explains what personal information we collect through Supasite, how we use and handle it, and the rights individuals have regarding their information.

This Privacy Policy explains our information-handling practices. Where applicable law requires consent for a particular collection, use, disclosure or transfer, we will request that consent separately. Using Supasite does not constitute consent where valid consent must be specific and affirmative.

2. Who This Policy Applies To

  • Users: This Policy applies to all users of the Supasite platform, whether you create an account or use our services in any capacity. It covers personal information we handle in our own capacity and information we process on behalf of our users through Supasite.
  • Personal Information: In this Policy, "personal information" (or "personal data") means any information about an identifiable individual, as defined under the Australian Privacy Act and GDPR. This Policy does not cover information about companies or organisations, but it does cover information about individuals within those entities.
  • Minors: Supasite is intended for users 18 years and older. We do not knowingly collect personal information from children under 18 without parental consent. If we become aware of such data collection, we will promptly delete the information. By providing us personal information about someone else, you must have their consent to do so.
  • Capture Participants: A Capture Participant is anyone whose voice, image, statements or personal information is captured through a phone call, meeting, voice note, photo or Photo + Voice capture. When a Supasite account holder captures other people, BuildPass may process their personal information on behalf of that account holder. The account holder is responsible for providing any required notice and obtaining any consent required by applicable privacy, recording, surveillance and workplace laws.

3. Information We Collect

We only collect information that is reasonably necessary to operate Supasite and provide our services. This may include:

  • Identity Information: Name, job title, and company/organization (if applicable).
  • Contact Information: Mobile phone number (required for account verification and service delivery). Email address (optional, collected only if you choose to link your Supasite account to a BuildPass account or opt in to email communications).
  • Account Credentials: Your account is authenticated via your verified mobile phone number. We do not collect passwords.
  • Profile and Usage Data: Information you provide when setting up your profile or using Supasite. We also collect usage data like feature use, clicks, and interactions to understand how our service is used.
  • Audio Capture Data: When you use phone-call notes, meeting notes, voice notes or Photo + Voice, Supasite processes audio and creates temporary transcript text to produce notes, tasks and other requested outputs. Audio may include the voices and personal information of people other than the account holder.
  • Saved Transcripts: Depending on your transcript settings when a capture begins, Supasite may retain the completed transcript as part of the capture. Saved transcripts may contain transcript text, timestamps, speaker or channel labels where available, the capture type, and technical metadata about the transcription process.
  • Generated Notes and Tasks: Supasite stores the notes, tasks, titles, reminders and other outputs generated from a capture. These outputs are separate from the saved transcript.
  • Call Metadata: For phone calls, we may retain the date, time, duration, call status, participating Supasite account, and the other party's number or contact details where provided.
  • Meeting and Capture Metadata: For meetings, voice notes and Photo + Voice captures, we may retain the capture title, date, duration, associated project, calendar or meeting identifiers, photos, agendas, locations, links and other context supplied by you or an authorised integration.
  • Transcript Preferences and Audit Data: We retain your transcript-storage preferences, when they were selected, the policy version that applied, and the preference applying when each capture began.
  • Photos (where available): Where Supasite supports the upload of photos, we will store the photo and any associated metadata you provide.
  • Google Calendar Data (optional): If you choose to connect your Google Calendar, Supasite accesses events that you own on your primary Google Calendar using read-only access. The information accessed may include event titles, dates and times, locations, descriptions, agendas, and links. Supasite does not create, modify, or delete events in your Google Calendar.
  • Analytics Data: We use analytics tooling to collect technical information when you use Supasite. This can include your device type, browser type, IP address, operating system, referring URLs, and timestamps of actions.
  • Cookies and Similar Technologies: Supasite uses cookies and similar tracking technologies to operate the website and gather analytics. (See Section 6: Cookies and Analytics below for more details.)
  • Communications: If you contact us (for example, via support email or feedback forms), we will collect the information you provide in those communications.

Supasite does not ask you to provide sensitive personal information unless it is required for a feature you choose to use. However, recordings, transcripts, photos and generated notes may incidentally contain sensitive information, including health information, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or criminal-history information. Do not capture sensitive information unless you and every affected participant are authorised to provide it and the collection is permitted by applicable law.

3A. Audio, Transcripts, Notes and Tasks

Supasite processes audio from phone calls, meetings, voice notes and Photo + Voice captures to create transcripts, notes, tasks and other requested outputs.

