Privacy Policy

THESSOVA · Last updated 30 August 2026 · Effective 8 August 2026

Thessova builds and licenses software for Autodesk Revit. This policy explains what personal information we collect when you visit thessova.com, request a quote, or purchase and use a licence: how we use it, who we share it with, and the control you have over it.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where you are located in the European Economic Area or the United Kingdom, the section on EEA and UK users also applies to you.

1. Who we are

Thessova is the business responsible for the personal information described in this policy. In this policy, "we", "us" and "our" mean Thessova.

2. What personal information we collect

We only collect information that we reasonably need to sell, deliver and support our software. That includes:

CategoryExamples
Identity and contactName, company or practice name, job title, email address, phone number, billing and postal address
Licence and accountLicence keys issued to you, product and version, seat count, subscription start and renewal dates, account username
TransactionPurchase history, invoices, tax details, currency and amount. We do not collect or store your full card number; card details are entered directly with our payment processor
SupportEmails and support tickets you send us, and any log files, screenshots or Revit files you choose to attach
TechnicalIP address, browser type, device and operating system, pages viewed and referring URL, collected automatically when you use our website

We do not collect sensitive information (as defined in the Privacy Act), such as health, biometric or racial information. Please do not send it to us.

If you don't provide it

Some information is required to issue and support a licence. If you choose not to provide it, we may be unable to sell you a licence, activate your software, or resolve a support request.

3. How we collect it

4. Why we use it

5. Who we disclose it to

We do not sell, rent or trade your personal information, and we do not disclose it to third parties for their own marketing purposes. Ever.

To run the business we use a small number of service providers who process personal information strictly on our instructions, under contract, and only for the purpose we engage them for:

Beyond those providers, we disclose personal information only where we are required or authorised by law (for example in response to a court order, a lawful request from a regulator or law enforcement, or to establish or defend a legal claim), or where you have asked us to.

If our business is sold or restructured, customer records may transfer to the acquiring entity. We will notify affected customers if that happens.

6. Overseas disclosure

Some of our service providers store or process data outside Australia, including in the United States and the European Union. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual data protection terms.

7. Cookies

Our website sets only cookies that are necessary for it to function: keeping you signed in, remembering a device you have already verified, and maintaining security. We do not use analytics cookies, advertising or retargeting pixels, or any third-party tracking. Every cookie we set is listed, with its purpose and lifetime, in our Cookie Policy.

You can block or delete cookies through your browser settings. Blocking necessary cookies may stop parts of the site, including sign in, from working.

8. Direct marketing

If you are a customer or have asked to hear from us, we may email you about product updates, new releases and offers. Every marketing email includes an unsubscribe link, and you can opt out at any time by emailing [email protected]. Opting out of marketing does not stop essential service messages such as licence expiry notices, security advisories or invoices.

9. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit (TLS), access controls limiting staff access to what their role requires, and use of reputable hosting and payment providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.

10. How long we keep it

We keep personal information only as long as we need it for the purposes described above. Transaction and tax records are retained for at least seven years as required by Australian law. Licence records are retained for the life of the licence plus the period needed to handle renewals and support. Marketing contact details are deleted once you unsubscribe. When information is no longer needed and we are not required to keep it, we destroy or de-identify it.

11. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct anything inaccurate, out of date or incomplete. Email [email protected]. We will respond within 30 days. We may need to verify your identity first. If we refuse access or correction, we will explain why in writing.

12. EEA and UK users

If you are in the EEA or UK, we process your personal information on the following legal bases: performance of a contract (supplying and supporting your licence), legal obligation (tax and accounting records), and legitimate interests (securing our products, preventing licence misuse, and improving our software). You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interests. To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with your local supervisory authority.

13. Children

Our software and website are intended for professional use and are not directed at anyone under 16. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

14. Complaints

If you believe we have mishandled your personal information, email [email protected] with the details. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:

15. Changes to this policy

We may update this policy as our products or legal obligations change. The current version always sits at thessova.com/legal/privacy with the "last updated" date at the top. If a change materially affects how we handle your information, we will notify customers by email before it takes effect.

16. Contact us

Privacy questions, access requests and complaints:
[email protected]