Privacy Policy
This policy explains what personal information we collect about you (the person reading this, enquiring about Plugboard, or administering a deployment) and what we do with it. It is written to meet Australian Privacy Principle 1.3.
Two different relationships are in play, and this policy covers the first.
When you enquire, book a walkthrough, or run a Plugboard deployment, we handle a small amount of information about you, and for that we are the data controller. This policy covers it.
When a school runs Plugboard, the pupil, parent and staff records inside it belong to the school. We are only a processor of those, acting on the school's instructions under its agreement with us. What we do and do not do with them is set out in Data processing and sub-processors, not here. If you are a parent or student asking about your own records, your school is the right first contact; they hold the data and control it.
1. Who we are
Plugboard is a product of Samios Software Solutions (ABN 29 966 784 797), an Australian business. In this policy "we", "us" and "our" mean Samios Software Solutions.
You can reach us at hello@plugboard.app about anything in this document, including a request to access or correct your information, or a complaint.
2. What we collect about you, and why
| What | When | Why |
|---|---|---|
| Name, work email address, institution, role, and a phone number if you give one | You email us, book a walkthrough, or ask for a trial | To answer you, and to run the trial you asked for |
| What you asked about and what we discussed, including the systems you told us you run and the times you offered | When you book a walkthrough, and during an enquiry or trial | To pick up the conversation where it left off, to set up the right connectors before the call, and to decide what to build next |
| Administrator account details for a deployment | You are set up as an administrator | To provision, support and update the deployment |
| Billing contact and payment records | You become a customer | To invoice you and to meet our tax and record-keeping obligations |
| Count-only deployment telemetry: technician accounts, managed devices, enabled modules, version, deployment id | Continuously, for managed and (unless disabled) self-hosted deployments | To bill correctly and to know which version an instance is on |
The telemetry contains no personal information about the people your desk serves. It is counts, versions and identifiers of the deployment, and carries no names, records, serial numbers, credentials or ticket content. Self-hosted deployments can switch it off entirely with USAGE_REPORTER_DISABLED=1.
We do not
- Buy or sell personal information, or trade it with anyone.
- Use your information, or your school's data, to train any machine-learning model.
- Run advertising trackers on this website. Cloudflare Web Analytics provides aggregate website measurements.
- Ask for a government identifier. If you send us one, we will delete it.
3. Cookies and this website
The marketing pages do not set application cookies. Your theme preference (dark or light) and an explicitly selected billing currency are kept in your browser's local storage. Cloudflare's country metadata suggests an initial currency; the pricing endpoint returns only the country and suggested currency, without an IP address. The currency you choose is included when you submit a walkthrough request. Cloudflare injects its Web Analytics script to measure website visits and performance. Cloudflare also processes request metadata and server logs for hosting and abuse prevention. The live demo is loaded from our demo service only when you choose to open it.
If you follow a link to demo.plugboard.app or docs.plugboard.app, those are our own services and are covered by this policy.
4. Who we share it with
We disclose personal information only to the suppliers who help us run the service, and only as far as they need it. The current list is published and kept up to date at Data processing and sub-processors. Today it is our regional hosting provider, Cloudflare for ingress, regional object storage for encrypted backups, an email provider for notifications, and, for managed deployments on a tier that includes AI, DigitalOcean for the assistant's inference.
We will also disclose information where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over a customer's data, we will tell that customer unless we are legally prohibited from doing so.
5. Where it is held, and overseas disclosure
The managed application database is hosted in the region agreed during onboarding, with backup destinations configured for that deployment. External connectors, email, AI inference and Cloudflare services can process information in other locations. Your application hosting region does not determine every supplier's processing location. Australia is available today; other application regions are arranged during onboarding.
Enquiries, invoices and correspondence are business records separate from the school application database. Our website and booking service use Cloudflare. Depending on the configured delivery channels, walkthrough requests can be stored in Cloudflare KV and sent through Resend email, Slack, Discord, Telegram or a configured webhook. These providers can process information outside Australia. Ask us for the active delivery and retention arrangements before sending information with a location restriction.
6. How long we keep it
- Enquiries that go nowhere: deleted within 24 months.
- Customer and billing records: kept for seven years after the relationship ends, because Australian tax law requires it.
- Deployment data: for the term of the agreement, then exported to you and deleted, including from backups, after the window set in that agreement.
- Audit logs inside a deployment: for the retention period the school sets. The school runs its own erasure.
7. Keeping it safe
Connector credentials are encrypted in the deployment's vault. Integrations decrypt them when needed; some operations use private temporary credential files that are removed afterwards. Traffic is encrypted in transit. Separation between institutions is enforced by the database as well as by the application. The product supports multi-factor authentication, access permissions and audit logging; deployment-specific controls are described in our security model.
If a breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. Our process is written down in Incidents.
8. Your rights
You can ask us to:
- Give you a copy of the personal information we hold about you.
- Correct it if it is wrong, out of date, or incomplete.
- Delete it, where we are not required to keep it.
- Stop emailing you. Ask us directly to stop marketing correspondence. Operational messages about an active account or requested service may still be needed.
Email hello@plugboard.app. We will respond within 30 days and will not charge you for access. If we refuse a request we will tell you why, in writing.
If you are covered by the GDPR or UK GDPR, you additionally have the rights to restriction, objection and data portability, and a right to lodge a complaint with your local supervisory authority.
9. Complaints
Complain to us first, at hello@plugboard.app, with "Privacy complaint" in the subject. We will acknowledge within 5 business days and give you a decision within 30 days.
If you are not satisfied with how we handled it, you can escalate to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
10. Changes
If we change this policy we will update the date at the top. If a change materially affects how we handle your information, we will tell affected customers directly and give them time to object before it takes effect.