1. Who we are
Selinda OS is provided by Bouchard Pty Ltd (ABN 45 633 217 473, ACN 633 217 473), trading as Selinda, based in Adelaide, South Australia, Australia.
In this Policy, "Selinda", "we", "us" and "our" mean Bouchard Pty Ltd. "Selinda OS" means the platform we provide.
You can contact us at:
| Purpose | Address |
|---|---|
| General enquiries | hello@selinda.io |
| Privacy | privacy@selinda.io |
| Legal | legal@selinda.io |
| Security | security@selinda.io |
2. Scope of this Privacy Policy
This Policy explains how we handle personal information in connection with:
- our websites, including selinda.io and oreiq.ai;
- enquiries and demonstration requests made through those websites; and
- Selinda OS, including its applications, APIs, integrations and edge components.
This Policy applies globally. Where a particular country's privacy law applies to our handling of your information, we will comply with it. Sections 23 and 24 set out additional information for Australian and international users.
Selinda OS is intended for use by people aged 18 or over in a workplace context. It is not directed to children and we do not knowingly collect personal information from anyone under 18.
3. Roles: our information, and Customer-controlled operational records
Selinda handles information in three distinct situations. The distinction matters, because it changes who decides how information is used.
Layer 1 — Website visitors and enquiries. When you visit our websites or submit a demonstration or contact request, we decide how that information is used. This Policy governs it in full.
Layer 2 — Authorised users of Selinda OS. If your employer or another organisation (a Customer) gives you a Selinda OS account, we hold information about you as an individual in order to operate the service: your name, email address, role, access level, site, optional phone number, notification preferences, and a record of the actions you take in the platform. This Policy governs that information, and it is the information this Policy describes when it is presented to you for acceptance inside Selinda OS.
Layer 3 — Customer operational records. Shift logs, laboratory results, metallurgical test data, historian measurements, safety records, investigations, documents, reports and similar records belong to the Customer. The Customer decides why that information is collected and how it is used. We process it to provide Selinda OS under our agreement with that Customer, and on that Customer's instructions.
Where operational records contain personal information — for example, a person named in a shift narrative or a safety investigation — the Customer's own privacy policy governs how that information is handled, and requests about it are usually best directed to the Customer. We will help a Customer respond to such a request.
If you are not sure which layer applies to a question, contact us at privacy@selinda.io and we will tell you, or point you to the right organisation.
4. Personal information we collect
4.1 Account and profile information
For each Authorised User we hold:
- full name;
- email address (held within our authentication provider's system rather than in the Selinda OS application database);
- role — for example Operator, Supervisor, Metallurgist, Engineer, Manager, HSE Advisor, Contractor or Read Only;
- access level — for example Full, Standard or Read Only;
- the site and organisation the account belongs to;
- phone number, if provided;
- notification preferences and quiet hours;
- whether the account is active, and whether the initial password has been changed; and
- where temporary access to a particular circuit has been granted, the fact of that grant, who granted it, when it expires and the reason recorded for it.
4.2 Customer contact information
For each Customer site we may hold a primary contact name and email address, and internal notes about the customer relationship.
4.3 Enquiry and demonstration requests
If you submit a demonstration or contact request, we collect your name, email address, company, role, product interest and any message you write.
4.4 Authentication information
Authentication is provided by our authentication provider. We do not store your password, and we do not receive it. Your browser holds a session cookie.
4.5 Activity and audit information
Selinda OS keeps an audit trail. Actions such as creating or approving a laboratory result, finalising a specialised test, publishing a report, changing site configuration, or creating and revoking a share link are recorded against your user identifier and your name, together with a timestamp and, in many cases, the before-and-after values and any reason you recorded.
This audit trail is a core function of the product. It is what allows a Customer to demonstrate who did what, and when.
4.6 AI interaction information
Where you use AI-assisted features, we store the question you asked, the resulting conversation history, any rating or feedback you give, and the generated output, associated with your user identifier and your site. Section 9 explains this in more detail.
4.7 Communications
We hold the notifications generated for you within Selinda OS, and records of emails we send you.
4.8 Sharing information
Where you send a link to an artefact by email, the recipient's email address is recorded in the sharing audit log, together with who sent it, when, and whether the recipient was external to your organisation.
