180 Degrees IT SolutionsBack to App

Privacy Policy

Last updated: 2026-07-27

This Privacy Policy explains how 180 Degrees IT Solutions (“we”, “us”), an Australian company, handles information when you use Data Table. We aim to be straightforward about what we collect, why, and who else touches it. If something here is unclear, email [email protected].

1. What we collect

  • Account details: your name, email address, and (optional) profile image.
  • Authentication data: a scrypt-hashed password, session tokens, and — if you choose to enable them — a two-factor (TOTP) secret or a passkey (WebAuthn) credential. We never store passwords in plain text.
  • Your workspace content:the tables, rows, columns, views, comments, and files you or your team create. This is your content, organised into a workspace that is logically isolated from every other customer’s workspace.
  • Usage and security logs: request timestamps, IP addresses, and account-security events (sign-ins, exports, deletion requests) used to keep the service secure and to investigate abuse.

Data Table does not currently process payments in-app — there is no billing or payment-processor integration built into the product. If that changes, this policy will be updated before any card or billing data is collected.

2. Why we collect it

  • To provide the service and keep your workspace data available to you.
  • To authenticate you and protect your account.
  • To send transactional email you’ve triggered or opted into — workspace invitations, reminders, weekly digests, and automation notifications.
  • To diagnose bugs, investigate abuse, and improve the product.
  • To power the in-app AI features, when you choose to use them.

We do not sell your data, and we do not share it with advertisers.

3. Multi-tenant workspace isolation

Data Table is multi-tenant software: many customers share the same application, each inside their own workspace. Every table, row, column, view, and comment is scoped to a workspace, and access is checked at both the application and database layer so that one customer’s data is never visible to another customer’s workspace.

4. Third parties who process data on our behalf

We use a small number of vendors to run the service. We don’t sell access to your data to any of them — each is used for a specific operational purpose:

  • Anthropic (Claude API):when you use an in-app AI feature — AI chat, “Ask This Table”, AI-powered automations, or autonomous AI agents you’ve configured — the relevant prompt and the workspace data needed to answer it or carry out the action are sent to Anthropic’s Claude API to generate a response. Under Anthropic’s commercial API terms, this data is not used to train their models. AI features only run against data you or your workspace choose to expose to them.
  • SMTP2GO: our transactional email relay. It sends workspace invitations, reminder notifications, weekly digests, and automation emails on our behalf, from [email protected]. It does not send marketing email and holds no ongoing copy of your workspace content beyond what’s needed to deliver each message.
  • Hosting infrastructure: the application and database run in Docker containers on a VPS, deployed and managed through Coolify, our deployment platform. Coolify orchestrates deployments; it does not independently process your data outside that hosting role.

Operational secrets that protect this infrastructure — database credentials, our authentication signing secret, and our encryption keys — are stored in Azure Key Vault rather than in application code or plain configuration files. Key Vault is a secrets store for our own infrastructure; it does not itself hold customer workspace data.

5. Where your data is processed

Our application and database run on infrastructure we manage via Coolify. When you use an AI feature, the relevant prompt and workspace context are sent to Anthropic’s Claude API, which may process that data outside Australia as part of generating a response. We do not otherwise transfer your workspace content to overseas third parties.

6. Sensitive data protection

If your workspace stores sensitive personal information — for example names, email addresses, phone numbers, or health-related notes — a column holding that kind of data can be marked as a Sensitive Column. Values in a Sensitive Column are encrypted at rest using AES-256-GCM, and are masked by default whenever data is read (in the grid, in AI responses, in exports, and in shared views) — a user has to explicitly reveal a value, and have permission to do so, before it’s shown in the clear.

7. How long we keep it

  • Workspace content (tables, rows, columns, views) is retained while your workspace is active.
  • A deleted table is recoverable from “Recently Deleted” for 30 days, after which an automated nightly job permanently purges it.
  • Security/audit history (e.g. field-change history) is retained for around 90 days for accountability and troubleshooting.
  • Infrastructure backups are kept for a limited rotation window for disaster-recovery purposes only, and are not a substitute for the account-deletion request described below.

8. Your rights

  • Access and export: you can download a copy of the personal data we hold on your account — your profile, memberships, comments, notifications, and session/API-key metadata (never raw tokens or key secrets) — at any time from inside the app via /api/account/export.
  • Deletion: you can request deletion of your account via /api/account/delete. This immediately revokes your sessions and API keys, scrubs your comments, and anonymises your profile (name, email, and image) so it can no longer identify you. If you are the sole owner of a workspace, you’ll be asked to transfer ownership first, so the workspace isn’t orphaned for the rest of your team.
  • Correction: you can edit your profile details from your account settings at any time.
  • Workspace content:rows and tables in a workspace are shared work product, not individual personal data — deleting your account does not delete rows you contributed to a shared workspace, in the same way leaving a shared document doesn’t delete what you wrote in it. If you need specific workspace content removed, ask the workspace owner, who can delete it directly.
  • Complaints: if you believe we have mishandled your personal information, contact [email protected] first. You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

9. Cookies

We use a small number of cookies and equivalent local storage entries. These are essential for sign-in (session cookies) and for remembering your preferences (theme, layout density, zoom). We do not use advertising or cross-site tracking cookies.

10. Security

We encrypt data in transit (HTTPS/TLS), hash passwords with scrypt, encrypt Sensitive Column values and operational secrets at rest, and support two-factor authentication (TOTP) and passkeys on top of password sign-in. We apply standard hardening (rate limiting, Content-Security-Policy, HSTS). No system is perfectly secure, but we apply industry-standard security practices and keep improving them — we do not hold any formal security certification (e.g. SOC 2, ISO 27001) today, and don’t claim one.

11. Children

Data Table is a business tool, not intended for children under 16. We do not knowingly collect personal information from children.

12. Governing law

This policy is written to align with the Australian Privacy Act 1988(Cth) and the Australian Privacy Principles (APPs), which govern how we handle personal information as an Australian business. It does not make any representation about compliance with non-Australian privacy regimes (for example the EU GDPR or US state privacy laws) — Data Table is operated for 180 Degrees IT Solutions’ own customers, not marketed to EU or US consumers specifically.

13. Changes to this policy

If we make material changes, we will update the “Last updated” date above and, where appropriate, notify account holders by email. The current version is always available at /privacy.

14. Contact

Privacy questions or requests: [email protected]. See also our Terms of Service.