Permitech Home

Legal

Privacy Policy

Last updated: 22 August 2026

1. About this policy

This Privacy Policy explains how Tenac Solutions Pty Ltd ("Tenac Solutions", "we", "us" or "our") collects, uses and discloses personal information in connection with Permitech, our public website and related support and business activities (the "Service").

Permitech is a hosted permit-to-work service used by organisations. Where an organisation provides your account, it decides who may use its workspace, which records should be collected and how its authorised users may access them. This policy should be read together with that organisation's own privacy notices and policies.

Questions about this policy may be sent to info@tenacsolutions.com, Western Australia.

2. Personal information we collect

Depending on how you use Permitech, we may collect:

  • account and work-profile information, such as your name, email address, phone number, organisation, role and access assignments;
  • permit-to-work information, including project and site records, locations, responsibilities, controls, competency evidence, approvals, signatures, comments and audit history;
  • documents, photographs, maps, utility information and other material that you or an authorised user uploads or links;
  • requests and results associated with enabled integrations, external providers and AI-assisted features;
  • technical, usage and security information, such as device and browser details, sign-in and access events, IP address, error diagnostics and feature activity; and
  • communications, feedback and support information that you send to us.

Permit and workplace records may contain information about other people. Only submit information that is relevant to the authorised work purpose and that you are permitted to provide.

3. How we collect information

We may collect personal information:

  • directly from you when you use or contact the Service;
  • from your organisation and its administrators when they create, invite, assign or manage users and work records;
  • from identity, mapping, utility, document, AI and other providers when an authorised feature is used; and
  • automatically from the Service and its security, audit and diagnostic systems.

4. How we use information

We may use personal information to:

  • authenticate users and enforce organisation, role, site, project and permit access;
  • provide permit workflows, evidence handling, collaboration, notifications, reports and authorised integrations;
  • protect the Service, prevent misuse, investigate errors and maintain security and audit records;
  • administer accounts, respond to support requests and communicate about the Service;
  • operate, maintain and improve the Service using appropriately controlled operational information; and
  • comply with applicable legal requirements and enforce applicable agreements.

5. AI-assisted and provider features

When an authorised user invokes an AI-assisted or external provider feature, Permitech may send the user's request and the minimum relevant permit context or evidence needed to perform that request. Permitech may record the request, provider response, citations, status and operational diagnostics so the result can be reviewed, traced and administered within the organisation.

AI-assisted and provider outputs do not make permit approvals or other final safety decisions. They must be reviewed against authoritative evidence by a competent person and do not replace statutory, workplace health and safety or other safety duties. Do not include unnecessary personal information in a request.

6. Organisation administrators and other users

Organisation administrators may invite, suspend and remove users; assign roles and access scopes; configure features; and access or manage records held for their organisation. Other authorised users may see personal information where their role and work scope permit it.

If your account is controlled by an organisation, contact its administrator first about workspace access, correction or removal. We may need to coordinate a request with that organisation and verify your identity before acting.

7. When information may be disclosed

We may disclose personal information:

  • to your organisation and its authorised users according to their roles and access scopes;
  • to hosting, identity, communications, document, mapping, utility, AI and other providers that help deliver an authorised Service feature;
  • to a recipient that you or your organisation directs us to contact or provide information to;
  • to professional advisers and service providers where reasonably required to operate, secure or support our business; and
  • where required or authorised by law, or where reasonably necessary to protect people, rights, property or the security of the Service.

We may also transfer information as part of a business restructure, financing, acquisition or sale, subject to applicable legal and contractual requirements.

8. Overseas processing

Our service providers and enabled integrations may process information outside Australia. Locations can vary by provider, service configuration and your organisation's chosen integrations. Where information is processed overseas, we take steps appropriate to the circumstances to manage privacy and security risks and comply with applicable requirements.

9. Security

We use technical and organisational measures designed to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Access to organisation data is controlled through authenticated accounts and assigned scopes.

No internet service can guarantee absolute security. You must protect your sign-in credentials, use only authorised devices and promptly report suspected unauthorised access to us or your organisation administrator.

10. Retention and deletion

We retain personal information for as long as reasonably needed to provide and secure the Service, maintain required operational and audit records, comply with applicable agreements and legal obligations, and resolve disputes. The applicable period depends on the record, organisation configuration and purpose for which it is held.

Deletion or de-identification may be subject to organisation instructions, backup cycles, audit integrity, legal holds and other lawful recordkeeping requirements.

11. Access, correction and privacy requests

You may ask for access to or correction of personal information that we hold about you. You may also make another privacy request available under applicable law. Contact info@tenacsolutions.com and provide enough detail for us to identify the relevant information. We may verify your identity and may need to consult the organisation that controls the relevant workspace.

A request may be limited or refused where permitted or required by law. If that occurs, we will communicate with you as required in the circumstances.

12. Website information and cookies

When you visit Permitech at https://primasite.tech, we may receive browser, device, network, referring-page and usage information. We use this information to operate, secure, diagnose and improve the website and Service.

Permitech and its identity or infrastructure providers may use cookies or similar storage for sign-in, security, session continuity and user preferences. Blocking necessary cookies may prevent authenticated features from working correctly.

Our website may link to third-party sites. Their privacy practices are governed by their own notices, not this policy.

13. Children

Permitech is a workplace service and is not directed to children. Do not create an account or submit personal information unless you are authorised by the relevant organisation and permitted to do so under applicable law.

14. Complaints and changes to this policy

You may send a privacy complaint to info@tenacsolutions.com. Please describe the issue and the organisation or workspace involved. We will assess the complaint and communicate with you about the response.

We may update this policy when our practices, providers or legal requirements change. We will publish the revised policy and update the date shown above. Where appropriate, we or your organisation may also notify account users of a material change.