Privacy Policy

Floor 04 Pty Ltd trading under the registered business name Aperture Creative Solutions

Last updated: 1 July 2026

This Privacy Policy explains how Floor 04 Pty Ltd (ABN: 94 682 174 536) trading under the registered business name Aperture Creative Solutions (Aperture Creative Solutions, Aperture-CS, Aperture, we, us, our) collects, uses, discloses, stores and protects personal information when you access or use our client dashboard at app.aperture-cs.com and any related services made available through that dashboard (the Services).

This Privacy Policy is intended to be clear, practical and transparent. It is designed to help meet the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and to provide information relevant to the EU General Data Protection Regulation (GDPR) where personal data of people in the European Economic Area (EEA) or the United Kingdom is processed.

If you use the Services on behalf of a business, organisation, school or other customer, that organisation may also have its own privacy obligations to you and to its own end users.


1. Summary

In summary:

  • Aperture provides a web dashboard for business and organisation customers to manage access, view usage analytics, access administrative features and contact support.
  • We collect limited account, access, support, billing and technical information needed to provide and secure the Services.
  • Users sign in using Google or Microsoft OAuth. We do not provide password-based login for the dashboard.
  • Payments, where applicable, are processed by Stripe. We do not store payment card details.
  • We do not sell personal information.
  • We do not display third-party advertising in the dashboard.
  • Dashboard data is stored in Australia. Some third-party providers may process data in other countries as part of providing their services.
  • We use cookies and similar technologies that are necessary for authentication, security and core functionality.
  • You may contact us to request access to, correction of, or deletion of personal information, subject to legal and operational limits.

2. Who this policy applies to

This Privacy Policy applies to individuals who access or use the Services, including:

  • authorised users of a customer account
  • administrators who manage users, roles or permissions
  • billing or account contacts
  • people who contact us for support
  • people whose information may appear in usage, audit, account or support records connected with the Services

The Services are primarily designed for business and organisational use. If you are using the Services on behalf of a customer, the customer may control your access, role, permissions and use of certain features.

This policy applies to the Aperture client dashboard and related services made available through that dashboard. Other Aperture products, websites, apps, campaigns or client projects may have separate or additional privacy information depending on their design and purpose.


3. Our role

Depending on the context, Aperture may handle personal information in different roles.

For account administration, authentication, billing, support, security, analytics about the dashboard, and our own business operations, Aperture usually acts as the organisation responsible for deciding how and why personal information is handled.

Where a customer uses Aperture services to collect, manage, display or analyse information about its own users, staff, students, clients or customers, the customer may be responsible for deciding how and why that information is handled. In that case, Aperture may act as a service provider or processor for the customer, subject to our agreement with that customer.

Customers are responsible for ensuring they have appropriate notices, permissions and lawful bases for the data they provide to us or make available through the Services.


4. About the Services

The Services currently include a web dashboard that allows customers to:

  • view product and account information for products and services purchased from Aperture
  • invite, manage and remove authorised users
  • assign roles and permissions
  • view usage analytics and reporting for the customer’s products and services
  • export or download reports
  • access administrative settings
  • contact Aperture for support

We may add, remove or change dashboard features over time. This Privacy Policy applies to the Services generally, even if particular features change.


5. Personal information we collect

5.1 Information you provide

When you use the Services, we may collect personal information that you or the customer provide, including:

  • name
  • email address
  • company, school or organisation name
  • job title or role
  • account role, permissions and access level
  • user invitations and user management actions
  • support requests and messages
  • information included in support attachments, screenshots or descriptions, if you provide them
  • billing contact details, where applicable
  • any other information you choose to submit through the Services

Please do not include sensitive information in support requests unless it is necessary for us to help you.

5.2 Information from Google or Microsoft sign-in

The Services use OAuth sign-in through Google or Microsoft. When you sign in, those providers may share information with us, such as:

  • your name
  • email address
  • profile photo, if available
  • organisation domain
  • unique account identifier
  • authentication status and related account metadata

We use this information to create and manage your dashboard account, authenticate you, apply permissions, secure the Services and maintain audit records.

We do not receive or store your Google or Microsoft password.

5.3 Billing and payment information

Where paid subscriptions or invoices apply, we may collect and store information needed to manage billing and subscriptions, such as:

  • customer name
  • billing contact name and email address
  • billing address
  • subscription status
  • plan, entitlement or order details
  • invoice history
  • payment status
  • Stripe customer or subscription identifiers

Payments are processed by Stripe. Aperture does not store full payment card details. Stripe may handle card details and other payment information under its own terms and privacy practices.

