This Privacy Policy explains how THE MAIT Limited ("we", "us") collects, uses, discloses and protects personal information when you use Build MAIT (the "Service"). We handle personal information in accordance with the New Zealand Privacy Act 2020 and, where it applies, the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the GDPR.
1. Information we collect
- Account & company info — name, email, phone, company details, role.
- Content you submit — site logs, voice recordings/transcripts, photos, timesheets, safety records, variations, delays, meeting minutes, quotes, invoices, client and subcontractor details.
- Billing info — handled by our payment processor; we do not store full card numbers.
- Usage & device data — log data, IP address, browser/device type, and cookies necessary to run the Service.
2. How we use it
To provide, secure, maintain and improve the Service; to process AI features you request; to handle billing; to send service and account emails; to comply with legal obligations; and to prevent fraud or misuse.
3. Our role (controller & processor)
For account, billing and usage data, we are the agency/controller responsible for that information. For the content you upload about other people — such as your staff, clients and subcontractors — you are the agency/controller, and we process that information on your behalf and on your instructions to provide the Service. You are responsible for having a lawful basis and any necessary consents to collect and upload that information, and for telling those people how it is used.
4. Service providers & sub-processors
We share data only as needed with trusted third-party providers who process it on our behalf, in the following categories:
- cloud hosting, database, authentication and file storage;
- AI processing (transcribing, organising and drafting content from your input);
- payment processing;
- transactional email.
We require these providers to protect personal information and to use it only to provide their services to us. A current list of our key providers is available on request.
5. Overseas disclosure
Some of our providers store or process data outside New Zealand (for example in Australia, the United States or the European Union). Before disclosing personal information overseas we take reasonable steps to ensure it is protected by comparable safeguards, consistent with Information Privacy Principle 12 of the New Zealand Privacy Act 2020 and Australian Privacy Principle 8 (cross-border disclosure).
6. AI processing
When you use AI features, the relevant input (for example a transcript or notes) is sent to the AI provider to generate the requested output. We do not sell your data, and we do not use Your Content to train our own models. Our AI providers act as sub-processors and do not use your input to train their models other than as needed to return your result.
7. Retention
We retain personal information for as long as your account is active and you continue to use the Service.
- On account or data deletion — we remove your data from our active systems within 30 days, and from routine encrypted backups within a further 90 days.
- Legal retention — certain records (for example financial, tax, payroll/time and health-and-safety records) may need to be kept for longer to meet legal obligations. Where this applies we retain only those records for the period required by law (in New Zealand, generally up to 7 years) and then delete them.
- Inactive free accounts — free or trial accounts that have not been used for 6 months may be deleted automatically. We email the account's administrators a warning beforehand, and logging in keeps the account. Paid accounts are not affected.
You can delete your account and associated data at any time in-app under Settings. Because you may have your own legal obligation to keep site, timesheet, invoice and safety records, please export any records you need before deleting.
8. Security
We use reasonable technical and organisational measures to protect personal information, including access controls, role-based permissions and per-company data isolation. No system is completely secure; we cannot guarantee absolute security.
9. Data breaches
If a privacy breach occurs that is likely to cause serious harm, we will notify the relevant regulator — the New Zealand Office of the Privacy Commissioner, and/or the Australian Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme — and affected individuals, as required by law. Where you are the controller of the affected information, we will also notify you so you can meet your own obligations.
10. Your rights
Subject to applicable law, you may request access to, and correction of, your personal information, ask us to delete it, and object to or restrict certain processing. Where the GDPR applies, you may also have rights to data portability and to withdraw consent. To exercise these rights, contact info@themait.net; we may need to verify your identity. If the information is content uploaded by another customer (where they are the controller), we will refer your request to them. You may also complain to the New Zealand Office of the Privacy Commissioner or the Australian Office of the Australian Information Commissioner.
11. Cookies
Essential cookies — needed to keep you logged in and run the Service — are always on. We do not use third-party advertising cookies.
Where product analytics are enabled, we use non-essential analytics cookies only after you accept them in the cookie banner; you can decline, and analytics will not run. We also use error-monitoring that records a masked replay of the moments leading up to a crash, to keep the Service reliable and secure.
12. Children
The Service is for business use and not directed at children under 16. We do not knowingly collect their information.
13. Changes & contact
We may update this Policy; material changes will be notified through the Service or by email. Data controller: THE MAIT Limited (New Zealand). Registered address available on request. Contact: info@themait.net.

