Legal

Privacy Policy

How Arenius collects, uses, stores, and protects personal information when you use our carbon accounting platform.

Effective date1 June 2026
Last updated23 July 2026

1. Who we are

Arenius ("Arenius", "we", "us", "our") is a carbon accounting and management platform operated by General Exporlations Limited, a company incorporated in New Zealand (New Zealand Business Number 9429053829672), with its registered office at 29 Clare Road, Christchurch.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you use the Arenius platform (the "Service"), accessible at arenius.org.

We are committed to handling personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles (IPPs). Where we handle personal information of individuals in Australia, we also have regard to the Australian Privacy Principles.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

2. Two roles: our data, and your customers' data

Arenius handles personal information in two distinct capacities, and it is important you understand the difference.

Where we act as an agency (controller). For information about you as a user of the Service (your account and identity information), and about the organisation you register, we determine how that information is handled. This Privacy Policy governs that information.

Where we act on your behalf (processor). When you connect an accounting system or otherwise load information about your own suppliers, customers, and other counterparties into the Service, you are the party that controls that information. We store and process it on your instructions so that we can provide the Service to you. In that capacity we act as your processor. You are responsible for having a lawful basis to provide that information to us and for your own privacy obligations to those individuals. Our handling of that information is governed by the agreement between us (see our Terms of Service), and we do not use it for our own purposes.

3. Information we collect

3.1 Account and identity information

When you create an account we collect and store your name, email address, avatar image (if you provide one), notification preferences, and authentication credentials. Authentication (email and password) is managed by our infrastructure provider, Supabase. We do not store your password in a form we can read.

3.2 Organisation information

When you set up an organisation in the Service, we collect information about that organisation, including company name, industry and sector code, country, currency, employee count, annual revenue, baseline and target years, financial year end, reporting boundary, and freight spend.

3.3 Financial and transaction information

To measure emissions, the Service holds financial line items associated with your organisation, including expense and revenue entries, amounts, descriptions, dates, payment methods, vendor and customer names, and accounting account codes. This is your organisation's accounting information and we treat it as confidential.

3.4 Counterparty information

The Service allows you to record information about your organisation's contacts, including suppliers and customers. This may include names, addresses, notes, contact type, and associated emissions totals. As set out in section 2, we hold this information as your processor.

3.5 Other organisation information

We also store the working data you create in the Service, including categories, emission factors, offsets, carbon goals, budgets and actuals, balance sheet lines, company valuation figures, carbon statements, financed emissions registers, scheduled reports and report archives, compliance fields, notifications, and team memberships and invitations (including the email addresses of people you invite before they have an account).

Company valuation figures are treated as highly confidential and access to them within your organisation is controlled by the role and visibility settings you configure.

3.6 Information from connected accounting systems

If you connect an accounting system such as Xero, we read information from it to build your emissions picture. This may include contacts, bank transactions, invoices, and your chart of accounts. Our access is read-only. We request only the minimum access needed to provide the Service. Access tokens for connected systems are encrypted at rest and are never exposed to your browser. You can disconnect a connected system at any time, and you may choose whether imported data is erased or retained when you do so.

3.7 Technical information

Our hosting and content delivery provider processes standard technical information when you use the Service, such as IP address and request metadata, in server logs. We use browser local storage (not tracking cookies) to keep you signed in and to remember interface preferences such as onboarding progress and your selected reporting period.

3.8 Billing information

When you subscribe to a paid plan, payments are processed by Stripe. Your card details are entered directly with Stripe and are never received or stored by us. Any billing address and tax identification information you provide is collected and held by Stripe for tax calculation purposes; we do not store it.

We store a limited billing record for your organisation so we can manage your subscription. This record contains your plan tier, subscription status, billing cycle, the Stripe customer and subscription identifiers, your renewal or expiry date, whether the subscription is set to cancel, and any trial end date. It does not contain your card details, billing name, billing email, or billing address.

4. What we do not do

We think it is worth stating plainly what we do not do, because it is unusual.

5. Why we collect and use information

We collect and use information to:

6. Our AI assistance feature

The Service includes an in-app help assistant. When you send a message to the assistant, the content of that message is transmitted to our AI provider, Anthropic, to generate a response. We do not send your financial records or counterparty data to the AI provider as part of ordinary use of the Service; only the content of your messages to the assistant is processed in this way. This feature is currently enabled.

7. Who we share information with

We share information with a small number of service providers who help us run the Service. Each acts on our instructions and is bound to protect the information.

ProviderRoleWhat is involved
SupabaseDatabase, authentication, storageHosts your account and organisation data and manages sign-in
Xero (if you connect it)Accounting integrationWe read financial and contact data from your Xero organisation, read-only
VercelHosting and content deliveryServes the application and processes standard request logs
Anthropic (if the AI assistant is enabled)AI help assistantProcesses the content of your support messages to the assistant
StripeBilling and paymentsProcesses your subscription payments, card details, and billing and tax information

Stripe processes your payment information for the purposes of taking payment, tax calculation, fraud prevention, and meeting its own legal and compliance obligations. In doing so, Stripe acts as an independent controller of that information under its own privacy policy, rather than solely on our instructions.

We may also disclose information where we are required or authorised to do so by law, to protect our legal rights, or in connection with a sale or restructure of our business (in which case we will require any acquirer to honour this policy).

We do not otherwise disclose your information to third parties without your authorisation.

8. Where your information is stored and cross-border disclosure

Your information is stored by our hosting providers. Our primary database is hosted by Supabase in the Sydney, Australia region. Our application hosting and content delivery is provided by Vercel, and our payment processing is provided by Stripe, both of which operate globally.

This means that some of your information, and information you provide to us about others, may be stored or processed outside New Zealand. Where we disclose personal information to an overseas provider, we take reasonable steps, consistent with Information Privacy Principle 12, to ensure that the provider is required to protect the information with safeguards comparable to those under the Privacy Act 2020.

9. How we keep information secure

We take the security of your information seriously and maintain measures including:

No system can be guaranteed to be completely secure. While we work to protect your information, we cannot warrant absolute security, and you use the Service on that understanding.

10. How long we keep information

We keep personal information for as long as your account and organisation remain active and for as long as needed to provide the Service. If you delete your organisation, associated data is deleted. If you disconnect a connected accounting system, you may choose to erase the imported data at that time.

If you close your account or delete your organisation, we permanently delete the associated data within 90 days, other than limited records we are required to keep for legal, tax, or accounting purposes, which we may retain for up to seven years. Residual copies in routine backups are overwritten on our providers' normal backup cycles. Billing records held by Stripe are retained by Stripe under its own retention policy.

11. Your rights

Under the Privacy Act 2020 you have the right to:

To exercise these rights, contact us at ned@arenius.org. We will respond within the timeframes required by law. We may need to verify your identity before acting on a request. There is generally no charge, although we may charge a reasonable fee for certain requests as permitted by law.

If your request concerns information we hold as a processor on behalf of an organisation (for example, information about you that one of our customers has loaded into the Service), we will direct you to, or work with, that organisation, which controls that information.

12. Complaints

If you have a concern about how we have handled your personal information, please contact us first at ned@arenius.org so we can try to resolve it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (www.privacy.org.nz).

13. Eligibility and children

The Service is intended for business use by individuals aged 18 or over. It is not directed at children, and we do not knowingly collect personal information from children.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after a change takes effect means you accept the updated policy.

15. Contact us

Questions about this policy or about how we handle personal information can be sent to:

General Exporlations Limited 29 Clare Road, Christchurch ned@arenius.org