Who we are
Mitoma Systems is operated by Leva Nu Pty Ltd (ABN 20 694 850 747, ACN 694 850 747), of 5 Nerli Street, Everton Park, Queensland, Australia. Our Privacy Officer can be contacted at info@mitoma.systems.
This Privacy Policy explains how we handle personal information when you visit this website, contact us, request access, or use Mitoma Systems services under an agreed order form or account.
We generally act as a processor or service provider when we handle personal information contained in customer content on a customer's instructions. We act as an independent controller or equivalent responsible party for matters such as website operations, account administration, billing, security, legal compliance, and our business communications.
Personal information we collect
The information we collect depends on how you interact with us.
- Contact details, such as your name, email address, organisation, role, and any message you send us.
- Account and organisation details, such as users, roles, permissions, billing contacts, and workspace configuration.
- Product and support information, such as support requests, usage events, logs, audit records, evidence metadata, and operational diagnostics. Evidence metadata may include confidential project names, program identifiers, customer or supplier names, locations, and other engineering context.
- Customer content that you or your organisation chooses to submit, which may contain personal information about personnel, contractors, suppliers, or other people.
- Billing information handled by us or our payment providers, such as billing contacts, plan, subscription, purchase, credit, refund, invoice, tax, entitlement, usage-allowance, and payment-status metadata. Payment-card details submitted directly to a payment provider are not intended to be stored by Mitoma Systems.
- Technical information, such as IP address, device and browser details, referrer, timestamps, and security logs.
- Website analytics and performance information collected through Vercel Web Analytics and Speed Insights, such as page or route visited, referrer, approximate country, browser, device and operating system, network performance, and web-vital measurements. These services are configured to provide aggregated or anonymous measurements without third-party analytics cookies.
- Marketing preferences, such as whether you have opted in to updates or asked us not to contact you.
How we collect information
- Directly from you when you email us, request access, join a call, sign an agreement, or use the product.
- From your organisation when it creates or administers a Mitoma Systems workspace.
- Automatically from the website or product where logs, security controls, diagnostics, or essential service operations require it.
- From service providers such as payment, hosting, email, analytics, identity, or support providers when those services are enabled.
When information is required
You may browse the public website without creating an account. Fields marked as required on a contact, account, checkout, or support form are needed for us to respond, enter into or perform a contract, administer the service, or meet applicable legal requirements. If you do not provide that information, we may be unable to respond to the request or provide the relevant service.
Unless we tell you otherwise, other information is optional. We will explain any information that must be provided by law or for a particular contract when that requirement applies.
How we use information
- To operate, secure, support, and improve Mitoma Systems. Service improvement uses account, operational, support, or de-identified and aggregated information where appropriate; customer content is used only as described in the Customer content and confidentiality section and applicable customer terms.
- To respond to enquiries, provide demos, manage access requests, and communicate with customers.
- To administer accounts, workspaces, billing, subscriptions, onboarding, support, and service notices.
- To maintain auditability, evidence records, product integrity, security monitoring, and misuse prevention.
- To comply with legal, tax, accounting, export-control, procurement, and contractual obligations.
- To send marketing updates where permitted, with an unsubscribe option for commercial electronic messages.
Legal bases for EU and UK processing
Where the EU GDPR or UK GDPR applies, the legal basis depends on the activity and context. The main bases we rely on are set out below.
| Processing activity | Legal basis |
|---|---|
| Responding to enquiries, arranging demonstrations, and taking steps before an agreement | Your request and steps taken before entering into a contract; legitimate interests in responding to business enquiries. |
| Creating accounts and providing, supporting, or administering the service | Performance of a contract and our legitimate interests in operating and supporting the service. |
| Security logging, audit records, fraud or misuse prevention, diagnostics, and service improvement | Our legitimate interests in keeping the service secure, reliable, auditable, and effective, where those interests are not overridden by your rights. |
| Billing, invoicing, tax, accounting, and legal compliance | Performance of a contract and compliance with legal obligations. |
| Marketing communications | Consent where required, or our legitimate interests in relevant business-to-business communications where permitted by law. |
| Optional processing that we specifically ask you to approve | Consent, which you may withdraw at any time without affecting earlier lawful processing. |
Customer content and confidentiality
We process customer engineering inputs, requirements, files, mission descriptions, generated artifacts, evidence metadata, and decision traces only to provide, secure, support, and administer the services described in our agreements, and to meet applicable legal or contractual obligations.
We treat customer content and related evidence metadata as customer confidential information, whether or not it contains personal information. Access is limited to personnel and contracted providers with a legitimate business need, appropriate authorisation, and confidentiality obligations.
Ownership and permitted use of customer material are governed by our Terms of Service and any signed customer agreement.
AI and automation services
Where AI functionality is enabled, relevant customer content may be processed by contracted model or automation providers solely to deliver, secure, and support the functionality requested by the customer. Depending on the approved deployment, an enabled model route may use Microsoft Azure OpenAI Service, Amazon Bedrock, or a customer-controlled or customer-approved endpoint. The provider and deployment-specific controls are recorded in our Subprocessors page and applicable customer terms before customer data is sent.
We do not use customer content to train shared or public foundation models, and we do not permit a contracted provider to do so unless the customer expressly agrees in writing.
