1. About this policy
Survetify is an Australian-based business-to-business software service operated from Melbourne, Victoria. In this policy, Survetify, we, us and our refer to the Australian operator identified in the applicable customer Order Form, proposal or invoice. Survetify is the name of the service and mobile application.
This policy applies to survetify.com, app.survetify.com, Survetify's native iOS and Android applications, demonstrations, support communications and related services. It is designed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. We aim to follow the same core practices even where a statutory exemption may be available.
2. Information we collect
Depending on how you use Survetify, we may collect:
- Identity and business contact information: name, work email, phone number, role, job title, organisation and account identifiers.
- Account and access information: authentication identifiers, organisation memberships, roles, permissions, invitations, session information and security events. We do not receive your plain-text password.
- Survey operations information: projects, requests, schedules, tasks, controls, coordinates, datum and grid references, calibrations, equipment, field records, issues, as-builts and audit history.
- Address and route-planning information: project and office addresses, a surveyor's nominated travel-start or home address where their organisation chooses to record it, geocoded coordinates, estimated route distance and duration, and estimated travel savings.
- Work-time information: planned job windows, actual field, travel and office start and finish times, timesheet status and related productivity summaries.
- Files and evidence: drawings, PDFs, CAD and field files, JXL/JobXML information, mark-ups, photographs, signatures, Setout sign-offs and related metadata.
- AI information: prompts, project context supplied to an AI feature, extracted metadata, generated responses, risk findings, actions, feedback and usage amounts.
- Technical information: IP address, browser or device type, operating system, app version, diagnostic events, push notification token and basic request logs.
- Commercial information: plan, seats, storage and AI allowance, invoices, payment status and billing contacts. Card details are handled by the relevant payment provider if payments are introduced; Survetify does not currently ask users to enter card details in the mobile application.
- Communications: demo requests, support enquiries, privacy requests and other correspondence.
Standard route planning uses addresses deliberately entered by authorised users; it does not continuously track a device or collect live GPS location. We do not intentionally collect health information, government identifiers or biometric templates. Customers should not upload unnecessary sensitive information and should tell personnel how nominated home/travel-start addresses and work-time records will be used.
3. How we collect information
We collect information directly from you when you sign in, complete a form, upload a file, sign a field record, contact us or use a feature. We also receive information from:
- your employer, client or organisation administrator when they invite you or manage project access;
- devices and browsers through normal service and security logs;
- connected service providers used to authenticate, host, process, notify or support the service; and
- project records created by authorised users in the same customer organisation.
If someone supplies us with another person's information, they must have authority to do so and must make any required privacy notice available to that person.
4. How we use information
We use information where reasonably necessary to:
- provide, administer and secure Survetify;
- authenticate users and enforce organisation, project and role permissions;
- store and link survey records, drawings, requests, schedules and field evidence;
- autocomplete and verify user-entered addresses, estimate routes, recommend practical job assignments and report travel efficiency;
- create, display and approve operational timesheets and capacity summaries for authorised personnel;
- perform requested AI extraction, comparison, briefing and risk-analysis functions;
- send operational, account, security and service notifications;
- provide support, demonstrations and customer administration;
- measure service usage, manage entitlements and invoice customer organisations;
- detect misuse, investigate incidents and maintain audit records;
- improve reliability and usability using feedback and aggregated or de-identified information; and
- comply with law, resolve disputes and enforce agreements.
Route duration and savings are estimates affected by traffic, provider coverage and planning assumptions. They are kept distinguishable from actual user-submitted work and travel time. We do not sell personal information, run third-party advertising in Survetify or use personal information for cross-context behavioural advertising.
5. AI processing
When an authorised user invokes an AI feature, Survetify may send the minimum relevant prompt, file content, extracted text or project context to an AI service provider to produce the requested result. AI outputs and related evidence may be stored in the customer's workspace for review, audit and follow-up.
- We do not intentionally use customer project content to train a public or general-purpose AI model unless the customer expressly agrees in writing.
- We configure our providers and service arrangements to process customer data for delivering the requested service, subject to their security and data-processing terms.
- AI output can be incomplete or wrong. It is decision support, not a cadastral certification, engineering approval, registered survey, safety approval or substitute for competent professional review.
Customers control whether their authorised users may access AI features through plan and role settings.
