LaityOS Logo

Privacy Policy

LaityOS Community Platform

Legal Review Required

This privacy policy must be reviewed and approved by a qualified Australian privacy lawyer before being published.

Effective Date: [To Be Determined]

Last Updated: November 28, 2025

Our Commitment to Your Privacy

M. P. S. Bilo (ABN: [TBD]) ("LaityOS," "we," "us," or "our") is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, disclose, and secure your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using LaityOS services, you agree to the collection and use of information as described in this policy.

1. What Information We Collect

We collect the following types of personal information:

Account Information

Service Usage Information

Technical Information

Authentication Information

Optional Information

You may choose to provide:

We Do NOT Collect

2. How We Collect Information

Directly From You

Automatically

From Third Parties

We Will Always Notify You

When we collect your personal information, we will provide a collection notice explaining: what information we're collecting, why we need it, how we'll use it, who we may share it with, and your rights regarding the information.

3. Why We Collect Your Information

Primary Purposes

Secondary Purposes (Related to Primary)

We Will Not Use Your Information

4. How We Use Your Information

Account Management

Service Delivery

Communications

Security and Compliance

Analytics and Improvement

5. When We Disclose Your Information

Within Your Organization

Service Providers

We use trusted third-party service providers who process personal information on our behalf:

Service ProviderPurposeLocationData Shared
Supabase Inc.Database hosting, authenticationAustralia (AWS Sydney)All account and service data
Vercel Inc.Application hostingAuto-routed (preference: Australia)Usage logs, session data
[Email Provider]Transactional emails[Location]Email addresses, names

All service providers are bound by confidentiality agreements and required to comply with Australian privacy standards or equivalent.

Legal Obligations

We may disclose your information when required by law:

Business Transfers

If LaityOS is acquired, merged, or reorganized:

With Your Consent

We Will Never

  • Sell your personal information to third parties
  • Share your information for third-party marketing without consent
  • Disclose information beyond what is necessary for the stated purpose

6. Direct Marketing

Marketing Communications

We may send you marketing communications about:

Your Consent

We will only send marketing communications if:

How to Opt Out

You can opt out of marketing at any time:

We will process opt-out requests within 5 business days.

Service Communications: You cannot opt out of service announcements, security alerts, event confirmations, or support responses. These are necessary to provide our services.

7. Overseas Disclosure

Data Storage Location

Your personal information is primarily stored in Australia:

Overseas Service Providers

Some service providers may access your information from overseas:

ProviderLocationSafeguards
Supabase Inc.United States (HQ)Standard contractual clauses, SOC 2 Type II certified
Vercel Inc.United States (HQ)Standard contractual clauses, ISO 27001 certified

Countries We May Disclose To

We only disclose information to countries with:

8. Data Security

We take reasonable steps to protect your personal information:

Technical Controls

Organizational Controls

Infrastructure

Data Breach Notification

If a data breach occurs that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) within 30 days and notify affected individuals as soon as practicable.

Your Responsibility

Please help us protect your information:

9. Data Retention

How Long We Keep Your Information

Data TypeRetention PeriodReason
Account information7 years after account closureLegal compliance, audit requirements
Posts and comments7 years or until you delete themService delivery, community history
Event registrations3 years after eventService delivery, attendance records
Audit logs7 yearsSecurity, breach detection, compliance
Marketing consentsUntil you withdraw + 1 yearCompliance, suppression list
Support inquiries5 yearsCustomer service, legal defense
Session data30 daysSecurity, technical troubleshooting

Active Accounts

Closed Accounts

Anonymization

10. Your Rights

Under the Australian Privacy Principles, you have the following rights:

Right to Access (APP 12)

You can request a copy of your personal information:

What You'll Receive:

Right to Correction (APP 13)

You can correct inaccurate personal information:

Right to Deletion

You can delete your personal information:

Important Notes:

  • Deletion is permanent and cannot be reversed
  • Some data may be retained for legal/audit purposes (see Section 9)
  • Deleted content is removed from public view immediately
  • Complete purge from backups occurs within 30 days

Right to Complain

If you believe we've mishandled your information:

Right to Anonymity

11. Cookies and Tracking

What Are Cookies?

Cookies are small text files stored on your device by your web browser. We use cookies to:

Types of Cookies We Use

Essential Cookies (Required)

These cookies are necessary for the platform to function:

You cannot disable these cookies without losing core functionality.

Functional Cookies (Optional)

These cookies enhance your experience:

You can disable these cookies in your browser settings.

Third-Party Cookies

We do not use third-party advertising or tracking cookies.

Our service providers (e.g., Vercel) may use cookies for performance monitoring, error tracking, and analytics (anonymized).

How to Control Cookies

Browser Settings:

Our Settings: Account Settings → Privacy → Cookie Preferences

Note: Disabling essential cookies will prevent you from using LaityOS.

Do Not Track

12. Children's Privacy

Age Requirement

LaityOS is not intended for children under 13 years of age.

Parental Consent

For users aged 13-17:

If We Discover Children's Data

If we learn we have collected information from a child under 13 without parental consent:

Parents' Rights

Parents/guardians can request access to, correction of, or deletion of their child's data by contacting [email protected].

13. Changes to This Policy

How We Update This Policy

We may update this Privacy Policy to:

Notification of Changes

Minor changes (clarifications, formatting):

Material changes (new data collection, uses, disclosures):

Your Options

If you don't agree with changes:

14. Contact Us

14. Contact Us

Privacy Officer

Name: [To Be Assigned]

Email: [email protected]

Phone: [To Be Determined]

Mail: [Physical Address]

Response Time: We will respond to privacy inquiries within 5 business days

General Inquiries

Business Details

15. Complaints

Internal Complaint Process

If you believe we have breached the Privacy Act or APPs:

Step 1: Contact Our Privacy Officer

Step 2: Investigation

Step 3: Resolution

We will provide a written response with:

Step 4: External Complaint (if needed)

Office of the Australian Information Commissioner (OAIC)

If you're not satisfied with our response, you can complain to the OAIC:

Office of the Australian Information Commissioner

Website: https://www.oaic.gov.au/privacy/privacy-complaints

Phone: 1300 363 992

Email: [email protected]

Mail: GPO Box 5218, Sydney NSW 2001

What the OAIC Can Do:

Note: The OAIC will usually require you to complain to us first before accepting your complaint.

Summary: Your Privacy at a Glance

  • ✅ We collect only information necessary to provide our services
  • ✅ We store your data securely in Australia
  • ✅ We protect your information with industry-standard security
  • ✅ We notify you if a data breach occurs
  • ✅ We respect your rights to access, correct, and delete your data
  • ✅ We don't sell your information to third parties
  • ✅ We comply with the Privacy Act 1988 and Australian Privacy Principles

Have questions? Contact us: [email protected]

For Complete Implementation Details: This privacy policy is based on the comprehensive template in docs/legal/PRIVACY_POLICY.md. Please ensure all placeholders are customized and the policy is reviewed by a qualified Australian privacy lawyer before publication.

© 2025 M. P. S. Bilo. All Rights Reserved.

Last Updated: November 28, 2025

Effective Date: [To Be Determined - after legal review]