Privacy
ArcSolar Privacy Policy
Version 2026.09.1 · Effective 15 September 2026
This Privacy Policy explains how Arush Vandana Mittal trading as Argonix Digital (ABN 50 878 724 301) of 2608/344 City Road, Southbank VIC 3006, Australia (we, us, our) collects, holds, uses and discloses personal information in connection with the ArcSolar platform (Platform).
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy is written to satisfy APP 1.3 and to give notice under APP 5.
This policy forms part of, and is incorporated into, the ArcSolar Platform Subscription Agreement. Section 6 sets out in detail the telemetry and analytics information we collect about how the Platform is used. Please read it.
1. Who this policy covers
1.1 This policy covers three groups of people, whose information we handle in different capacities:
- Subscribers: the businesses that subscribe to the Platform, and the individuals who create and administer their accounts.
- Platform users: the employees, contractors, installers and agents a Subscriber authorises to use the Platform.
- End customers: the homeowners, occupiers and businesses that a Subscriber quotes, sells to, installs for or services using the Platform.
1.2 For Subscribers and Platform users, we decide the purposes for which information is handled, and we are accountable for it under this policy.
1.3 For end customers, the Subscriber decides what information is collected and why. We handle it on the Subscriber's behalf in order to provide the Platform. If you are an end customer and you want to access, correct or complain about your information, contact the business that quoted or installed your system in the first instance. We will assist that business to respond, and you may also contact us using the details in section 15.
1.4 Separately from the Platform, we handle information about visitors to our websites, people who contact us, and people who apply for a role with us. This policy covers that handling too.
2. The kinds of personal information we collect
2.1 Account and identity information: name, business email address, business telephone number, job title, role and permissions, profile photograph, password credentials in hashed form, multi-factor authentication status, and records of account creation, verification, sign-in, password reset and deactivation.
2.2 Business information: business name, Australian Business Number, trading name, business address, electrical and accreditation licence details, logo and branding, the products and services the business supplies, and the answers given during onboarding.
2.3 Billing and payment information: selected plan, billing contact, invoices, payment history, payment authority and mandate status, the last four digits and expiry of a payment instrument, bank account identifiers held by our payment processor, metered usage and the charges derived from it, refunds, failed payments, chargebacks and disputes. We do not store complete payment card numbers or full bank account credentials; those are held by our payment processor.
2.4 End customer information entered by a Subscriber: name, contact details, property address and geographic coordinates, property and roof characteristics, energy retailer and tariff, electricity consumption and bill information, site photographs and imagery, system design and product selections, quotations and pricing, finance and payment information, acceptance records, installation and service records, and notes recorded by the Subscriber's staff.
2.5 Communications content: the content and metadata of telephone calls, short message service messages, electronic mail and in-Platform messages sent or received through the Platform, including call recordings where the Subscriber has enabled them, call direction, duration, time, the numbers involved, message text, delivery status and message segment counts.
2.6 Support and feedback information: support requests, bug reports, diagnostic attachments, screenshots submitted with a report, survey responses and correspondence with us.
2.7 Technical and telemetry information: described in full in section 6.
2.8 Sensitive information: we do not seek to collect sensitive information as defined in the Privacy Act. A Subscriber should not enter health information, biometric information, or information about a person's racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record into the Platform. If sensitive information is entered, the Subscriber is responsible for having obtained the consent required by APP 3.3.
3. How we collect personal information
3.1 Directly from you, when you create an account, complete onboarding, configure your workspace, make a payment, contact support, or use the Platform.
3.2 From a Subscriber, when it enters information about its staff or its end customers into the Platform.
3.3 Automatically, through the operation of the Platform. Every interaction with the Platform generates records as described in section 6.
3.4 From third parties, including mapping and imagery providers, solar and property data providers, payment processors, identity and business registry services, telecommunications carriers, and publicly available sources.
3.5 Where we collect information about you from someone other than you, APP 5 requires us to take reasonable steps to notify you. Where a Subscriber enters your information into the Platform, the Subscriber is responsible for giving you that notice, and has agreed with us that it will do so.
4. Why we collect, hold, use and disclose personal information
4.1 We handle personal information for the following purposes:
- creating, authenticating, administering and securing accounts and workspaces;
- providing the Platform and its features to Subscribers and Platform users;
- enabling a Subscriber to quote, sell, install and service energy systems for its end customers;
- producing estimates, designs, documents and other outputs requested through the Platform;
- sending and receiving communications on a Subscriber's behalf;
- calculating, invoicing, collecting and substantiating fees and usage charges;
- verifying usage and defending payment disputes, chargebacks and reversals;
- detecting, investigating and preventing fraud, abuse, unauthorised access and breach of our terms;
- maintaining the security, integrity, availability and performance of the Platform;
- providing support and diagnosing and fixing faults;
- measuring how the Platform is used, and improving, developing and testing it and new products;
- communicating with you about the Platform, including service, security, billing and change notices;
- marketing our products and services, subject to section 9;
- complying with our legal, taxation, record-keeping and regulatory obligations; and
- establishing, exercising and defending legal claims.
