Privacy Policy
Last updated: September 2026
1. Who We Are
Bitpool Pty Ltd (ABN 80 646 766 592) ("Bitpool", "we", "us", or "our") is an Australian company that provides an AI-powered building intelligence platform.
If you have any questions about this policy or your personal data, contact us at privacy@bitpool.com.
1.1 What This Policy Covers
This policy applies to www.bitpool.com and every Bitpool service reached at a bitpool.com address, including:
- Our website at www.bitpool.com, including the enquiry and application forms published on it.
- The Bitpool platform at app.bitpool.com, the web application through which customers view, analyse and report on their building data.
- The Bitpool mobile application, a companion client that provides access to that same platform from a mobile device.
References to "the platform" below cover the web application and the mobile application together, except where a difference is called out.
Bitpool is an enterprise business-to-business platform. Organisations — building owners, facilities and energy managers, and systems integrators — licence it under a commercial contract to analyse operational data from their own buildings and equipment. Accounts are provisioned during onboarding, by Bitpool or by the organisation's own administrator; the mobile application does not offer account creation, sells nothing, and takes no payment from individual users. It is a window onto data the organisation already licences.
1.2 Our Role: Controller and Processor
Our role differs depending on whose data is involved, and that determines who you should approach to exercise your rights.
- We are the data controller for personal information we collect in our own right: enquiries and applications submitted through our website, website analytics, and the account details of the people who use the platform.
- We are a data processor for the data a customer loads into their own Bitpool tenancy. That data belongs to the customer organisation, which decides what is collected and why, and we act on its instructions. Where you are an employee, contractor or occupant of one of our customers and your question concerns data held in their tenancy, we will direct you to that organisation and support them in responding to you.
2. Information We Collect
We collect the following categories of personal information:
2.1 Information you provide directly
When you submit a form on our website (partner application, building management enquiry, demo booking, early access request, career interest, or AI readiness assessment), we collect:
- Name
- Email address
- Company name (where provided)
- Job role (where provided)
- Your responses to form questions (e.g., organisation type, portfolio size, assessment answers)
- Whether you have opted in to receive marketing communications
2.2 Information collected automatically
When you visit our website, we may collect the following only if you have consented to analytics via our consent banner:
- Pages visited and sections viewed
- Approximate geographic location (city, region, country) derived from your IP address
- Browser type (derived from the user agent string)
- A random session identifier (stored in your browser's session storage for the duration of your visit)
We store a cryptographic hash of your IP address for analytics and security purposes. We do not store your raw IP address.
2.3 Information collected through the platform and mobile application
If you hold a Bitpool account, we collect:
- Account details — your name and work email address, provided when your organisation provisions your account.
- Authentication and activity records — sign-in events and platform audit records. You sign in to the mobile application with a username and password, with optional two-factor authentication.
- Content you enter — anything you type, paste or attach while using the platform, including the prompts you write for the AI features and the conversation history of an AI chat.
- Location, in the mobile application only — where you grant the permission, the application reads your device's location. You can decline it, or withdraw it later in your device settings, and the rest of the application continues to work. On the web application, site and equipment locations are not derived from you at all: they are entered by your organisation as part of its own data.
We do not collect, store or process voice or audio recordings. Where the mobile application asks for microphone permission, it is so that your device's own operating-system speech function can be used, and for nothing else. The conversion is performed by your device; only text reaches us, as an ordinary chat message. No recording of your voice reaches Bitpool or any of our sub-processors.
An AI answer can also be read aloud to you. That works the other way round: we send the text of the answer to our AI provider and receive synthesised speech back. Nothing recorded from you is involved.
The platform also holds your organisation's building operational data — equipment, data-point, site, floor and zone names, semantic tags, engineering units, and time-series measurements from sensors and meters. We process that data on your organisation's instructions. It is not personal information as a rule, although an organisation's own naming conventions can embed a person's name in a space or equipment name.
