Vick Solutions Pty Ltd (Trading as Digital Roadmap) — ABN 34 657 016 487
Effective 21 May 2026 · Version 2.0
Vick Solutions Pty Ltd (trading as Digital Roadmap and operating the Roadmapp platform) is incorporated in Australia. We operate Roadmapp at app.roadmapp.com.au.
Privacy contact: hello@roadmapp.com.au
| Information | Why we collect it |
|---|---|
| Full name | Identify you within your organisation and display your name in the platform |
| Work email address | Account login, notifications, and support communications |
| Job title / role | Permission management |
| Phone number (optional) | Displayed in the team directory if provided |
| Password (hashed) | Authentication — passwords are never stored in plain text |
| MFA data | Account security where MFA is enabled |
Project records, tasks, milestones, RAID logs, timesheets, resource allocation, stakeholder details, and uploaded files. This data is owned by your organisation.
IP address (country/state level only), browser type, pages visited, error logs. Not used for advertising profiles.
| Processing activity | Lawful basis |
|---|---|
| Account creation and login | Contract performance (Art. 6(1)(b)) |
| Work and project data | Contract performance / Legitimate interests (Art. 6(1)(b), (f)) |
| Transactional emails | Contract performance (Art. 6(1)(b)) |
| Usage analytics and error logging | Legitimate interests (Art. 6(1)(f)) |
| Security and audit logging | Legitimate interests / Legal obligation (Art. 6(1)(f), (c)) |
When your organisation subscribes to Roadmapp, it is the data controller for all project and operational data entered into the platform. Vick Solutions Pty Ltd acts as the data processor for that data. A full Data Processing Agreement (DPA) incorporating EU SCCs (Module 2) and the UK IDTA is available.
| Sub-processor | Purpose | Data location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. (USA) | Database, auth, file storage | AWS ap-southeast-2 (Sydney) | DPA + SCCs / IDTA |
| Netlify Inc. (USA) | Web hosting and CDN | Global CDN (static assets only) | DPA + SCCs |
| Microsoft Corporation (USA) | Transactional email (Graph API) | Microsoft datacentres | Microsoft DPA + SCCs |
We provide at least 30 days’ notice before adding any new sub-processor that processes EU or UK personal data.
Transfers are protected by EU Standard Contractual Clauses (Module 2: Controller to Processor), Commission Implementing Decision 2021/914. We have conducted a Transfer Impact Assessment confirming Australian law does not unduly impair SCC protections.
Australia holds a UK adequacy decision under the UK GDPR (Section 17A, Data Protection Act 2018). No additional mechanism is required for UK→Australia transfers. Onward transfers to US sub-processors are covered by the UK International Data Transfer Agreement (IDTA).
| Data category | Retention period |
|---|---|
| Account and identity data | Active account duration; anonymised within 30 days of account deletion |
| Project and work data | Duration of subscription; export available 30 days post-termination |
| Usage / technical logs | Up to 12 months |
| Audit logs | Up to 3 years |
| Support communications | Up to 3 years |
TLS 1.2+ encryption in transit · AES-256 encryption at rest · bcrypt/Argon2 password hashing · Row-level security (RLS) · Role-based access control · MFA available · Audit logging with IP capture · Automatic session timeout.
Access · Correction · Deletion · Complaint to OAIC
| Right | Article | How to exercise |
|---|---|---|
| Access | Art. 15 | Download My Data in Profile settings, or email us |
| Rectification | Art. 16 | Update in Profile settings, or email us |
| Erasure | Art. 17 | Delete Account in Profile settings, or email us |
| Restriction | Art. 18 | Email hello@roadmapp.com.au |
| Portability | Art. 20 | Download My Data (CSV export) in Profile settings |
| Object to processing | Art. 21 | Email hello@roadmapp.com.au |
| Withdraw consent | Art. 7(3) | Email hello@roadmapp.com.au |
We respond to rights requests within 30 days. No fee charged unless the request is manifestly unfounded or excessive.
We use only strictly necessary and functional cookies — authentication session tokens, refresh tokens, and UI preferences. No advertising cookies, tracking pixels, or third-party analytics that profile individuals.
Privacy contact: hello@roadmapp.com.au
| Jurisdiction | Supervisory authority |
|---|---|
| Australia | Office of the Australian Information Commissioner (OAIC) — oaic.gov.au · 1300 363 992 |
| United Kingdom | Information Commissioner’s Office (ICO) — ico.org.uk · 0303 123 1113 |
| European Union | Your local national data protection authority — full list at edpb.europa.eu |