4.2 We will not use or disclose personal information for a purpose other than the purpose for which it was collected, unless you would reasonably expect it, you have consented, or the use or disclosure is required or authorised by law.
5. Automated processing and generated outputs
5.1 The Platform uses automated processing, including machine learning and artificial intelligence services, to analyse imagery, model solar generation and savings, propose system designs, summarise records and communications, and generate documents and text.
5.2 Information may be transmitted to a third party artificial intelligence service provider for that processing. We select providers that contractually undertake not to use the information to train their general models, and we take reasonable steps to limit the information sent to what is necessary.
5.3 Outputs of automated processing are indicative only and are not a substitute for professional verification. No decision producing a legal or similarly significant effect about an individual is made solely by automated means without human involvement.
6. Telemetry, usage records and analytics
6.1 This section describes information we collect automatically about how the Platform is used. We collect it continuously and in detail. Collecting it is a condition of access to the Platform, and the Platform cannot be billed, secured or supported without it.
6.2 We record each discrete action taken in the Platform. For each action we may record:
- which workspace the action occurred in, which account and user performed it, and which session it belonged to;
- what the action was, identified by a registered action identifier, and which category of activity it falls into;
- which page or route it occurred on, and which feature was used;
- whether the action succeeded, failed or was denied, and any error code returned;
- the type and identifier of the record the action was performed on;
- when it occurred, how long it took, how long the user was actively engaged, and how many times an operation was retried;
- correlation and request identifiers that link the action in your browser to the processing of it on our servers;
- how many records were created, read, updated, deleted, selected, imported or exported;
- how the action was invoked, for example by mouse, keyboard, form submission or automatically by the system; and
- the stage of the workflow the action belonged to.
6.3 We also record technical information about the device and connection used, including internet protocol address, browser user agent string, browser and operating system, device class, screen and viewport characteristics, language and time zone, and the approximate geographic location derived from the internet protocol address.
6.4 We record consumption of metered and chargeable services, including telephone calls and their direction and duration, short message service messages and their segment counts, telephone number rentals, and requests made to mapping, imagery, solar analysis and artificial intelligence services, together with the charge attributable to each.
6.5 We record security and integrity events, including sign-in attempts and outcomes, permission checks, access denials, rate limiting, credential changes, administrative actions, and changes to workspace configuration.
6.6 We record acceptance of legal documents, including which document and version was accepted, a cryptographic hash of the exact text presented, the time of acceptance, the internet protocol address it came from, and the browser user agent.
6.7 Every record described in this section is bound at the point of collection to the workspace in which the action occurred, and is stored with that workspace identifier as an inseparable attribute. This means activity can be attributed to the responsible business, and that one business's records are separated from another's.
6.8 We use this information to calculate and substantiate charges; to prove access and consumption when a payment is disputed, charged back or reversed; to detect fraud, abuse and circumvention of usage limits; to secure the Platform and investigate incidents; to provide support and diagnose faults; to plan capacity and measure performance; to measure feature adoption and improve the Platform; and to meet our legal and record-keeping obligations.
6.9 We may disclose these records to a payment service provider, bank, card scheme, payment authority operator, debt collection agency, commercial credit reporting body, insurer, professional adviser, dispute resolution body, regulator or court, where it is necessary to substantiate a charge, recover a debt, or establish, exercise or defend a legal claim.
6.10 We retain records bearing on charges, payments and disputes for at least seven years from the end of the financial year to which they relate. Other telemetry is retained for as long as it is needed for the purposes described in clause 6.8.
6.11 Telemetry collected for billing, security, audit and integrity purposes cannot be switched off while the Platform is in use. Where we offer a setting controlling optional product analytics, a Subscriber may configure it in the Platform's settings.
6.12 We take steps to keep credentials, secrets, full identifiers and free-text content out of telemetry metadata, and we validate telemetry against a schema that rejects values which appear to be credentials, tokens, internet addresses or web addresses.
6.13 We create aggregated and de-identified statistics, benchmarks and models from this information. Aggregated and de-identified material does not identify you and may be used and disclosed for any purpose, including publishing industry benchmarks.
7. Cookies and similar technologies
7.1 We use cookies and similar browser storage to keep you signed in, maintain your session, remember your preferences, secure the Platform against cross-site request forgery, and measure use of the Platform and our websites.
7.2 Cookies that are strictly necessary for authentication, security and session management cannot be disabled without preventing the Platform from working. You can configure your browser to reject other cookies, though some features may then not function correctly.