2.4 Information we do not collect
We do not use third-party advertising trackers, social media pixels, or marketing cookies. We do not use Google Analytics. Our analytics are hosted by us rather than by an analytics provider — the only third party involved is the geolocation lookup described under Who We Share Your Data With.
3. How We Use Your Information
We use personal information for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing the Bitpool platform and mobile application to you | Performance of our contract with your organisation |
| Using your device's location in the mobile application, where you grant the permission | Consent, which you may withdraw in your device settings |
| Generating the AI analysis, summaries and insights you ask for, from your organisation's own data | Performance of that contract |
| Keeping audit and usage records of platform and AI activity | Legal obligation, and legitimate interest in security and accountability |
| Responding to your enquiry or application | Legitimate interest (pre-contractual relationship) |
| Sending marketing communications (only if you opted in) | Consent |
| Website analytics (page views, section engagement) | Consent (via our analytics consent banner) |
| Security and fraud prevention (rate limiting) | Legitimate interest |
| Notifying our team of new enquiries | Legitimate interest |
| Complying with legal obligations | Legal obligation |
4. Who We Share Your Data With
We do not sell your personal information, and we do not share it with advertisers, data brokers, or any other third party for their own marketing purposes.
We use the following sub-processors. Each is engaged under a written agreement — see Our Commitments About Third-Party Processors below.
| Sub-processor | What it does for us | Where it processes your data |
|---|---|---|
| Amazon Web Services | Hosts our website, the platform, and all customer data | Sydney, Australia (ap-southeast-2) |
| OpenAI | AI inference, and text-to-speech where you choose to have a response read aloud | United States |
| Anthropic | AI inference — the Claude models in our approved set | United States |
| OpenRouter | AI inference gateway — routes an AI request to the model your administrator has selected | United States |
We also use two operational services that receive limited data:
- A team messaging platform, which delivers a notification to our team when you submit a form on our website. The notification contains your name, email address, company and enquiry type. Operated from the United States.
- A third-party IP geolocation lookup service, which converts an IP address into an approximate city, region and country for website analytics, where you have consented to them. Only the geographic result is stored; your raw IP address is not retained by us. This applies to our website only — it is not used by the platform or the mobile application.
The AI sub-processors receive data only when the AI features are used. Where you do not have access to those features, none of your data reaches an AI provider.
5. Artificial Intelligence Features
Our platform includes optional generative-AI features: a chat assistant that answers questions about your building data, on-demand analysis of a chart or table, narrative commentary in reports, scheduled insights, dashboard generation, spoken output, and suggested semantic tags for raw data points.
This section explains what those features do with your data, because they involve sending it to companies other than Bitpool.
5.1 What we send to the AI providers
When you use an AI feature, we send to the AI provider:
- The text of your prompt, and any file you attach to it.
- The conversation history of that AI chat, so the assistant can follow what you have already asked.
- The building operational data needed to answer it — sensor and meter readings, equipment and building structure, and similar telemetry belonging to your organisation — retrieved at that moment under your own access permissions. You cannot reach data through the AI features that you could not reach directly.
5.2 What we do not send
Your identity is not sent to the AI providers. Your name, email address and account identifier do not appear in the content we send them. We keep the link between you and the request in our own records, for audit and usage accounting, and it stays with us.
No voice recordings are sent, because none are collected. Where an answer is read aloud to you, we send the text of that answer to the provider and receive synthesised speech in return; nothing recorded from you is involved.
We do not intentionally send special-category personal data to the AI providers: no contacts, no health data, no financial records of individuals, no precise location, and no photographs. We say "intentionally" because, as above, we cannot control what a user chooses to type or attach.
We cannot control what you choose to type or attach. Please do not enter personal information about yourself or anyone else into an AI prompt unless your organisation has told you it is appropriate to do so.
