OZR Labs Pty Ltd ("OZR Labs", "we", "us", or "our") is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Notifiable Data Breaches scheme. This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information. By creating an account or using any part of the OZR Labs service (the "Service"), you consent to the practices described in this Policy.
01 / Introduction & Compliance
OZR Labs is an Australian proprietary company, ACN ### ### ###, with its registered office in Brisbane, Queensland. We provide a cloud-based engineering analysis platform for structural and geotechnical engineers.
This Policy is issued in compliance with, and is to be read alongside:
- The Privacy Act 1988 (Cth) (the "Privacy Act");
- The Australian Privacy Principles (APPs) contained in Schedule 1 of the Privacy Act;
- The Notifiable Data Breaches scheme under Part IIIC of the Privacy Act;
- The Telecommunications Act 1997 (Cth) (in relation to cookies and online tracking);
- The Spam Act 2003 (Cth) (in relation to marketing communications); and
- Any other applicable privacy or data-protection law.
Where this Policy is inconsistent with any applicable law, the law prevails. Capitalised terms not defined in this Policy have the meaning given to them in the Terms of Service.
02 / Information We Collect
We collect personal information directly from you, automatically through your use of the Service, and from third-party service providers. The categories of personal information we collect are:
2.1 Account & Identity Information
- Full name;
- Email address;
- Password (hashed using a one-way salted hash; we never store plaintext passwords);
- Organisation name and email domain (if you sign up with a work email);
- Professional credentials (e.g., RPEQ, RPEV, CPEng registration number) — only if you choose to provide these;
- Phone number — only if you choose to provide it for support purposes;
- Profile photograph — only if you choose to upload one.
2.2 Payment & Billing Information
- Billing name, address, and email (for tax invoices);
- Last four digits and brand of your payment card (the full card number, CVV, and expiry are never stored on our servers — they are tokenised by Stripe);
- Stripe customer ID and subscription ID;
- Transaction history.
2.3 Project & Engineering Data
- Site address and coordinates;
- Project parameters (structure type, dimensions, materials, loads);
- Engineering analyses you run, including inputs, outputs, and generated reports;
- Wind-region classification, terrain category, shielding multiplier, and topographic multiplier values for your project.
2.4 Usage & Telemetry Data (automatically collected)
- IP address;
- Browser type, version, and language;
- Operating system and device type;
- Pages viewed, features used, buttons clicked, and time spent on each page;
- Referring URL (the page that linked you to us);
- Session duration and authentication events.
2.5 Support & Communications
- Records of communications with our support team, including emails and chat messages;
- Feedback, survey responses, and feature requests you submit.
We do not knowingly collect sensitive information (as defined in the Privacy Act), such as information about your race, ethnicity, political opinions, religious beliefs, sexual orientation, or health. Please do not upload such information to the Service.
03 / How We Use Your Information
We collect, hold, use, and disclose your personal information for the following primary purposes ("Primary Purposes"):
- To provide, operate, maintain, and improve the Service;
- To process payments and manage your subscription;
- To verify your identity and authenticate you when you sign in (including via multi-factor authentication);
- To generate engineering analyses, calculation reports, and other outputs that you request;
- To provide customer support and respond to your enquiries;
- To send you service-related communications (e.g., account verification emails, password resets, billing receipts, critical security alerts, and changes to these Terms or this Policy);
- To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity;
- To comply with our legal obligations and assist law enforcement and regulatory authorities;
- To enforce our Terms of Service and other agreements;
- To de-identify, aggregate, and analyse usage trends so we can improve the Service (such de-identified data cannot reasonably be re-identified).
We may also use your personal information for the following "Secondary Purposes" (with your consent or where otherwise permitted by the Privacy Act):
- To send you marketing communications about new features, special offers, and industry insights (you may opt out at any time — see Section 9);
- To invite you to participate in user research, surveys, or beta programs;
- To publish aggregated, de-identified case studies or testimonials (only with your express consent).
If we use your personal information for a purpose other than a Primary or Secondary Purpose set out above, we will obtain your consent (or rely on another exception in the Privacy Act) before doing so.
04 / Data Storage & Security
Hosting region. Your data is primarily stored in
data centres located in Sydney, Australia (AWS
ap-southeast-2 region). Some limited data (for example,
cached map tiles) may be served from edge locations in other regions to
improve performance.
