Skip to main content

Legal

Privacy Policy

Nebula Platform Pty Ltd. Published 27 July 2026. Effective 31 July 2026. Weather-provider disclosure updated 1 August 2026.

1. Introduction

This Privacy Policy (“Policy”) describes how Nebula Platform Pty Ltd (ACN 667 540 025) (“Nebula”, “we”, “us”, or “our”) collects, uses, discloses, stores, and protects personal information when you access or use the Nebula platform, website, APIs, and all related services (collectively, the “Platform”).

This Policy should be read together with our Terms of Service. By using the Platform, you consent to the collection and use of your information as described in this Policy. If you do not agree, you must not use the Platform.

2. Information We Collect

We collect the following categories of information:

2.1. Information you provide

  • Account registration details: name, email address, password, and organisation name;
  • Profile information: job title, contact details, and organisation details;
  • User Content: agreements, scopes, briefs, grants, specifications, engagement communications, formal notices, evidence and any other documents or data you upload to the Platform;
  • Billing information, where the billing path is enabled: customer email where supplied or collected, organisation identifier, selected product or price, checkout intent and provider-issued subscription and payment identifiers. Payer name and payment-card details are entered on the payment provider’s hosted surface rather than into Nebula;
  • Appointment information: if you use the Business or Enterprise booking action, the attendee name, email address and selected appointment time you enter on Google’s hosted appointment page;
  • Communications: messages you send to us, including support requests and feedback; and
  • Optional dashboard location preference: a city saved in your browser for the weather display.

2.2. Information collected automatically

  • Access information: route, request method, authentication decision, user agent and a salted hash of the client IP address where the shared access-log path succeeds;
  • Usage and activity information recorded by defined Platform paths, including selected actions, events and timestamps;
  • Browser timezone used to resolve a coarse city-centre location inside Nebula for the dashboard weather display when no saved city is available;
  • Public lead attribution: a contact, white-paper or founding submission can include the source, medium, campaign, term and content UTM fields present on that form page, the first landing path carried through a supported internal link, and an HTTP or HTTPS referrer reduced to its origin and path. This first-party lead attribution is collected with the form submission independently of your optional analytics choice;
  • On the public website after analytics consent, page view information, ordinary browser request metadata and the limited, non-free-text funnel values described in Section 9. On static marketing pages, the page URL our manual call sends can retain only the source, medium, campaign, term and content UTM fields. On record-specific pages the page path, page URL and internal referrer fields our page-view call sends are all reduced to a route class before they leave your browser; and
  • Cookies and similar technologies: as described in Section 9 below.

2.3. Information derived from your use

  • AI-derived engagement data: source-grounded interpretations of requirements, responsibilities, milestones, deliverables, commercial positions, deadlines, relationships and risks derived from your User Content; and
  • Reputation data: eligible attributable engagement events, delivery and response information, evidence and verification coverage, and dispute or review history.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • to provide, operate, and maintain the Platform and its features;
  • to process User Content using artificial intelligence and propose source-grounded engagement information;
  • to support engagement delivery through plans, deadlines, risks, evidence, changes, decisions and controlled workflows;
  • to calculate and display contextual reputation information from eligible attributable engagement events;
  • to create and report available tamper-evident proof records for eligible events;
  • to display local weather on the authenticated dashboard;
  • where billing is enabled, to initiate provider-hosted checkout and manage subscription records;
  • to arrange a Business or Enterprise introduction appointment that you request;
  • to send you transactional notifications about engagement activity, deadlines, decisions, recorded actions and account events;
  • to respond to your enquiries, support requests, and feedback;
  • to analyse defined activity and operational records for service improvement;
  • after consent, to understand public website use and selected lead and founding conversion steps and, where an analytics tag is available, selected signup steps;
  • to detect, investigate, and prevent fraudulent, unauthorised, or illegal activity; and
  • to comply with applicable legal obligations.

4. Artificial Intelligence and Your Data

4.1. When you upload User Content, an AI provider available through Nebula’s configured model boundary may process it to propose structured engagement information, including requirements, responsibilities, milestones, commercial positions, deadlines, relationships and identified risks. The results are stored within your account and are accessible only to authorised users in the relevant engagement workspace.

4.2. We use your uploaded documents, their contents and private derived information only to provide the Platform services within your account and authorised workspaces. We do not use that material to train, fine-tune or improve AI models, or to create cross-customer patterns. An organisation may separately make an explicit contribution under terms that define its scope and permission.

4.3. AI output is treated as a proposed interpretation. An authorised user may review it and correct a position within the scope of that user’s access and authority. A correction remains attributable to the participant who supplied it and does not overwrite another participant’s position or make a disputed matter agreed.