8. Who we disclose personal information to
8.1 We disclose personal information to the following categories of recipient:
- the Subscriber whose workspace the information belongs to, and its authorised users;
- hosting, content delivery, database and storage providers;
- payment processing and payment authority providers;
- telecommunications and messaging carriers;
- mapping, imagery, property and solar data providers;
- electronic mail delivery providers;
- artificial intelligence and machine learning service providers;
- analytics, error tracking, observability and session diagnostic providers;
- our professional advisers, including lawyers, accountants, auditors and insurers;
- debt collection agencies and commercial credit reporting bodies, where an amount is overdue;
- a purchaser or prospective purchaser of our business, or a company we incorporate to carry on the business; and
- law enforcement agencies, regulators, courts and other parties, where required or authorised by law.
8.2 We require our service providers to handle personal information only for the purposes for which we engage them, and to protect it appropriately.
8.3 We do not sell personal information.
9. Direct marketing
9.1 We may use your business contact details to send you information about our products, services, features and offers, where you would reasonably expect it or you have consented.
9.2 Every marketing message includes an unsubscribe facility. You may opt out at any time by using it or by contacting us using the details in section 15. Opting out of marketing does not stop service, security, billing, legal or other operational messages, which are a necessary part of providing the Platform.
9.3 We do not use end customer information to market our own products to end customers.
10. Overseas disclosure
10.1 We host the Platform and its primary data stores in Australia. Some of our service providers are located overseas or process information overseas, including in the United States, the European Union and the United Kingdom.
10.2 Before disclosing personal information to an overseas recipient we take steps reasonable in the circumstances to ensure the recipient does not breach the APPs, ordinarily by contract. You should be aware that an overseas recipient may be subject to the laws of its jurisdiction, and that those laws may compel disclosure to a foreign authority.
11. Security and data breaches
11.1 We take steps reasonable in the circumstances to protect personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure. These include encryption in transit, access controls, tenant isolation at the database level, authentication requirements, audit logging and monitoring.
11.2 No system is completely secure. We cannot guarantee the security of information transmitted to or stored in the Platform, and security depends substantially on the controls maintained by Subscribers and their users.
11.3 If we become aware of an eligible data breach that is likely to result in serious harm, we will assess it and, where required by Part IIIC of the Privacy Act, notify affected individuals and the Office of the Australian Information Commissioner. Where the breach concerns end customer information, the Subscriber is responsible for notifying its end customers where the breach arises from the Subscriber's acts, omissions or systems.
12. How long we keep personal information
12.1 We keep personal information for as long as it is needed for the purposes described in this policy, and for as long as we are required to keep it by law.
12.2 Financial records, including invoices, payment records, usage records and dispute records, are kept for at least seven years from the end of the financial year to which they relate, as required by the Income Tax Assessment Act 1936 (Cth) and the Corporations Act 2001 (Cth).
12.3 Working solar imagery and analysis data obtained from a mapping provider is retained for no more than 30 consecutive days and is then removed from editable drafts and analysis storage, except where it has been incorporated into a fixed customer proposal or transaction record.
12.4 When a subscription ends, we make workspace data available for export for a limited period and then delete or de-identify it, except where we are required to retain it, or where it is needed to establish, exercise or defend a legal claim.
12.5 We take reasonable steps to destroy or de-identify personal information we no longer need, as required by APP 11.2.
13. Access and correction
13.1 You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details in section 15.
13.2 We will respond to a request within a reasonable period, ordinarily within 30 days. We may need to verify your identity before we do. We do not charge for making a request, though we may charge a reasonable cost-based fee for giving access.
13.3 We may refuse access or correction where the Privacy Act permits, for example where giving access would unreasonably affect another person's privacy, would reveal commercially sensitive information, or would prejudice an investigation or a legal claim. If we refuse, we will tell you why in writing and how to complain.
13.4 If you are an end customer, your information is held in the workspace of the business that quoted or installed your system. Direct your request to that business first. If you cannot reach it, or it does not respond, contact us and we will assist.
14. Complaints
14.1 If you believe we have breached the Australian Privacy Principles, contact us at hello@argonix.com.au setting out the details of your complaint. We will acknowledge it promptly and aim to respond substantively within 30 days.
14.2 If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, by telephone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.
15. Contact us and changes to this policy
15.1 Privacy enquiries, access and correction requests and complaints may be sent to hello@argonix.com.au, or by post to 2608/344 City Road, Southbank VIC 3006, Australia.
15.2 We may update this policy from time to time. The version in force is the one published on this page, identified by the version number and effective date shown at the top. Where a change materially affects how we handle your personal information, we will notify Subscribers by email or by prominent notice in the Platform.
15.3 We keep a record of each version of this policy and of the version accepted by each Subscriber.
This policy forms part of the Platform Subscription Agreement. If you are reviewing a proposal rather than subscribing, see the customer portal Terms of Use.
Privacy enquiries, access and correction requests and complaints can be sent to hello@argonix.com.au.
Document fingerprint (SHA-256): 489b5aa133b115d9e2d23ffd280e5a41f0b17a1408dcaab9f480248f1dad8048
© 2026, Argonix Digital.