Privacy policy
Last updated 2 October 2026
Tueora is built and operated by LJBStudios.com.au (“we”, “us”). This policy explains how we handle personal information when you visit tueora.com, try the demo, or use the Tueora service, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
What we collect
Account information. When you sign in with Microsoft we receive your name, work email address and organisation. We record which users belong to which workspace and their role.
Customer data. When your organisation connects Tueora, we process information about your devices and the people who use them: device names, hardware and software inventory, security and compliance state, policy settings, Windows event logs, Microsoft 365 users, groups and licences, Defender alerts and recommendations, and, if you connect a firewall, network clients, traffic flows and security events. Some of this is personal information about your staff.
Enquiries. If you contact us we keep your name, email, company and message.
Technical information. Our hosting providers log IP addresses, browser details and request times to keep the service secure and working. The Tueora app uses essential cookies to keep you signed in. This marketing site uses no advertising or analytics cookies.
How we collect it
- From you, when you sign up, use the app or contact us.
- From Microsoft 365 (Intune, Entra ID and Defender) after an administrator in your organisation grants consent.
- From the Tueora agent installed on your organisation's Windows devices.
- From your network equipment, if your organisation connects it.
Our role and yours
For customer data, your organisation decides what is connected and why, and we process it to provide the service on its behalf. Your organisation is responsible for telling its staff that devices and accounts are monitored and for having a lawful basis to do so. Where we hold personal information for our own purposes, such as account and billing details, we are responsible for it.
How we use it
- To provide, secure and support the Tueora service.
- To show your organisation its devices, policies, security and network.
- To bill for subscriptions and send service notices such as trial reminders.
- To answer enquiries.
- To improve the product, using aggregated information that doesn't identify anyone.
Who we share it with
We don't sell personal information or use it for advertising. We share it only with service providers who help us run Tueora, under contracts that require them to protect it:
- Supabase, for the database and sign-in (customer data is stored in Sydney, Australia).
- Vercel, for hosting the website and application.
- Microsoft, whose APIs we call on your organisation's behalf.
- An email delivery provider, for service and enquiry emails.
- A payment provider, for billing, when card payments are introduced.
We may also disclose information where the law requires it.
Overseas disclosure
Customer data is stored in Australia. Some of our service providers are based in, or operate infrastructure in, other countries, mainly the United States, and may process information there to deliver the service (for example, serving pages through a global network, or Microsoft's own cloud). We take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles.
Storage and security
- Data is encrypted in transit and at rest.
- Each customer's data is isolated from every other customer's at the database level.
- Credentials for connected services are stored in an encrypted secret store and never shown again after entry.
- Access by our staff is limited to what is needed for support and is recorded.
How long we keep it
We keep customer data while your organisation's account is active. Detailed operational data such as network flows, event logs and metrics is kept for limited periods, from hours to a year depending on the type. If a trial ends without a paid plan, the workspace pauses and its data is deleted 30 days later. When a subscription ends, we delete customer data within 30 days unless the law requires us to keep it longer. Enquiries are kept for as long as needed to respond and follow up.
Access and correction
You can ask for the personal information we hold about you, or ask us to correct it, by emailing hello@ljbstudios.com.au. If the information is customer data controlled by your organisation, we may refer you to your organisation's administrator. We will respond within 30 days.
Data breaches
If a data breach is likely to result in serious harm, we will notify affected organisations and individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
Complaints
If you have a concern about how we handle personal information, email hello@ljbstudios.com.au. We will acknowledge it within 5 business days and aim to resolve it within 30 days. If you are not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We may update this policy. We will post the new version here with a new date, and tell customers by email if a change materially affects how we handle their data.
Contact
LJBStudios.com.au, email hello@ljbstudios.com.au.