Privacy Policy

This Privacy Policy was last updated on 25th August, 2026

1. General

This policy applies to Lander Systems Pty Ltd (ABN 21 664 176 845), With Momentum Pty Ltd (ABN 12 688 268 662) and Cloudfuse Pty Ltd (ABN 36 664 148 930). These entities commit to complying with the Privacy Act 1988 (Cth) and Australian Privacy Principles.

The policy explains how personal information is collected, used, disclosed and controlled. Using the website or services constitutes consent to these practices. Disagreement means you should not use their services.

Where Lander Systems holds or uses personal information provided by a Lander Customer about that Lander Customer's own clients (Customer Personal Information), Section 6 sets out how that information is handled and takes precedence over the general provisions of this policy to the extent of any inconsistency.

2. Definitions

Key terms include:

Personal information covers anything that identifies you or could reasonably do so.

Applications means the software products Lander Systems builds and maintains — currently Cloudfuse, Momentum and ActivitySource

Services means the implementation and ongoing support Lander Systems provides to Lander Customers in connection with the Applications.

Websites means landersystems.com and the web addresses through which the Applications are made available, namely admin.cloudfuse.net, dashboard.withmomentum.com and secure.activitysource.net

Lander Customer means a business or organisation that has entered into an agreement with Lander Systems for the supply of the Services.

Customer Personal Information means personal information that a Lander Customer, or someone acting on a Lander Customer's behalf, submits, uploads, enters or otherwise provides to Lander Systems through the Services about the Lander Customer's own clients, customers, contacts or other individuals. It is distinct from personal information Lander Systems collects about individuals in its own right, including a Lander Customer's own personnel who deal directly with Lander Systems.

Sub-processor means a third party engaged by Lander Systems to store, host or otherwise process personal information in order to provide the Services.

3. What types of Personal Information do we collect?

The company collects personal details (name), contact details (email, address, phone), profile details (username, password, preferences), technical details (IP address, browser type, location), usage records (cookies, website activity) and marketing preferences.

Where possible, anonymous or pseudonymous interaction is allowed, though this may limit access. Information is generally collected directly from individuals, though third-party sources may be used for legislative compliance (verification services, publicly available sources).

Personal information is collected when you access services, communicate with staff, or otherwise deal with the company. Only necessary non-sensitive information or consented sensitive information is solicited. Where collected from third parties without prior consent, the company takes reasonable steps to inform you.

This section describes personal information Lander Systems collects about individuals who deal with it directly. Customer Personal Information — personal information a Lander Customer provides to Lander Systems about the Lander Customer's own clients through use of the Services — is addressed in Section 6.

4. How do we store and protect Personal Information?

Physical files are secured in access-controlled premises. Electronic files are stored on protected systems accessible only through secure networks. All staff and contractors have confidentiality provisions in employment contracts.

The company takes reasonable steps to ensure collected information is accurate, up-to-date, complete and relevant. Information used or disclosed must meet these standards. Protection from misuse, loss, and unauthorised access is maintained. Information no longer needed is destroyed or de-identified, except where client records must be maintained.

Internet transmission cannot be guaranteed secure, so transmission risk rests with you. Third-party information supply and receipt are also at your own risk, with no warranties regarding their privacy practices.

The security measures described in this section apply equally to Customer Personal Information.

5. Why do we collect, hold, use, and disclose Personal Information?

Information is collected for stated purposes: facilitating interactions, responding to enquiries, providing services to clients, processing forms, storing information at third-party data centres, performing quality assurance and IT security, updating information, and complying with legal obligations.

Secondary use is permitted where reasonable to expect and related to primary purposes. Consent for other purposes is obtained when needed.

Information is disclosed to supply services to third parties, facilitate interactions, share with employees and contractors assisting with services, run anonymised analytics, improve services through anonymised reporting, respond to enquiries, update information, meet regulatory reporting requirements, comply with law, and for purposes identified at collection time. Disclosure extends to related bodies corporate, professional associations, and registration bodies with proper interest in the disclosure.

This section does not apply to Customer Personal Information, which Lander Systems collects, uses and discloses only as described in Section 6.

6. Personal information we process on behalf of Lander Customers

(a) Our role The Applications are how a Lander Customer submits, uploads or otherwise captures personal information about its own clients, customers or other contacts — for example, through forms and account administration functionality. In relation to that Customer Personal Information, Lander Systems acts as a service provider to the Lander Customer. The Lander Customer remains responsible for its own relationship with, and obligations to, the individuals whose Customer Personal Information it provides to Lander Systems, including under the Privacy Act 1988 (Cth) and any other applicable law.

(b) How we use and disclose Customer Personal Information Lander Systems only collects, uses, holds and discloses Customer Personal Information to provide, maintain, support and improve the Services, in accordance with the instructions of the relevant Lander Customer and the applicable services agreement, or as required or authorised by law. Lander Systems does not use Customer Personal Information for its own direct marketing, does not sell it, and does not otherwise use or disclose it for purposes unrelated to supplying the Services, except with the Lander Customer's consent or on a de-identified or aggregated basis for product improvement and analytics.

(c) Notice and consent The Lander Customer is responsible for ensuring it has all necessary notices, consents and legal grounds to provide Customer Personal Information to Lander Systems, including for any sensitive information (such as health information) contained in that data. Lander Systems relies on the Lander Customer's representations in the applicable services agreement that it holds these rights.

