Privacy Policy
How Terrabit Pty Ltd collects, uses and protects personal information.
Last updated: 2025-08-24 · Version: 1.0
1.0Who we are (Controller)
Terrabit Pty Ltd (trading as “Terrabit”) operates satellite-imagery services and related software. Terrabit is the controller for the processing described in this Policy.
Identity
Terrabit Pty Ltd (ABN: 56 689 756 830). Trading name: Terrabit.Privacy contact
[email protected] · 1800 183 772
2.0Scope & applicability
This Policy applies to personal information we handle as an Australian APP entity under the Privacy Act 1988 (Cth). It also describes additional information for individuals in the EEA/UK under the GDPR/UK GDPR.
3.0Personal data we process
Categories of data
Account & identity
Name, email, company, role, authentication details (e.g., password hash or SSO tokens).Order & billing
Purchase records, invoices, payment status, tax/billing details (card data handled by our payment processor).Portal content & files
Content you upload (e.g., tasking instructions, AOIs/GeoJSON, notes, imagery). Unless a DPA states otherwise, we act as controller for portal data provided to us.Usage, device & logs
IP address, device/user-agent, pages viewed, session timestamps, referrers, error logs.Cookies/analytics
Identifiers and events from Google Analytics 4 where consented. See the Cookie Policy.Support & communications
Messages sent to us and metadata necessary to route/answer them.Sensitive information
We generally do not seek to collect sensitive information. If you choose to provide it, we will handle it as required by law and this Policy.
4.0Where we collect data from
We collect personal information directly from you (e.g., forms, console, API), automatically through your use of our Services, and from third parties such as identity providers, payment processors, and service partners where lawful.
5.0Purposes & legal bases
Provide and operate the Services
Account creation, authentication, portal operation, fulfilling orders, delivering imagery. Legal basis: contract performance; legitimate interests for continuity.Customer care & operations
Responding to requests, troubleshooting, incident notifications. Legal basis: contract; legitimate interests.Security & abuse prevention
Access controls, audit logs, incident detection and response, rate limiting. Legal basis: legitimate interests; legal obligation where applicable.Billing & compliance
Invoicing, tax records, fraud checks. Legal basis: contract; legal obligation.Analytics & product improvement
GA4 event metrics where consented; measurement of features. Legal basis: consent where required; legitimate interests for strictly necessary, non-identifying telemetry.Marketing communications (optional)
News and updates if you opt in. Legal basis: consent; you may withdraw at any time.Recruitment
Handling applications. Legal basis: steps prior to a contract; legitimate interests.
Where we rely on legitimate interests, we assess necessity and balance against your rights and expectations.
7.0Security measures
We use TLS encryption in transit, database backups, role-based access controls, least-privilege administration, logging, and vendor due diligence. We regularly review and improve these measures as our Services evolve.
8.0Retention
Contract-specific retention
Where an MSA or Order specifies retention for project data, that prevails.Portal uploads/content
Retained as needed to provide the Service or as specified in contract; deleted or anonymised within 90 days after termination unless a longer legal retention applies.Account data
For the life of the account and up to 24 months after closure.Order & billing records
Retained for 7 years for tax/audit purposes.Web logs
Retained for 30–90 days for security/operations.Analytics events (GA4)
Retention set to a maximum of 14 months where enabled/consented.Support tickets
Retained for 24 months.
9.0Your rights (APPs; GDPR/UK GDPR where applicable)
Under the Australian Privacy Principles you may request access to and correction of your personal information. We will verify your identity and respond within applicable timelines (typically 30 days). If you are in the EEA/UK, you may also have rights to portability, restriction and objection, and to lodge a complaint with your data protection authority.
You may request anonymity or use a pseudonym for certain interactions where lawful and practical; however, some Services require identification to function.
10.0Direct marketing & Spam Act
We send electronic marketing messages only with consent or as otherwise permitted by the Spam Act 2003 (Cth). Messages include clear sender information and an unsubscribe facility. You can opt out at any time.
12.0Children
Our Services are intended for business users. We do not knowingly collect personal information from children.
13.0Changes
We may update this Policy to reflect operational or legal changes. We will post the updated version with a new “Last updated” date and, where appropriate, provide notice by email or in-app.
14.0Contact & complaints
For privacy matters contact [email protected] or call 1800 183 772. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.