4.1 Security Measures
We implement industry-standard technical and organisational measures to protect your personal information, including:
- Encryption in transit: TLS 1.2+ for all client-server and service-to-service communications;
- Encryption at rest: AES-256 for all databases and object-storage volumes that hold personal information;
- Password hashing: bcrypt with a per-user salt;
- Access control: role-based access control (RBAC) with least-privilege; multi-factor authentication for all administrative access;
- Network segregation: separate virtual private clouds (VPCs) for production, staging, and development;
- Logging and monitoring: centralised logging with 90-day retention, real-time alerting on suspicious activity, and quarterly security reviews;
- Vulnerability management: regular penetration testing, dependency scanning, and patch management;
- Personnel security: background checks for staff with access to personal information, confidentiality obligations in employment contracts, and annual privacy and security training.
4.2 Data Retention
We retain your personal information for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are:
| Data category | Retention period |
|---|---|
| Account & identity data | While your account is active; deleted within 30 days of account closure |
| Payment & billing records | 7 years (Australian Taxation Office requirement) |
| Engineering project data | While your account is active; 30-day grace period after closure, then deleted |
| Generated reports (PDFs) | While your account is active; 30-day grace period after closure, then deleted |
| Server logs (containing IP addresses) | 90 days |
| Support correspondence | 3 years from last contact for quality and training purposes |
| Backups | Encrypted; retained 30 days, then rotated out |
4.3 Your Data, Your Control
You can export your engineering projects at any time in standard formats (PDF, JSON, CSV). Upon account closure, you have a thirty (30) day grace period to download your data, after which it will be permanently deleted in accordance with our secure-deletion procedures.
05 / Cookies & Tracking
We use cookies and similar tracking technologies to provide and improve the Service. The categories of cookies we use are:
- Strictly necessary cookies — required for the Service to function (e.g., session cookies, CSRF tokens, MFA challenges). These cannot be disabled.
- Functional cookies — remember your preferences (e.g., theme, units, language). The Service will function without them but may be less convenient.
- Analytics cookies — collect aggregated usage statistics (e.g., Google Analytics, with IP anonymisation enabled). The Service will function without them.
You can control cookies through your browser settings. Note that blocking strictly necessary cookies will prevent the Service from functioning.
We do not use cookies for advertising or cross-site tracking, and we do not sell your personal information to third parties for advertising or any other purpose.
06 / Third-Party Services
We use a number of third-party service providers to operate the Service. Where these providers may receive your personal information, we enter into a written agreement with them that requires them to handle your personal information in accordance with the APPs and our instructions. The current sub-processors are:
| Sub-processor | Purpose | Data shared | Hosting region |
|---|---|---|---|
| Stripe Payments Australia Pty Ltd | Payment processing & subscription management | Billing name, address, email, last-4 of card, card brand, card expiry, transaction history | USA / Australia |
| Amazon Web Services (AWS) | Cloud hosting, object storage, database | All account, project, and report data | Sydney (ap-southeast-2) |
| Postmark (or alternative transactional email provider) | Transactional email (account verification, password reset, billing receipts) | Email address, email content | USA |
| Sentry (error monitoring) | Application error monitoring & crash reporting | IP address, browser metadata, error stack traces (no personal information in stack traces) | USA |
| Google Analytics (with IP anonymisation) | Aggregated, anonymised usage analytics | IP address (anonymised), browser metadata, page views | USA / Australia |
| Mapbox / Google Maps / OpenStreetMap | Map tiles, geocoding | IP address, geocoding queries | USA / EU |
| OpenTopoData | SRTM elevation data (optional, manual) | Lat / lng coordinates | EU |
| National Computational Infrastructure (NCI) — DEA Land Cover | Land-cover raster (Australia only) | Lat / lng coordinates (no personal data) | Australia |
We update this list whenever we add or remove a sub-processor. The current list is always available on this page.
07 / International Data Transfers
OZR Labs is headquartered in Australia. Your personal information is
primarily stored and processed in Australia (Sydney,
ap-southeast-2). Where we engage sub-processors that store or
process personal information outside Australia (for example, Stripe, AWS
global edge, or Sentry), we take reasonable steps to ensure that the
recipient is required to protect your personal information in a manner
that is, in substance, comparable to the protection afforded under the
APPs.
Where your personal information is disclosed to an overseas recipient, OZR Labs will:
- Take reasonable steps to ensure the recipient will handle your personal information in accordance with the APPs (e.g., by incorporating standard contractual clauses into the sub-processor agreement);
- Comply with APP 8 (cross-border disclosure) by obtaining your consent, or by relying on one of the other exceptions in the Privacy Act (e.g., where the recipient is subject to a law or binding scheme that, in substance, protects the information in a manner comparable to the APPs);
- Make the relevant sub-processor agreements available to you on request.
You acknowledge that by using the Service, you consent to the disclosure of your personal information to overseas recipients as set out in this Section, to the extent such consent is required by APP 8.2.
