Welcome to Neztdo ("we", "us", "our"). This Privacy Policy explains how NEZTDO CORPORATION PTY LTD collects, uses, discloses, and protects your personal information when you access or use the Neztdo website (neztdo.com), the Neztdo web application (neztapp.com), and related services (collectively, the "Service").

1. Who We Are

NEZTDO CORPORATION PTY LTD is an Australian company registered at:
44 Lakeview Drive, Scoresby VIC 3179, Australia

We are the data controller for personal information processed in connection with the Service.

For privacy questions or requests: privacy@neztdo.com
General inquiries: info@neztdo.com

2. Information We Collect

Account Information: name, email address, password, workspace/team name, role or job title provided at registration.

Workspace Content: projects, epics, stories, tasks, deliverables, role assignments, sprint plans, time-tracking entries, comments, files, and activity history created by you or your team.

Billing Information: plan type, subscription status, and billing history. Payment card details are processed directly by third-party payment processors; we never store full card numbers.

Technical & Usage Data: IP address, browser type, device information, pages visited, features used, access times, and log data.

Analytics Data: We use Google Analytics and Microsoft Clarity to understand Service usage and improve our platform.

3. How We Use Information

We use information to:

  • Provide, operate, and maintain the Service
  • Manage accounts, subscriptions, and billing
  • Provide customer support and respond to inquiries
  • Send service communications and (with consent) marketing communications
  • Understand usage, improve, and develop new features
  • Protect security and prevent fraud
  • Comply with legal obligations

4. Legal Bases for Processing

Where GDPR/UK GDPR applies, we process data on the basis of:

  • Performance of a contract — providing the Service
  • Legitimate interests — security, fraud prevention, product improvement
  • Consent — marketing and optional cookies
  • Legal obligation — required record-keeping

5. How We Share Information

Within your workspace: User Content is visible according to roles and permissions configured by administrators.

Service providers: cloud hosting, payment processors, analytics providers, and communication tools process data under contract.

Business transfers: in connection with mergers or acquisitions, subject to confidentiality.

Legal requirements: to comply with law or protect rights and safety.

No sale of data: we do not sell personal information.

6. Cookies and Tracking

We use essential cookies (required for functionality) and analytics cookies (Google Analytics, Microsoft Clarity) with consent where required.

7. Data Retention

  • Account information retained while account is active
  • Upon deletion, personal data deleted within 30 days; backup copies retained up to 90 days
  • Billing records retained as required by Australian tax law

8. Data Security

We implement encryption in transit (TLS) and at rest (AES-256), role-based access controls, and security monitoring. No system is completely secure.

9. International Transfers

Data may be processed in Australia and countries where our providers operate. We use Standard Contractual Clauses where required.

10. Your Privacy Rights

GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, withdrawal of consent.

CCPA/CPRA (California): know, delete, correct, opt-out. We do not sell data.

Australian Privacy Principles: access, correction, complaint to OAIC.

PDPA (Sri Lanka): access, correct, delete, restrict, withdraw consent, prevent automated decisions.

Contact privacy@neztdo.com to exercise rights.

11. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect their data.

12. Third-Party Links

We are not responsible for third-party privacy practices.

13. Changes to This Policy

Material changes communicated via email or in-app notice.

14. Contact Us

Complaints may be lodged with the OAIC or your local data protection authority.