Model services may apply automated content-safety or abuse monitoring. Provider retention, residency, and any human-review conditions depend on the approved deployment, configuration, and contract. We only represent AI processing as zero-retention where that control has been confirmed and agreed in writing.
Automated processing and decisions
Mitoma Systems uses software rules and automated processing to support authentication, workspace permissions, security and misuse detection, policy screening, usage metering, subscriptions, paid entitlements, and access to product functions. These processes may use account, organisation, role, authentication, device, IP, usage, billing, entitlement, security, and policy-classification information and may affect whether an account, request, purchase, or feature is allowed, paused, limited, or sent for review.
You may contact info@mitoma.systems to ask for information about, or request review of, an automated account, billing, entitlement, security, or policy outcome. We may need to verify your identity and authority before discussing an account or organisation.
AI-assisted engineering functionality is not the final authority for decisions about a person, safety, certification, procurement, deployment, or operation. We do not configure our independent website, account, billing, or security processing to make a solely automated decision producing legal or similarly significant effects for an individual. A customer must not configure the Service for such a decision unless its agreement permits it and the customer has established the required lawful basis, notices, safeguards, and human-review rights.
Disclosure
We disclose personal information only where needed to provide the service, meet obligations, protect the service, or with consent.
- Service providers who help with hosting, cloud infrastructure, identity, email, support, analytics, payments, logging, security, and model or automation services where enabled. Our public Subprocessors page identifies the providers currently used or planned for an enabled production service.
- Customer administrators and authorised users inside your organisation, according to workspace permissions.
- Professional advisers, insurers, auditors, banks, payment processors, and legal or compliance advisers.
- Government, regulatory, law-enforcement, export-control, or court bodies where required or reasonably necessary.
- A buyer, investor, or successor in connection with a corporate transaction, subject to appropriate confidentiality controls.
Overseas disclosure
For the current marketing website and business communications, recipients and processing are likely to be located in Australia and the United States. For a customer service deployment, information may also be processed in the United Kingdom or a country within the European Economic Area where that location is selected and documented for the customer.
Our Subprocessors page identifies current providers, purposes, and likely processing locations. A customer-directed integration or deployment may involve another country only where identified in the applicable deployment documentation. We will update the register and this policy where practical before materially expanding our ordinary processing into another jurisdiction.
For high-assurance programs, data residency, sovereign hosting, and provider constraints must be specified in the signed order form, statement of work, DPA, or security schedule.
Security and retention
We use administrative, technical, and organisational measures designed to protect information, including access controls, least-privilege permissions, encryption in transit, logging, provider review, and security review appropriate to the service stage. Personnel access is limited to people with a legitimate business need and appropriate confidentiality obligations.
We determine retention periods by considering the type and sensitivity of the information, the purpose for which it was collected, the customer agreement and workspace configuration, security and audit requirements, backup cycles, dispute periods, and applicable legal, tax, and accounting obligations.
Customer content and account information are retained for the service term and the return, deletion, backup, or audit period agreed with the customer. Enquiry and support records are kept while needed to manage the relationship and related legal obligations. Billing and corporate records are retained for applicable statutory periods, while security logs are kept for periods proportionate to the risk and investigation need.
When information is no longer needed for a permitted purpose, we take reasonable steps to delete it or de-identify it, subject to lawful retention, backup integrity, legal holds, and technical limitations.
If an incident is an eligible data breach or otherwise requires notice, we will notify affected individuals and the Office of the Australian Information Commissioner or another applicable regulator as required by law.
Access, correction, and complaints
You may ask to access or correct personal information we hold about you by contacting our Privacy Officer at info@mitoma.systems or writing to 5 Nerli Street, Everton Park, Queensland, Australia. We may ask for information reasonably necessary to verify your identity, authority, and the scope of the request.
To make a privacy complaint, describe the conduct or decision you are concerned about, the personal information involved, and the outcome you seek, and send it to info@mitoma.systems or our postal address. We will acknowledge the complaint, investigate it fairly, and aim to provide a written response within 30 days. If we need more time, we will explain why and provide an expected response date.
If you are not satisfied with our response, or we do not respond within 30 days, you may be able to complain to the Office of the Australian Information Commissioner or another applicable privacy regulator. Access, correction, complaint, and external-review rights depend on the law that applies.
EU and UK data subjects
Subject to the EU GDPR or UK GDPR, you may have the right to access, correct, erase, restrict, or object to processing of your personal information, the right to data portability, and the right to withdraw consent. To exercise any of these, contact our Privacy Officer at info@mitoma.systems.
You may also lodge a complaint with your supervisory authority, such as the UK Information Commissioner's Office or an EU data protection authority. Where a restricted transfer requires a safeguard, we use a legally recognised mechanism such as an adequacy decision, the European Commission's standard contractual clauses, the UK international data transfer agreement or UK Addendum, or another applicable safeguard. Residency or sovereign deployment may reduce or avoid a transfer but is not, by itself, a legal transfer mechanism.
Direct marketing and children
Any commercial electronic message we send includes an unsubscribe option, and you can ask us to stop sending marketing at any time by contacting info@mitoma.systems.
Mitoma Systems services are intended for business users aged 18 years or older. We do not knowingly collect personal information from children.
Changes
We may update this Privacy Policy as Mitoma Systems changes. We will update the date above and, where the change is material, provide reasonable notice through the website, product, email, or contract channel.