Privacy notice
On this page
This notice explains what personal data Tractrix collects when you use the Tractrix website, Tractrix Cloud, the Tractrix desktop products and our support channels, why we use it, who receives it, how long we keep it and what rights you have. The global notice applies everywhere; the regional supplements add what the law of your country or state requires.
Summary
- The website uses only strictly necessary storage unless you opt in to anything else. See the cookie notice.
- The desktop products (Tractrix for QGIS, the OpenAirside engine, and the AutoCAD and Revit add-ins with the local engine) run on your computer and send us nothing. They contain no telemetry.
- Tractrix Cloud processes the account data needed to run the service (name, e-mail address, organisation roles, security events). We are the controller of that data.
- Your drawings and results in Tractrix Cloud are customer content. We process them only on your organisation's instructions, as its processor, under the Data Processing Addendum.
- We do not sell or share personal data for cross-context behavioural advertising, do not use it for automated decisions with legal effects, and do not use customer content to train models.
- You can exercise your rights through Settings → Privacy in Tractrix Cloud or on the privacy request page.
1. Who we are and how to contact us
2. What this notice covers
| Service or activity | Covered | Our role |
|---|---|---|
| The Tractrix website (tractrix.io) and its help centre and documentation | Yes | Controller |
| Tractrix Cloud: accounts, organisations, security, billing and service communications | Yes | Controller |
| Tractrix Cloud: customer content (projects, drawings, runs, results, exports) | Yes, see section 3 | Processor for the customer |
Tractrix for QGIS, the OpenAirside engine and the tractrix-engine CLI | Yes — no personal data reaches us | None |
| Tractrix for AutoCAD and Tractrix for Revit (local engine) | Yes — no personal data reaches us | None |
| Tractrix for AutoCAD and Revit in cloud mode | Yes | As for Tractrix Cloud |
| Support, sales enquiries, security reports and privacy requests | Yes | Controller |
| Events and webinars we organise (if any) | Yes | Controller |
| GitHub repositories, issues and discussions | Only what we do with content you post; GitHub's own processing is governed by GitHub's privacy statement | GitHub is an independent controller |
| Job applicants, employees and contractors | No — covered by a separate notice given at the time | — |
3. Controller and processor roles
For account data (who you are, how you sign in, what organisations you belong to, security events and billing), Tractrix decides why and how the data is processed and is the controller.
For customer content — the projects, drawings, simulation requests, results, reports and exports that an organisation stores in Tractrix Cloud — the customer organisation is the controller and Tractrix is its processor (in US state-law terms, its service provider or processor; in POPIA terms, its operator). We process customer content only to provide the service, on the customer's documented instructions, as set out in the Data Processing Addendum. Customer content is mostly airport geometry and is usually not personal data, but it may contain personal data (for example names in drawing titles or layer names) and it may be security-sensitive. If you want to exercise your rights over customer content, please contact the organisation that controls it; we will pass on any request we receive.
Where your employer or client invited you to an organisation, that organisation's owners and admins can see your name, e-mail address, role and the security events recorded for their organisation.