  • Audio is not retained by Supasite: Supasite streams audio to its contracted transcription provider while a capture is taking place. Supasite does not retain the audio as a durable record in your account or application database. Our contracted transcription and telecommunications providers process audio only as needed to transmit, transcribe, secure and operate the service, under contractual data-protection terms. See Sections 7 and 8.
  • Temporary transcript processing: Supasite must temporarily process transcript text to create notes and other outputs. Turning saved-transcript storage off does not prevent this temporary processing. Unless transcript storage was enabled when the capture began, temporary transcript text is removed from Supasite's active application systems after the capture is finalised.
  • Meetings, voice notes and Photo + Voice: Saving the completed transcript is on by default. You can turn transcript saving off before starting a new capture. The preference applying when the capture begins determines whether its transcript is saved.
  • Phone calls: Saving the completed transcript is off by default. A phone-call transcript is saved only where you have enabled phone-call transcript storage before that call begins. This is an account-level preference for future calls, not consent on behalf of other people participating in a call.
  • Prospective preferences: Changing a transcript preference affects captures that begin after the change. It does not change the storage decision recorded for a capture already in progress.
  • Access and deletion: When a transcript is saved, you can view it from the corresponding capture. You can permanently delete a saved transcript without deleting the associated notes or tasks. Turning transcript storage off does not delete transcripts already saved.
  • Sharing: Saved transcripts are not included in ordinary public shares or BuildPass synchronisation unless Supasite clearly offers that action and you choose it. Notes, tasks or other outputs derived from a transcript may still be shared through existing sharing and integration features.
  • No voiceprints: Supasite does not create biometric voiceprints or perform biometric speaker identification. Any speaker or channel labels are derived from call channels, capture metadata or transcription context rather than biometric voice matching.
  • Other participants: A transcript may contain the voice, statements and personal information of other people. The account holder must provide any legally required notice and obtain any legally required consent before using Supasite to capture another person.

3B. US SMS/Text Messaging

This subsection applies to service and transactional text messages we send to Supasite Users in the United States, and explains how we handle mobile and SMS data for that purpose.

  • What we use: We use your mobile phone number, your SMS opt-in record, and your consent status to send transactional and service text messages. These include one-time passcodes, login verification, account notices, and service notices. We do not send marketing or promotional texts through this program.
  • Non-sale and non-sharing: We do not sell or rent your mobile information, and we do not share your mobile information or SMS opt-in/consent data with third parties or affiliates for their marketing or promotional purposes.
  • Service providers: We share mobile information only with service providers that help us deliver these messages — carriers, telecommunications and messaging infrastructure providers, and our hosting and support vendors — solely to operate SMS delivery on our behalf and under contractual data-protection terms.

4. How We Collect Information

We collect personal information in several ways:

  • Directly from You: Most data is provided directly by you. For example, you enter information when signing up for Supasite, completing your user profile, or contacting us for support.
  • Through Your Use of Supasite: As you interact with our platform or app, we automatically collect technical data via cookies, log files, and analytic scripts.
  • Audio Capture: When you start a phone call with notes enabled, meeting, voice note or Photo + Voice capture, audio is captured by your device or telecommunications provider and transmitted to our transcription provider. The resulting transcript is processed by our model providers to create the requested notes, tasks and other outputs. See Section 3A.
  • Collection from other participants: Where a capture includes another person, we ordinarily receive their personal information through the Supasite account holder rather than directly from that participant. The account holder is responsible for providing any required collection notice. Participants can contact us using Section 12.
  • AI Processing of User Content: If you use our AI Features, the content you provide will be transmitted to our AI model providers for processing. (See Section 7 for more details on how AI inputs/outputs are handled.)
  • Third-Party Services: Some information may be collected or transmitted through third-party service providers integrated with Supasite. For example, when you sign up or log in, our identity and SMS verification provider processes your phone number on our behalf to authenticate you. These third parties collect and share information with us as needed to provide the Supasite service.

We will always endeavor to let you know when personal information is being collected and the purpose (for instance, by providing just-in-time notices or through this Privacy Policy). You may choose not to provide certain information; however, this may limit your ability to use some Supasite features. For example, if you choose not to enable certain cookies or not to provide an email address, some functionalities (like account creation or staying logged in) may not work.

