Privacy Policy
Last updated 4 August 2026
1. Who we are
Mount Bensley Pty Ltd (ACN 686 491 476, ABN 92 686 491 476), an Australian company registered in New South Wales, operates solstral.com and the Solstral platform ("Solstral", "we", "us"). Mount Bensley Pty Ltd is the entity responsible for personal information handled through the platform, and also trades under the registered business name Adcrayons. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, the GDPR for individuals in the EEA/UK.
2. Two roles, two datasets
As a controller, we collect information about our own customers and site visitors: account details (name, email, company), billing information, support correspondence, and usage telemetry. As a processor, we host Customer Data — the contact records our customers store in their workspaces. Our customers control that data; if your information appears in a customer's workspace, contact that organisation first, and we will assist them with your request.
3. What we collect and why
- Account data — to create and secure your account, provide support and send service notices (contract performance).
- Billing data — processed by our payment provider; we do not store full card numbers (legal obligation and contract).
- Usage telemetry — feature usage and diagnostics, to operate and improve the Service (legitimate interests).
- Site analytics — privacy-conscious, consent-gated analytics on the marketing site (consent).
- Email interaction data — opens, clicks, bounces and complaints on email sent through the platform, processed on behalf of the sending customer.
4. What we never do
We do not sell personal information. We do not use Customer Data to train machine-learning models. We do not send marketing to our customers' contacts.
5. Storage and security
Data is hosted on Amazon Web Services in Sydney, Australia (ap-southeast-2), encrypted at rest and in transit. Access is role-restricted, logged and protected by MFA. See our Security page for the full control set.
6. Disclosure
We share personal information only with the sub-processors published at solstral.com/legal/subprocessors and listed in our DPA, with professional advisers under confidentiality, or where required by law. Where a public authority asks us for personal information we follow the procedure in section 7 below, and we will challenge overbroad demands where lawful.
Most of those providers are located outside Australia — principally in the United States — so using the Service involves cross-border disclosure under Australian Privacy Principle 8. The list names each provider's location and what it can access.
7. Requests from public authorities
We rarely receive requests from law enforcement, regulators or other public authorities for personal information, and we do not disclose personal information to them unless we are legally required to. When a request arrives we follow a documented procedure:
- We review its legality. Every request is checked to confirm the authority has jurisdiction over us, that the instrument is valid and properly served, and that it is legally binding rather than a voluntary request. We take legal advice where the position is unclear, and we decline requests that are not compulsory.
- We challenge requests we consider unlawful. Where a request exceeds the authority’s power, lacks a valid legal basis, or seeks more than the law permits, we object and, where necessary and lawful, contest it — including through the courts.
- We disclose the minimum necessary. We provide only the specific data the request compels, for only the individuals and time period named. We do not grant bulk access, direct or automated access to our systems, or entire datasets, and we build no tools to give authorities access.
- We document every request. Each one is recorded with the requesting authority, the legal instrument relied on, the data sought, our legal analysis, the people involved in the decision, and exactly what was disclosed and when. The record is retained and reviewed.
- We notify you where we are permitted to. If a request concerns Customer Data we tell the affected customer so they can respond themselves, unless we are legally prohibited — in which case we seek to have the prohibition lifted or narrowed.
Where the data sought is Customer Data, our customer is the controller and we will direct the authority to them wherever the law allows. The full procedure is set out in our internal Government and Public Authority Data Request Policy, which is available to customers on request.
7. Requests from public authorities
We receive requests for personal information from courts, law-enforcement agencies, regulators and other public authorities. We have a written policy governing how those are handled, and it applies to every request in every country. All requests route to a single point of contact (our Director); no one else may confirm, deny or respond, and no record is searched before the review below is complete.
Legality review. Nothing is disclosed until we have established that the request is compulsory rather than voluntary, that the authority has jurisdiction over us, that the instrument is valid on its face, that a specific legal basis exists and that the scope actually follows from it, and that we are the right party at all. We are an Australian company and Customer Data is hosted in Australia; a foreign authority generally cannot compel us directly without a recognised cross-border arrangement or an order enforceable in Australia. Any request that is not plainly valid and plainly narrow goes to a lawyer before we respond.
Challenging over-broad requests. We object where a request is invalid, exceeds the authority’s power, lacks a valid basis, is disproportionate in scope, or seeks data we hold as a processor without the controller being involved. We escalate from written objection, to negotiated narrowing, to formal challenge through counsel where the defect is material. We do not comply while challenging unless compelled to, and we do not treat an unanswered objection as consent to disclose.