4. The personal data we process
| Category | What it includes | Where it comes from |
|---|---|---|
| Website technical data | IP address, date and time, requested URL, HTTP status, referrer, browser user-agent string, processed by our web host in server logs. No analytics by default. | Your browser, automatically |
| Website preferences | Your cookie-consent record and your colour theme (tx-theme) and, only if you consent, your “Was this page helpful?” answers (tx-fb:…). Stored in your browser only and not sent to us. | Your browser |
| Account data | Name, e-mail address, password (stored only as an Argon2id hash, never in readable form), e-mail verification status, account creation time, last sign-in time, account status. | You |
| Organisation data | Organisations you create or join, their names, your role (viewer, member, admin, owner), invitations (invitee e-mail, role, inviter, dates). | You, or an admin of the organisation that invited you |
| Session and security data | Sign-in sessions (a hashed refresh token, its creation and expiry time, and the browser user-agent string); security audit events (the action, time, your user and organisation identifiers, the target of the action — which can be an e-mail address, for example an invitee or the address entered in a failed sign-in — and the network part of the IP address from which the request was made — truncated to /24 for IPv4 or /48 for IPv6 before it is stored); full IP addresses held briefly in memory for rate limiting only. | Your device, automatically |
| API token data | Token name, a short display prefix, a hash of the token (never the token itself), creation, expiry and last-used times, and the organisation it is bound to. | You |
| Usage and plan data | Number of simulation runs per organisation per month, plan, limits reached, projects and seats in use, a payment-provider customer reference. | Generated by the service |
| Billing data (paid plans) | Billing contact name and e-mail, company name, billing address, tax/VAT number, invoices and payment status. Card details are collected directly by our payment processor; we see only limited details such as card brand, last four digits and expiry. | You; our payment processor |
| Consent and preference records | An append-only history of what you accepted, gave or withdrew and when: the Cloud Terms and Acceptable Use Policy version, acknowledgement of this notice, marketing choice, age confirmation, consent to cloud processing in the CAD add-ins, acceptance of the DPA for an organisation, and Global Privacy Control signals received — each with the method, the source (web, API, CAD or e-mail) and a truncated IP address. | You |
| Communications | The content of e-mails and messages you send us (support, sales, security reports, privacy requests), with your contact details and our replies. | You |
| Customer content (processor role) | Project names, airport codes and descriptions; uploaded drawings (GeoJSON or DXF geometry, file and layer names); simulation requests, results, reports and exports; the identity of the member who created each item. | Your organisation's members |
| CAD add-in cloud mode | The simulation request (path coordinates, pavement and obstacle outlines, aircraft or vehicle and parameters), your API token (sent over HTTPS for authentication), and a Tractrix-CAD/1.0 user-agent string. | The add-in, when you choose the cloud engine |
We do not ask for, and ask you not to provide, special-category or sensitive data (for example health data, or data revealing racial or ethnic origin, political opinions or religious beliefs). We do not buy personal data from data brokers and do not combine your data with data from third-party sources for profiling.
Is providing data mandatory? A name, e-mail address and password are needed to create a Tractrix Cloud account, and billing details are needed for paid plans. Without them we cannot provide the service. Everything else is optional or generated by your use of the service. The website and desktop products can be used without giving us any personal data.
5. Purposes and legal bases
Table 3 lists why we use personal data and, for the EEA, the UK and similar laws, the legal basis under Article 6(1) GDPR / UK GDPR. Where we rely on legitimate interests we have balanced them against your rights; you can ask for details of that assessment.
| Purpose | Data used | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Create and administer your account; sign you in; verify your e-mail; reset your password | Account, session | (b) contract |
| Provide organisations, roles, invitations and API tokens | Account, organisation, API token | (b) contract; for invitees, (f) legitimate interests of the inviting organisation and us in letting teams collaborate |
| Host and process customer content and run simulations | Customer content | Processed as processor on the customer's instructions (Art. 28); the customer determines its own legal basis |
| Keep the service secure: rate limiting, fraud and abuse prevention, the security audit log, investigating incidents | Session and security, IP address, user agent | (f) legitimate interests in protecting our users, customer content and systems; (c) legal obligation where security is required by law |
| Show organisation admins the audit log of their organisation | Security audit events | (f) legitimate interests of the customer in accountability and security; (b) contract with the customer |