5. How We Use Personal Information

We use the collected information for purposes necessary to provide and improve Supasite. The primary purposes include:

  • Providing Services: We use your information to create and manage your Supasite account, authenticate you upon login, and deliver the features of the service.
  • Captures, Transcripts and Notes: We process audio and temporary transcript text to provide phone-call notes, meeting notes, voice notes, Photo + Voice walkthroughs, tasks and other requested outputs. Where transcript storage was enabled when the capture began, we retain the completed transcript so the account holder can review and manage it.
  • Improving and Developing Supasite: Usage data and analytics help us understand how our product is performing. We analyse this data to fix bugs, optimise user experience, and inform new features.
  • Communications: We may use your contact information to send service-related communications. This includes confirmations, technical alerts, and customer support responses, as well as material change notices to these Terms or to this Privacy Policy.
  • Analytics and Product Research: We use third-party analytics (e.g., PostHog) to gather aggregated information on user behaviour.
  • Platform Integration: We may use your information to facilitate integration between Supasite and the main BuildPass platform pursuant to our legitimate business interests in providing a cohesive suite of services. This includes using your data to enhance user experience across our products and to offer relevant BuildPass services based on your Supasite activity.
  • AI Model Training and Improvement: We may use anonymised data from AI interactions that does not originate from Google Workspace APIs to evaluate and improve Supasite, subject to this Policy and applicable law. Google Workspace API data—including raw, aggregated, anonymised, or derived data—is expressly excluded from these activities. Neither Supasite nor its service providers use or transfer Google Workspace API data to create, train, or improve generalized or foundational machine learning or artificial intelligence models.
  • Security and Fraud Prevention: We may process personal information to monitor for suspicious or malicious activity, verify user identities where necessary, and otherwise protect against unauthorised access, fraud, or abuse of our services.
  • Legal Compliance: Where required, we will use and disclose personal information to comply with legal obligations, resolve disputes, enforce our Terms of Service, or respond to lawful requests by public authorities.

We do not use the contents of recordings, transcripts, notes or tasks to train our own or our providers' general-purpose models without explicit consent.

We will only use your personal information for the purposes outlined above or for purposes that are compatible with those original purposes. If we need to use your information for an unrelated purpose, we will notify you and obtain your consent or ensure we have a lawful basis as required by applicable law.

5A. Lawful Bases

We identify and document a lawful basis for each purpose for which we process personal information. Depending on the processing activity and our relationship with you, this may include performance of a contract, compliance with a legal obligation, legitimate interests, or consent.

Where we rely on legitimate interests, the relevant interests include providing, securing and improving the Supasite service, subject to an assessment that those interests are not overridden by the affected person's rights and interests. Where we rely on consent, you may withdraw that consent at any time, without affecting processing that occurred before withdrawal.

5B. Retention of Captures, Transcripts, Notes and Tasks

  • Audio: Supasite does not retain capture audio as a durable record. Providers involved in transmitting or transcribing audio may process or retain it for the limited operational, security and abuse-prevention periods permitted by our contracts and provider settings. Provider handling must match the disclosures in Sections 7 and 8.
  • Temporary transcript text: Where transcript storage is disabled, temporary transcript text is removed from Supasite's active application systems after finalisation or failure handling is complete.
  • Saved transcripts: A saved transcript is retained for as long as you keep the corresponding capture, unless you delete the transcript earlier or a different period is required by law.
  • Notes, tasks and other outputs: Deleting only a transcript does not delete the notes, tasks or other outputs generated from it. These remain until you delete the corresponding capture or account.
  • Preferences and audit records: We retain versioned preference and audit records where reasonably necessary to demonstrate the storage decision applying to a capture and to meet legal, security and compliance obligations.

6. Cookies & Analytics

Supasite uses cookies and similar technologies to ensure the platform functions correctly and to analyse usage:

  • What Are Cookies: Cookies are small text files stored on your device that allow us to remember certain information between pages or visits.
  • Essential Cookies: Some cookies are necessary for the website to operate.
  • Analytics Cookies: We use PostHog to understand how people interact with Supasite. Where applicable law requires a choice before non-essential analytics technologies are used, we will present that choice first.
  • Your Choices: Upon your first visit, and from time to time, we may present a cookie notice or preferences tool where required by law. You can manage or disable cookies in your browser settings.
  • Do Not Track: Supasite does not currently respond to "Do Not Track" signals.

You can manage cookies through any preferences tool we provide and through your browser settings. Disabling some technologies may affect non-essential analytics or website functionality.