Data minimisation. Where we must comply, we disclose only the individuals, categories and period the instrument compels — nothing adjacent. We never grant bulk access, direct system access, credentials or a standing feed, and we never build tooling for an authority. Third-party personal information incidental to a request is redacted.
Documentation. Every request is logged, with the review findings, any objection made, and what was ultimately disclosed and why.
Where you are the controller. If the data sought sits in your workspace, you are the controller and we are the processor. Our default position is that the authority should approach you directly, and we say so in writing wherever the law allows. Where a non-disclosure order is attached we seek to have it lifted, narrowed or time-limited so that we can tell you.
8. Retention
Account data is retained while your account is active and for up to 7 years afterwards where required for tax and legal purposes. Customer Data is deleted within 30 days of workspace termination. Backups age out on a rolling schedule of no more than 35 days.
9. Your rights
You may request access to, correction of, or deletion of your personal information, object to processing, or request portability by emailing [email protected]. We respond within 30 days. If unsatisfied, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au) or your local supervisory authority.
10. Cookies
The marketing site uses only essential cookies plus consent-gated analytics. The application uses session cookies necessary to keep you signed in. We honour withdrawal of consent at any time via the cookie banner.
11. Google user data (calendar integration)
If you choose to connect a Google account to Solstral's scheduling and meetings features, we access your Google Calendar data through Google's authorised OAuth APIs, requesting only the minimum scopes needed:
- Read for availability — we read your calendar's free/busy information (the
calendar.events.freebusyscope) and the list of calendars you are subscribed to (thecalendar.calendarlist.readonlyscope) solely to calculate the times you are available, let you choose which calendars count, and prevent double-booking on your booking pages. We do not read the contents of your events. - Write for booked events — when a meeting is booked, rescheduled or cancelled, we create, update or delete the corresponding event on your calendar (the
calendar.eventsscope), including generating a Google Meet link where you enable it. - Account identification — we read your Google account email address (the
userinfo.emailscope) to identify and label the connected calendar.
We use this Google user data only to provide these user-facing scheduling features, and only while your Google account remains connected — you can disconnect at any time from the app, which revokes our access. OAuth tokens are stored encrypted and are never logged in plaintext. We do not sell Google user data, do not transfer or share it with third parties except as necessary to provide the feature you requested (or for security or legal reasons), do not use it for advertising of any kind, and do not use it to train machine-learning models. We do not allow humans to read it except with your affirmative consent, for security, or where required by law.
Solstral's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
12. Meta Platform Data (Instagram, Facebook and Threads)
If you connect a social account to Solstral's social engagement features, we access data from Meta's platforms through their authorised APIs — on your instruction, and only for accounts you own or administer. You connect through Meta's own login and consent screens; we never ask for or store your password for those platforms. We request the minimum permissions each feature needs:
- Instagram —
instagram_business_basicto identify the connected professional account,instagram_business_manage_commentsto read and reply to comments on that account’s own posts,instagram_business_manage_messagesto receive and send that account’s direct messages, andinstagram_business_content_publishto publish the feed posts you schedule from your content calendar. - Facebook Pages and Messenger —
pages_show_listso you can choose which Page to connect,pages_read_engagementandpages_read_user_contentto read that Page’s own posts and the comments left on them,pages_manage_poststo publish, edit and delete the posts you schedule,pages_manage_metadatato subscribe the Page to notifications so new comments and messages reach your inbox,pages_manage_engagementto reply to and hide comments on that Page’s posts, andpages_messagingto receive and send that Page’s Messenger conversations. - Threads —
threads_basicto identify the connected profile,threads_content_publishandthreads_deleteto publish and remove the posts you schedule,threads_read_repliesandthreads_manage_repliesto read, answer and hide replies to your own posts, andthreads_keyword_searchandthreads_profile_discoveryto find public posts and profiles relevant to keywords you configure.
Through those permissions we receive the connected account's identifiers (account id, username or Page name, profile picture), and the content, sender identifier and timestamp of messages and comments sent to that account, together with delivery and engagement metadata. Where the sender matches a record in your workspace, the conversation is attached to that record.
How we use it. Only to provide the features you connected the account for: showing those conversations in your workspace's shared inbox, attaching them to your CRM records, sending the replies your team writes or the rules you configure, and reporting on your own account's engagement. For this data we act as a processor and you are the controller — the same as for the rest of your Customer Data.
