Privacy policy

Operational data deserves clear handling rules.

Effective 1 August 2026. This policy explains how Oakhampton handles personal information associated with this website and digital twin services.

1. Scope and contact

Oakhampton Capital Pty Ltd, ABN 58 684 868 915 (Oakhampton, we, us), manages personal information in connection with the Operations Twin website, enquiries, customer accounts and paid services. Our address is Level 38, 71 Eagle Street, Brisbane QLD 4000. Privacy enquiries: ops@oakhampton.ai.

We aim to handle personal information consistently with the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply. Project-specific data-handling terms may add controls for confidential or regulated information.

2. Information we collect

Depending on how you use the service, we may collect:

  • business contact details such as name, role, company, email and phone;
  • account and organisation information used for authentication and access control;
  • project enquiries, correspondence, support requests and scope information;
  • files authorised for a project, such as plans, photos, CAD, BIM, GIS, operational exports and related metadata;
  • service, security and audit information such as timestamps, actions, IP address, browser type, errors and access events;
  • billing and transaction references, where a paid service is used. Payment-card data is handled by Stripe and is not stored by Oakhampton; we retain transaction references, product, amount and payment status needed to administer the order.

Please avoid including personal or sensitive information inside operational data unless it is necessary for the agreed purpose and an appropriate handling process has been confirmed.

3. Why we collect and use information

We use information to respond to enquiries, scope and deliver services, authenticate users, keep organisations separated, build and calibrate authorised twins, produce deliverables, invoice and administer engagements, secure and troubleshoot the platform, keep audit records, comply with law and improve the service using de-identified or aggregated learnings where appropriate.

We do not add an enquiry contact to general marketing without a separate permission or another lawful basis. Transactional service messages are handled separately from marketing consent.

4. Storage, service providers and overseas disclosure

Authorised customer geometry can be stored in an Australian-region object-storage lane. Application, communication, identity, monitoring and development providers may process limited information in Australia, Singapore, the United States or another location identified in the relevant project scope. We take reasonable steps to use providers and contractual controls appropriate to the information and service.

We may disclose information to personnel and contractors who need it to deliver or secure the service, professional advisers, payment and technology providers, regulators or law-enforcement bodies where required, and another party to a corporate transaction subject to appropriate confidentiality and privacy controls. We do not sell personal information.

5. Retention and deletion

We keep personal information and project records only for as long as reasonably required for the service, legal obligations, security, disputes and agreed audit needs. Files submitted through the public conversion intake are scheduled for deletion after 90 days unless they become part of an agreed engagement or must be retained for a lawful transaction, security or dispute purpose. In the authenticated customer geometry workflow, a user-requested deletion hides the source immediately and schedules the underlying object for purge after 30 days. Other project retention periods are stated in the scope or can be requested from us.

Backups and security records may persist for a limited period after deletion before being overwritten. De-identified information that can no longer reasonably identify a person may be retained.

6. Security

We use access controls, organisation separation, encrypted transport, controlled storage, audit events, rate limits and operational monitoring appropriate to the service. No method is completely secure. If you believe information has been exposed or access is incorrect, contact us promptly and do not continue uploading data.

7. Cookies, concierge and website measurement

The public marketing pages do not use advertising cookies. We use privacy-preserving first-party event measurement to understand page use, product selection, checkout progress and reliability. These records use a short session identifier and a one-way network hash; they do not record form contents, concierge text, uploaded files or payment-card data. Authentication and customer features use necessary signed session cookies.

The marketing concierge provides grounded product guidance using predefined Oakhampton product, pricing, input and privacy information. Its typed question is processed in the browser and is not stored as telemetry. Use the secure intake or authenticated portal for project-specific or confidential information.

8. Access, correction and complaints

You may ask to access or correct personal information we hold about you, subject to lawful exceptions. You may also ask a privacy question or make a complaint by emailing ops@oakhampton.ai. Please describe the relevant interaction and information. We will verify identity where needed, investigate and respond within a reasonable period.

If you are not satisfied with our response and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

9. Updates

We update this policy when information handling changes. The effective date appears above. Material changes affecting an active paid project will be communicated through an appropriate project channel.