4.9 What we do not collect
We have verified the following against the Selinda OS database schema and application code. We do not collect or store:
- IP addresses. A visitor's IP address is used momentarily, in memory, to limit the rate of sign-in attempts and public requests. It is never written to our database. There is no IP address column anywhere in the schema;
- precise geolocation or GPS coordinates;
- payment card or bank account details;
- government identifiers such as passport, licence, tax file or social security numbers;
- biometric information;
- advertising identifiers or device identifiers.
5. Customer operational records that may contain personal information
Selinda OS holds a large volume of operational information on behalf of Customers, including shift and handover records, laboratory results, specialised metallurgical test data, process historian measurements, mass balances and metal accounting information, plant configurations, procedures, documents, knowledge objects, reports and uploaded files.
Much of this is not personal information at all. However, because operational records are written by people and often describe events involving people, some of it may be.
5.1 Safety records and investigations — please read this carefully
Selinda OS includes functionality for recording hazards and for assisting with incident investigations, including structured root-cause and ICAM-style analysis.
Records created through this functionality may contain sensitive personal information about identifiable individuals — for example, a description of an injury, an account of what a named person did or did not do, or information relevant to a person's conduct or fitness for work.
Where that occurs:
- the Customer decides what is recorded and why, and the Customer's own policies and legal obligations govern that information;
- access is restricted by the Customer's own role and access-level configuration within Selinda OS;
- we process it only to provide the service to that Customer; and
- if AI-assisted investigation features are used, the content of the investigation may be transmitted to an AI processing provider as described in section 9.
Customers should consider carefully what personal information is recorded in these features, and should ensure their own privacy notices to their workers cover it.
6. How we collect information
We collect information:
- directly from you — when you submit an enquiry, use Selinda OS, or contact us;
- from your organisation — when an administrator creates your account and assigns your role and access level;
- automatically as a by-product of use — audit entries, notifications and AI conversation records are generated as you work; and
- from systems your organisation connects — including its process historian, through an edge component installed in the Customer's own environment.
7. How we use information
We use personal information to:
- provide, operate, secure and support Selinda OS;
- authenticate you and enforce the role and access-level permissions your organisation has assigned;
- maintain the operational audit trail, which is a core product function;
- provide AI-assisted features when you invoke them;
- generate and deliver notifications and service communications;
- respond to enquiries and demonstration requests;
- diagnose faults, investigate incidents, and improve reliability and quality; and
- comply with legal obligations, and establish, exercise or defend legal claims.
We do not sell personal information. We do not use it for advertising, and we do not disclose it to advertising networks or data brokers.
8. Authentication and account security
Authentication uses signed tokens issued by our authentication provider. Selinda OS verifies each token locally against the provider's published public keys, with the signing algorithm pinned and the issuer, audience and expiry checked on every request.
Your browser session is held in a cookie. Access is enforced both in the application and at the database, which applies row-level access rules independently of application logic.
Sign-in attempts are rate limited — both per account and per originating network — to make credential guessing impractical. As noted in section 4.9, this uses the network address in memory only.
When an administrator invites you, we send you an email containing a temporary password, which you are required to change on first sign-in.
9. AI-assisted functionality and AI providers
9.1 Not everything uses AI
Most of Selinda OS does not involve AI. In particular, the metallurgical calculation engines are conventional software running on our servers. Particle size distribution, isotherm, kinetics, phase disengagement, maximum loading, solvent-extraction kinetics, statistical process control and mass balance results are computed deterministically by our own code. They are not generated by a language model.
AI-assisted functionality is used for specific features, which may include operational guidance, briefing and report drafting, document and attachment reading, investigation assistance, diagnostics, optimisation suggestions and analytical commentary.
9.2 What is sent, and to whom
When you invoke an AI-assisted feature:
- Anthropic receives the operational context assembled for that request. Depending on the feature, that can include shift information, laboratory and metallurgical values, document extracts, knowledge content, timeline events, hazards and investigation content.
- Where you use a document- or attachment-reading feature, **the file itself — including whole PDFs and images — may be transmitted** to Anthropic for processing.
- Voyage AI receives extracts of document text, divided into chunks, so that documents can be searched by meaning rather than by keyword. Voyage AI returns numeric representations of that text.