What we never do. We do not sell Meta Platform Data, do not license or broker it, do not use it for advertising, ad targeting, audience building or profiling, do not use it to make eligibility decisions, and do not use it to train machine-learning models. We do not share it with anyone except the sub-processors published at solstral.com/legal/subprocessors that host and operate the service, or where required by law. We do not allow humans to read it except with your affirmative consent (for example when you raise a support request), for security, or where required by law. Access tokens are encrypted at rest with a dedicated key, are never logged in plaintext, and are held only for as long as the connection exists.
Automated replies. Where you enable automated replies, disclosure that the reply is automated is on by default, every automated conversation offers a handoff to a person on your team, and sending stays within each platform's messaging-window rules — free-form only inside the customer-care window, and approved templates outside it. You are responsible for having the consent each platform’s rules require before messaging someone.
Solstral's access to and use of information received from Meta's APIs adheres to the Meta Platform Terms and the Meta Developer Policies, including their restrictions on the use, sharing and retention of Platform Data.
Deleting Meta Platform Data
You can end the connection and remove the data at any time, by any of these routes:
- Disconnect the account in Solstral at Settings → Social accounts. We stop receiving messages and comments from that account immediately and send nothing further from it. You can also revoke our access directly from Instagram's apps and websites settings, Facebook's business integrations settings, or Meta Business Manager.
- Delete the conversations in your workspace — an admin can remove them at any time.
- Ask us to erase everything by emailing [email protected] from the address on the account, naming the connected account. We confirm and complete the erasure — including any stored access tokens — within 30 days.
When a workspace is terminated, its social conversations and tokens are deleted within 30 days, and backups age out on a rolling schedule of no more than 35 days. If you are a member of the public whose message to a business appears in that business's Solstral workspace, contact the business you messaged — it controls that data, and we will assist it with your request.
12. Artificial intelligence
Solstral includes optional AI features: an in-app assistant, a website chatbot, AI steps inside automations, and AI-assisted drafting. These are the only parts of the product that send data to a third-party model provider.
- What is sent, and when. Nothing is sent unless someone uses an AI feature. When they do, we send only the content that feature needs to respond — for example the records in view, the message being drafted, or the knowledge-base article being answered from.
- Who receives it. OpenAI, in the United States, named in our sub-processor list. There is one model provider, chosen and published by us — a workspace cannot connect a different one, because that would send your data to a company we have not disclosed to you.
- Training and retention. Customer Data is never used to train machine-learning models — not ours, and not the provider's. Content sent to the model provider is retained by them only transiently for abuse monitoring and deleted within 30 days; it is never added to a training set or used for any purpose of their own.
- Turning it off. An owner or admin can disable AI for the whole workspace in Settings → AI. This is enforced in the application, not merely a setting: with AI off, no Customer Data reaches a model provider by any route, including automations.
- Records of use. We log which AI feature ran, which model was used, on whose behalf and what it did. Prompt and response content is not stored unless a workspace explicitly opts in.
- Human oversight. AI features assist people; they do not make decisions about individuals on their own. Actions that send email, delete records or act in bulk require a person to confirm them.
13. Automated decision-making
Solstral does not make automated decisions that produce legal or similarly significant effects about individuals. Customers can configure automations that route, assign, tag or score records based on rules they define — those are the customer's decisions, made with the customer's rules, and the customer is the controller for them. If we introduce any automated decision-making of our own that significantly affects individuals, we will describe it here before it takes effect, as required by the Privacy Act from 10 December 2026.
14. Recipients of email sent through Solstral
If you received a marketing email sent through our platform, the sender controls your data. Every such email includes a one-click unsubscribe that takes effect immediately across the sender's lists. To escalate abuse, email [email protected] with the message headers.
15. Changes
We will post changes here and, for material changes, notify account holders by email at least 14 days in advance.
16. Contact us
Solstral is operated by Mount Bensley Pty Ltd (ACN 686 491 476, ABN 92 686 491 476), an Australian company registered in New South Wales, which also trades under the registered business name Adcrayons. Mount Bensley Pty Ltd is the entity responsible for personal information handled through the platform.
For any privacy question, to access or correct your personal information, or to make a privacy complaint, email [email protected]. We acknowledge complaints within 5 business days and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local supervisory authority if you are in the EEA or UK.