Critus

Privacy Policy

Last updated: 6 August 2026

1. Who we are

Critus Pty Ltd (ABN [ABN to be inserted]) ("Critus", "we", "us") provides in-situ X-ray diffraction measurement instruments and the software used to operate them. This policy explains how we handle personal information collected through this website and the operator console.

This policy is available on this page. We will give you a copy in another format free of charge if you ask.

2. What we collect

When you contact us. Your name, email address, organisation, and whatever you include in your message.

When you use the operator console. Your name and email address from your user account, and a record of actions you take through the console — including which instrument was accessed, when, and by whom. These records exist for security and auditing.

Technical information. Our hosting provider records standard server logs (IP address, browser type, pages requested, timestamps) for security and reliability.

We do not seek sensitive information, and we ask that you do not include it in enquiries. We use your information only for the purposes described in this policy, for a directly related purpose you would reasonably expect, where you consent, or where the law requires or authorises it. We do not sell personal information.

3. Cookies and browser storage

We use only the cookies and browser storage needed to operate the site:

NameTypePurposeDuration
authjs.session-tokenCookie — strictly necessaryKeeps you signed in to the operator consoleSession
authjs.csrf-tokenCookie — strictly necessaryProtects sign-in against cross-site request forgerySession
critus.cookie-consentBrowser local storage — not a cookieRecords that you have seen our storage notice, so we do not show it againUntil you clear site data

We do not use analytics, advertising or tracking cookies. If that changes, we will update this policy and ask for your consent first. You can clear or block cookies in your browser, but the operator console will not work without the authentication cookie.

4. How we use it

Marketing. If you ask us to, or if you are an existing customer, we may send you occasional updates about our products. Every such message identifies us and contains an unsubscribe link, and we action unsubscribe requests within 5 business days. You can also opt out at any time by emailing privacy@critus.com.au. We will not use your information for marketing if you have told us not to, and we never provide it to anyone else for their marketing.

5. Disclosure and overseas recipients

We disclose personal information to:

We do not disclose personal information to third parties for their own marketing purposes.

Where your information is stored. Our database, file storage and site hosting all run in the Asia Pacific (Sydney) region (ap-southeast-2). Personal information held in the operator console — including your account details and instrument access records — is stored in Australia.

Overseas access. Some services we rely on are not offered from the Sydney region. In particular, transactional email may be processed in Japan or in the United States, and content delivery networks cache page assets at edge locations worldwide.

Our service providers act on our instructions and are contractually restricted from using or disclosing your information for their own purposes. Where a disclosure to an overseas recipient occurs, we take reasonable steps before disclosing to ensure the recipient does not breach the Australian Privacy Principles — including by binding contractual commitments, restricting the data to what the recipient needs, and requiring encryption.

Under section 16C of the Privacy Act 1988 (Cth) we remain accountable to you for an act or practice of an overseas recipient that would breach the Australian Privacy Principles.

6. Security

We use access controls, encryption in transit, and audit logging to protect personal information. No system is completely secure, but we take reasonable steps to protect the information we hold and to destroy or de-identify it when it is no longer needed.

6A. How long we keep information

InformationHow long we keep it
Enquiry and contact form messages2 years from our last contact with you
Quotations and customer records7 years, to meet tax and contractual record-keeping obligations
Operator console account recordsFor as long as the account is open, then 7 years
Instrument access and audit logs7 years from the date of the session
Server logs90 days

We destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to keep it.

7. Access, correction and complaints

Access. You can ask for access to the personal information we hold about you. We will respond within 30 days, and will give access in the way you ask for if that is reasonable and practicable. There is no charge for making a request. If giving access involves significant work we may charge a reasonable cost-based fee, and we will tell you the amount before we incur it. If we refuse access, we will tell you in writing why, and how to complain.

Correction. You can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We will respond within 30 days. If we have disclosed the information to anyone else, you can ask us to tell them about the correction, and we will unless it is impracticable or unlawful. If we refuse to correct, we will tell you why, and you can ask us to attach a statement to the record noting that you consider it inaccurate.

Deletion. We will delete personal information we hold about you where we are not required to keep it. We cannot delete security and instrument-access audit records — we retain those for the periods set out in section 6A, because they are how we protect customer instruments, meet our obligations to customers, and defend against claims.

Anonymity. You can deal with us anonymously or under a pseudonym for general enquiries. We cannot provide an operator console account, a quotation, or product support without knowing who you are.

Complaints. If you are unhappy with how we have handled your information, contact us at privacy@critus.com.au. We will acknowledge your complaint within 5 business days and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner — oaic.gov.au, 1300 363 992, GPO Box 5218 Sydney NSW 2001.

8. Data breaches

We maintain a data breach response plan. If we suspect a data breach, we assess it promptly and in any event within 30 days.

If a breach is likely to result in serious harm to any individual whose personal information is involved, and we cannot prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, as required by Part IIIC of the Privacy Act 1988 (Cth) — the Notifiable Data Breaches scheme. Our notification will describe the breach, the kinds of information involved, and what we recommend you do in response.

If a breach involves, or may involve, unauthorised access to a customer's instrument or to data held on it, we will notify that customer without undue delay, whether or not personal information is involved, and provide the relevant audit records.

Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach where Article 33 requires it, and affected individuals where Article 34 requires it.

9. Security contact

To report a security vulnerability or a suspected compromise, email security@critus.com.au. We will acknowledge your report and keep you informed of our response.

10. Changes

We may update this policy. The version published here is the current one.

11. If you are in the European Union or the United Kingdom

Where the EU General Data Protection Regulation or the UK GDPR applies to our handling of your personal data, the following also applies.

Controller. Critus Pty Ltd (ABN [ABN to be inserted]), PO Box 1122, Bondi Junction NSW 1355, Australia, privacy@critus.com.au.

Representatives. Our representative in the European Union under Article 27 is [EU representative to be appointed]. Our representative in the United Kingdom is [UK representative to be appointed].

Legal bases. We rely on:

International transfers. Your personal data is transferred to Australia, which is not the subject of a European Commission adequacy decision. We rely on the Standard Contractual Clauses adopted by the Commission in Decision (EU) 2021/914, and for transfers from the United Kingdom on the UK International Data Transfer Addendum, supported by a transfer impact assessment. A copy of the clauses is available on request.

Your rights. You may request access to your personal data, and its rectification or erasure; restriction of processing; portability; and you may object to processing based on our legitimate interests (Articles 15 to 22). We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

Retention. As set out in section 6A.

Complaints. You may complain to the supervisory authority in your country of residence, place of work or place of the alleged infringement, or — in the United Kingdom — to the Information Commissioner's Office (ico.org.uk).

12. Contact

privacy@critus.com.au
PO Box 1122
Bondi Junction NSW 1355
Australia