> ## Documentation Index
> Fetch the complete documentation index at: https://docs.antlect.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How Antlect collects, uses, stores, and protects your personal data.

**Last updated: July 2026**

Antlect is a research and innovation intelligence platform operated by Antlect Limited, formerly AcademicFellows Limited ("we", "us"), a company registered in New Zealand. This policy explains how we collect, hold, use, and disclose personal information in connection with antlect.com, docs.antlect.com, and the Antlect platform (together, the "Services").

We handle personal information in accordance with the New Zealand Privacy Act 2020 and, where it applies to our activities, the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles.

In this policy, "personal information" means information about an identified or reasonably identifiable individual. "Sensitive information" is a category of personal information that includes information about matters such as health, ethnicity, political opinions, and religious beliefs. We do not seek to collect sensitive information, and we ask that you do not provide it to us.

## 1. Information we collect from you

**Account information.** When your organisation provisions access to Antlect, we collect your name, work email address, organisation, and role. Authentication is provided through Auth0, hosted in the Australian region.

**Billing information.** Antlect is licensed to organisations. We collect billing contact details and retain records of orders and invoices issued under your organisation's agreement with us.

**Usage information.** We collect information about how you use the Services, including queries, saved projects, generated reports, log data, IP address, browser type, and device information. We use this to operate, secure, and improve the Services.

**Correspondence.** If you contact us, we keep a record of that correspondence.

**Unsolicited information.** If we receive personal information we did not request, and we could not lawfully have collected it had we asked for it, we will destroy or de-identify it where it is lawful and reasonable to do so.

## 2. Information we collect from public sources

Antlect's Trusted Data Foundation aggregates information about research and innovation activity in New Zealand and Australia. This includes information about identifiable researchers, such as names, institutional affiliations, publications, patents, clinical trial involvement, and funding records.

This information is collected from publicly available sources, including published research outputs, ORCID records, patent registers, clinical trial registries, and public funding announcements. Aggregating and connecting published research information is standard practice in research intelligence services. We collect this information because linking it produces a clearer picture of research capability than any single source provides.

We want to be direct about what this means for researchers:

* We compile a profile of your public research activity whether or not you are a user of Antlect.
* We do not collect private information about you from these sources. The underlying records are already public.
* You may contact us at any time to access the information we hold about you, request a correction, or request that your profile be suppressed from the Services. We will respond within 20 working days.

Where we collect personal information from publicly available publications rather than from the individual directly, we rely on the relevant exceptions in Information Privacy Principle 2 of the Privacy Act 2020 and Australian Privacy Principle 3.

## 3. How we use personal information

We use personal information to:

* provide, operate, and maintain the Services;
* authenticate users and manage accounts, seats, and organisational subscriptions;
* build and maintain the Trusted Data Foundation and the intelligence features of the platform;
* respond to enquiries and provide support;
* monitor, secure, and improve the Services, including detecting misuse;
* meet our legal obligations.

We do not sell personal information. Your queries, projects, and reports are not used to train third-party AI models.

## 4. Marketing communications

Where you have subscribed to updates or would reasonably expect to hear from us, we may send you information about Antlect features, releases, and research. Every message includes a functional unsubscribe facility, and we honour opt-out requests promptly, in accordance with the Unsolicited Electronic Messages Act 2007 (NZ) and the Spam Act 2003 (Cth). We do not use sensitive information for marketing.

## 5. Disclosure of personal information

To operate the Services, we use trusted third-party service providers for infrastructure, authentication, communications, documentation, and AI processing. These providers may process personal information only as necessary to deliver their services on our behalf. Current providers include:

* Amazon Web Services (Sydney): application hosting and data storage
* Cloudflare: network security and content delivery
* Auth0 (Australia): user authentication and identity management
* Anthropic: AI processing within the platform
* Vercel: website hosting and privacy-friendly, cookieless analytics
* Zoho: email and communications
* Neo4j Aura: research graph database
* Mintlify: documentation hosting

We may also disclose personal information where required or permitted by law, or in connection with a corporate transaction such as a sale of the business, in which case this policy will continue to apply to the information transferred.

Researcher profile information described in section 2 is visible to users of the Services. That is the purpose of the platform. Your projects and reports are visible only to you and, where your organisation's agreement provides for it, to other authorised users within your organisation.

## 6. Overseas storage and disclosure

Our platform infrastructure is hosted in Australia. Some of our service providers, including those that host and deliver our websites, store or process information in other countries, including the United States. Where we disclose personal information overseas, we take reasonable steps to ensure it is protected by safeguards comparable to those in the Privacy Act 2020, consistent with Information Privacy Principle 12 and Australian Privacy Principle 8.

## 7. Security

We take reasonable steps to protect personal information from loss, misuse, interference, and unauthorised access, modification, and disclosure. These steps include encryption in transit, access controls on a need-to-know basis, network security controls, audit logging, and confidentiality obligations on staff and providers. Our security practices are aligned with ISO 27001. No online service can guarantee absolute security.

## 8. Retention and data quality

We retain personal information for as long as it is needed for the purposes described in this policy or as required by law. Account information is retained while your organisation's subscription is active and for a reasonable period afterwards. When personal information is no longer required, we destroy or de-identify it.

Public research information in the Trusted Data Foundation is retained while it remains relevant to the purpose of the platform, subject to suppression requests under section 2.

We take reasonable steps to keep personal information accurate, complete, and up to date, and we rely on you to tell us about changes or corrections to the information we hold about you.

## 9. Access and correction

You have the right to request access to the personal information we hold about you and to request correction of it. Researchers may additionally request suppression of their researcher profile as described in section 2.

We do not charge a fee for making a request. We will respond within 20 working days. If we decline a request, we will give you our reasons in writing and tell you how to complain. If we do not agree with a correction you have requested, you may ask us to attach a statement of the correction sought to the information.

To exercise any of these rights, contact us at [hello@antlect.com](mailto:hello@antlect.com).

## 10. Data breaches

If a privacy breach occurs that causes, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner (New Zealand) and affected individuals as required by the Privacy Act 2020, and the Office of the Australian Information Commissioner where the Australian Notifiable Data Breaches scheme applies. We will also notify affected organisational customers without undue delay.

## 11. Complaints

If you have a concern about how we have handled your personal information, please contact us first at [hello@antlect.com](mailto:hello@antlect.com) with the details of your complaint, and we will review it and respond. If you are not satisfied with our response, you may complain to:

* Office of the Privacy Commissioner, New Zealand ([privacy.org.nz](https://privacy.org.nz))
* Office of the Australian Information Commissioner ([oaic.gov.au](https://www.oaic.gov.au))

## 12. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a revised date, and will notify customers of material changes.

## 13. Contact

Antlect Limited \
Christchurch, New Zealand \
[hello@antlect.com](mailto:hello@antlect.com)
