Skip to main content
  • Agile Geoscience
  • Mineral Exploration
    • Project Generation
    • Target Definition
    • Drill Testing
    • Resource Delineation
  • Technology
  • ExoSphere
  • Space
  • Company
    • About
    • Spacecraft
    • Team
    • STEM Program
  • Solutions
    • Project Generation
    • Target Definition
    • Drill Testing
  • Our Approach
    • Agile Geoscience
    • Mineral Exploration
    • Technology
    • Space Exploration
    • Defence
  • ExoSphere
  • Comet
  • Resources
  • Stories
  • Newsroom
  • Careers
  • Events
  • Contact

Legal

Quicklinks

  • Privacy Policy
  • Quality Policy
  • Whistleblower and Complaints Policy
  • Vulnerability Disclosure Policy

Privacy Policy

1. About this policy

Fleet Space Technologies Pty Ltd (Fleet Space, we, us) is committed to handling personal information responsibly. This policy explains what we collect, why we collect it, how we use and share it, and the rights you have.

It applies to our websites (including fleet.space, exosphere.fleet.space and comet.fleet.space), our products and services (including ExoSphere and Comet), and our dealings with customers, suppliers, job applicants and others who interact with us.

We comply with the Privacy Act 1988 (Cth) (as amended), and the General Data Protection Regulation (GDPR) where it applies to you.

2. What is personal information

Personal information means information about an identified or reasonably identifiable individual. This broadly aligns with “personal data” under the GDPR. Some personal information is treated as sensitive information (or “special category data” under the GDPR) and receives additional protection.

3. Information we collect

The information we collect depends on how you interact with us.

3.1 Information you provide

  • Customers and leads: name, email, phone number, address, job title, and records of your enquiries, preferences and survey responses.
  • Job applicants and contractors: details in your CV, interview notes, pre-employment checks and government identifiers such as Tax File Numbers.
  • Suppliers and partners: contact details, banking information for payments, and business details relevant to our relationship.
  • Support and enquiries: any information you share when contacting us for feedback or support.

3.2 Product and platform data

When you use our platforms we collect:

  • Account credentials: usernames and authentication data.
  • Telemetry and metadata: feature usage, session duration and performance metrics.
  • Project context: information you enter to configure your services (for example, site names or deployment coordinates).
  • Collaboration data: communications sent through our platforms to our support or account teams.

3.3 Automatically collected technical data

When you visit our websites we automatically collect:

  • Device and connection data: IP address, device type, unique identifiers, browser version and operating system.
  • Behavioural data: referring sites, pages viewed, time on page and navigation paths.
  • General location derived from your IP address.

3.4 Sensitive information

We generally do not collect sensitive information. We may do so in limited circumstances, including:

  • Employment: citizenship, residency, criminal history or professional memberships where needed for export controls, national security checks or working-with-children requirements.
  • Wellbeing: health or dietary information you voluntarily provide for your safety at our sites or events.
  •  CCTV: images captured by security cameras at our physical offices.

4. How we collect your information

We usually collect personal information directly from you — when you use our websites or services, apply for a role, contact us, or subscribe to our communications. Where reasonable, we only collect information directly from you.

In some cases we collect information from third parties, such as publicly available sources, organisations we do business with, or referees you have nominated.

You can deal with us anonymously or under a pseudonym for general enquiries where we do not need to respond to you personally. For most interactions, however, we need some contact details to assist you.

5. Why we collect, use and disclose information

We collect, use and disclose personal information to:

  • Provide and improve our products, services and websites;
  • verify your identity and communicate with you;
  • Consider you for employment or contractor engagements;
  • Manage our supplier, customer and partner relationships;
  • Address complaints or disputes;
  • Send direct marketing (see section 10);
  • Meet our legal and regulatory obligations.

Our legitimate interests include operating and securing our business, marketing our products and services, and managing our commercial relationships. 

Where the GDPR applies, we rely on one of the following lawful bases: your consent, performance of a contract with you, compliance with a legal obligation, or our legitimate business interests.

If we cannot collect the personal information we need, we may not be able to provide you with our products, services or opportunities.

6. Use of artificial intelligence

We use a range of AI and machine-learning tools to support our operations — including generative AI platforms for content and code, AI-powered systems for geophysical data interpretation, and AI-assisted support and communication tools. Our AI toolset evolves over time.

