Legal
Data & Security Policy
Your operation's data is yours. This policy sets out who owns it, how we use it, how we protect it, and what we will never do with it.
Last updated: 12 July 2026
1. Scope
This Data & Security Policy explains how Cotton IQ handles the operational data you upload to or generate within the IQ1 platform (“Platform Data”) — including HVI classing data, harvester and picker records, agronomic inputs, RCTIs, financial returns, and the analysis produced from them. It sits alongside our Privacy Policy, which governs personal information more broadly. Where Platform Data includes personal information, both policies apply.
2. Your data is yours
As between you and Cotton IQ, you own the Platform Data you provide, and you retain all rights, title and interest in it. We do not claim ownership of your data. You grant us a limited licence to host, process and use that data solely to provide and improve the Services for you, as described in this policy.
3. What we do with your data
We use Platform Data to:
- map your bales back to the fields they came from and attribute quality and cost;
- generate your dashboards, visualisations, insights and recommendations;
- make your data available to the users and representatives you authorise;
- provide support and troubleshoot issues at your request; and
- maintain, secure, back up and improve the Platform.
4. What we will never do
- We do not sell your data to anyone, for any purpose.
- We do not share your individual results — your quality, yield or financial outcomes — with other growers, merchants, gins or third parties for their own purposes.
- We do not use your data to advantage another party in their dealings with you.
- We do not disclose your data except as you direct, or as required by law.
5. Aggregation and de-identification
We may create aggregated and de-identified information from Platform Data — for example, industry-wide or regional benchmarks — to operate, improve and develop the Services. Before any data is used in this way:
- it is aggregated across multiple operations and de-identified so that it cannot reasonably be used to identify you, your business or your fields; and
- it is never presented in a way that reveals an individual grower's results.
If we ever wish to use identifiable data for a purpose beyond providing the Services to you, we will seek your consent first.
6. Where your data is stored
We use reputable cloud infrastructure and service providers to host and process Platform Data. We aim to store data in Australia. Some providers may store or process data outside Australia; where that occurs we take reasonable steps to ensure it is protected to a standard consistent with Australian law. A current list of the categories of sub-processors we use is available on request at privacy@cottoniq.app.
7. How we protect your data
We apply technical and organisational security measures appropriate to the sensitivity of the data, including:
- Encryption — data is encrypted in transit (TLS) and at rest;
- Access controls — role-based access, so users only see the data they are authorised to see, with access to production systems limited to authorised personnel on a need-to-know basis;
- Authentication — secure credentials and support for strong authentication on accounts;
- Backups — regular backups to support recovery and continuity;
- Monitoring — logging and monitoring of systems for unusual activity; and
- Vendor diligence — service providers are selected and bound to appropriate confidentiality and security obligations.
No system can be guaranteed to be completely secure. We continue to review and improve our controls, and we ask that you help protect your account by keeping your credentials secure and notifying us of any suspected unauthorised access.
8. Data breach response
We maintain a data breach response plan. If we become aware of a breach affecting Platform Data, we will act promptly to contain and assess it. Where the breach is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
9. Retention and deletion
We retain Platform Data for as long as your account is active and as needed to provide the Services. On termination of your account, you may request a copy of your data and/or its deletion. We will return or delete Platform Data within a reasonable period after your request, subject to any legal obligation to retain certain records. Backups are overwritten on a rolling cycle.
10. Data portability
Your data should not be locked in. On request, we will provide your Platform Data in a common, machine-readable format so you can move it or use it elsewhere.
11. Contact
Questions about how we handle your data can be directed to privacy@cottoniq.app. This policy may be updated from time to time; the current version is always available at cottoniq.app/data-security.