5.4 Information collected automatically

When you access or use the Services, we may collect technical and usage information, including:

  • IP address
  • device information
  • browser type and version
  • operating system
  • approximate location inferred from IP address
  • timestamps
  • pages viewed
  • actions taken within the dashboard
  • authentication and access logs
  • session information
  • error logs
  • security, audit and diagnostic data

We use this information to operate, secure, monitor and improve the Services.

5.5 Cookies and similar technologies

We use cookies and similar technologies that are necessary for authentication, session management, security and core functionality.

These technologies help us keep you signed in, remember session state, protect the dashboard and detect unauthorised activity. If you block necessary cookies, the Services may not work properly and you may not be able to access the dashboard.

We do not use the dashboard to display third-party advertising.

If we introduce optional analytics, marketing or tracking cookies in the future, we will provide notices and choices where required by law.

5.6 Analytics and customer usage data

The dashboard may display analytics and usage information about a customer’s products and services.

Where practicable, analytics are designed to be aggregated, minimised or de-identified, and not to include information that directly identifies individual end users. Depending on the relevant product or service, analytics may relate to internal users, staff, students, customers, clients or other end users of the customer.

Customers are responsible for ensuring that they have appropriate privacy notices, consents, lawful bases and internal approvals for any information they provide to Aperture or make available through Aperture services.


6. Sensitive information

We do not intentionally collect sensitive information through the dashboard unless it is necessary for a particular support request, legal requirement, customer instruction or agreed service.

Sensitive information may include information about health, racial or ethnic origin, religious beliefs, political opinions, biometric information, criminal records or other categories of sensitive information under applicable law.

You should avoid submitting sensitive information through the Services unless it is necessary. If you provide sensitive information, you confirm that you have the authority and lawful basis to do so.


7. How we use personal information

We use personal information for the following purposes:

  • to provide, operate and maintain the Services
  • to create and manage accounts
  • to authenticate users through Google or Microsoft
  • to manage roles, permissions and access controls
  • to provide administrative dashboard features
  • to display, generate and export reports and analytics
  • to process billing, subscriptions and payment status
  • to respond to support requests
  • to communicate with customers and authorised users about the Services
  • to monitor usage, performance and reliability
  • to protect the security and integrity of the Services
  • to detect, investigate and prevent unauthorised access, misuse, fraud or security incidents
  • to maintain business records
  • to comply with legal obligations
  • to enforce our agreements and resolve disputes
  • to improve the Services, including usability, reliability and performance

We do not sell personal information.


8. Legal bases for processing for EEA and UK users

If the GDPR or UK GDPR applies, we process personal data under one or more of the following legal bases:

  • Contract: where processing is necessary to provide the Services, manage accounts, authenticate users, provide support or perform our agreement with a customer.
  • Legitimate interests: where processing is necessary for our legitimate interests or those of a customer, such as operating the dashboard, maintaining security, improving the Services, preventing misuse, generating business records and supporting customer administration.
  • Legal obligations: where processing is necessary to comply with laws, regulatory obligations, court orders or lawful requests.
  • Consent: where consent is required, such as for optional cookies or certain optional communications if introduced in the future.

Where we process personal data on behalf of a customer, the customer may be responsible for determining the applicable legal basis.


9. How we disclose personal information

We may disclose personal information to the following categories of recipients:

  • service providers that help us operate, host, secure and maintain the Services
  • authentication providers, including Google and Microsoft
  • payment processors, including Stripe
  • cloud infrastructure, content delivery, security and monitoring providers
  • email, support, administration and communication providers
  • professional advisers, including lawyers, accountants, insurers and auditors
  • related contractors or personnel who need access to support the Services
  • regulators, courts, law enforcement agencies or government authorities where required or authorised by law
  • another organisation involved in a merger, acquisition, restructure, sale of assets or similar transaction, subject to appropriate confidentiality protections

We require service providers to handle personal information only as needed to provide services to us and to apply appropriate security and confidentiality measures.


10. Key third-party services

The Services may use or integrate with third-party services, including:

  • Google and Microsoft for OAuth sign-in and authentication
  • Stripe for payment processing, billing and subscription management
  • Amazon Web Services (AWS) for infrastructure and hosting
  • Cloudflare for content delivery, performance and security services

These third parties have their own terms, policies and security practices. Where you use those services directly, your use is subject to their separate terms and privacy policies.


11. International data transfers

Dashboard data is stored in Australia.

If you access the Services from outside Australia, including from the EEA or the United Kingdom, your personal information may be transferred to and stored in Australia.

Some third-party providers may process personal information in countries outside Australia, the EEA or the United Kingdom as part of providing authentication, payment, hosting, security, support, analytics or infrastructure services.

