Privacy Policy

Ravelation Pty Ltd (ACN 609 809 707) Effective 19 August 2026 | Version 1.0


1. About this policy

1.1 Who we are

Ravelation Pty Ltd (ACN 609 809 707) of 7 Gordon Avenue, Coogee NSW 2034, Australia (“Ravelation”, “we”, “us”, “our”) develops and licenses the Ravel data analytics plugin and the RavelSim systems dynamics platform, and contributes to the open-source Minsky application.

1.2 What this policy covers

This policy applies to personal information we handle across all of our services, including:

  • the marketing website at  marketing.ravelation.net;
  • the customer account and subscription service at  ravelation.net;
  • the Ravel plugin and RavelSim  software; and
  • our email, support and sales communications.

It explains what personal information we collect, why we collect it, who we share it with, how we hold it, and the rights you have in relation to it.

1.3 Our commitment

We handle personal information in accordance with the standards set by the Australian Privacy Principles

Where we handle personal information about individuals in the European Economic Area or the United Kingdom, we also comply with the General Data Protection Regulation and the UK GDPR.


2. What personal information we collect

We collect only what we need to run the service. The categories are:

2.1 Account and authentication information

Your name, email address and basic profile metadata. Account identities are managed on our behalf by Clerk. We do not store your password — authentication credentials are held by Clerk.

2.2 Billing and subscription information

Your billing name, email address, country, subscription plan, renewal status and transaction history.

We do not collect, see or store your credit card, debit card or bank account details. Payment instruments are collected and held by Paddle, our Merchant of Record. We receive only the transaction and subscription metadata described above.

2.3 Enquiry and correspondence information

Where you submit a form (training interest, consulting enquiry, support request, newsletter signup) or contact us by email, we collect the information you provide and our correspondence with you, so that we can respond and keep a record of the matter.

2.4 Usage and technical information

When you use our websites we collect page views, feature usage, approximate location derived from IP address, browser and device type, and server log data including IP address and timestamps. See section 6 for how this works and the choices you have.

2.5 Legacy subscriber information (Patreon migration)

If you are migrating from our former Patreon arrangement, we retain your email address and subscription history for the purpose of maintaining your grandfathered access during the 12-month transition period. We delete this information at the end of the transition period unless you have an active account with us.

2.6 Content you process in our software

Models, datasets and other content you create or load into the Ravel plugin or RavelSim are processed locally on your own device. We do not receive, transmit, store or have access to that content, and it never reaches our servers. If that content contains personal information, you remain responsible for it and this policy does not apply to it.

Where you voluntarily send us a model or dataset — for example, as an attachment to a support request — we handle it under section 2.3.

Where you voluntarily upload your model or dataset to the Ravelation Library, that data is stored within our cloud-hosted database, and made publically available when the "publish" checkbox is ticked. Such information is provided "as is", and Ravelation accepts no responsibility for its contents.

2.7 Information we do not collect

We do not collect sensitive information as defined in the Privacy Act (including health, biometric, racial or ethnic origin, political, religious or sexual orientation information). Please do not send us sensitive information.


3. How we collect personal information

We collect personal information:

  • directly from you — when you create an account, subscribe, submit a form, or contact us;
  • automatically — through analytics and server logs when you use our websites (section 6); and
  • from our service providers — Clerk provides account metadata and Paddle provides transaction and subscription metadata arising from your purchase.

Where it is reasonable and practicable, we collect personal information directly from you.


4. Why we collect, hold, use and disclose personal information

We use personal information for the following purposes:

PurposeWhat this involves
Providing the serviceCreating and authenticating your account, delivering licence entitlements, enabling access to the Ravel plugin and RavelSim
Billing and subscription managementProcessing your subscription through Paddle, managing renewals and cancellations, meeting tax and accounting obligations
SupportResponding to your enquiries, diagnosing technical issues, maintaining a record of the matter
Service communicationsSending essential notifications about your subscription, security, billing and technical changes
Marketing communicationsSending occasional product news and updates, where permitted and subject to your right to opt out (section 9)
Improving our productsUnderstanding which features are used and where the service is failing, using aggregated and de-identified usage data wherever possible
Legal and complianceMeeting our obligations under Australian law, enforcing our terms, and establishing or defending legal claims

We will not use or disclose your personal information for any other purpose unless you would reasonably expect it, you have consented, or we are required or authorised by law to do so.