| Enforce plan limits, meter usage and bill | Usage and plan, billing | (b) contract; (c) legal obligation for tax and accounting records |
| Send service messages (verification, password reset, invitations, security alerts, changes to terms, billing) | Account | (b) contract; (f) legitimate interests for security notices |
| Answer support, sales and security enquiries | Communications | (b) steps at your request before or under a contract; (f) legitimate interests in answering enquiries |
| Handle privacy requests and keep records of consents | Communications, consent records | (c) legal obligation; (f) legitimate interests in demonstrating compliance |
| Product news and marketing e-mails | Name, e-mail | (a) consent, or, for existing customers where permitted, (f) legitimate interests under the “soft opt-in” (see section 13) |
| Deliver and protect the website (server logs) | Website technical data | (f) legitimate interests in operating a secure website |
| Optional website experiments on all supported language pages, when enabled and you opt in | Random browser identifiers (30 days), variant assignment, qualified CTA clicks, active time, animation completion, error flags and performance metrics. Pseudonymous measurements in our EU Cloud service are retained for 90 days; aggregate decision reports are retained. No account linkage. As described in the cookie notice | (a) consent |
| Improve the service using aggregated, de-identified statistics (for example run counts and error rates, not content) | Usage and plan | (f) legitimate interests in improving the service |
| Establish, exercise or defend legal claims; comply with law and lawful requests from authorities | Any relevant data | (c) legal obligation; (f) legitimate interests |
| Corporate transactions (merger, acquisition, financing, sale of assets), under confidentiality | Any relevant data | (f) legitimate interests |
We do not use customer content for any purpose other than providing the service to the customer, and we do not use it to train machine-learning models.
6. How long we keep data
We keep personal data only as long as needed for the purposes above. Table 4 sets out the schedule. Tractrix Cloud applies these rules automatically in a daily purge job whose periods are configurable. Refer to your service agreement for any additional retention terms..
| Data | Retention |
|---|---|
| Accounts whose e-mail address was never verified | Deleted 30 days after sign-up |
| Active accounts | For as long as the account exists |
| Deleted accounts | Deactivated immediately; purged from the live database after a 30-day grace period during which you can cancel the deletion from the link we e-mail you |
| Security audit events | 12 months (365 days), then deleted. IP addresses are truncated when stored. When an account is erased, its events are pseudonymised for the rest of the period |
| Expired or revoked sign-in sessions; used or expired verification, reset and invitation tokens | Deleted 7 days after expiry, revocation or use; accepted, revoked or expired invitations 30 days after that event. Verification links expire after 24 hours, reset links after 60 minutes, invitations after 14 days, sessions after 30 days |
| IP addresses held for rate limiting | In memory only, for the length of the rate-limit window (about one minute) |
| API tokens | Until revoked or expired, then as for sessions |
| Customer content | Until the customer deletes it, or for a result-retention period an organisation admin can set; after the subscription ends, kept for a 30-day export period and then deleted (see the Cloud Terms) |
| Usage counters | For the life of the organisation; aggregated statistics without personal data may be kept longer |
| Support, sales and security correspondence | 3 years after the last contact (proposed), unless needed longer for a claim |
| Privacy request records | 3 years (1,095 days), which exceeds the 24-month minimum of the CCPA regulations |
| Marketing preferences | Until you unsubscribe; we keep a suppression record of your e-mail address so that we do not contact you again |
7. Who receives personal data
- Your organisation. Owners and admins of an organisation you belong to see members' names, e-mail addresses and roles, the organisation's audit log (including IP addresses of recorded actions), and the content created in it.
- Sub-processors who host and operate the service for us under written contracts: cloud hosting and database, e-mail delivery, payment processing, customer support tooling and error monitoring. The current list, with locations and transfer mechanisms, is on the sub-processors page.
- Our payment processor, which is an independent controller for the card data it collects and for its own fraud-prevention and regulatory purposes.
- Professional advisers (lawyers, accountants, auditors, insurers) under duties of confidentiality.
- Authorities, courts and regulators where we are legally required to disclose, or where disclosure is necessary to protect rights, safety or security. We review each request, disclose only what is required, and, where the law allows, tell the affected customer first. Our approach to government requests for customer content is set out in the DPA.
- A buyer or successor in a merger, acquisition or sale of assets, subject to confidentiality and to this notice.
We do not sell personal data, do not rent it, and do not share it with advertisers or data brokers.