When we use AI tools, we:

  • Only provide personal information where necessary for a legitimate business purpose;
  • Select providers based on their privacy, security and data-handling commitments, and apply technical and contractual safeguards;
  • De-identify personal information before use where practical;
  • Do not rely on AI to make fully automated decisions that significantly affect individuals without human oversight;
  • We maintain human-in-the-loop oversight to review AI outputs for accuracy and fairness before they are used to inform significant business decisions.

7. Automated decision-making

We do not use automated systems to make decisions that significantly affect your rights or interests without meaningful human involvement.

8. Sharing your information

We may share your personal information with:

  • Our related companies;
  • Service providers who support our business — including cloud hosting, payments, IT and cyber security, analytics, marketing, logistics and professional advisers;
  • Third parties you have authorised us to share information with (for example, referees);
  • A potential buyer of our business or assets, and their advisers;
  • Any other party where required or permitted by law.

We take reasonable steps to ensure service providers handle your information consistently with this policy and applicable law. Where the GDPR applies, we require processors to act only on our written instructions and to apply appropriate safeguards.

9. Overseas disclosure

We store personal information in Australia and may disclose it to overseas service providers and affiliates, typically in the United States, and to our related companies in Canada, Luxembourg, Chile, Zambia and Saudi Arabia. Subject to exceptions under the Privacy Act, we take reasonable steps to ensure overseas recipients comply with the Australian Privacy Principles.

Where the GDPR applies, we only transfer your personal information outside the EU/EEA where the European Commission has made an adequacy decision or we have implemented appropriate safeguards, typically the European Commission's Standard Contractual Clauses. You can request a copy of the relevant safeguards by contacting us. .

10. Cookies and tracking

Our websites use cookies, web beacons and similar technologies to operate the site, remember your preferences, measure usage and support marketing. We use analytics providers such as Google, HubSpot and Webflow, which may set their own cookies — those cookies are subject to the providers’ own privacy policies.

Some parts of our websites may not work as intended if you do. Where required by law, we ask for your consent before setting non-essential cookies. You can withdraw consent or adjust your preferences at any time via our cookie settings or your browser. Some parts of our websites may not work as intended if you do.

11. Direct marketing

We may send you marketing communications by email, SMS, mail or phone where you have consented or where we are otherwise permitted to do so under the Privacy Act and the Spam Act 2003 (Cth). You can opt out at any time using the unsubscribe link in our emails or by contacting us (see section 17).

12. How we protect your information

We maintain an information security management system aligned with ISO/IEC 27001 and review our controls regularly. Our measures include encryption in transit and at rest, access controls and authentication, network monitoring, patching and backup, staff training, vendor due diligence, and incident response and breach notification procedures.

No system is perfectly secure. While we take reasonable steps to protect your information, we cannot guarantee the security of information transmitted over the internet. If you believe your information has been compromised, please contact us immediately.

Where an incident qualifies as a notifiable data breach, we comply with our obligations under the Notifiable Data Breaches scheme and, where relevant, the GDPR.

13. How long we keep your information

We retain personal information only for as long as necessary for the purposes it was collected, or as required by law. Typical retention periods are:

  • unsuccessful job applicants: up to 2 years;
  • employees and contractors: up to 7 years after the engagement ends;
  • suppliers, customers and partners: up to 7 years after your last interaction with us;
  • marketing contacts: until you ask us to stop, plus a short period to action your request (we keep a record of opt-outs indefinitely to honour them).

We may retain information for longer where needed to meet legal obligations, resolve disputes or maintain security. When no longer required, we delete or de-identify the information.

14. Your rights

You can ask us to:

  •  access the personal information we hold about you;
  •  correct information that is inaccurate, out of date or incomplete;
  •  stop using your information for direct marketing;
  • make a complaint about how we have handled your information.

We may need to verify your identity before acting on a request. We will acknowledge your complaint promptly, investigate it, and respond to you with our findings, usually within 30 days. 

15. Additional rights under the GDPR

If you are in the EU or EEA, Fleet Space acts as a “controller” of your personal information. In addition to the rights above, you may have the right to:

  • erasure of your personal information;
  •  restriction of processing while we verify accuracy or consider objections;
  • data portability — a copy of your personal information in a structured, commonly used and machine-readable format;
  • withdraw consent at any time where we rely on your consent;
  • object to processing based on our legitimate interests, and to direct marketing at any time; 
  •  lodge a complaint with your local supervisory authority (see edpb.europa.eu).

