1. Who we are
Arenius ("Arenius", "we", "us", "our") is a carbon accounting and management platform operated by General Exporlations Limited, a company incorporated in New Zealand (New Zealand Business Number 9429053829672), with its registered office at 29 Clare Road, Christchurch.
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you use the Arenius platform (the "Service"), accessible at arenius.org.
We are committed to handling personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles (IPPs). Where we handle personal information of individuals in Australia, we also have regard to the Australian Privacy Principles.
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Two roles: our data, and your customers' data
Arenius handles personal information in two distinct capacities, and it is important you understand the difference.
Where we act as an agency (controller). For information about you as a user of the Service (your account and identity information), and about the organisation you register, we determine how that information is handled. This Privacy Policy governs that information.
Where we act on your behalf (processor). When you connect an accounting system or otherwise load information about your own suppliers, customers, and other counterparties into the Service, you are the party that controls that information. We store and process it on your instructions so that we can provide the Service to you. In that capacity we act as your processor. You are responsible for having a lawful basis to provide that information to us and for your own privacy obligations to those individuals. Our handling of that information is governed by the agreement between us (see our Terms of Service), and we do not use it for our own purposes.
3. Information we collect
3.1 Account and identity information
When you create an account we collect and store your name, email address, avatar image (if you provide one), notification preferences, and authentication credentials. Authentication (email and password) is managed by our infrastructure provider, Supabase. We do not store your password in a form we can read.
3.2 Organisation information
When you set up an organisation in the Service, we collect information about that organisation, including company name, industry and sector code, country, currency, employee count, annual revenue, baseline and target years, financial year end, reporting boundary, and freight spend.
3.3 Financial and transaction information
To measure emissions, the Service holds financial line items associated with your organisation, including expense and revenue entries, amounts, descriptions, dates, payment methods, vendor and customer names, and accounting account codes. This is your organisation's accounting information and we treat it as confidential.
3.4 Counterparty information
The Service allows you to record information about your organisation's contacts, including suppliers and customers. This may include names, addresses, notes, contact type, and associated emissions totals. As set out in section 2, we hold this information as your processor.
3.5 Other organisation information
We also store the working data you create in the Service, including categories, emission factors, offsets, carbon goals, budgets and actuals, balance sheet lines, company valuation figures, carbon statements, financed emissions registers, scheduled reports and report archives, compliance fields, notifications, and team memberships and invitations (including the email addresses of people you invite before they have an account).
Company valuation figures are treated as highly confidential and access to them within your organisation is controlled by the role and visibility settings you configure.
3.6 Information from connected accounting systems
If you connect an accounting system such as Xero, we read information from it to build your emissions picture. This may include contacts, bank transactions, invoices, and your chart of accounts. Our access is read-only. We request only the minimum access needed to provide the Service. Access tokens for connected systems are encrypted at rest and are never exposed to your browser. You can disconnect a connected system at any time, and you may choose whether imported data is erased or retained when you do so.
3.7 Technical information
Our hosting and content delivery provider processes standard technical information when you use the Service, such as IP address and request metadata, in server logs. We use browser local storage (not tracking cookies) to keep you signed in and to remember interface preferences such as onboarding progress and your selected reporting period.
3.8 Billing information
When you subscribe to a paid plan, payments are processed by Stripe. Your card details are entered directly with Stripe and are never received or stored by us. Any billing address and tax identification information you provide is collected and held by Stripe for tax calculation purposes; we do not store it.
We store a limited billing record for your organisation so we can manage your subscription. This record contains your plan tier, subscription status, billing cycle, the Stripe customer and subscription identifiers, your renewal or expiry date, whether the subscription is set to cancel, and any trial end date. It does not contain your card details, billing name, billing email, or billing address.
4. What we do not do
We think it is worth stating plainly what we do not do, because it is unusual.
- We do not use analytics, tracking, advertising, or behavioural profiling tools in the Service.
- We do not sell, rent, or trade personal information to anyone.
- We do not use your organisation's financial or counterparty information for any purpose other than providing the Service to you.
5. Why we collect and use information
We collect and use information to:
- create and administer your account and your organisation;
- provide the core function of the Service, which is measuring and reporting greenhouse gas emissions from your financial information;
- import and synchronise data from accounting systems you choose to connect;
- allow you to invite and manage team members;
- generate reports, statements, and compliance outputs at your direction;
- communicate with you about the Service, including service notices and support;
- maintain the security, integrity, and performance of the Service; and
- meet our legal obligations.
