Privacy policy

We respect your privacy – protecting your personal information is important to us.

Effective date: 6 August 2026

This Privacy Policy explains how Geminum Pty Ltd ACN 658 804 714 (“Geminum”, “we”, “us”, “our”) collects, uses, discloses and protects personal information when you visit our website at www.geminum.co (the “Website”) and when you use our products and services, including the Site Twin platform and related consulting and support services (together, the “Services”).

We are committed to protecting privacy in line with the Australian Privacy Principles (APPs), the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws, and in a manner consistent with good practice frameworks such as ISO 27701 and SOC 2.

1. Who we are and how to contact us

Geminum Pty Ltd is an Australian company based in New South Wales, providing digital twin and related analytics services through our Site Twin platform and associated consulting.

If you have any questions about this Privacy Policy or how we handle your personal information, you can contact:

Data Protection Officer (DPO): David Hynes, COO
Email: david@geminum.co
Phone: +61 409 026 637
Postal: Geminum Pty Ltd, NSW, Australia

2. What information we collect

We collect personal and technical information in the following categories:

2.1 Information you provide directly

  • Names (first name, last name, preferred name).
  • Contact details (email address, phone number, organisation name, country or region).
  • Job titles, roles and areas of responsibility.
  • Account details for the Site Twin platform (username, role, permissions, preferences).
  • Support requests, feedback and other communications you send to us.
  • Information contained in contracts, statements of work and related client documentation.

2.2 Information collected automatically

When you visit the Website or use the Services, we automatically collect certain technical and usage information, including:

  • IP address and approximate location derived from IP.
  • Device identifiers, operating system, browser type and settings.
  • Dates and times of access, pages viewed, links clicked and navigation paths.
  • Session information, performance and diagnostic data, error logs.
  • Cookies and similar technologies used for essential site operation, security and analytics (see section on Cookies and similar technologies).

2.3 Technical, asset-related and environmental data

In providing the Site Twin platform and related Services, we may process data about physical sites, equipment, processes and systems, which may include:

  • Sensor and telemetry data, equipment identifiers and configuration settings.
  • Asset inventories, maintenance records and related metadata.
  • Operational metrics, usage patterns and performance information.

This technical and asset-related data is usually not personal information on its own. However, it may become linked to individuals (for example, through user accounts, logs, or audit trails) and, in that case, we treat it as personal information and protect it accordingly.

2.4 Information we receive from third parties

We may receive information about you from:

  • Your employer or organisation, if they are our customer or prospective customer.
  • Partners, resellers or service providers that help us deliver or support the Services.
  • Publicly available sources (such as professional networking sites or public records) where permitted by law.

3. How we use your information

We use the information we collect for the following purposes:

  • To operate, maintain and improve the Website and the Site Twin platform.
  • To provide consulting, implementation and support Services to you or your organisation.
  • To create and manage user accounts and authenticate users.
  • To respond to inquiries, support requests and feedback.
  • To analyse usage of the Website and Services and develop new features.
  • To manage our relationship with customers and prospects, including contract administration, billing and collections.
  • To ensure security, monitor for fraud or abuse, and maintain audit logs.
  • To comply with legal obligations and respond to lawful requests (see section on compelled disclosures).
  • With your consent, to send you relevant updates, newsletters or marketing communications, which you may opt out of at any time.

4. Legal bases for processing (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we rely on one or more of the following legal bases:

  • Contract: processing is necessary to enter into or perform a contract with you or your organisation.
  • Legitimate interests: to operate and improve our Services, secure our systems, and manage our business, provided these interests are not overridden by your rights and interests.
  • Consent: where required (for example, certain marketing or cookies), which you can withdraw at any time.
  • Legal obligation: to comply with laws, regulations or court orders.

5. Cookies and similar technologies

We use cookies and similar technologies on the Website and in our Services to:

  • Enable core functionality such as session management and security.
  • Remember your settings and preferences.
  • Understand how visitors use the Website and Services so we can improve them.

You can usually configure your browser to block or delete cookies, but this may affect how the Website or Services function.

6. How we share your information

We may share personal information with:

  • Service providers and processors who help us operate, secure and support the Website and Services (for example, hosting providers, analytics providers, support tools and communications platforms). They are only allowed to use the information on our instructions and must protect it.
  • Your organisation if you use the Services as part of a corporate or institutional account.
  • Professional advisers (lawyers, auditors, insurers) where necessary for advice, audits, risk management or dispute resolution.
  • Regulators and law enforcement where we are legally required to do so, or where it is necessary to protect our rights, users or others (see section on compelled disclosures).
  • Business transfers: if we are involved in a merger, acquisition, restructuring or sale of assets, information may be transferred as part of that transaction, subject to appropriate protections.

7. International transfers

Geminum is based in Australia. We may store and process information in Australia and in other countries where we or our service providers operate, including the United States.

For individuals in Australia, we comply with the Australian Privacy Principles regarding overseas disclosures. Where we disclose personal information to an overseas recipient (for example, a hosting provider in the United States), we take reasonable steps to ensure that the recipient will handle the information in a manner consistent with the APPs, or otherwise in accordance with applicable law.

For individuals in the EEA, UK or other regions with data transfer restrictions, we use appropriate safeguards such as standard contractual clauses or other lawful transfer mechanisms where required.