We do not send raw database tables, credentials, or our calculation engines to any AI provider.
We cannot describe our AI features as keeping everything inside Selinda. They do not. Content leaves our systems for processing, and this section is written so you know exactly what that means.
9.3 What is stored
AI questions, conversation history, feedback, ratings and generated outputs are stored as records within your organisation's Selinda OS environment, and are visible to appropriately permissioned users of your organisation.
9.4 Your responsibility for what you submit
Please do not submit to AI-assisted features any information you are not entitled to disclose, including third-party confidential information, personal information you have no lawful basis to provide, or material subject to legal professional privilege where disclosure would waive it.
10. Customer Data and AI model training
Customer Data is not training data for general-purpose AI models.
This is our policy position, and it is supported by how we have configured our providers:
Anthropic. We use Anthropic's commercial API. Under Anthropic's applicable commercial terms, inputs and outputs submitted through that API are not used to train its general models by default. Anthropic may retain content for a limited period — commonly described as up to 30 days — for operational and trust-and-safety purposes, subject to its own terms and any exceptions in them.
Voyage AI. Our organisation is explicitly opted out of model training. Data submitted after the opt-out took effect is not used for future general model training. Voyage AI's current documentation describes zero-day retention applying under that arrangement.
Three different things. It is worth separating them, because they are often confused:
| What it means | Our position | |
|---|---|---|
| Training | Content is used to improve a general-purpose model | Does not happen |
| Processing | Content is transmitted and computed on to produce a result | Happens whenever you invoke an AI feature |
| Retention | Content is held by the provider for a period afterwards | May occur, for limited periods, as described above |
Selinda's own use. As set out in our Terms of Use, we may derive aggregated and genuinely de-identified statistical information from use of Selinda OS to improve the platform. We may use such information only where it cannot reasonably identify a Customer, a site or operation, an individual, commercially sensitive plant performance, or confidential Customer information.
11. Service providers and subprocessors
We use the following providers to deliver Selinda OS. We do not use any others to process Customer Data.
| Provider | What they do | What they may receive |
|---|---|---|
| Supabase | Database, authentication and file storage | All Customer operational data, account profiles, email addresses and uploaded files |
| Vercel | Hosting for the web application and its server-side routes | Request traffic, session cookies, and content passing through server routes |
| Railway | Hosting for the backend API | All API traffic, and application logs |
| Anthropic | AI processing | Content described in section 9.2, including whole files where attachment reading is used |
| Voyage AI | Text embeddings for document search | Extracts of document text |
| Resend | Transactional email | Recipient email addresses, message content, and any attachment we send |
Uploaded files are held in object storage and served through links that expire after a short period — currently five minutes — so that a link cannot usefully be forwarded or retained.
We require our providers to handle information consistently with this Policy and with our obligations to Customers.
11.1 This list is versioned, and we tell you when it changes
The list above is a versioned subprocessor list. Each version carries a version number and an effective date, and superseded versions remain available so you can see what changed and when.
If we intend to engage a new subprocessor to process Customer Data, or to replace one on this list, we will give affected Customers at least 30 days' notice before the change takes effect, unless a shorter period is necessary to maintain the security or availability of the service, in which case we will give notice as soon as reasonably practicable.
Customers may subscribe to notification of changes to this list by contacting privacy@selinda.io.
Where a Customer has a reasonable, good-faith objection to a proposed subprocessor on data protection grounds, we will work with that Customer in good faith to address it.
11.2 The terms we engage providers under
Each provider is engaged under its standard data processing terms, which we have confirmed are appropriate for the way Selinda OS uses that provider.
If your organisation requires contractual data protection terms beyond a provider's standard terms — for example a specific data processing agreement, a named processing region, or a particular audit right — please raise it with us through your Customer Agreement so it can be addressed specifically rather than assumed.
12. International processing and data residency
Information may be processed or stored in jurisdictions other than the country in which the Customer or user is located. This is true whether you are in Australia, the United States or elsewhere.
12.1 Hosting
The location in which a Customer's data is hosted depends on the deployment. The hosting arrangement that applies to your organisation is recorded in its agreement with us. If you are unsure, ask your administrator or contact us.
Regional or in-country hosting may be available where it is specifically agreed in the applicable Customer Agreement and technically supported by us and our providers. We do not make a blanket guarantee that all data remains in any particular country.