16. Changes to this policy

We may update this policy from time to time. The current version will always be available on our website. Material changes will be highlighted where appropriate.

17. How to contact us

To exercise your rights, make a complaint, or ask about this policy, contact our Privacy Officer:

Privacy Officer, Fleet Space Technologies
28 Butler Boulevard, Adelaide Airport SA 5950
Email: privacy@fleet.space

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) on 1300 363 992 or at oaic.gov.au.

Updated August 17 2026.

Quality Policy

1 Purpose

This policy establishes the framework for the Quality Management System to ensure alignment with Fleet’s strategic direction and the fulfillment of organisational objectives.

2 Application

This policy applies to all directors, employees, and contractors, regardless of location and material business activities. Compliance with this policy is subject to auditing and review. It interacts with other key company policies and management system documents, including:

  • Fleet ISO 9001 & ISO 27001 Management Manual
  • Risk Management Policy
  • Security of Information and Information Systems Policy
  • Code of Conduct
  • Ethics Charter

3 Commitments

Fleet Space Technologies is dedicated to revolutionising critical mineral discovery and spacenexploration using satellite-enabled solutions, advanced geophysical sensing technology, and AI-driven uncertainty modelling to increase speed and precision, and reduce environmental impact.

To achieve this, we are committed to:

  1. Customer Focus: Deeply understanding customer needs to design and develop the right products and services
  2. Standards of Excellence: Maintaining full compliance with the ISO 9001 standard and driving high standards across all business areas
  3. Quality Integration: Embedding quality directly into our products, services, and internal processes
  4. Continual Improvement: Actively improving our processes and the Quality Management System to enhance performance
  5. Regulatory Compliance: Meeting all applicable legal, statutory, and regulatory requirements

To ensure our commitments are measurable and actionable, Fleet establishes Quality Objectives, documented and tracked in Fleet's ISO Management System, which are:

  • Aligned with Fleet’s strategic direction and this policy
  • Integrated into functional and departmental activities within the organisation
  • Measurable and monitored through Key Performance Indicators
  • Reviewed at least annually during Management Review meetings to ensure ongoing suitability and to drive progress

Whistleblower and Complaints Policy

1 Purpose

Fleet Space is committed to conducting business with integrity, transparency, and accountability.

This Policy seeks to ensure all stakeholders have accessible avenues to resolve complaints and can raise concerns safely and confidentially.

This Policy sets out:

  • A framework for raising concerns about misconduct or unlawful behaviour.
  • Our approach to managing complaints in line with the Telecommunications Industry Ombudsman (TIO) scheme and AS/NZS 10002:2014 – Guidelines for Complaint Management.

2 Application

This Policy applies to:

All directors, officers, employees, contractors, consultants, suppliers, and other third parties with a business relationship with the company.

All customers and stakeholders.

3 How to make a complaint

Whistleblower or customer complaints may be made through the following channels:

  • Whistleblower and Complaints Portal: This is confidential and independently managed and is accessible at: Veremark: Tell (https://tell.veremark.app/disclose/fleet-space-AIcXRw)
  • Directly to a key representative of the company, the General Counsel or Chief People Officer
  • Email to the Ethics Officer: Ethics.Officer@fleet.space
  • By phone: 1300 024 854
  • In writing to our postal address: 28 Butler Boulevard, Adelaide Airport, South Australia, 5950, Att: Ethics Officer or General Counsel
  • Where required, directly to ASIC, APRA, or other regulators under the Corporations Act 2001 (Cth) (Corporations Act).

Whistleblower disclosures may be made anonymously if desired.

4 Whistleblower disclosures

4.1 What can be reported

A whistleblower disclosure may be made under this Policy if it concerns suspected or actual:

  • Breaches of law (including corporations, employment, health and safety, and environmental laws).
  • Fraud, bribery, corruption, or theft.
  • Breaches of the company’s Code of Conduct, policies, or values.
  • Misconduct in financial reporting or accounting controls.
  • Unsafe practices or serious risk to health, safety, or the environment.
  • Bullying, harassment, discrimination, or other workplace misconduct.*
  • Any other behaviour that undermines the company’s integrity or stakeholder trust.