8. Data subject and consumer rights

Depending on where you live and which laws apply, you may have some or all of the following rights in relation to your personal information:

  • Right of access: to obtain confirmation of whether we process your personal information and to access a copy.
  • Right to correction (rectification): to ask us to correct inaccurate or incomplete information.
  • Right to erasure (“right to be forgotten”): to request deletion of personal information, subject to legal or contractual retention requirements.
  • Right to restriction: to ask us to restrict processing in certain circumstances (for example, while we verify accuracy or assess an objection).
  • Right to data portability: to receive certain information in a structured, commonly used and machine-readable format and to request that we transmit it to another controller where technically feasible.
  • Right to object: to object to processing based on our legitimate interests, and to object at any time to direct marketing.
  • Right to withdraw consent: where processing is based on consent, you can withdraw consent at any time. This will not affect processing that has already occurred.
  • Right to non-discrimination (CCPA/CPRA): you will not receive discriminatory treatment for exercising your privacy rights.

Some of these rights may be subject to conditions, exemptions or limitations under applicable law. If we cannot meet your request, we will tell you why.

9. Submitting a privacy request (SAR/DSAR)

You can submit a Subject Access Request (SAR), Data Subject Access Request (DSAR) or equivalent privacy request using one of the following:

  • Email: david@geminum.co
  • A web form on the Website (where available).

9.1 Acknowledgement and response timelines

  • We aim to acknowledge receipt of your request within 10 business days.
  • We aim to respond in full within 30 calendar days of receiving a complete and verified request.

If your request is complex or we receive multiple requests from you, we may need more time as permitted by law. If that happens, we will let you know and explain the reason for the delay.

9.2 Identity verification

To protect privacy, we must verify your identity before we respond to a rights request. The level of verification depends on the type of request and the sensitivity of the information involved:

  • For most requests, we will use a reasonable level of certainty. This may involve verifying control of the email address associated with your account or asking you to confirm limited information we already hold.
  • For more sensitive requests (for example, access to detailed logs or technical records that could affect security), we may require a high degree of certainty. This could involve additional steps such as confirmation through your organisation, or other documentation as permitted by law.

If we cannot reasonably verify your identity, we may not be able to comply with your request. We will tell you if this is the case.

9.3 Requests via authorised agents (CCPA/CPRA)

If you are a California resident, you may authorise an agent to submit a request on your behalf under the CCPA/CPRA. We will require:

  • Proof that the agent is authorised to act for you (for example, a signed authorisation or power of attorney), and
  • Verification of your identity directly with us, unless the law allows us to rely solely on the agent’s verification.

10. CCPA/CPRA-specific information (California residents)

For residents of California, the CCPA/CPRA provides specific rights, including the right to know, delete and correct certain personal information, and the right to opt out of “sales” or “sharing” of personal information as those terms are defined in the law.

We do not sell personal information and we do not share personal information for cross-context behavioural advertising as defined under the CCPA/CPRA.

You may exercise your rights under the CCPA/CPRA by following the SAR/DSAR process described above or by contacting us using the details in section 1.

11. Security safeguards

We use technical and organisational measures to protect personal information against unauthorised access, use, alteration or destruction. These measures include:

  • Encryption of data in transit using modern transport layer security (TLS) protocols.
  • Encryption of data at rest in our core systems and storage platforms.
  • Access controls based on role and need-to-know, with authentication and authorisation mechanisms.
  • Logging and monitoring of access and activity on key systems.
  • Regular backups and resilience measures appropriate to the Services we provide.
  • Administrative controls such as policies, training and vendor due diligence.

No system can be completely secure. If we become aware of a data incident that affects your personal information, we will investigate and, where required by law, notify you and relevant authorities.

12. Retention and secure disposal

We keep personal information only for as long as reasonably necessary for the purposes described in this Policy, for our legitimate business needs, and to meet legal and regulatory obligations.

In general, client files and related records (including technical and asset-related information linked to a client engagement) are retained for up to seven (7) years from the end of the relevant engagement or the closure of the client account, unless a longer period is required by law or necessary for the establishment, exercise or defence of legal claims.

When information is no longer required, we take steps to dispose of it securely. Depending on the medium and system, this may include secure deletion, de-identification, or destruction of physical media in line with industry good practice.

13. Compelled disclosures and legal requests

We may be required by law to disclose personal information in response to lawful requests, such as warrants, subpoenas, court orders or requests from law enforcement or regulatory authorities. Where we receive such a request, we will:

  • Review the request to confirm that it is valid and legally binding.
  • Only disclose the minimum amount of information that is reasonably necessary to comply.
  • Where legally permitted, notify the affected customer or individual before disclosing information, or as soon as reasonably practicable afterwards.

14. Complaints and how to contact regulators

If you have a concern or complaint about how we handle your personal information, please contact our DPO first so we can try to resolve it:

Data Protection Officer: David Hynes, COO
Email: david@geminum.co
Phone: +61 409 026 637

We will acknowledge your complaint and aim to respond promptly. If you are not satisfied with our response, or prefer not to contact us first, you may have the right to lodge a complaint with a privacy regulator in your country or region.

14.1 Office of the Australian Information Commissioner (OAIC)

For individuals in Australia, you can contact the Office of the Australian Information Commissioner:

Website: www.oaic.gov.au
Phone (Australia): 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001, Australia

If you are in the EU, UK or another jurisdiction, you may also contact your local data protection authority. Details are usually available on the authority’s website.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements or other factors. When we make material changes, we will post the updated Policy on the Website and, where appropriate, notify you by email or through the Services. The “Effective date” at the top of this page shows when this Policy was last updated.