7. AI and Automated Processing

Supasite is an AI-powered platform. We leverage third-party artificial intelligence services to provide certain features, including voice transcription and the creation of notes, tasks and other requested outputs from phone calls, meetings, voice notes and Photo + Voice captures. It is important for you to understand how your data is handled in these processes.

7.1 AI Providers and Processing

Supasite integrates with third-party AI model providers to power our intelligent features, including contracted voice-transcription providers and one or more large language model providers used to create notes, tasks and other requested outputs.

These providers act as processors of data on our behalf when you use our AI-powered features. They receive the input data we provide on your behalf (such as capture audio for transcription, or transcripts used to create requested outputs) and return an output (such as transcript text, notes, tasks or reminders).

Supasite currently uses ElevenLabs to provide voice transcription. Transcript text and other requested inputs may also be processed through Vercel AI Gateway by Google Gemini, depending on the feature and model selected. These providers process information on our behalf under contractual data-protection terms.

7.2 Data Handling in AI Features

  • Audio Capture Data: When you use phone-call notes, meeting notes, voice notes or Photo + Voice, audio is transmitted to our voice transcription provider over an encrypted connection. The provider returns transcript text, which is then transmitted to one or more AI model providers to create notes, tasks and other requested outputs. Both categories of provider act as processors on our behalf and are bound by contractual data-protection terms. They do not use this Content to train their general-purpose models.
  • Input Data Transmission: When you use any AI Feature, the necessary data is sent securely to the corresponding AI provider's API. We send only the information required for the task.
  • Provider-specific retention: ElevenLabs uses standard non-Enterprise retention and retains Speech-to-Text audio and transcript output in its request history. Google Gemini is accessed through Vercel AI Gateway with team-wide Zero Data Retention enabled, so prompts and outputs are not retained by the gateway.
  • No Secondary Use by Supasite: We do not use the contents of recordings, transcripts, notes or tasks to train our own AI models without your explicit consent. We may review AI interactions in an aggregated or anonymised way to evaluate performance. For clarity, Google Workspace API data is never included in model training, generalized model improvement, or routine human review, even where the data has been aggregated, anonymised, or derived from other Google Workspace data.
  • Human Oversight: We reserve the right to observe AI interactions both by human and automated processes for quality and improvement purposes. On occasion, authorised team members might review specific interactions if needed to investigate a problem or misuse, always under strict privacy controls. This general quality-review provision does not apply to Google Workspace API data. Human access to Google Workspace API data is limited to the circumstances described in Section 7.3.

7.3 Google Workspace API Data and Limited Use

If you choose to connect Google Calendar, Supasite requests read-only access to events that you own on your primary Google Calendar.

How we use Google Calendar data: Supasite uses event details to show upcoming meetings and reminders, prefill meeting notes, and provide relevant event titles and agendas as context when you choose to start Supasite's AI note-taking feature. Supasite does not create, modify, or delete Google Calendar events.

AI processing and sharing: When you request an AI note-taking feature associated with a Calendar event, relevant event details may be transmitted to our contracted AI service providers solely to provide that user-facing feature. Those providers process the information on our behalf under contractual data-protection and Limited Use restrictions. They are not permitted to use Google Workspace API data for their own purposes or to create, train, or improve generalized or foundational AI or machine-learning models.

Storage and retention: Supasite securely stores the OAuth credentials and connected-account metadata needed to maintain the integration. Calendar events are retrieved to provide the features described above. If you create a Supasite meeting note from a Calendar event, selected event details—such as its title, time, agenda, location, links, and Calendar event identifier—may be stored as part of that Supasite note. These details are retained and deleted according to the applicable retention and deletion provisions in this Policy.

Disconnecting and deleting data: You can disconnect Google Calendar through Supasite's Calendar integration settings. Disconnecting removes Supasite's stored Google connection credentials and prevents further access to your Google Calendar. Event details already included in saved Supasite notes remain subject to Supasite's normal retention and deletion processes. You may request deletion of those notes or your account as described in Sections 5B, 11, and 12. You may also revoke Supasite's access through your Google Account settings.

Human access: Supasite personnel do not access Google Workspace API data except with your explicit consent for support, when necessary to investigate security or abuse, or when required to comply with applicable law.

Limited Use compliance: The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Supasite does not sell Google Workspace API data, use it for advertising, or use, transfer, or share it to create, train, or improve generalized or foundational machine-learning or artificial-intelligence models.