8. International transfers
- the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the appropriate module;
- for UK data, the UK International Data Transfer Addendum to those clauses, or the UK International Data Transfer Agreement;
- for Swiss data, the clauses with the amendments required by the Swiss Federal Data Protection and Information Commissioner (FDPIC);
- adequacy decisions, where they exist for the destination country.
9. Security
10. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, and we do not profile you. Plan limits are applied automatically (for example, a run is refused when a monthly limit is reached); this is a transparent rule of your plan, not a profile, and you can contact us about it. Simulations compute the motion of aircraft and vehicles, not assessments of people.
11. Children
12. Your rights
Depending on where you live, you have some or all of these rights over personal data we hold as controller:
- Access — to know whether we process your data and to receive a copy;
- Rectification — to correct inaccurate or incomplete data (you can edit your name in Tractrix Cloud yourself);
- Erasure — to have your data deleted, subject to legal exceptions;
- Restriction — to have processing limited while a dispute is resolved;
- Portability — to receive data you gave us in a structured, machine-readable format (JSON) and have it sent to another controller where technically feasible;
- Objection — to object to processing based on legitimate interests, and at any time to direct marketing;
- Withdraw consent at any time, without affecting processing that took place before;
- Not to be subject to solely automated decisions with legal or similar effects (we make none);
- Complain to us and to a supervisory authority (see the regional supplements).
If you are the only owner of an organisation, you will need to transfer ownership or delete the organisation before your account can be deleted, so that your colleagues do not lose their work unexpectedly.
13. Marketing communications
14. Cookies and similar technologies
The website uses only strictly necessary browser storage by default; any other category is off until you opt in. Tractrix Cloud uses one strictly necessary cookie — an HTTP-only, same-site refresh cookie that keeps you signed in for up to 30 days, is rotated on every use and is not used for tracking — and stores the organisation you last selected (tx.currentOrg) in your browser's local storage. Full details, and a way to change your choices, are in the cookie notice. We honour the Global Privacy Control signal as described in Your privacy choices.
15. Changes to this notice
We will publish any change on this page with a new version number and date, and keep earlier versions available on request. If a change is material, we will notify Tractrix Cloud account holders by e-mail or in the service at least 30 days before it applies, and, where the law requires, ask for your consent again. The history of this notice is in the legal centre change log.
16. Regional supplements
These supplements apply in addition to sections 1 to 15 if you are in the country or state concerned. Where a supplement conflicts with the global notice, the supplement prevails for residents of that place.
Counsel: confirm for each market whether Tractrix is within scope (thresholds, targeting criteria, B2B exemptions) and whether registration, a representative or a local officer is required. Where a law does not apply, the supplement may be retained as a voluntary commitment or removed.
EEA · United Kingdom · Switzerland · United States · Canada · Brazil · South Africa · Ethiopia · Kenya · Nigeria · United Arab Emirates · Saudi Arabia · India · Singapore · Australia · New Zealand · Japan · South Korea · China
European Economic Area (GDPR)
- Law: Regulation (EU) 2016/679 (GDPR) and national implementing laws; the ePrivacy Directive as transposed for cookies and e-mail marketing.
- Legal bases: as in Table 3.
- Rights: Arts 15–22 as listed in section 12. We respond within one month, extendable by two further months for complex or numerous requests, and tell you within the first month if we extend.
- Complaints: you may complain to the supervisory authority of the member state where you live, work or where the alleged infringement took place. A list is published by the European Data Protection Board at edpb.europa.eu.
- Transfers: section 8.
United Kingdom
- Law: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended by the Data (Use and Access) Act 2025 (DUAA), whose provisions are being commenced in stages.
- Subject access: we carry out reasonable and proportionate searches and reply within one month (extendable by two months); the time limit may pause while we wait for information needed to identify you or clarify the request.
- Supervisory authority: the Information Commissioner's Office (ICO), ico.org.uk, which is being reconstituted as the Information Commission under the DUAA.