5. How we hold and protect personal information

We hold personal information in electronic form on systems operated by us and by the service providers listed in section 7. We do not hold personal information in paper form.

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include:

  • encryption of data in transit using TLS across all of our websites and services;
  • delegating authentication to Clerk, so that we never hold your credentials;
  • delegating payment handling to Paddle, so that we never hold your payment instrument;
  • restricting internal access to personal information to those personnel who need it;
  • multi-factor authentication on administrative accounts; and
  • periodic review of our service providers’ security practices.

No method of transmission or storage is completely secure. While we take reasonable steps, we cannot guarantee absolute security.

5.1 Data breaches

We maintain a data breach response plan. If a data breach occurs that is likely to result in serious harm to any individual whose personal information is involved, we will assess it promptly and, where the Notifiable Data Breaches scheme applies, notify the affected individuals and the Office of the Australian Information Commissioner as required by Part IIIC of the Privacy Act.


6. Cookies, analytics and your choices

6.1 Essential cookies

Clerk sets cookies that are strictly necessary to sign you in and maintain your session. These cannot be disabled without breaking the service, and we do not ask for consent to them.

6.2 Analytics — cookieless by default

We use PostHog for product analytics, to understand which pages and features are used and to improve the service.

By default this runs cookieless. No cookies or other identifiers are stored on your device, and we cannot recognise you across visits.

6.3 If you accept analytics cookies

If you accept analytics cookies via our consent banner, we enable cookie-based analytics so that we can recognise return visits and understand user journeys over time.

You can change or withdraw your choice at any time using the  “Cookie preferences” link in the footer of every page. Withdrawing consent is as easy as giving it. If you withdraw consent, analytics reverts to cookieless operation.

6.5 Proxying

Analytics traffic is routed through our own domain using a reverse proxy. This is a technical measure to improve reliability and does not change what is collected or who receives it.


7. Who we disclose personal information to

We disclose personal information to the service providers below, only as needed to run the service. Each is bound by its own contractual and privacy obligations.

ProviderWhat they do for usInformation disclosedWhere they process it
ClerkAccount authentication and session managementName, email, profile metadataUnited States
PaddleMerchant of Record — payments, subscriptions, sales tax complianceName, email, billing address, transaction dataUnited Kingdom, European Union, United States
PostHogProduct and website analyticsUsage data, IP address, device and browser dataEuropean Union
BrevoEmail delivery, newsletter and enquiry follow-upName, email, message contentFrance (European Union)
GitHubHosting of our public repositoriesAny information you choose to submit when interacting with our repositoriesUnited States

Paddle acts as an independent controller of your payment information, not as our processor, and handles that information under its own privacy notice. Your purchase contract is with Paddle as Merchant of Record.

Your interaction with our public GitHub repositories is governed by GitHub’s own privacy statement.

We may also disclose personal information:

  • to our professional advisers (lawyers, accountants, auditors) under obligations of confidentiality;
  • to a purchaser or prospective purchaser in connection with a sale of our business or assets, subject to confidentiality;
  • where required or authorised by law, or to a court, regulator or law enforcement agency; and
  • where necessary to establish, exercise or defend a legal claim.

We do not sell personal information, and we do not disclose personal information to third parties for their own marketing purposes.


8. Overseas disclosure

We are likely to disclose your personal information to recipients located outside Australia.

Based on our current service providers, those recipients are located in:

  • the United States
  • the United Kingdom
  • the European Union (including France and Ireland)

The specific countries applicable to each provider are set out in the table in section 7.

Before disclosing personal information overseas, we take steps that are reasonable in the circumstances to ensure the recipient does not breach the Australian Privacy Principles, including contractual data protection commitments with each provider. You should be aware that we remain accountable under section 16C of the Privacy Act for acts and practices of these overseas recipients in relation to your information, except where an exception applies.


9. Direct marketing

We may send you marketing communications about our products, features and company news where you are an existing customer or subscriber and you would reasonably expect to receive them, or where you have consented.

You can opt out at any time. Every marketing email contains a working unsubscribe link, and you can also change your preferences in your account settings or by emailing [email protected]. We action unsubscribe requests within five business days, as required by the Spam Act 2003 (Cth).

Opting out of marketing does not stop service communications — essential notices about your subscription, billing, security or technical changes. These are part of the service and cannot be opted out of while you hold an account.

If you ask us to tell you where we obtained your information for marketing purposes, we will tell you within a reasonable period and free of charge.


10. How long we keep personal information

InformationRetention period
Account informationFor as long as your account is active, then 12 months after closure
Billing and transaction recordsSeven years from the end of the relevant financial year, as required by Australian tax and corporations law
Enquiry and support correspondenceTwo years from last contact
Marketing subscription recordsUntil you unsubscribe, plus a suppression record retained indefinitely so that we do not contact you again
Legacy Patreon subscriber dataUntil the end of the 12-month transition period
Analytics data12 months, in aggregated or de-identified form thereafter

When we no longer need personal information for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or de-identify it.


11. Accessing and correcting your personal information

11.1 Access

You may request access to the personal information we hold about you by emailing [email protected]. We will respond within 30 days. We do not charge for making a request; if a charge applies to providing access we will tell you in advance and it will not be excessive.

We may refuse access in the limited circumstances permitted by APP 12. If we refuse, we will tell you why in writing and how you may complain.

11.2 Correction

If information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it by emailing [email protected], or by updating it directly in your account settings. We will respond within 30 days and correct the information where we agree it needs correcting.

If we refuse to correct information, we will tell you why in writing, and you may ask us to attach a statement to the information noting that you consider it inaccurate.

11.3 Deletion

You may ask us to delete your account and associated personal information by emailing [email protected]. Note that deleting your account immediately terminates your access to the proprietary Ravel plugin and RavelSim, and that we may need to retain certain records (particularly billing records) for the periods set out in section 10.

11.4 Additional rights for EEA and UK individuals

If you are in the EEA or the UK, you also have rights to data portability, restriction of processing, objection to processing, and to lodge a complaint with your local supervisory authority. Contact us at [email protected] to exercise these rights.


12. Complaints

If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, we want to hear about it.

Step 1 — Contact us. Email  [email protected] with the words “Privacy Complaint” in the subject line, setting out what happened and how you would like it resolved. You can also write to us at Ravelation Pty Ltd, 7 Gordon Avenue, Coogee NSW 2034, Australia.

Step 2 — We acknowledge. We will acknowledge your complaint within five business days.

Step 3 — We investigate and respond. We will investigate and give you a written response within 30 days of receiving your complaint, setting out our findings and any action we propose to take. If we need longer, we will tell you why and when you can expect a response.

Step 4 — If you are not satisfied. You may refer your complaint to the Office of the Australian Information Commissioner:

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5218, Sydney NSW 2001

The OAIC will generally expect you to have raised the matter with us first.

If you are in the EEA or the UK, you may instead complain to your local data protection supervisory authority.


13. Children

Our services are intended for business and professional users and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact [email protected] and we will delete it.


14. Automated decision-making

We do not use computer programs to make, or to substantially assist in making, decisions about you that could reasonably be expected to significantly affect your rights or interests.

The Ravel plugin and RavelSim are analytical tools operated by you. Any decision you make using their outputs is your decision, not ours, and this policy does not apply to how you use them.


15. Changes to this policy

We may update this policy from time to time. The current version is always available at the links in the footer of our websites, and the effective date appears at the top of this page.

Where a change materially affects how we handle your personal information, we will notify account holders by email before it takes effect.


16. Contact us

Privacy enquiries and complaints[email protected]
Sales and billing[email protected]
PostRavelation Pty Ltd, 7 Gordon Avenue, Coogee NSW 2034, Australia
ACN609 809 707

We will respond to privacy enquiries within 30 days.