08 / Your Rights (Australian Privacy Principles)
Subject to the APPs and other applicable law, you have the right to:
- Access your personal information (APP 12) — you can request a copy of the personal information we hold about you;
- Correct inaccurate, out-of-date, or incomplete personal information (APP 13) — most fields can be edited directly via the Account Profile page;
- Delete your personal information, subject to certain legal exceptions (for example, we may need to retain payment records for 7 years for tax purposes) (APP 11.1);
- Opt out of marketing communications (APP 7) — every marketing email contains an "unsubscribe" link;
- Request de-identified data — we can de-identify your project data on request, subject to APP 6 (use or disclosure of de-identified information);
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs (see Section 13).
To exercise any of these rights, contact our Privacy Officer at privacy@ozrlabs.io. We will respond to your request within thirty (30) days. If we need more time, we will notify you in writing of the extension and the reasons for it.
We may refuse to act on a request to the extent permitted by the APPs (for example, where the request is frivolous or vexatious, would unreasonably interfere with the privacy of others, or where we are required or authorised by law to refuse). If we refuse your request, we will give you written reasons and inform you of the available complaint mechanisms.
09 / Marketing Communications
We may send you marketing communications about new features, special offers, industry insights, events, and other OZR Labs news. We will only send you marketing communications if you have opted in (or if the Spam Act 2003 (Cth) and APP 7 permit us to do so without express consent in the limited circumstances allowed by those laws).
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Updating your communication preferences in the Account Profile page; or
- Contacting us at privacy@ozrlabs.io.
Opting out of marketing communications will not affect transactional or service-related communications (e.g., account verification, password reset, billing receipts, security alerts), which we will continue to send as needed to provide the Service.
10 / Notifiable Data Breaches
OZR Labs complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we reasonably believe that there has been an eligible data breach involving your personal information, we will:
- Promptly assess the breach to determine whether it is an "eligible data breach" within the meaning of the NDB scheme;
- If the breach is likely to result in serious harm to any affected individual, prepare a statement that complies with the requirements of the Privacy Act and submit it to the Office of the Australian Information Commissioner (OAIC) as soon as practicable;
- Notify each affected individual as soon as practicable if the breach is an eligible data breach, providing a statement that includes the information required by the Privacy Act (e.g., the identity and contact details of OZR Labs, a description of the breach, the kinds of information concerned, and recommended steps).
Where the breach is an eligible data breach, we will notify affected individuals and the OAIC as soon as practicable, and in any case within 72 hours of becoming aware of the breach (subject to the limited exceptions in the NDB scheme).
For the avoidance of doubt, OZR Labs' notification obligations under this Section are in addition to, and do not limit, any other rights or remedies you may have under the Privacy Act or any other applicable law.
11 / Children's Privacy
The Service is not directed to, and may not be used by, individuals under the age of 18. We do not knowingly collect personal information from individuals under 18. If you are under 18, do not use the Service and do not provide any personal information to us.
If we become aware that we have collected personal information from an individual under 18, we will take reasonable steps to delete that information as soon as possible, in accordance with the APPs and our internal data-deletion procedures.
If you believe we have collected personal information from an individual under 18, please contact us at privacy@ozrlabs.io and we will take appropriate steps to delete the information.
12 / Changes to this Policy
We may modify this Policy at any time. If we make material changes, we will provide at least thirty (30) days' notice before the changes take effect by:
- Posting the updated Policy on the Service;
- Sending an email to the address associated with your account; and/or
- Displaying an in-product notification.
Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must stop using the Service and may close your account in accordance with our Terms of Service.
Non-material changes (for example, clarifications, typographical corrections, or updates to contact information) may take effect immediately upon posting.
If the changes affect the way we handle your personal information in a manner that requires your consent under the Privacy Act, we will obtain your consent (or rely on another applicable exception) before the changes take effect.
13 / Contact & Complaints
If you have any questions about this Policy, would like to exercise your rights under the APPs, or wish to make a complaint, please contact our Privacy Officer:
- Privacy Officer, OZR Labs Pty Ltd
- Email: privacy@ozrlabs.io
- Postal: PO Box ###, Brisbane QLD ####, Australia
We take all complaints seriously and will investigate each complaint in a fair, transparent, and timely manner. We will acknowledge your complaint within seven (7) business days and provide a full response within thirty (30) days. If we need more time, we will notify you in writing.
If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
- Office of the Australian Information Commissioner (OAIC)
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Online complaint form: www.oaic.gov.au/privacy/privacy-complaints
The OAIC is the independent Australian Government agency that investigates privacy complaints under the Privacy Act.
14 / Last Updated
This Privacy Policy was last updated on 09 July 2026 (version v1.0-2026-07-09). Material changes will be notified in accordance with Section 12.