Privacy Policy
How Terrabit Pty Ltd collects, uses and protects personal information.
Last updated: 2025-08-24 · Version: 1.0
1.0Who we are (Controller)
Terrabit Pty Ltd (trading as “Terrabit”) operates satellite-imagery services and related software. Terrabit is the controller for the processing described in this Policy.
- IdentityTerrabit Pty Ltd (ABN: 56 689 756 830). Trading name: Terrabit.
- Privacy contact[email protected] · 1800 183 772
2.0Scope & applicability
This Policy applies to personal information we handle as an Australian APP entity under the Privacy Act 1988 (Cth). It also describes additional information for individuals in the EEA/UK under the GDPR/UK GDPR.
3.0Personal data we process
Categories of data
- Account & identityName, email, company, role, authentication details (e.g., password hash or SSO tokens).
- Order & billingPurchase records, invoices, payment status, tax/billing details (card data handled by our payment processor).
- Portal content & filesContent you upload (e.g., tasking instructions, AOIs/GeoJSON, notes, imagery). Unless a DPA states otherwise, we act as controller for portal data provided to us.
- Usage, device & logsIP address, device/user-agent, pages viewed, session timestamps, referrers, error logs.
- Cookies/analyticsIdentifiers and events from Google Analytics 4 where consented. See the Cookie Policy.
- Support & communicationsMessages sent to us and metadata necessary to route/answer them.
- Sensitive informationWe generally do not seek to collect sensitive information. If you choose to provide it, we will handle it as required by law and this Policy.
4.0Where we collect data from
We collect personal information directly from you (e.g., forms, console, API), automatically through your use of our Services, and from third parties such as identity providers, payment processors, and service partners where lawful.
5.0Purposes & legal bases
- Provide and operate the ServicesAccount creation, authentication, portal operation, fulfilling orders, delivering imagery. Legal basis: contract performance; legitimate interests for continuity.
- Customer care & operationsResponding to requests, troubleshooting, incident notifications. Legal basis: contract; legitimate interests.
- Security & abuse preventionAccess controls, audit logs, incident detection and response, rate limiting. Legal basis: legitimate interests; legal obligation where applicable.
- Billing & complianceInvoicing, tax records, fraud checks. Legal basis: contract; legal obligation.
- Analytics & product improvementGA4 event metrics where consented; measurement of features. Legal basis: consent where required; legitimate interests for strictly necessary, non-identifying telemetry.
- Marketing communications (optional)News and updates if you opt in. Legal basis: consent; you may withdraw at any time.
- RecruitmentHandling applications. Legal basis: steps prior to a contract; legitimate interests.
Where we rely on legitimate interests, we assess necessity and balance against your rights and expectations.
7.0Security measures
We use TLS encryption in transit, database backups, role-based access controls, least-privilege administration, logging, and vendor due diligence. We regularly review and improve these measures as our Services evolve.
8.0Retention
- Contract-specific retentionWhere an MSA or Order specifies retention for project data, that prevails.
- Portal uploads/contentRetained as needed to provide the Service or as specified in contract; deleted or anonymised within 90 days after termination unless a longer legal retention applies.
- Account dataFor the life of the account and up to 24 months after closure.
- Order & billing recordsRetained for 7 years for tax/audit purposes.
- Web logsRetained for 30–90 days for security/operations.
- Analytics events (GA4)Retention set to a maximum of 14 months where enabled/consented.
- Support ticketsRetained for 24 months.
9.0Your rights (APPs; GDPR/UK GDPR where applicable)
Under the Australian Privacy Principles you may request access to and correction of your personal information. We will verify your identity and respond within applicable timelines (typically 30 days). If you are in the EEA/UK, you may also have rights to portability, restriction and objection, and to lodge a complaint with your data protection authority.
You may request anonymity or use a pseudonym for certain interactions where lawful and practical; however, some Services require identification to function.
10.0Direct marketing & Spam Act
We send electronic marketing messages only with consent or as otherwise permitted by the Spam Act 2003 (Cth). Messages include clear sender information and an unsubscribe facility. You can opt out at any time.
12.0Children
Our Services are intended for business users. We do not knowingly collect personal information from children.
13.0Changes
We may update this Policy to reflect operational or legal changes. We will post the updated version with a new “Last updated” date and, where appropriate, provide notice by email or in-app.
14.0Contact & complaints
For privacy matters contact [email protected] or call 1800 183 772. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