12.2 AI processing and email — not affected by hosting choice
Choosing a particular hosting region does not keep all processing within that region.
- Anthropic processing may occur across multiple global regions, with standard storage in the United States unless otherwise agreed.
- Voyage AI processing location is not contractually established with us, and we therefore do not state one rather than state one we cannot stand behind.
- Resend may store customer and email service data in the United States.
12.3 What this means
Recipients in other countries may be subject to laws that differ from those of your own country, and in some circumstances may be required to disclose information to authorities in their jurisdiction.
13. Sharing and public links
Selinda OS allows a permissioned user to create a link to a report, chart or other artefact that can be opened without signing in.
Anyone who has the link can view that artefact until the link expires or is revoked. Links can be forwarded, and we cannot control what a recipient does with one.
Customers control this. A Customer can disable external sharing entirely, restrict which email domains links may be sent to, and set how long links remain valid by default. Every creation, send and revocation is recorded, including the recipient address where a link was emailed.
14. Cookies and local browser storage
We use a cookie for one purpose: to keep you signed in. It is strictly necessary — if you block it, you cannot use Selinda OS. We do not use advertising, marketing or third-party analytics cookies.
Selinda OS also uses your browser's local storage for application functionality. This information stays in your browser and is not transmitted to us as an analytics signal. It includes:
- unsaved drafts, such as a shift log you have started but not submitted — so that a browser crash does not lose your work;
- whether you have completed or dismissed the onboarding introduction;
- an in-progress AI conversation reference, so a session can resume;
- interface preferences and dismissed prompts; and
- short-lived caches of document analysis results.
15. Analytics and tracking
Selinda does not currently use website visitor analytics, advertising pixels, behavioural advertising, session recording or browser fingerprinting.
We have verified this against our codebase and against the live production website. Specifically, we do not currently use Vercel Web Analytics, Vercel Speed Insights, Google Analytics, Google Tag Manager, Meta Pixel, Microsoft Clarity, Hotjar, Segment, Mixpanel, Amplitude, PostHog, Plausible, Fathom or Matomo, and we load no third-party scripts in your browser.
Our typefaces are packaged into our own site at build time and served from selinda.io. Loading a Selinda page does not send a request to any font provider or other third party.
We do generate and use:
- strictly necessary authentication and session technologies;
- local browser storage for application functionality, as described in section 14; and
- ordinary infrastructure, security and operational logs produced by our hosting providers.
If this changes, we will update this Policy before or at the time the change takes effect.
16. Our access to Customer Data
Selinda personnel may access Customer Data in production only where there is a legitimate business need, on a least-privilege basis, and limited in scope and duration to what the task requires.
Permitted purposes are:
- providing support at a Customer's request;
- authorised maintenance;
- investigating a security concern;
- investigating a reliability incident;
- recovery activities; and
- meeting a legal obligation.
Selinda personnel must not browse Customer Data casually or out of curiosity. Production access is subject to appropriate audit.
We are not able to tell you that we cannot access Customer Data — we can, because operating and supporting the service requires it. What we can tell you is the basis on which we do.
17. Security
We maintain technical and organisational measures appropriate to the nature of the platform, including:
- encryption of data in transit, and encryption at rest as provided by our infrastructure providers;
- access control enforced at the database as well as in the application;
- short-lived signed links for stored files;
- locally verified authentication tokens with the signing algorithm pinned;
- rate limiting of sign-in and public requests; and
- restricted, purpose-bound personnel access as described in section 16.
No system is completely secure, and we do not claim otherwise.
If you believe you have found a vulnerability, or that an account or information has been compromised, please contact security@selinda.io.
18. Security incidents
A Security Incident means an actual compromise involving unauthorised access to, or acquisition, disclosure, alteration, loss or destruction of, Customer Data. It does not include unsuccessful attempts, such as failed sign-in attempts or automated scans that do not compromise Customer Data.
If we become aware of a confirmed Security Incident involving a Customer's data, we will:
- notify the affected Customer without undue delay, targeting notification within 72 hours where reasonably practicable, and sooner where a shorter legal deadline applies;
- provide the material information we have, and update it as more becomes known;
- take reasonable steps to contain and remediate; and
- cooperate with the Customer in meeting its own legal and regulatory notification obligations.
