Legal
Data & Security Policy
Your operation's data is yours. This policy sets out who owns it, how we use it, how we protect it, and what we will never do with it.
Last updated: 24 September 2026
1. Scope
This Data & Security Policy explains how Cotton IQ handles the operational data you upload to or generate within the IQ1 platform (“Platform Data”) — including HVI classing data, harvester and picker records, agronomic inputs, RCTIs, financial returns, and the analysis produced from them. It sits alongside our Privacy Policy, which governs personal information more broadly. Where Platform Data includes personal information, both policies apply.
2. Your data is yours
As between you and Cotton IQ, you own the Platform Data you provide, and you retain all rights, title and interest in it. We do not claim ownership of your data. You grant us a limited licence to host, process and use that data solely to provide and improve the Services for you, as described in this policy.
3. What we do with your data
We use Platform Data to:
- map your bales back to the fields they came from and attribute quality and cost;
- generate your dashboards, visualisations, insights and recommendations;
- make your data available to the users and representatives you authorise;
- provide support and troubleshoot issues at your request; and
- maintain, secure, back up and improve the Platform.
4. What we will never do
- We do not sell your data to anyone, for any purpose.
- We do not share your individual results — your quality, yield or financial outcomes — with other growers, merchants, gins or third parties for their own purposes.
- We do not use your data to advantage another party in their dealings with you.
- We do not disclose your data except as you direct, or as required by law.
5. Aggregation and de-identification
We may create aggregated and de-identified information from Platform Data — for example, industry-wide or regional benchmarks — to operate, improve and develop the Services. Before any data is used in this way:
- it is aggregated across multiple operations and de-identified so that it cannot reasonably be used to identify you, your business or your fields; and
- it is never presented in a way that reveals an individual grower's results.
If we ever wish to use identifiable data for a purpose beyond providing the Services to you, we will seek your consent first.
6. Where your data is stored
Our main database is hosted in Sydney, Australia. Some of our service providers store or process data outside Australia; these providers and their locations are listed in section 7 of our Privacy Policy. Where that occurs, we take reasonable steps to ensure your data is protected to a standard consistent with Australian law.
7. How we protect your data
We apply technical and organisational security measures appropriate to the sensitivity of the data, including:
- Encryption — data is encrypted in transit (TLS) and at rest;
- Access controls — role-based access, so users only see the data they are authorised to see, with access to production systems limited to authorised personnel on a need-to-know basis;
- Authentication — secure sign-in using one-time email codes or links;
- Backups — regular backups to support recovery and continuity;
- Monitoring — logging and monitoring of systems for unusual activity; and
- Vendor diligence — service providers are selected and bound to appropriate confidentiality and security obligations.
No system can be guaranteed to be completely secure. We continue to review and improve our controls, and we ask that you help protect your account by keeping your credentials secure and notifying us of any suspected unauthorised access.
8. Data breach response
We maintain a data breach response plan. If we become aware of a breach affecting Platform Data, we will act promptly to contain and assess it. Where the breach is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
9. Retention and deletion
We retain Platform Data for as long as your account is active and as needed to provide the Services. On termination of your account, you may request a copy of your data. We will delete Platform Data in accordance with your Customer Agreement or, if there is none, within a reasonable period after your request, subject to any legal obligation to retain certain records. Backups are overwritten on a rolling cycle.
10. Data portability
Your data should not be locked in. On request, we will provide your Platform Data in a common, machine-readable format so you can move it or use it elsewhere.
11. Contact
Questions about how we handle your data can be directed to privacy@cottoniq.app. This policy may be updated from time to time; the current version is always available at cottoniq.app/data-security.