7.4 No Fully Automated Decisions with Legal Effects

Supasite's AI Features are tools to assist users in capturing and organising information from phone calls, meetings, voice notes and Photo + Voice captures. They do not independently make binding decisions about individuals. All AI outputs should be reviewed by a human user. We do not subject anyone to purely automated decisions that have legal or significant effects on them, as defined under GDPR Article 22.

7.5 Accuracy and Limitations

While we strive to use high-quality AI models, AI predictions or generated outputs can sometimes be incorrect or misleading. We do not guarantee the accuracy or completeness of any AI-generated content. Users should not rely on Supasite's AI Features as professional advice or the sole basis for decisions.

7.6 User Control

If you do not want information processed through an AI-powered feature, do not start or request that feature. When you request an AI-powered feature, we process the information needed to provide it under the lawful basis described in Section 5A. Where applicable law requires consent for a particular processing activity or transfer, we will request that consent separately.

8. Disclosure of Personal Information to Third Parties

We treat your personal information with care and confidentiality. We do not sell your personal data to unrelated third parties for their own marketing or any other purposes. However, we do share information with certain trusted third parties in order to run Supasite effectively, as outlined below:

Service Providers: We use third-party companies to support our operations and services. These providers only receive the information necessary for them to perform their function, and they are contractually obligated to protect it and use it only for our purposes. Our key service providers include:

  • Convex: Hosts our application database in Virginia, United States. Backups run daily at 1:00 am and expire after seven days.
  • Vercel: Hosts and serves the Supasite web application. Vercel AI Gateway has team-wide Zero Data Retention enabled. Prompts and outputs are not retained, prompt training is prohibited, and requests are restricted to qualifying zero-retention providers. Google Gemini is accessed through this gateway, although its processing location is not region-restricted.
  • PostHog: Provides analytics services from the United States. Prompt and generated-output content is retained for 30 days. Model, provider, token, cost, latency and trace metadata remains available after content expiry.
  • Voice Transcription Providers: ElevenLabs processes live audio and transcript output in the United States under its standard non-Enterprise retention arrangements. Zero Retention Mode is not available to Supasite. ElevenLabs retains Speech-to-Text audio and transcript output in its request history. Supasite does not currently delete that provider data when an in-app transcript is deleted. ElevenLabs' “Improve the models for everyone” setting is disabled, so new Supasite data is not used for model training. If provider data is separately deleted, primary database content is removed, backups may retain it for up to 30 days, and debugging or moderation information may remain under ElevenLabs' standard policies.
  • AI Providers: Google Gemini processes transcript text and other requested inputs through Vercel AI Gateway to generate requested outputs. It acts as a processor on our behalf under contractual data-protection terms.
  • Telecommunication and Voice Infrastructure Providers: Twilio carries phone calls and text messages and processes Supasite calls in its US1 region. Voice Trace is disabled on the Supasite Twilio account. Ordinary calls use Media Streams and Twilio does not store call audio because Supasite does not invoke Twilio recording for those calls. Voicemail is the exception. Voicemail audio is temporarily recorded for transcription and then deleted. Recording media may take up to 30 days to be completely removed from Twilio systems, while recording metadata remains for 40 days after deletion. Twilio call and conference logs are available through the Console and API for 13 months. This is an availability period, not a guaranteed deletion deadline. Supasite's live audio bridge operates in Sydney, Australia, and does not intentionally persist raw audio.
  • Expo/EAS: We use Expo's services for building and updating the mobile app.
  • Sentry: Provides error monitoring from the United States on its Team plan. Errors are retained for 90 days; logs, profiles and ordinary spans or transactions for 30 days; sampled transaction data for up to 13 months; and attachments, replays and uptime data for 90 days where those features are used.
  • Provider changes: We may replace a provider or add another provider where reasonably necessary to operate Supasite. If a change materially alters how personal information is handled, we will update this Policy and present any notice or choice required by law before the change applies to the affected user.

9. International Data Transfers

Supasite is a global service. The personal information we collect may be accessed or processed in countries other than the country you reside in. In particular, many of our third-party providers are based in (or may store data in) the United States and other jurisdictions outside of Australia or the European Economic Area (EEA).

