Sheet 10 of 10 · Privacy policy
Privacy policy
What we collect, where it is kept, who else touches it, and how long we hold it.
In effect 6 September 2026
The short version
- Your database and your files are stored in Sydney, Australia.
- We use a small number of service providers to run the platform, and we will tell you who they are if you ask.
- We do not sell personal information, and we do not use your content to train AI models.
- You can ask us for a copy of your information, ask us to correct it, or complain, at sales@kojomfg.com.
A plain-English summary, not a substitute for the clauses below. Where the two differ, the clauses are what applies.
01Who this covers
This policy explains how Nour Engineering Solutions Pty Ltd (ABN 99 654 141 689), trading as Kojomfg, handles personal information. It covers this website and the NE Vault platform. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
02Two different roles
It matters which hat we are wearing, because it changes who you should ask about your information.
For our own customers — the manufacturers who subscribe to NE Vault — we decide what we collect and why. Ask us directly.
For our customers' customers — the businesses who sign in to a manufacturer's portal to order parts — the manufacturer decides what is collected and why. We hold and process that information on their instructions. If you are a portal user asking about your information, contact the manufacturer whose portal you use, and we will support them in answering you.
03What we collect
- Account information: name, work email address, phone number, the organisation you belong to, your role, and two-factor authentication settings.
- Business information: company name, ABN, trading and delivery addresses, bank and invoicing details you enter, and trade references you provide on a credit application.
- Content you upload: parts, CAD models, drawings, photographs, quotes, orders, invoices and the notes attached to them.
- Supplier and purchasing information: your suppliers' contact details, the purchase orders you raise with them, prices, and delivery and receipt records.
- Production and inventory records: work orders, bills of materials, machine schedules, stock levels and stock movements, including which staff member received, issued or scanned a given item.
- Billing information: your subscription, what it costs, and its payment status. Card details go directly to Stripe and are never stored on our systems.
- Technical information: sign-in times and device type, IP address, pages and actions in the application, and error logs.
- Audit records: who signed in, who downloaded which file, and who changed settings. These exist so that you can answer a compliance question with evidence.
Some of these records name the staff member who performed an action, because a stock movement or a file download is only useful if you know who made it. We do not run timesheets, and we do not measure or report on an individual employee's productivity.
On this website, we collect only what you type into the demo request form: your name, work email, company, phone and message.
04Where your data is stored
The NE Vault database and every file you upload are stored in Australia, in Amazon Web Services' Sydney region (ap-southeast-2). We chose that deliberately, because engineering drawings are sensitive and our customers are Australian.
Some of the providers below operate globally, so limited information such as an email address, an invoice, or a request routed through our hosting may be processed overseas, including in the United States and the European Union. We only use providers that offer appropriate protection for that information.
05Service providers
We rely on a small number of specialist providers to run the platform. We keep that list deliberately short, and we only engage providers who are required to protect your information and to use it solely to perform their function for us.
- The database and file storage that hold your workspace, both located in Australia.
- Application hosting and content delivery.
- Card payment and subscription billing.
- Sending transactional email, such as quote and order notifications.
- Security services that protect sign-in against automated attacks.
Some of these providers operate globally, so limited information may be processed overseas, including in the United States and the European Union. Your workspace database and uploaded files remain in Australia.
If you would like to know exactly which providers we use, ask us and we will tell you. If we add or change a provider in a way that materially affects how your data is handled, we will tell subscribing customers by email.
06Services you connect yourself
Separately from the providers we use to run the platform, NE Vault may let you connect your workspace to other software your business already uses — accounting, logistics or similar. Those connections are optional, you turn them on, and you can turn them off.
When you connect one, you are instructing us to send that service the data the connection needs. Once that data leaves NE Vault it is held by that provider under their own privacy policy and terms of service, not this policy, and we are not responsible for what they do with it. Read their terms before you connect, and disconnect at any time from your settings.
We will never connect your workspace to a third-party service without your instruction.
07How we use it
- To provide the service: showing your parts to the right people, producing quotes, orders and invoices, and running the features you have switched on.
- To bill you, and to collect payment.
- To send transactional email, such as quote and order notifications, invoices and password resets.
- To provide support when you ask for it.
- To keep the platform secure and reliable, including investigating suspicious activity.
- To meet our legal obligations, such as keeping financial records.
We do not sell personal information. We do not use your content or your customers' CAD files to train machine-learning models. We do not send marketing email to your customers.
08When we disclose information
We disclose personal information only:
- To the categories of service provider described above, so they can perform their function.
- To any third-party service you have chosen to connect to your workspace, on your instruction and for as long as you leave that connection switched on.
- To you and the users you have authorised in your own workspace.
- Where the law requires it, such as a court order or a lawful request from a regulator.
- To protect someone's safety, or to investigate a serious security incident.
- To a buyer, if our business is sold, in which case we will tell you before your information moves.
09How we protect it
- Workspaces are isolated from one another, enforced when data is queried rather than only in the interface.
- Files are served on signed links that expire in minutes. They are never on public URLs.
- Data is encrypted in transit, and at rest by our database and storage providers.
- Two-factor authentication is available for staff and portal users, and each staff user is limited to one desktop and one mobile session at a time.
- Sign-ins, downloads and setting changes are written to an audit log.
- Access by our own people is limited to those who need it, is used only to run the service or provide support, and is recorded.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
10How long we keep it
We keep your workspace data for as long as you are a customer. After your subscription ends we keep it for 90 days so that you can export it, then we permanently delete it. You can ask us to delete it sooner.
It matters whose financial records they are. Our own records of what you paid us — your subscription invoices and payment history — are kept for seven years, because Australian tax and corporate law requires us to keep them. That is a small set of data about your business, not about your customers.
The invoices, orders and purchase records you raise inside NE Vault are your business records, not ours. They are deleted with the rest of your workspace at the end of the 90-day window. Keeping your own copies is your responsibility, and you should export them before the window closes — your obligations to the ATO continue after you stop using our software. If you need longer, ask us before the window closes and we will arrange it.
We also keep security and audit logs for as long as they are needed to investigate incidents, and enquiries from this website's demo form for two years unless you ask us to remove them.
12Your rights
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, or ask us to delete it where we are not required to keep it. Email sales@kojomfg.com and we will respond within 30 days.
If you are unhappy with how we have handled your information, tell us first and we will try to put it right. If you are still unhappy, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
NE Vault is a business tool and is not directed at children. We do not knowingly collect information about anyone under 16.
13Changes and contact
We will update this policy as the platform changes. The date at the top shows when it last changed, and we will email subscribing customers about anything material.
Privacy enquiries, including a request for a copy of your information or a complaint: email sales@kojomfg.com. We will give you a postal address on request.
The commercial agreement is set out separately.
Terms of service · sheet 9