- Cookies: we do not rely on the DUAA's new exemptions for analytics storage; non-essential storage stays opt-in.
- Transfers: UK adequacy regulations, the UK Addendum or IDTA, or the UK Extension to the Data Privacy Framework where the recipient is certified.
Switzerland
- Law: the Federal Act on Data Protection of 25 September 2020 (nFADP) and its Ordinance, in force since 1 September 2023.
- Rights: access (Art. 25), data portability (Art. 28), rectification and deletion; we respond within 30 days.
- Transfers: to countries on the Federal Council's adequacy list (Annex 1 of the Ordinance), or with the Standard Contractual Clauses as amended for Swiss law, or under the Swiss–US Data Privacy Framework where the recipient is certified.
- Authority: the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch.
United States
California — Notice at Collection and privacy policy (CCPA as amended by the CPRA)
| Category (§ 1798.140) | Examples | Sources | Business purposes | Disclosed for a business purpose to | Sold or shared | Retention |
|---|---|---|---|---|---|---|
| Identifiers | Name, e-mail address, account and organisation IDs, IP address | You; your device; your organisation's admin | Providing the service; security; support; billing | Service providers (hosting, e-mail, support); your organisation | No | Table 4 |
| Customer records (§ 1798.80(e)) | Name, billing address, telephone number if given, limited payment-card details | You; payment processor | Billing; accounting | Payment processor; professional advisers | No | Table 4 |
| Commercial information | Plan, subscription and purchase history, usage counts | Generated by the service | Billing; plan limits | Service providers | No | Table 4 |
| Internet or other electronic network activity | Security audit events, sign-in sessions, user-agent strings, server logs | Your device | Security; debugging; auditing | Service providers; your organisation's admins (audit log) | No | Table 4 |
| Professional or employment-related information | Your organisation and your role in its Tractrix workspace | You; your organisation | Providing the service | Your organisation | No | Table 4 |
| Sensitive personal information | Account log-in (e-mail address with password, stored as a hash) | You | Only to authenticate you (Regs. § 7027(m) purposes) | Hosting service provider | No | Life of the account |
- We do not collect precise geolocation, biometric, audio or visual, health or financial-account information (other than payment details handled by our payment processor), and we do not draw inferences to create profiles.
- No sale or sharing. We do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16. We honour the Global Privacy Control signal as an opt-out request; see Your privacy choices.
- Sensitive personal information is used only for purposes permitted by § 7027(m) of the CCPA Regulations, so the right to limit does not apply.
- Your rights: to know what personal information we collect, use and disclose (categories and specific pieces); to delete; to correct; to opt out of sale or sharing; to limit use of sensitive personal information; and not to be discriminated or retaliated against for exercising these rights. We will not deny service, charge different prices or provide a different quality of service because you exercised a right.
- Verification: we match the information you give against our records, normally by confirming control of the e-mail address on the account. For specific pieces of information we apply a higher degree of certainty. We confirm receipt within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice.
- Authorised agents: an agent may submit a request on your behalf with your signed permission or a power of attorney; we may ask you to verify your identity directly.
- Employees and B2B contacts: California applies the CCPA to personal information collected in an employment or business-to-business context. This notice covers business contacts; job applicants and staff receive a separate notice.
- Shine the Light (Cal. Civ. Code § 1798.83): we do not disclose personal information to third parties for their own direct-marketing purposes.
Other US state privacy laws
This part applies to residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, and of any other state with a comparable consumer privacy law, to the extent those laws apply to us. Most of them exclude individuals acting in a commercial or employment context, which is how we mainly interact with people; we nonetheless offer the rights below to all US residents.
- Rights: to confirm whether we process your personal data and to access it; to correct it; to delete it; to obtain a portable copy; to opt out of targeted advertising, of the sale of personal data and of profiling in furtherance of decisions that produce legal or similarly significant effects (we do none of these); where the law provides, to obtain a list of the categories or specific third parties to which we disclosed personal data (Oregon, Delaware, Maryland, Minnesota); and, in Minnesota, to question the result of profiling and to be told the reasons.