Where required, we take steps designed to protect personal information in connection with international transfers. These steps may include:

  • using reputable service providers with privacy and security commitments
  • contractual protections
  • data processing agreements
  • standard contractual clauses or equivalent safeguards where required for EEA or UK transfers
  • access controls and technical safeguards
  • limiting the information transferred where practicable

Customers using the Services from outside Australia are responsible for ensuring their own use of the Services complies with any local privacy, data protection or sector-specific requirements that apply to them.


12. Data security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.

Security measures may include:

  • OAuth-based authentication through Google or Microsoft
  • role-based access controls
  • access logging and audit records
  • encryption in transit
  • network and infrastructure security controls
  • monitoring and diagnostic logging
  • least-privilege access practices
  • operational security procedures
  • service provider due diligence

No method of transmission, storage or electronic processing is completely secure. We cannot guarantee absolute security, but we work to maintain appropriate safeguards for the nature of the Services and the information we handle.


13. Data breaches

If we become aware of a data breach affecting personal information, we will assess the incident and take steps to contain, investigate and remediate it.

Where required by applicable law, including the Australian Notifiable Data Breaches scheme, we will notify affected individuals, customers, regulators or other relevant parties.

Customers must promptly notify us if they become aware of any unauthorised access, misuse or security issue involving the Services, their users or their account.


14. Data retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  • provide the Services
  • maintain customer accounts
  • support security and audit logging
  • manage billing and business records
  • provide support
  • comply with legal, accounting and tax obligations
  • resolve disputes and enforce agreements

Retention periods may vary depending on the type of information, the customer agreement, legal requirements and operational needs.

Customers may request deletion or purging of Customer Data. We will delete or de-identify data where we are reasonably able to do so and where we are not required or permitted to retain it by law, contract, security requirements or legitimate business record obligations.

Backup copies may persist for a limited period before being overwritten or deleted in accordance with normal backup processes.


15. Account deletion and access management

Authorised users can request account changes, access removal or deletion by contacting the customer administrator, using the dashboard support request feature, or emailing us at contact@aperture-cs.com.

If your account was created under a customer organisation, we may need to verify the request with the relevant customer administrator before making changes.

Customers can request account closure or data deletion by contacting Aperture through the dashboard support option or by emailing contact@aperture-cs.com.


16. Your rights and choices

16.1 Australia

You may request access to, or correction of, the personal information we hold about you.

You may also make a privacy complaint if you believe we have breached the Australian Privacy Principles or mishandled your personal information. We will consider and respond to your complaint within a reasonable time.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

16.2 EEA and United Kingdom

If the GDPR or UK GDPR applies, you may have rights to:

  • access your personal data
  • correct inaccurate personal data
  • request deletion of personal data
  • restrict processing
  • object to processing
  • request data portability
  • withdraw consent where processing is based on consent
  • lodge a complaint with a supervisory authority

Some rights may be limited depending on the circumstances, including where we process personal data on behalf of a customer, where we need to retain information for legal or security reasons, or where another lawful basis applies.

To exercise your rights, contact us using the details below. We may need to verify your identity and authority before acting on a request.


17. Children and minors

The dashboard is intended for authorised business and organisational users who are at least 18 years old.

We do not knowingly allow individuals under 18 to create a dashboard account or sign in to the Services. If you believe a person under 18 has accessed the dashboard, please contact us so we can investigate and take appropriate action.

Some Aperture services provided to customers may be used in environments involving students, schools or younger end users. Where that occurs, the customer is responsible for ensuring appropriate notices, permissions, lawful bases and safeguards are in place, unless otherwise agreed in writing.


18. Direct marketing

We may send service-related communications, such as account, security, billing, support or administrative notices.

We may also send limited business communications to customer contacts where permitted by law. You can opt out of non-essential marketing communications by using the unsubscribe option where available or by contacting us.

We do not use dashboard personal information for third-party advertising.


19. Anonymity and pseudonymity

Because the Services involve secure customer accounts, role-based access, authentication, audit logging and support, users generally cannot use the dashboard anonymously or under a pseudonym.

Where practical, we will consider requests to interact anonymously or pseudonymously for general enquiries.


20. Links and third-party websites

The Services may contain links to third-party websites or services. We are not responsible for the privacy practices, content or security of those third-party websites or services.

You should review the privacy policies of any third-party services you use.


21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will take reasonable steps to notify customers, such as by posting the updated policy on app.aperture-cs.com, notifying users through the dashboard, or contacting customer administrators.

The updated Privacy Policy will apply from the date it is published, unless a later effective date is stated.


22. Contact us

Privacy enquiries, access requests, correction requests, deletion requests and complaints can be sent to:

Aperture Creative Solutions
Floor 04 Pty Ltd trading under the registered business name Aperture Creative Solutions
ABN: 94 682 174 536
Email: contact@aperture-cs.com