5.3 Which models and providers
Your organisation's administrator selects which model the AI features use, from the set Bitpool approves. That set comprises models from two developers:
| Model developer | Models in the approved set | Reached via |
|---|---|---|
| Anthropic | Claude Opus 4.8, Claude Opus 4.6, Claude Sonnet 5, Claude Sonnet 4.5 | OpenRouter |
| OpenAI | GPT-5.2, GPT-5.4 Mini, GPT-4.1 Mini | The OpenAI API directly, and OpenRouter |
We pin model versions explicitly. The approved set is fixed and controlled: adding, changing or removing a model is a change to the platform, goes through our formal change control process, and triggers a review of this policy.
5.4 We do not train models on your data
Bitpool does not build, train, fine-tune or host any AI model of its own. We do not use your data, your organisation's data, or the AI output to train any model, and our AI providers are engaged on commercial terms under which they do not train on it either.
5.5 AI output is advisory
AI output is analysis for a person to read. The AI features make no automated decision about any individual, carry out no profiling or scoring of people, and cannot issue a control command to a building management system, plant or equipment. Output is returned to the person who asked for it, or delivered into that organisation's own reports and emails; it is never published, and never shown to another customer.
AI output can be wrong. Check it before you act on it.
5.6 What we keep
We retain a record of each AI interaction — who asked, for which organisation, when, which model was used, and the tokens consumed — together with the full content of the interaction: your prompt, the data supplied to the model, and the model's response. These records are held in Sydney with the rest of the platform data, and can be provided to your organisation on request.
AI interaction records are retained for three months, then deleted.
5.7 Controlling access to the AI features
Access to the AI features is set per user, in that user's access level, by your organisation's administrator. Where it is not granted, you cannot use the AI features. If you want your access changed, speak to your organisation's administrator, or contact us at privacy@bitpool.com.
Two things that access level does not govern, so that you are not misled about its reach. Your administrator can configure scheduled AI insights and AI tasks, which run to a schedule against your organisation's data rather than at any individual's request — so an organisation with those configured sends data to an AI provider whether or not you personally use the chat. And the AI features can be reached from the web application as well as from the mobile application.
We are honest about the limit of that control today: it operates per user rather than as a single switch for a whole organisation, and there is no in-application step at which an individual user consents separately before using the features. Both are on our roadmap — an organisation-level control, and an explicit consent step for the user — and we will update this policy when they ship.
6. Our Commitments About Third-Party Processors
We share personal information with a third party only where an executed written agreement is in place that sets out the security, confidentiality and privacy requirements for the transfer and processing of that information.
Every third party named in this policy is required, under that agreement, to:
- Provide protection of your data at least equivalent to the protection stated in this policy.
- Process the data only to provide their service to us, and for no purpose of their own.
- Refrain from selling, publishing or otherwise disclosing it, and from using it to train any model.
- Apply appropriate technical and organisational security measures, including encryption in transit and at rest.
- Assist us in responding to individuals exercising the rights set out below.
- Delete or return the data when the agreement ends.
We assess each vendor before engaging them, and review that assessment at least annually.
7. International Data Transfers
Bitpool is based in Australia. The platform and all customer data are stored and processed in Amazon Web Services' Sydney region (ap-southeast-2).
There is one exception: AI inference happens outside Australia. When an AI feature is used, the prompt and the data needed to answer it are sent to one of our AI sub-processors, which processes it and returns a response. The response, and a record of the exchange, are then stored back in Sydney. Every other part of the service keeps data in Australia.
Our AI sub-processors — OpenAI, Anthropic and OpenRouter — are all established in the United States. Inference itself is performed in the United States, the European Union, or another location in which those providers operate, depending on which model your administrator has selected and on how our gateway provider routes the request. We do not restrict inference to a single country, and we do not claim to. What we do control is which models are available: the set contains only models offered by the providers named above, it is fixed under change control, and it cannot change without a controlled decision and a review of this policy.
Notifications of website form submissions are also delivered to our team through a messaging platform operated from the United States.
Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards — Standard Contractual Clauses, or transfer to a country covered by an adequacy decision from the European Commission. Where personal information is disclosed outside Australia, we take the steps required by Australian Privacy Principle 8 to ensure the recipient handles it consistently with the Australian Privacy Principles.
If your organisation requires that its data never leave Australia, its users must not be granted access to the AI features, and no scheduled AI insight or AI task may be configured for it. Contact us and we will work through that with your administrator.
8. Data Retention
We retain personal information for no longer than necessary:
- Lead and enquiry data (name, email, company, form responses): Retained for up to 24 months from submission, then anonymised or deleted.
- Analytics data (page views, section engagement): Retained for up to 13 months, then automatically deleted.
- Blog view data: Retained for up to 13 months, then automatically deleted.
- AI interaction records (your prompt, the data supplied to the model, the model's response, and the usage metadata): Retained for three months, then deleted.
- Device location in the mobile application: Held only for the session in which it is used, and not retained afterwards.
- Account details and platform audit records: Retained for as long as your organisation holds an account with us. Where an organisation closes its account, it should export its data first: closed-account data is retained rather than deleted, and an organisation that wants it erased should ask us.
- Your organisation's building operational data: Retained for as long as your organisation holds an account with us, on its instructions. It is the organisation's data, and the organisation decides when it goes.
You can request deletion of your data at any time (see Your Rights below).
9. Browser Storage and Analytics
Our website does not use traditional cookies. We use the following browser storage technologies:
- Session storage (analytics): If you consent to analytics, a random session identifier is stored in your browser's session storage. This identifier is automatically deleted when you close your browser tab. It is used solely to group page views within a single visit.
- Local storage (consent preferences): Your consent choice (accept or reject analytics) is stored in your browser's local storage so that we remember your preference and do not ask again on each visit. This is strictly necessary for respecting your privacy choice.
- Local storage (admin only): If you are an authenticated administrator, an authentication token and display preferences are stored in local storage. These are strictly necessary for providing the admin service.
You can manage your analytics preferences at any time by clicking "Cookie Settings" in the footer of any page. You can also clear browser storage through your browser settings.
10. Your Rights
Under applicable data protection laws (including the EU General Data Protection Regulation and the Australian Privacy Act), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten").
- Right to restrict processing: Request that we limit how we use your data.
- Right to data portability: Request your data in a structured, commonly used, machine-readable format.
- Right to object: Object to processing based on legitimate interest, including for direct marketing.
- Right to withdraw consent: Where processing is based on consent (e.g., analytics, marketing communications), you may withdraw consent at any time. For analytics, click "Cookie Settings" in the footer. For marketing, use the unsubscribe link in any email or contact us directly.
To exercise any of these rights, email us at privacy@bitpool.com. We will respond within one month of receiving your verified request.
Where your request concerns data held in a customer's Bitpool tenancy, that organisation is the data controller and we act on its instructions. Approach that organisation directly. If you contact us instead, we will tell you who to approach and will assist them in responding, but we cannot alter or delete their data on your request alone.
11. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (HTTPS/TLS 1.2 or above) for all data transmitted to and from our website and platform, including every request we send to an AI provider.
- Encryption at rest using AES-256, with keys managed and protected through AWS Key Management Service.
- Hashing of IP addresses before storage.
- Access controls and authentication for database and administrative systems, and on every platform and AI endpoint.
- Rate limiting to prevent abuse of our forms and APIs.
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure.
12. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time, and we review it at least annually. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. We will additionally notify customers of changes to this notice and of the nature of those changes — including where we begin using personal information for a purpose not previously identified, such as engaging a new AI sub-processor. If we make significant changes to how we process your data, we will seek fresh consent where required.
14. Complaints
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority:
- Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- European Union: Your local Data Protection Authority (DPA). A list is available at edpb.europa.eu
15. Contact Us
For any questions about this Privacy Policy, your personal data, or to exercise your rights, please contact us at: