Legal · Draft

Privacy Policy

Last updated: 14 February 2026 · Beta programme edition · Draft for legal review.

Legal review required
The service is now presented as Subtend Studio. The legal contracting entity, ABN, registered business name and privacy contact email domain remain to be confirmed by the owner before general availability.

1. Who we are

[Legal Entity — LEGAL REVIEW REQUIRED] operates Subtend Studio, a design-to-proposal SaaS workspace. This Policy describes how we handle information when you use the Service.

2. Information we collect

  • Business account data (business name, contact email, phone, address).
  • Client data your business enters (client name, contact details, project address).
  • Uploaded photos and files (room photos, reference images).
  • Project and design data (dimensions, materials, layouts).
  • Email addresses of portal invitees.
  • Authentication data (password hashes, session tokens).
  • Product analytics and error logs.

3. How we use it

To provide the Service, respond to support requests, secure the Service against abuse, generate proposals and other documents on your behalf, and improve the Service. We do not sell your data.

4. Third-party processors

The Service uses a small set of trusted subprocessors:
  • Emergent Platform — hosting, database, object storage.
  • Resend — transactional email delivery.
  • Emergent LLM Universal Key — AI-assisted text where enabled.
Each subprocessor is bound by its own privacy commitments.

5. Data location

Customer Data is stored on infrastructure operated by our hosting subprocessor. Some processing may occur outside Australia. Where this is the case, we take reasonable steps to protect the data.

6. Retention

Customer Data is retained while your account is active and for a reasonable period afterwards to allow reactivation and to satisfy legal obligations. Backups may retain data for up to 35 days after deletion from active systems.

7. Access, correction and deletion

You can access and correct most account data through the Service settings. To request a full export or deletion of your data, contact privacy@luxemediawalls.com. We will respond within 30 days.

8. Security

We use industry-standard measures including transport encryption (HTTPS), password hashing, tenant isolation and controlled access to production systems. No system is perfectly secure — we will notify affected customers of material incidents in accordance with Australian law.

9. Cookies and tracking

We use a small number of essential cookies for authentication and session management. We do not use third-party advertising cookies.

10. Children

The Service is intended for use by businesses. It is not directed to individuals under 16.

11. Updates

We may update this Policy. Material changes will be announced via the Service or by email to your primary account contact.

12. Contact

Questions or requests can be sent to privacy@luxemediawalls.com. Email domain migration is pending owner decision — see the header notice above.