4.4. PII redaction. By default, configured prompt and extracted-text fields sent through the AI boundary are pattern-redacted for Australian phone numbers, email addresses, tax file numbers, Medicare numbers and driver licence numbers, and the redacted tokens are restored inside your account. Filenames and native PDF binaries are not guaranteed to be redacted. The control can be disabled by deployment configuration, so the active setting must be confirmed for an enterprise deployment. ABNs and ACNs remain because they are public business registry identifiers used to resolve organisations and roles within an engagement.

4.5. Processing architecture. Source configuration contains a syd1 instruction for Vercel Functions. That instruction does not establish the region serving a current request. Operational records use managed Neon Postgres and documents use Cloudflare R2 object storage. Document intelligence uses a code-available provider and the session-bound model selected for the reading path. Provider processing may occur outside Australia. Exact locations, including whether processing occurs in the United States, require confirmation from the applicable provider terms and deployment settings.

4.6. Automated decision-making

Nebula’s reading pipeline uses personal information in User Content and related engagement records, including names, contact details, organisation roles and activity attributed to named users or parties. It reads that information with the relevant requirements, commercial positions, dates, evidence and participant positions.

The Platform may make or substantially support decisions about deadlines, risk, enforcement actions and reputation events involving named parties. AI systems propose the structured interpretation used by those features. AI output does not by itself establish that a disputed proposition is true, grant authority, determine fault or cause a material effect.

Approved Platform workflows may send reminders or apply configured state transitions when recorded conditions are met. A shared or material effect is processed through the server-owned control and recorded authority requirements applicable to that effect. AI output can be reviewed before operational use, and relevant disputes, reviews and appeal outcomes remain attached to the affected record.

5. Blockchain Records

5.1. Where the eligible proof paths are enabled, the Platform can publish a cryptographic hash rather than the source document to Polygon and send a signed canonical event payload to the Nebulad gateway. The canonical preimage is retained to support hash recomputation. A Nebulad payload may include internal user, project and item identifiers, title, description, dates, status and hashes of supporting evidence files. Source document files are not included in that payload. Current Polygon activation and the production Nebulad deployment must be verified separately.

5.2. A Polygon hash that has been confirmed on the public network cannot be removed by Nebula. Canonical preimages and signed Nebulad events may also be retained as engagement, security and evidence records, including after account closure or an erasure request where clause 10 permits retention.

5.3. A cryptographic hash does not disclose its source text by itself, but it can be used to test whether a separately obtained candidate payload matches the recorded commitment. If you follow a Polygonscan link, your browser sends ordinary request metadata and the public transaction hash to that third-party site.

6. Disclosure of Your Information

We may disclose your information to the following categories of recipients:

6.1. Engagement participants

Other authorised users in an engagement may see your organisation name, role, engagement communications, released reputation information and relevant engagement data as necessary for collaboration.

6.2. Service providers

We use service providers for managed application hosting, database, object storage, transactional email, document intelligence and proof-gateway services. Public website analytics operates only after consent. Where billing is enabled, checkout occurs on Stripe’s hosted surface and Nebula uses the provider-issued subscription and payment identifiers described in Section 2 for server-side reconciliation. Error reporting, shared rate limiting and customer-selected integrations remain configuration-dependent. The applicable provider roles, terms and data-processing arrangements require confirmation for the customer scope. Provider-specific details are in the provider register.

After analytics consent, your browser connects directly to Google Analytics. The information sent or exposed through that request, and the separately configured Google Ads relationship, are described in Section 9. Google’s legal role, processing locations, retention, transfer position and applicable signed terms cannot be confirmed by Nebula.

When you follow a Business or Enterprise booking action, your browser opens the owner-operated Google Calendar appointment schedule linked from Nebula. Google receives your client IP address and ordinary request metadata, and its hosted page collects attendee name, email address and selected appointment time. The hosted schedule is configured to send calendar invitations and updates by email and to create Google Meet links. Australia/Sydney is the appointment display and availability timezone, not evidence of a processing location. Google’s booking-specific account type, legal role, contracting entity, signed terms, processing, support and backup locations, retention, deletion and transfer position cannot be confirmed by Nebula. This owner-operated, Google-hosted path is separate from customer-selected Google identity and Google Workspace integrations.

When the authenticated dashboard displays local weather, your browser requests it from Nebula. Nebula resolves a saved, entered or timezone-derived city inside its own service, rounds the resulting coordinates to no more than four decimals, and uses a cached server proxy to request forecast data from MET Norway Locationforecast. The provider request contains the rounded coordinates, Nebula’s server IP address, a stable Nebula service identity and ordinary server request metadata. Your client IP address, cookies, session data, account or organisation identifiers, and city text remain within Nebula. MET Norway states that its API access logs are held in its Oslo data centre and that IP addresses for unauthenticated websites can be retained for up to 90 days. The dashboard credits MET Norway and links its open-data licence. MET Norway’s legal role for this path cannot be confirmed by Nebula.

