1. Reporting an incident
Report suspected account compromise, malware, phishing, an exposed record or unusual data loss to sales@tradepilot.com.au with the subject Security incident. Include the affected company, a safe contact method, the approximate time and a short description. Do not include passwords, one-time codes, private keys, unnecessary personal information or live malware.
For a payment scam, contact your bank promptly using independently verified details as well as telling us. For immediate danger, contact emergency services through the normal emergency channel. TradePilot messaging and this email contact are not emergency-response services or a promise of round-the-clock support.
2. Our responsibilities and your responsibilities
TradePilot must take reasonable technical and organisational steps to protect the information and systems it controls and meet its contractual and legal obligations. We assess access, authentication, secure transmission, maintenance, monitoring, recovery and incident handling in light of the service and its risks. Detailed configuration may change and is not fully disclosed publicly where that would create risk.
The customer should maintain authorised users and appropriate permissions, secure its own devices, email accounts and telephone numbers, remove former users, review integrations and keep independent copies of essential records. Each party should promptly report and mitigate concerns within its control.
Nothing here promises a particular certification, penetration-testing frequency, immutable backup, encryption configuration or universal malware scanner. Specific assurances must be verified for your deployment and expressly documented where required. A provider's certification is not automatically a certification of TradePilot.
3. Phishing, malicious emails and changed bank details
Fraudulent messages can imitate a familiar sender, use a compromised mailbox or include realistic company details. Treat unexpected links, urgent payment demands, credential requests and changes to banking details with care. Open TradePilot through your known address or installed app rather than relying on an unexpected link.
Independently verify a payment or bank-detail change through a contact method you already trust. Do not approve an authentication request you did not initiate. Do not disclose a password or verification code to a person claiming to be support.
A display name, SMS sender label, message delivery report or file preview does not establish authenticity. Conversely, receiving a scam message does not by itself prove the TradePilot service was breached. We investigate reported concerns on the available evidence and meet our notification obligations where an incident occurs.
4. Uploads, previews and malware
Files can be corrupt or malicious even when their names look like ordinary photographs, PDFs or business documents. We may reject unsupported content, enforce size or type limits, quarantine suspicious files or restrict access while investigating. These protective rights are subject to appropriate confidentiality and proportionality.
No validation, preview, antivirus result or accepted upload guarantees safety. Do not enable unexpected macros, bypass device warnings or open a suspicious file merely because it arrived through a business account. Avoid sending a dangerous attachment to support; explain the issue and ask how to provide evidence safely.
These statements describe risks and permitted responses. They do not represent that a particular malware-scanning product is installed on every upload path.
5. Data loss, backups and continuity
Accidental deletion, failed synchronisation, device failure, software defects, ransomware and infrastructure incidents can affect availability or integrity. A backup reduces some risks but can itself be incomplete, inaccessible or outside the recovery point needed for a particular incident.
The standard Terms do not promise a specific backup interval, retention duration, restore time, recovery point or complete record-by-record restore. A protected infrastructure snapshot is not necessarily an export a customer can open independently. Ask about the arrangements applicable to your deployment where your business needs defined recovery commitments.
Keep copies of essential job sheets, plans, compliance and financial records using available exports or an agreed process. Check the copies are readable and complete. Keep a practical way to continue urgent work without TradePilot. These customer measures complement, rather than replace, TradePilot's obligations.
6. How a data incident is handled
The response depends on the circumstances and normally involves containing the incident, preserving appropriate evidence, assessing the affected data and people, taking remedial action, notifying those who must be informed and reviewing steps to prevent recurrence. We may revoke sessions, disable an integration or temporarily limit a feature where necessary.
When Customer Personal Data is breached in our processing, the Data Processing Terms require notification to the customer without undue delay. This is separate from the legal test for notifying affected individuals or a regulator. Initial information can be supplemented as the investigation progresses; we do not wait for every fact before meeting a notification duty.
Under the Australian Notifiable Data Breaches scheme, where it applies, an eligible breach generally involves unauthorised access, disclosure or loss likely to cause serious harm where effective remedial action has not prevented that likelihood. Required notifications are made as soon as practicable. The statutory assessment process is not a general 30-day notification grace period.
We share appropriate information with affected customers and cooperate on communications, without exposing other customers' information or unlawfully compromising an investigation. Neither party may prevent the other from making a legally required notification.
7. Account closure and retained copies
Archiving a job or user is not the same as deleting a workspace. Removing an app from a phone does not close the company account or erase its server-side records. Copies already sent to customers, downloaded or transferred to integrations cannot necessarily be recalled by TradePilot.
The Terms provide a 30-day post-termination window to request an export of data still held. Deletion and protected backup rotation are handled according to lawful purposes and the applicable processing arrangements, not a promise that every historic backup disappears immediately. Contact us to discuss a particular request.
8. Service levels, warranties and liability
This page is not a service-level agreement, insurance policy or guarantee of uninterrupted access, zero loss or immunity from cyberattacks. An agreed Order may specify additional commitments. Our Terms of Service set out contractual limits, while preserving non-excludable rights and our own responsibilities.
The Privacy Policy covers personal information and the Acceptable Use Policy explains prohibited activity and proportionate enforcement.
TradePilot Pty Ltd · 2026-09-R1
Back to top ↑