6. Our AI assistance feature
The Service includes an in-app help assistant. When you send a message to the assistant, the content of that message is transmitted to our AI provider, Anthropic, to generate a response. We do not send your financial records or counterparty data to the AI provider as part of ordinary use of the Service; only the content of your messages to the assistant is processed in this way. This feature is currently enabled.
7. Who we share information with
We share information with a small number of service providers who help us run the Service. Each acts on our instructions and is bound to protect the information.
| Provider | Role | What is involved |
|---|---|---|
| Supabase | Database, authentication, storage | Hosts your account and organisation data and manages sign-in |
| Xero (if you connect it) | Accounting integration | We read financial and contact data from your Xero organisation, read-only |
| Vercel | Hosting and content delivery | Serves the application and processes standard request logs |
| Anthropic (if the AI assistant is enabled) | AI help assistant | Processes the content of your support messages to the assistant |
| Stripe | Billing and payments | Processes your subscription payments, card details, and billing and tax information |
Stripe processes your payment information for the purposes of taking payment, tax calculation, fraud prevention, and meeting its own legal and compliance obligations. In doing so, Stripe acts as an independent controller of that information under its own privacy policy, rather than solely on our instructions.
We may also disclose information where we are required or authorised to do so by law, to protect our legal rights, or in connection with a sale or restructure of our business (in which case we will require any acquirer to honour this policy).
We do not otherwise disclose your information to third parties without your authorisation.
8. Where your information is stored and cross-border disclosure
Your information is stored by our hosting providers. Our primary database is hosted by Supabase in the Sydney, Australia region. Our application hosting and content delivery is provided by Vercel, and our payment processing is provided by Stripe, both of which operate globally.
This means that some of your information, and information you provide to us about others, may be stored or processed outside New Zealand. Where we disclose personal information to an overseas provider, we take reasonable steps, consistent with Information Privacy Principle 12, to ensure that the provider is required to protect the information with safeguards comparable to those under the Privacy Act 2020.
9. How we keep information secure
We take the security of your information seriously and maintain measures including:
- Tenant isolation. Row-level security is enforced at the database level so that each organisation can only access its own data. This is tested as part of our development process.
- Role-based access. Within an organisation, access is controlled by role (owner, admin, editor, approver, viewer).
- Encryption of connected-system credentials. Access tokens for connected accounting systems are encrypted at rest using AES-256-GCM.
- Secret handling. Server-side secrets are never shipped to your browser.
- Authenticated sessions. Access to the Service requires authentication.
No system can be guaranteed to be completely secure. While we work to protect your information, we cannot warrant absolute security, and you use the Service on that understanding.
10. How long we keep information
We keep personal information for as long as your account and organisation remain active and for as long as needed to provide the Service. If you delete your organisation, associated data is deleted. If you disconnect a connected accounting system, you may choose to erase the imported data at that time.
If you close your account or delete your organisation, we permanently delete the associated data within 90 days, other than limited records we are required to keep for legal, tax, or accounting purposes, which we may retain for up to seven years. Residual copies in routine backups are overwritten on our providers' normal backup cycles. Billing records held by Stripe are retained by Stripe under its own retention policy.
11. Your rights
Under the Privacy Act 2020 you have the right to:
- access the personal information we hold about you; and
- request correction of that information if you believe it is wrong.
To exercise these rights, contact us at ned@arenius.org. We will respond within the timeframes required by law. We may need to verify your identity before acting on a request. There is generally no charge, although we may charge a reasonable fee for certain requests as permitted by law.
If your request concerns information we hold as a processor on behalf of an organisation (for example, information about you that one of our customers has loaded into the Service), we will direct you to, or work with, that organisation, which controls that information.
12. Complaints
If you have a concern about how we have handled your personal information, please contact us first at ned@arenius.org so we can try to resolve it. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner (www.privacy.org.nz).
13. Eligibility and children
The Service is intended for business use by individuals aged 18 or over. It is not directed at children, and we do not knowingly collect personal information from children.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after a change takes effect means you accept the updated policy.
15. Contact us
Questions about this policy or about how we handle personal information can be sent to:
General Exporlations Limited 29 Clare Road, Christchurch ned@arenius.org