- Sensitive data: we do not process sensitive data as defined in these laws (for example precise geolocation or health data) other than what is strictly needed to provide the service; where consent is required, we will ask for it first. We do not sell sensitive data (as Texas and other states require us to state, we do not sell any personal data).
- Timing: we respond within 45 days, extendable once by 45 days where reasonably necessary.
- Authorised agents may act for you where the law allows (for example in Colorado, Connecticut, Oregon, Texas, Montana, Delaware, New Jersey, Minnesota and Maryland, including through a universal opt-out mechanism such as Global Privacy Control).
- We do not discriminate against you for exercising your rights.
Nevada
Other US notices
Our marketing e-mails comply with the CAN-SPAM Act (see section 13). If a data breach affects you, we will notify you as required by the breach-notification law of your state.
Canada
- Law: the Personal Information Protection and Electronic Documents Act (PIPEDA); in Québec, the Act respecting the protection of personal information in the private sector as amended by Law 25; in Alberta and British Columbia, their Personal Information Protection Acts.
- Consent: we rely on your consent, express or implied as appropriate, which you can withdraw subject to legal or contractual restrictions.
- Rights: access and correction; in Québec, also data portability in a structured, commonly used technological format, de-indexation where applicable, and information about automated decisions (we make none). We respond within 30 days.
- Complaints: the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in Québec, the Commission d'accès à l'information (cai.gouv.qc.ca).
- E-mail marketing: CASL, see section 13.
Brazil
- Law: Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13,709/2018).
- Legal bases (Art. 7): performance of a contract, legitimate interest, compliance with a legal obligation, exercise of rights in proceedings, and consent (marketing), mirroring Table 3.
- Rights (Art. 18): confirmation and access, correction, anonymisation, blocking or deletion of unnecessary or excessive data, portability, information about sharing, information about the consequences of refusing consent, withdrawal of consent, and review of automated decisions (we make none). We respond to simplified access requests immediately and to full requests within 15 days.
- International transfers (Art. 33): on the basis of the standard contractual clauses approved by the ANPD (Resolution CD/ANPD No. 19/2024) or other mechanisms allowed by the LGPD.
- Authority: Autoridade Nacional de Proteção de Dados (ANPD), gov.br/anpd.
South Africa
- Law: the Protection of Personal Information Act 4 of 2013 (POPIA) and the Promotion of Access to Information Act 2 of 2000 (PAIA). We are the responsible party for account data and an operator for customer content.
- Cross-border transfers (s. 72): only to recipients bound by law, binding corporate rules or an agreement providing substantially similar protection, or with your consent or where necessary for a contract with you.
- Direct marketing (s. 69): by electronic communication only with your consent or, for customers, in respect of similar products with an opportunity to object each time.
- Authority: the Information Regulator, inforegulator.org.za.
Ethiopia
- Law: the Personal Data Protection Proclamation No. 1321/2024.
- Principles and bases: we process personal data lawfully, fairly and for specified purposes, on the bases listed in Table 3 (including consent, contract, legal obligation and legitimate interest) as permitted by the Proclamation.
- Rights: to be informed, to access, to rectify, to erase, to object and to restrict processing, to data portability, and to lodge a complaint.
Kenya
- Law: the Data Protection Act, 2019 and its Regulations (2021).
- Rights (s. 26): to be informed, access, object, correction and deletion of false or misleading data; data portability (s. 38).
- Transfers (ss. 48–50): with appropriate safeguards, adequacy or your consent, as the Act requires.
- Authority: Office of the Data Protection Commissioner (ODPC), odpc.go.ke.
Nigeria
- Law: the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive (GAID) 2025 issued by the Nigeria Data Protection Commission.