*Work-related personnel grievances will generally be managed through the company’s HR grievance and issues management processes, unless they involve serious misconduct or systemic issues.

4.2 Protections for Whistleblowers

The company is committed to protecting whistleblowers who raise concerns in good faith.

  • Confidentiality: All disclosures will be treated in strict confidence. The identity of the whistleblower will not be disclosed without consent, except as required by law.
  • Protection from detriment: Whistleblowers will not suffer retaliation, dismissal, demotion, harassment, discrimination, or other harm for making a protected disclosure.
  • Legal protections: This Policy is designed to comply with the Corporations Act and other applicable whistleblower laws.

4.3 Investigation Process

An appropriately qualified person will be appointed to investigate all whistleblower disclosures made in accordance with this Policy. All disclosures will be assessed promptly and fairly.

Investigations will be conducted confidentially, with due regard to procedural fairness and findings and recommendations will be reported to the Board.

5 Customer complaints

5.1 What can be reported

A complaint may be made under this Policy in relation to our services, where a response or resolution is expected.

Customers can request updates at any time with respect to their complaint and, where relevant, they may escalate their complaint to the Telecommunications Industry Ombudsman (TIO) if unsatisfied with how the company has addressed the complaint.

5.2 Our commitments with respect to complaints

We are committed to:

  • Providing accessible and free complaint channels per section 3 of this Policy.
  • Acknowledging complaints within 2 working days and providing reference details.
  • Resolving simple complaints within 10 working days.
  • Keeping customers updated on progress every 10 working days for complex complaints.
  • Escalating unresolved complaints to the Telecommunications Industry Ombudsman if relevant and required.
  • All complaints are logged, regularly reported to the Board and subject to trend analysis for continuous improvement.

5.3 Complaint handling process

  • Acknowledgement – within 2 working days.
  • Assessment & Resolution – resolved as quickly as reasonably possible.
  • Complex Complaints – investigated and updated every 10 working days.

6 Governance & Responsibilities

  • Board: Oversight of whistleblower program and risk reporting.
  • General Counsel / Ethics Officer: Responsible for complaint and whistleblower handling.
  • All Staff: Responsible for treating any complaints seriously, respectfully, and in line with this Policy.

Vulnerability Disclosure Policy

We value security research that helps protect our systems and users. If you discover a vulnerability, please report it to us responsibly.

Scope

In scope:

  • exosphere.fleet.space
  • Other production services operated by Fleet Space (*.fleet.space, APIs, apps)

Out of scope:

  • Clickjacking on non-sensitive pages
  • Missing or non-optimal security headers (e.g., X-Frame-Options, CSP, HSTS, X-Content-Type-Options)
  • SPF/DMARC/DKIM/Email best-practice findings without exploitable spoofing or impact
  • SSL/TLS configuration suggestions (weak ciphers, preferred protocols) without a working exploit
  • Open ports, version banners, software version disclosure
  • Directory listing or stack traces without sensitive data exposure
  • Publicly available files or metadata without direct security impact
  • Use of vulnerable libraries without an exploitable path
  • Rate-limit, brute force, or DOS issues that only cause service slowdown
  • Self-XSS or issues requiring victim-controlled input
  • Automated scanner output without a clear, demonstrated impact
  • Social engineering, phishing, physical attacks, or attacks on third-party providers

Rules

  • Do not exploit, disrupt services, or access data you don’t own.
  • Only test accounts and data you control.
  • Stop immediately if sensitive data is encountered.

How to Report

Send reports to: security@fleet.space

Report format:

  • Summary + impact
  • Affected URL/asset
  • Steps to reproduce / PoC

Process

  • We acknowledge within 3 business days.
  • We’ll investigate, remediate, and coordinate disclosure.
  • Please allow up to 90 days before public disclosure.

Safe Harbor

We will not pursue legal action if you:

  • Act in good faith,
  • Stay within scope, and
  • Report responsibly without exploiting data.

Footer

Newsletter Signup
Newsletter Signup
Contact Us
Legal
28 Butler Boulevard
Adelaide Airport
SA 5950 AUSTRALIA
Social
©2026 Fleet Space Technologies Pty Ltd | Legal

Your Details

Close
Explore with us