Privacy Policy
Last updated 31 July 2026 · DRAFT
1. Who we are
PraxisIQ Orbit (“Orbit”, “the platform”) is operated by Bonnibel Pty Ltd (ABN 88 672 918 277) of Brisbane, Queensland, Australia (“we”, “us”). We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth).
This policy explains what personal information Orbit handles, why, and what you can do about it. Questions or requests: chris@bonnibel.com.
2. What Orbit is
Orbit is an internal marketing console. It is not a consumer product and there is no public sign-up. It is used by our own staff to capture marketing material, draft social media content with AI assistance, review and approve that content, publish it to our own business accounts on third-party platforms, and read back the resulting performance analytics.
Every Orbit account is created by invitation. Every page except this one, our terms, our data-deletion instructions and the sign-in screen itself requires an authenticated session.
3. Information we handle
3.1 Console user accounts
- Email address, and the authentication credentials held by our auth provider.
- Organisation, workspace and project membership, and the role attached to each membership.
- Session and sign-in records, including timestamps and IP address.
- A record of actions taken in the console, such as who approved or published an item.
3.2 Connected business accounts
When we connect one of our ownbusiness accounts on a third-party platform (Facebook Pages, Instagram professional accounts, X, Reddit), Orbit stores, through those platforms’ official APIs:
- The account or Page identifier, name and profile image.
- Access and refresh tokens issued to us by that platform, held encrypted and used only server-side.
- Content we have published or scheduled through Orbit, and the platform’s identifiers for it.
- Aggregate performance metrics returned by the platform — impressions, reach, engagement counts, follower totals and similar.
Orbit connects business Pages and professional accounts only. It never connects a personal Facebook profile, and it does not collect the personal information of the people who follow, like or comment on our accounts beyond the aggregate counts the platform returns.
3.3 Content we upload
Marketing material our staff put into Orbit — images, documents, notes, captions, campaign records and brand guidance. This is business content. If it happens to contain personal information (for example, a customer testimonial someone has given us permission to use), we handle it under this policy.
3.4 What we do not do
- We do not sell personal information, and we do not share it for advertising.
- We do not run advertising or tracking pixels inside the console.
- We do not buy or scrape personal information from third parties.
- We do not use content platforms return to us to build profiles of individual members of the public.
4. Why we handle it
- To authenticate users and control who can see and do what.
- To produce, review, approve and schedule our own marketing content.
- To publish that content to our own accounts, at our own direction.
- To measure how our own content performed and improve it.
- To keep the platform secure, diagnose faults and meet our legal obligations.
Human approval is mandatory. Orbit does not publish anything automatically. A person reviews and approves every item before it leaves the console.
5. AI processing
Orbit uses third-party AI services to draft and refine content. When it does, the material sent to the provider is the brief, the brand guidance and the marketing content we chose to include. Console user credentials and platform access tokens are never sent to an AI provider. We use these services under business terms that do not permit our content to be used to train their models.
6. Who we disclose information to
We disclose information to the service providers that run the platform:
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database and file storage |
| Vercel | Application hosting and delivery |
| Meta Platforms (Facebook, Instagram) | Publishing to and reading analytics from our own Pages and accounts |
| X Corp. | Publishing to and reading analytics from our own account |
| Publishing to and reading analytics from our own account | |
| AI providers | Drafting and refining content, as described in section 5 |
Some of these providers store and process data outside Australia, including in the United States and the European Union. We take reasonable steps to ensure they handle the information consistently with the Australian Privacy Principles.
We may also disclose information where the law requires it, or to protect our rights, property or safety.
7. Security
- All traffic to the console is encrypted in transit (HTTPS).
- Access to the console requires an authenticated session; every route is denied by default unless it is one of the public pages listed in section 2.
- Third-party platform tokens are stored encrypted, are only ever used server-side, and are never exposed to the browser.
- Access within the console is restricted by organisation, workspace and project membership and enforced in the database, not only in the interface.
- Credentials for our own infrastructure are held in an encrypted vault, outside the application.
No system is perfectly secure. If a data breach occurs that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
8. How long we keep it
- Console accounts — for as long as the person needs access, then deleted on request or when access ends.
- Platform tokens — until the account is disconnected or the token is revoked, then deleted.
- Content and analytics — for as long as they are useful as a record of our own marketing, unless deletion is requested.
- Operational and publishing logs — retained as a record of what was published and when.
9. Your rights
You may ask us to:
- tell you what personal information we hold about you and give you access to it;
- correct anything that is wrong or out of date;
- delete it — see our data-deletion instructions.
Email chris@bonnibel.com. We will respond within 30 days. There is no charge for making a request.
10. Complaints
If you think we have mishandled your personal information, contact us first at chris@bonnibel.com and we will investigate. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11. Changes to this policy
We may update this policy. The current version always appears at this address, with the date it last changed shown at the top.
12. Contact
Bonnibel Pty Ltd (ABN 88 672 918 277)
Brisbane, Queensland, Australia
chris@bonnibel.com