(d) Sub-processors and overseas transfer Lander Systems hosts the Applications, and stores Customer Personal Information, using Amazon Web Services (AWS) and Laravel Cloud as its primary infrastructure Sub-processors. Depending on the Application and the Lander Customer's configuration, Customer Personal Information may be processed and stored in Australia, the United States, the United Kingdom and Germany. Lander Systems requires its Sub-processors to protect Customer Personal Information consistently with this policy and applicable law, and remains accountable for their handling of that information as required by the Privacy Act 1988 (Cth). A current list of Sub-processors, including any change to the providers or countries named above, is available to a Lander Customer on request.

(e) Data breach notification If Lander Systems becomes aware of a data breach that has affected, or may have affected, Customer Personal Information, it will notify the relevant Lander Customer without undue delay and provide reasonably requested information and assistance to enable the Lander Customer to assess and, if required, notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

(f) Retention, return and deletion Lander Systems retains Customer Personal Information for as long as needed to provide the Services and in accordance with the applicable services agreement. On expiry or termination of a Lander Customer's agreement, Lander Systems will delete or return Customer Personal Information within the period specified in that agreement (or, if none is specified, within 90 days), except to the extent retention is required by law or the information exists in routine backups pending their scheduled deletion.

(g) Access, correction and complaints An individual who believes Lander Systems holds Customer Personal Information about them, and who wishes to access or correct that information or complain about how it has been handled, should in the first instance contact the relevant Lander Customer, which is best placed to respond given its direct relationship with that individual. Lander Systems will give the Lander Customer reasonable assistance to respond to such requests. If it isn't clear which Lander Customer to contact, or the Lander Customer can't be identified, contact Lander Systems using the details in Section 14 and Lander Systems will assist so far as reasonably practicable.

(h) Data Processing Addendum The detailed terms governing Lander Systems' handling of Customer Personal Information — including security standards, audit rights and specific sub-processor arrangements — are set out in the data processing terms incorporated into each Lander Customer's services agreement. This section summarises those arrangements and does not limit them.

7. Direct Marketing

Marketing communications via mail, email and social media require consent. Non-consent allows opt-out through contact details or opt-out facilities in communications. Personal data is not provided to other organisations for their direct marketing. Practices comply with Australia's Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth). Suspected violations should be reported to the company.

This section applies to marketing communications from Lander Systems to individuals with whom it has a direct relationship. It does not apply to Customer Personal Information, which Lander Systems does not use for its own direct marketing (see Section 6(b)).

8. Unsolicited information

Unsolicited information is retained only where reasonably necessary for services and you've consented or consent was impractical. Otherwise it's destroyed. Sensitive unsolicited information always requires consent before retention.

9. Overseas disclosure

Personal information may be shared with overseas service providers (IT, insurance, storage), representatives with consent, government bodies, regulators, law enforcement, and other entities identified at collection time.

Lander Systems' primary hosting and infrastructure providers are Amazon Web Services (AWS) and Laravel Cloud. Personal information is likely to be processed and stored in Australia, the United States, the United Kingdom and Germany.

Transfers use safeguards: agreements with overseas recipients confirming Privacy Act compliance and standard contractual clauses for transfers. Comparable obligations are imposed on overseas recipients.

You may refuse overseas transfer by contacting the privacy officer, acknowledging this may prevent website or service use.

Overseas transfer of Customer Personal Information is addressed specifically in Section 6(d).

10. Using our Website and cookies

Cookies are small data files stored on your device to improve experience. Three categories are used: functional cookies (operational improvement), analytics cookies (usage statistics), and advertising cookies (targeted advertising).

Cookies can be refused through browser settings, though this may limit website functionality.

11. Third parties

The website contains third-party links. These entities manage their own privacy practices, and you should review their policies. The company makes no representations about accuracy or completeness of third-party information and accepts no responsibility for third-party privacy practices. Integration with third parties doesn't imply endorsement.

A list of the Sub-processors engaged to help deliver the Services is available to a Lander Customer on request — see Section 6(d).

12. Data Retention

Personal information is retained as long as reasonably necessary for collection purposes, including legal, regulatory, tax and reporting requirements. Retention may extend if complaints or litigation prospects exist.

Retention periods consider information sensitivity, unauthorised use harm risks, processing purposes, alternative means availability, and applicable legal requirements. Anonymised information for research or statistics may be used indefinitely without notice.

Retention, return and deletion of Customer Personal Information on expiry or termination of a Lander Customer's agreement is addressed in Section 6(f).

13. Age of Consent

Websites and services are not intended for persons under 18. The company doesn't knowingly collect personal data from children. Inadvertent child information is deleted in accordance with law.

14. How you can access or correct Personal Information

This section applies to personal information Lander Systems holds about you as a result of your own dealings with Lander Systems. If your personal information has been provided to Lander Systems by a Lander Customer through its use of the Services, see Section 6(g).

The company maintains accurate, timely, relevant information. Requested copies of held personal information are provided per Australian Privacy Principles. Inaccurate, outdated, incomplete, irrelevant or misleading information is corrected on notification.

No charges apply for access or correction requests, though excessive volume may incur reasonable administration fees. Access or correction requests contact:

Privacy Officer for Lander Systems Post: GPO Box, 3645, Sydney, NSW Australia 2001 Email: [email protected]

Responses follow reasonable timeframes per the Act. Refused requests include reasons and complaint information where reasonable.

Identity confirmation documentation may be requested before information is released.

15. Making a complaint

Complaints about the policy or information handling should initially be directed to the company at the above details. Investigation follows the Act. Unsatisfied complainants may contact the Office of the Australian Information Commissioner. Complaints concerning Customer Personal Information should be directed as set out in Section 6(g).

16. Privacy Policy changes

The company may change this policy. The latest version on the website applies to all held personal information.

17. Further information

Further queries about the policy should contact the company. More information on the Act is available at www.oaic.gov.au.