6. When we disclose information
We may disclose information only as reasonably required to:
- the relevant customer organisation and its authorised users;
- infrastructure and service providers, including Supabase for authentication/database services, AI model providers such as OpenAI when an AI feature is used, Google Maps Platform for user-requested address autocomplete, geocoding and route estimates, Expo and notification providers for mobile delivery, hosting/email providers, and Apple or Google for app distribution and platform services;
- professional advisers, insurers, auditors or prospective transaction advisers subject to confidentiality duties;
- regulators, courts or law enforcement where legally required or reasonably necessary to protect rights, safety or service integrity; and
- a successor operator in a business restructure, financing or sale, subject to appropriate confidentiality and notice where required.
Only the address or coordinates needed for the requested lookup or route calculation are sent to the mapping provider. Service providers may process information only for contracted purposes and are expected to apply protections appropriate to the information and service.
7. Overseas processing
Survetify is operated from Australia, but cloud, AI, mobile and support providers may process or store information in Australia and overseas. Likely locations include the United States and locations selected for, or used by, the customer's Supabase/cloud project. Resilient provider networks may involve additional jurisdictions.
Where Australian Privacy Principle 8 applies, we take reasonable steps appropriate to the circumstances before disclosing personal information to an overseas recipient. Customers should contact us before uploading information subject to a contractual data-residency restriction.
8. Security
Survetify uses controls designed for a multi-tenant business platform, including encrypted network transport, authenticated private file access, role and project permissions, database row-level access controls, server-side secrets, audit records and security logging. Access is limited to people and providers who require it for legitimate service purposes.
No online service can guarantee absolute security. Customers must protect credentials, review memberships, remove former users promptly and avoid sharing confidential files outside authorised workspaces. Suspected compromise should be reported immediately to security@survetify.com.
If a data incident occurs, we will contain, assess, notify where required and review it. Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible breaches and notify affected individuals and the Office of the Australian Information Commissioner when legally required.
9. Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described above, the customer agreement and applicable law. Retention depends on the record:
| Record | Typical approach |
|---|---|
| Active workspace and project data | For the customer relationship and the export/deletion period stated in the Order Form or termination notice. |
| Account and contact data | While access is active, then deleted or de-identified after a verified request unless limited retention is required. |
| Backups | Removed through normal backup rotation; isolated copies may remain temporarily and are not restored except for continuity or security needs. |
| Audit, sign-off and security records | Retained where reasonably required to preserve project accountability, prevent fraud, establish legal claims or meet customer/legal obligations. |
| Financial and contractual records | Retained for applicable Australian recordkeeping and dispute periods. |
| Demo and support enquiries | For follow-up and service history, then deleted or de-identified when no longer reasonably required. |
When information is no longer required, we take reasonable steps to delete or de-identify it. An individual's deletion request does not automatically require deletion of every organisation-owned project record. We may de-identify or reassign records needed for safety, audit, contractual or legal purposes and will explain material retention to the requester.
10. Access, correction and deletion rights
You may ask to access or correct personal information we hold about you, request deletion, withdraw a consent that we rely on, or object to direct marketing. We may need to verify your identity and authority before acting.
- Authenticated mobile users can open More → Privacy & Account and submit a deletion request.
- Anyone can use our public Account & Data Deletion page.
- Access, correction and privacy enquiries can be sent to privacy@survetify.com.
Project information is often controlled by a customer organisation. We may coordinate with that organisation when responding, while still handling your personal information and request fairly. We may refuse or limit a request where permitted by law and will give reasons where required.
11. Cookies and local storage
The public landing website does not currently use third-party advertising trackers. It may use local browser storage to cache non-personal plan information and improve loading. The authenticated application uses session storage, authentication tokens and similar essential technologies to keep users signed in, secure access and deliver requested features.
If we introduce non-essential analytics or marketing cookies, we will update this policy and provide any notice or consent control required by applicable law.
12. Privacy complaints
Email privacy@survetify.com with your name, account email, organisation and enough detail for us to investigate. Do not email passwords, authentication tokens or confidential project files.
We will acknowledge and investigate complaints within a reasonable period and aim to provide a substantive response within 30 days after we have the information required to investigate. If you are dissatisfied and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner.
13. Contact and changes
We may update this policy when our service, providers or legal obligations change. The current version and effective date will remain published here. We will give reasonable notice of a material change where appropriate.