- Rights (ss. 34–38): information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and not to be subject to solely automated decisions.
- Transfers (ss. 41–43): to countries with an adequate level of protection or under appropriate safeguards such as standard contractual clauses.
- Authority: Nigeria Data Protection Commission (NDPC), ndpc.gov.ng.
United Arab Emirates
- Law: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). Organisations in the Dubai International Financial Centre and Abu Dhabi Global Market are subject instead to the DIFC Data Protection Law 2020 or the ADGM Data Protection Regulations 2021.
- Rights: information and access, portability, rectification and erasure, restriction, objection, and objection to automated processing.
- Transfers (Arts 22–23): to countries with adequate protection or under the exceptions and safeguards the PDPL provides, including contractual safeguards.
- Authority: the UAE Data Office (or the DIFC Commissioner of Data Protection / ADGM Office of Data Protection).
Saudi Arabia
- Law: the Personal Data Protection Law (Royal Decree M/19 of 1443H, as amended) and its Implementing and Transfer Regulations.
- Rights: to be informed, to access, to obtain a copy in a readable format, to correct, to destroy data no longer needed, and to withdraw consent.
- Transfers: outside the Kingdom only as the Transfer Regulations permit, with the safeguards they require (for example standard contractual clauses) and, where required, a risk assessment.
India
- Law: the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, whose obligations commence in phases. We are a Data Fiduciary for account data and a Data Processor for customer content.
- Consent and notice: where we rely on consent, you may withdraw it as easily as you gave it; certain processing relies on “legitimate uses” under section 7.
- Rights: access to a summary of your data and processing, correction, completion, updating and erasure, grievance redressal, and nomination of another person to exercise your rights in the event of death or incapacity.
- Transfers: permitted except to countries restricted by notification of the Government of India.
Singapore
- Law: the Personal Data Protection Act 2012 (PDPA).
- Rights: access, correction, withdrawal of consent and, when commenced, data portability. We respond to access requests within 30 days or tell you when we will.
- Transfers: we ensure a standard of protection comparable to the PDPA (Transfer Limitation Obligation), for example by contract.
- Authority: Personal Data Protection Commission (PDPC), pdpc.gov.sg. We do not send marketing messages to Singapore telephone numbers.
Australia
- Access and correction (APPs 12–13): we respond within 30 days.
- Complaints: contact us first; if you are not satisfied within 30 days, you may complain to the Office of the Australian Information Commissioner (OAIC), oaic.gov.au.
- You may deal with us anonymously or by pseudonym where practicable (for example general enquiries), but not to hold a Cloud account.
New Zealand
- Law: the Privacy Act 2020 and its Information Privacy Principles (IPPs), including IPP 3A on information collected from third parties.
- Access and correction: we respond within 20 working days.
- Overseas disclosure (IPP 12): only where the recipient is subject to comparable safeguards, including by contract.
- Complaints: the Office of the Privacy Commissioner, privacy.org.nz.
Japan
- Law: the Act on the Protection of Personal Information (APPI).
- Security control measures: summarised on the security page.
- Authority: Personal Information Protection Commission (PPC).
South Korea
- Law: the Personal Information Protection Act (PIPA).
- Destruction: at the end of the retention period data is deleted from electronic files in a way that cannot be restored.
- Rights and remedies: access, correction, deletion, suspension of processing and withdrawal of consent; complaints to the Personal Information Protection Commission (PIPC) or the Personal Information Dispute Mediation Committee.
China
- Law: the Personal Information Protection Law (PIPL), together with the Data Security Law and the Cybersecurity Law.
- Important data: airport geospatial and infrastructure data may be classified as important data or restricted geographic information under Chinese law. Customers must not upload such data to Tractrix Cloud unless its export is lawful; see the Acceptable Use Policy.
- Rights: to know and decide, to restrict or refuse, to access and copy, to portability, to correct, to delete, to an explanation of our rules, and, for close relatives, rights over a deceased person's data.