An organisation can configure an external webhook endpoint for selected project events. The endpoint can receive event type and time, project and record identifiers, status and action details, and event-specific information such as file names, payment amounts, dispute reasons, notification titles and user identifiers. The organisation is responsible for selecting and authorising that destination.

6.3. Legal and regulatory

We may disclose your information where required by law, regulation, legal process, or enforceable governmental request, or where we reasonably believe disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of others.

6.4. Business transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, your information may be transferred to the successor entity. Notice will be provided where required by applicable law or a signed customer agreement.

We do not sell your personal information to third parties. We disclose your uploaded documents only to authorised users in the relevant engagement workspace, service providers used for the stated service purpose, a successor in a business transfer, or where required or permitted by law, as described above.

7. Reputation and Track Record

7.1. Reputation information is derived from eligible, attributable engagement events. A presentation may show the engagement and role context, the event reason and time, the recorded score movement, and related evidence or a separate proof link where available. Where an event is linked to another engagement record, that record may separately show an extension-of-time claim and its recorded approval or rejection, a payment claim’s review, dispute, rejection, certification or payment record, or an item dispute and its recorded resolution. Those entries describe the related engagement record; they are not states of a reputation event.

7.2. Reputation data may include delivery timing, response activity, evidence and verification coverage, collaboration and dispute or review history. A reputation entry does not by itself establish fault, legal liability or the objective truth of a disputed event.

7.3. Other Platform users may see a reputation tier or information the organisation has chosen to release, subject to the applicable access and sharing controls.

7.4. If you believe reputation information is incorrect, lacks required context or should reflect the outcome of a dispute, you may request review at support@nebulaplatform.com.au. Nebula may correct a Platform error through the applicable review or appeal path. For supported contest and resolution actions, Nebula keeps the earlier movement and adds a compensating movement.

7.5. Reputation event data forms part of the engagement record and is retained under clause 10. A released profile shows the available context and separate proof references beside reported delivery information. When a supported contest or resolution produces a compensating movement, both movements remain part of the history.

8. Data Storage and Security

8.1. Current provider documentation states that the managed database and object-storage services encrypt data at rest. The deployed boundary, key custody and backup coverage cannot be confirmed from current account or applicable contract evidence. Application responses configure HSTS, and named HTTP provider endpoints use HTTPS. Live database and provider transport settings require deployment verification.

8.2. Current application controls include authenticated role and engagement access checks, TOTP multi-factor authentication, rate-limited password sign-in, best-effort access-log writes, defined activity-record paths, and HSTS configuration.

8.3. Account credentials are hashed using strong, one-way cryptographic algorithms. We do not store passwords in plaintext.

8.4. While we take reasonable measures to protect your information, no method of electronic storage or transmission is completely secure. We cannot guarantee absolute security.

8.5. The Security page explains the controls and standards that support the Platform’s security posture.

9. Cookies and Tracking Technologies

9.1. Essential cookies: We use cookies strictly necessary for the operation of the Platform, including session management and authentication. These cookies are not affected by the analytics choice below, and there is no in-product switch for them. Blocking them in your browser may prevent signed-in features from working.

9.2. Analytics cookies: On our public website, Google Analytics loads only after you agree through the analytics choice shown on the site. On static marketing pages, our manual page-view call retains only utm_source, utm_medium, utm_campaign, utm_term and utm_content from the query in the page-location field so a consented campaign visit can carry its source. Other query values are removed. For pages under certify, confirm, review, verify and the block explorer, the call removes every query value, replaces the record-specific value with a route class in the page-path field, overrides the page-location field with the same route class URL, and reduces internal referrer values the same way. This removes single-use confirmation tokens, expiring review tokens, organisation identifiers, anchor identifiers, ABNs and block heights from the page-path and page-location fields, and from the page-referrer field when the referrer is within Nebula. External referrers are passed through. Google also receives ordinary browser request metadata and may add browser, device, referral, session, user or cookie-derived fields. Not every provider-added field can be confirmed by Nebula. After analytics consent, limited event information may include a contact or white-paper form type, product enquiry category, and a founding workspace-presence flag, remaining-place count and programme duration. Those event parameters do not explicitly include names, email addresses, free-text messages, passwords, documents, organisation names, account identifiers or engagement content. The tag is configured to deny advertising storage, advertising user data and advertising personalisation, and to request IP anonymisation. No analytics tag loads before you agree, and you can change your choice at any time using the control below. The signed-in Platform does not carry this analytics tag. Google’s exact cookie set, automatically added fields, retention and processing locations cannot be confirmed by Nebula.