We notify the Customer. We do not automatically notify regulators or affected individuals on a Customer's behalf, because the obligation to do so, and the judgement about whether it is triggered, usually rests with the Customer. Where we have our own obligation to notify, we will meet it.
19. Retention and deletion
| Information | Retention |
|---|---|
| Customer operational data | Retained for the duration of the active Customer relationship |
| Identity linkage for deactivated users, within audit records | 7 years |
| Audit records | 7 years, or longer where a legal or contractual requirement applies |
| AI conversation history | Follows the retention period of the Customer record it relates to |
| Demonstration and contact requests | 2 years |
| Security records | 2 years, unless required longer for an investigation or legal purpose |
| Retrieval and export after termination | 90 days, unless the Customer Agreement provides otherwise |
After the retrieval period, production Customer Data may be deleted, subject to any legal or contractual retention requirement and to normal backup expiry cycles. Backup expiry periods depend on the deployment and the provider.
Deactivating a user does not erase that person's name from historical audit records. The audit trail is append-only by design, because its evidentiary value depends on not being rewritten. A record that a named person approved a laboratory result in 2026 remains a record of that fact.
20. Backups and resilience
We maintain backup and recovery measures appropriate to the relevant deployment.
The specific arrangements — including whether provider-managed database backups, independent backups of uploaded files, or point-in-time recovery are enabled — depend on the deployment and, where relevant, on the applicable Customer Agreement.
We do not state a universal backup frequency, recovery point objective or recovery time objective in this Policy. Where a Customer requires a specific commitment, it belongs in that Customer's agreement so that it can be defined and tested rather than assumed.
21. Access and correction
You can view and update parts of your profile within Selinda OS. Your organisation's administrators can correct your role, access level, site and status.
To request access to, or correction of, personal information we hold about you, contact privacy@selinda.io. We will respond within a reasonable period, and may need to verify your identity first.
Where the information forms part of a Customer's operational records, we will usually refer the request to that Customer, who is best placed to decide how to respond, and we will assist them.
If we decline a request, we will tell you why, unless it would be unreasonable to do so.
22. Privacy complaints
If you believe we have mishandled your personal information, please contact privacy@selinda.io. We will acknowledge your complaint, investigate it, and respond.
If you are not satisfied with our response and you are in Australia, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. If you are elsewhere, you may be able to complain to your local privacy or data protection authority.
23. Australian privacy position
Bouchard Pty Ltd operates Selinda OS using privacy practices designed with reference to the Australian Privacy Principles.
Where the Privacy Act 1988 (Cth), the Australian Privacy Principles, or another applicable privacy law applies to our handling of personal information, we will comply with it.
We handle personal information in a way intended to be consistent with those principles regardless of whether a particular obligation currently applies to us as a matter of law.
24. Additional information for international and United States users
If you are outside Australia, the information in sections 11 and 12 applies to you in the same way: your information may be processed or stored in jurisdictions other than your own, including Australia, Japan and the United States depending on the deployment and the provider.
If you are in the United States, the following may be relevant depending on your State:
- We do not sell personal information, and we do not share it for cross-context behavioural advertising.
- We do not use it for targeted advertising or for profiling that produces legal or similarly significant effects.
- Most information we hold about workplace users is held on behalf of the employing organisation, which is usually the entity to direct a request to.
25. Changes to this Privacy Policy
We may update this Policy. The current version is published at https://selinda.io/privacy.
Where a change is material, we will give notice, and may ask you to acknowledge the updated Policy within Selinda OS before you continue.
Where acceptance is recorded, the record consists of: the authenticated user, their site or organisation, the document type, the document version, a cryptographic hash of the exact text accepted, and the time of acceptance. We do not record an IP address, an IP hash or a browser user-agent string as part of that acceptance record.
26. Contact
Bouchard Pty Ltd (ABN 45 633 217 473, ACN 633 217 473), trading as Selinda Adelaide, South Australia, Australia
| Purpose | Address |
|---|---|
| Privacy enquiries, access, correction and complaints | privacy@selinda.io |
| Security | security@selinda.io |
| Legal | legal@selinda.io |
| General | hello@selinda.io |
See also our Terms of Use.