Railway Engineering Solutions Pty Ltd (ACN 647 587 326) (RES, we, us orour) provides Trax, including its web, mobile, desktop and Model Context Protocol (MCP) connector services. This policy explains how we collect, hold, use and disclose personal information.
1. Information we collect and hold
Depending on how you and your organisation use Trax, this may include:
- account and contact details, such as your name, email address, organisation, role and authentication identifiers;
- project content, such as asset and cable records, documents, photos, comments, issues, work logs, forms, signatures and work instructions;
- location information attached to project records or media, including precise coordinates where your organisation collects them;
- activity, audit and technical information, such as actions taken, device and browser details, IP address, timestamps, diagnostics and security logs; and
- support messages and feedback that you choose to send, including a quote from your conversation only when you expressly approve its inclusion.
Project content may contain personal or sensitive information entered by your organisation. Your organisation controls what it collects in Trax and is responsible for having an appropriate basis to do so.
2. How we collect information
We collect information directly from you when you create an account, use Trax, connect an AI service, submit project content, or contact us. We also receive information from your organisation, authorised team members, devices and browsers, and service providers that support authentication, hosting, security and delivery.
3. Why we use information
We use personal information to:
- provide, operate and support Trax and its connector;
- authenticate users and enforce project and role permissions;
- store, synchronise, search and report on authorised project records;
- secure the Services, investigate incidents and maintain audit trails;
- respond to support requests and approved product feedback;
- improve reliability and functionality using aggregated diagnostics; and
- meet contractual and legal obligations.
4. How the AI connector handles data
The connector uses OAuth to act as the signed-in Trax user. You select the projects it may access and choose either a read-only or read/write connection. Tokens are bound to that selection; stored token records use cryptographic hashes rather than retaining the bearer token itself.
When an AI service calls the connector, Trax returns only the information needed to fulfil the authorised request. Results may include identifiers, project text, documents, images, work history and precise asset or media locations. The AI provider receives and processes those results under its own terms and privacy policy. Disconnect the connector if you no longer want that provider to request Trax data.
We do not silently submit conversation content as product feedback. The connector asks for your approval before sending feedback and separately asks before including a verbatim quote.
5. Who we disclose information to
We may disclose information to:
- your organisation and users it authorises;
- providers that host, secure and support Trax, including Google Cloud and Firebase;
- an AI provider you or your organisation connects, such as OpenAI or Anthropic, when it makes an authorised connector request;
- professional advisers and business service providers where necessary;
- authorities or other parties where required by law or reasonably necessary to protect rights, safety or security; and
- a successor in a merger, acquisition or reorganisation, subject to appropriate safeguards.
We do not sell personal information.
6. Overseas processing
Some service providers and connected AI providers process information outside Australia, including in the United States and other countries where they or their subprocessors operate. Those locations may change. We take reasonable steps to use providers and contractual protections appropriate to the information and service involved.
7. Storage, security and retention
We use access controls, encryption in transit, security monitoring and other technical and organisational safeguards designed to protect information. No system is completely secure.
We retain account and project information for as long as needed to provide Trax to your organisation, satisfy its configured records requirements, and meet contractual, security and legal obligations. Temporary authorisation records, operational logs and support records are retained only as long as reasonably needed for their purpose, then deleted or de-identified where practicable.
8. Access, correction and choices
You can update some information in Trax or ask your organisation’s Trax administrator to do so. You may also ask RES to access or correct personal information we hold about you. We may need to verify your identity and may decline a request where permitted by law, explaining why.
You can revoke an AI connector connection, narrow its project access, choose read-only access, and decline optional feedback or quote collection.
9. Privacy questions and complaints
Contact us through our contact form with “Privacy” in the message. Please include enough detail for us to investigate. We will acknowledge and respond within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner atoaic.gov.au.
10. Changes to this policy
We may update this policy as Trax, our providers or legal requirements change. We will publish the current version here and update the effective date. We will give additional notice of material changes where appropriate.