9.3. Linked advertising service: The browser tag is configured to deny advertising storage, advertising user data and advertising personalisation. The Google Analytics property is linked to Google Ads. After analytics consent, a lead-submission event can include the form type and enquiry category for conversion measurement. Property-level ads personalisation and Google signals are disabled. The exact fields made available through the link or conversion, and Google’s resulting cookie or cross-site handling, cannot be confirmed by Nebula.

10. Data Retention

10.1. We retain your account data and User Content for as long as your account remains active.

10.2. The implemented self-service erasure path has a thirty (30) day cancellable grace period. After the grace period, it anonymises specified account data, disables sign-in, revokes keys and removes specified records. It does not establish complete deletion from every active system, object store, service provider or backup.

10.3. Deletion from provider backups depends on the applicable provider retention and lifecycle settings. Those settings must be verified for the customer scope before a fixed backup-deletion period is promised.

10.4. Confirmed Polygon hashes cannot be removed by Nebula. Canonical proof preimages and signed Nebulad events may remain where they form part of a shared engagement record, support verification, address security or legal requirements, resolve a dispute, or enforce our agreements. Those retained records can include identifiers and event details.

10.5. Information that is lawfully de-identified so that it is no longer personal information may be retained for service analysis, subject to the applicable legal standard.

10.6. We may retain certain data for longer periods where required by law, regulation, or to resolve disputes or enforce our agreements.

11. Your Rights

Subject to applicable law, you may have the following rights in relation to your personal information:

  • Access: the right to request a copy of the personal information we hold about you;
  • Correction: the right to request correction of inaccurate or incomplete personal information;
  • Deletion: the right to request deletion of your personal information, subject to our legal obligations and legitimate interests;
  • Portability: the right to receive your personal information in a structured, commonly used, machine-readable format;
  • Restriction: the right to request that we restrict processing of your personal information in certain circumstances;
  • Objection: the right to object to processing of your personal information where we rely on legitimate interests; and
  • Withdrawal of consent: where processing is based on your consent, the right to withdraw that consent at any time.

To exercise any of these rights, please contact us at privacy@nebulaplatform.com.au. We will respond within the period required by applicable law and any signed customer terms. We may ask you to verify your identity before processing your request. Some rights may be limited where we have an overriding legitimate interest or legal obligation.

Self-service erasure. You can initiate erasure yourself from your account settings. We hold the request for thirty (30) days as a grace period during which you may cancel. After the grace expires, the account email and name are replaced, sign-in is disabled, signing keys are revoked, notifications are removed and selected copied names are anonymised. Shared engagement, audit and proof records may remain under clauses 5 and 10. Canonical proof data retains the internal identifiers and event details required to preserve the evidence record.

12. International Data Transfers

12.1. Your data may be processed in countries other than your own, including Australia and the United States, where our cloud infrastructure providers operate.

12.2. The applicable recipient, purpose, data categories, location where known, contractual terms and transfer safeguards must be reviewed for the intended customer scope. The current codebase does not itself prove signed provider terms or every processing location.

12.3. Nebula’s privacy control model is designed around mechanisms in the Australian Privacy Principles, including purpose-limited processing, access and correction channels, disclosed overseas processing and erasure limits. This is a design position, not a legal conclusion that the Australian Privacy Principles apply or are satisfied. Nebula presents those mechanisms, data locations and approved-provider handling terms only where repository or signed evidence supports them. The customer and qualified counsel must confirm the resulting deployment against the applicable Australian Privacy Principles and any other jurisdictional requirements.

13. Children’s Privacy

The Platform is not directed at and is not intended for use by individuals under 18 years of age. The current source does not implement an age-verification control. If we become aware that personal information from a child has been collected, we will assess and address it under applicable law and any customer obligations. If you believe a child has provided personal information to us, please contact privacy@nebulaplatform.com.au.

14. Changes to This Policy

14.1. We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

14.2. We will provide notice of a material change where required by applicable law or a signed customer agreement. This Policy does not otherwise promise a fixed advance-notice period.

14.3. Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the changes. If you disagree with any changes, you may close your account before the changes take effect.

14.4. The publication and effective dates at the top of this page show when this Policy was issued and when it takes effect.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Privacy Officer

Nebula Platform Pty Ltd

privacy@nebulaplatform.com.au

For general legal enquiries, please refer to our Terms of Service or contact legal@nebulaplatform.com.au.

If you are not satisfied with our response to a privacy concern, you may have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or the relevant data protection authority in your jurisdiction.