  • Business Transactions: If BuildPass is involved in a merger, acquisition, sale of assets, or reorganisation, your information may be transferred as part of that transaction. We will provide notice before personal data is transferred or becomes subject to a different privacy policy.
  • Our Location: BuildPass Pty Ltd is based in Australia, but Supasite application data is stored with Convex in Virginia, United States. Audio and transcript data may also be processed by the providers described in Sections 7 and 8.
  • Risks: Different countries have different data protection laws. When your data is transferred from your home country to another country, it may become subject to those foreign laws.
  • Our Safeguards: We take reasonable steps to ensure that international data transfers comply with applicable laws. For transfers from Australia, we abide by Australian Privacy Principle 8. For transfers from the EEA/UK or other regions with data transfer restrictions, we utilise appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on an adequacy decision where applicable.
  • Your Consent in Some Cases: In certain situations, we may ask for your consent to transfer data overseas. If you agree to such a transfer, we will inform you of any relevant risks and handle the data in accordance with that consent and this Policy.

Despite the global transfer of data, your information remains protected by the measures described in this Policy. We maintain high standards of data protection regardless of where data is processed and continue to be responsible for it. If you have questions about our international data transfer practices, please contact us (see Section 12).

10. Data Security and Storage

We implement a variety of administrative, technical, and physical security measures to protect your data from unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption: Data exchanged with Supasite is encrypted in transit using SSL/TLS. Sensitive data in our databases is encrypted at rest.
  • Access Controls: Personal information is accessible only to those personnel and service providers who need it to perform their duties or services.
  • Security Testing and Maintenance: We regularly update our software and systems to address security vulnerabilities.
  • Anonymization: Where possible, we de-identify or pseudonymise personal data within our analytics and testing environments.
  • Physical Security: Our data is stored on secure servers operated by reputable cloud providers.

Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.

If we become aware of a data breach that compromises your personal information, we will notify affected individuals and relevant authorities as required by law.

11. Your Rights and Choices

You have certain rights regarding your personal information held by us:

  • Access: You have the right to request a copy of the personal information we hold about you
  • Correction: If you believe any personal data we have is incorrect or incomplete, you have the right to request we correct it.
  • Deletion (Right to Erasure): You may request that we delete your personal information.
  • Withdrawal of Consent: If we are processing your personal information based on your consent, you have the right to withdraw that consent at any time.
  • Objection to Processing: You have the right to object to certain processing activities.
  • Restriction of Processing: You can request that we temporarily limit the processing of your personal information in certain situations.
  • Data Portability: For EU/UK users (and others where applicable), you have the right to data portability.
  • Automated Decision-Making: Supasite does not make solely automated decisions with legal or similarly significant effects.

Capture Participant Rights: If you participated in, appeared in or were audible during a Supasite capture, you may request access to, correction of or deletion of personal information about you. We may need information that identifies the capture and may need to coordinate with the relevant account holder. We will still respond within the timeframes required by applicable law.

If an account holder does not cooperate with a valid request, BuildPass may act directly where legally permitted or required and may suspend the account under the Terms of Service.

How to Exercise Your Rights: You can exercise most of the above rights by contacting us (see Section 12). For certain requests, we may need to verify your identity to ensure we don't disclose or delete data to the wrong person.

12. Questions, Complaints, and Contacting Us

If you have any questions about this Privacy Policy, wish to exercise any of your rights, or have a concern or complaint about privacy, please contact us:

Privacy Contact Office: Email: hello@supasite.com

Australia: Postal Mail: The Privacy Officer BuildPass Pty Ltd (Supasite) Unit 2, 33 Stewart St Richmond, VIC 3121, Australia

United States: Postal Mail: The Privacy Officer BuildPass Inc (Supasite) 3212 E Cesar Chavez, Building 1, Suite 1115 Austin, TX 78702, United States

If you are not satisfied with our response to a privacy complaint, you have the right to escalate the matter to the appropriate supervisory authority. For Australian users, you may contact the Office of the Australian Information Commissioner (OAIC). For individuals in the EU/EEA, you can reach out to your local Data Protection Authority. UK users can contact the Information Commissioner's Office (ICO).

13. Changes to this Privacy Policy

Supasite and our data practices may change over time. The Last updated date at the top of this Policy shows when it was revised. The changes relating to saved transcripts apply to an account holder when they first open Supasite version 3.0.1 or later and acknowledge this updated Policy through the in-app legal gate. If we make another material change that requires action from an account holder, Supasite will present the updated policy in the app before the account holder can continue into the affected service. We may also provide notice on our website or by SMS or email where appropriate. Where applicable law requires consent for a particular collection, use, disclosure or transfer, we will request that consent separately.