1. Information we collect from you
Account information. When your organisation provisions access to Antlect, we collect your name, work email address, organisation, and role. Authentication is provided through Auth0, hosted in the Australian region. Billing information. Antlect is licensed to organisations. We collect billing contact details and retain records of orders and invoices issued under your organisation’s agreement with us. Usage information. We collect information about how you use the Services, including queries, saved projects, generated reports, log data, IP address, browser type, and device information. We use this to operate, secure, and improve the Services. Correspondence. If you contact us, we keep a record of that correspondence. Unsolicited information. If we receive personal information we did not request, and we could not lawfully have collected it had we asked for it, we will destroy or de-identify it where it is lawful and reasonable to do so.2. Information we collect from public sources
Antlect’s Trusted Data Foundation aggregates information about research and innovation activity in New Zealand and Australia. This includes information about identifiable researchers, such as names, institutional affiliations, publications, patents, clinical trial involvement, and funding records. This information is collected from publicly available sources, including published research outputs, ORCID records, patent registers, clinical trial registries, and public funding announcements. Aggregating and connecting published research information is standard practice in research intelligence services. We collect this information because linking it produces a clearer picture of research capability than any single source provides. We want to be direct about what this means for researchers:- We compile a profile of your public research activity whether or not you are a user of Antlect.
- We do not collect private information about you from these sources. The underlying records are already public.
- You may contact us at any time to access the information we hold about you, request a correction, or request that your profile be suppressed from the Services. We will respond within 20 working days.
3. How we use personal information
We use personal information to:- provide, operate, and maintain the Services;
- authenticate users and manage accounts, seats, and organisational subscriptions;
- build and maintain the Trusted Data Foundation and the intelligence features of the platform;
- respond to enquiries and provide support;
- monitor, secure, and improve the Services, including detecting misuse;
- meet our legal obligations.
4. Marketing communications
Where you have subscribed to updates or would reasonably expect to hear from us, we may send you information about Antlect features, releases, and research. Every message includes a functional unsubscribe facility, and we honour opt-out requests promptly, in accordance with the Unsolicited Electronic Messages Act 2007 (NZ) and the Spam Act 2003 (Cth). We do not use sensitive information for marketing.5. Disclosure of personal information
To operate the Services, we use trusted third-party service providers for infrastructure, authentication, communications, documentation, and AI processing. These providers may process personal information only as necessary to deliver their services on our behalf. Current providers include:- Amazon Web Services (Sydney): application hosting and data storage
- Cloudflare: network security and content delivery
- Auth0 (Australia): user authentication and identity management
- Anthropic: AI processing within the platform
- Vercel: website hosting and privacy-friendly, cookieless analytics
- Zoho: email and communications
- Neo4j Aura: research graph database
- Mintlify: documentation hosting
6. Overseas storage and disclosure
Our platform infrastructure is hosted in Australia. Some of our service providers, including those that host and deliver our websites, store or process information in other countries, including the United States. Where we disclose personal information overseas, we take reasonable steps to ensure it is protected by safeguards comparable to those in the Privacy Act 2020, consistent with Information Privacy Principle 12 and Australian Privacy Principle 8.7. Security
We take reasonable steps to protect personal information from loss, misuse, interference, and unauthorised access, modification, and disclosure. These steps include encryption in transit, access controls on a need-to-know basis, network security controls, audit logging, and confidentiality obligations on staff and providers. Our security practices are aligned with ISO 27001. No online service can guarantee absolute security.8. Retention and data quality
We retain personal information for as long as it is needed for the purposes described in this policy or as required by law. Account information is retained while your organisation’s subscription is active and for a reasonable period afterwards. When personal information is no longer required, we destroy or de-identify it. Public research information in the Trusted Data Foundation is retained while it remains relevant to the purpose of the platform, subject to suppression requests under section 2. We take reasonable steps to keep personal information accurate, complete, and up to date, and we rely on you to tell us about changes or corrections to the information we hold about you.9. Access and correction
You have the right to request access to the personal information we hold about you and to request correction of it. Researchers may additionally request suppression of their researcher profile as described in section 2. We do not charge a fee for making a request. We will respond within 20 working days. If we decline a request, we will give you our reasons in writing and tell you how to complain. If we do not agree with a correction you have requested, you may ask us to attach a statement of the correction sought to the information. To exercise any of these rights, contact us at hello@antlect.com.10. Data breaches
If a privacy breach occurs that causes, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner (New Zealand) and affected individuals as required by the Privacy Act 2020, and the Office of the Australian Information Commissioner where the Australian Notifiable Data Breaches scheme applies. We will also notify affected organisational customers without undue delay.11. Complaints
If you have a concern about how we have handled your personal information, please contact us first at hello@antlect.com with the details of your complaint, and we will review it and respond. If you are not satisfied with our response, you may complain to:- Office of the Privacy Commissioner, New Zealand (privacy.org.nz)
- Office of the Australian Information Commissioner (oaic.gov.au)
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a revised date, and will notify customers of material changes.13. Contact
Antlect LimitedChristchurch, New Zealand
hello@antlect.com