ROTOR

Records of Tests, Observations & Requirements

Siemens Energy
Privacy notice

How ROTOR handles your personal data

ROTOR records field-quality work. Doing that means holding some personal data about the people who do and witness the work. This notice explains what, why, where, for how long, and what you can ask of us.

Version
2026-09-07-draft
Last updated
7 September 2026
Status
Draft — pending legal review

Who operates ROTOR

ROTOR (Records of Tests, Observations & Requirements) is a field-quality records system operated by the Siemens Energy field-service organisation for gas-turbine outage and inspection work. It is used by Siemens Energy staff and by named representatives of the customers whose equipment is being inspected.

The entity responsible for your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles is Siemens Energy Pty Ltd (ABN 69 636 537 409), referred to as "we" in this notice. Supabase, Vercel, Cloudflare and SendGrid process data only on our instructions. Our privacy contact is Mitchell Schram, ROTOR Product Owner, Siemens Energy field service. Privacy questions, access or correction requests and complaints go to him through the contact link on the sign-in page.

This notice applies to everyone who uses ROTOR. If you are a Siemens Energy employee, the Siemens Energy employee privacy notice also applies to you and, where the two differ, it prevails in relation to your employment record. If you are a customer representative, this notice supplements any privacy notice your own employer has given you.

What we collect

  • Account details: name, work email address, company or organisation, job role, and the platform access group you have been assigned. Accounts are created by invitation only. If you are a customer representative, these details are given to us by your organisation or its Siemens Energy project lead when your account is set up; you then complete or correct them yourself.
  • You cannot use ROTOR anonymously or under a pseudonym: every record must be attributable to a named, accountable person, which is the purpose of the system.
  • Sign-in records: the time of your last sign-in, and the device and browser details your browser sends with each request. Accounts are protected by a password you set; passwords are stored only as a salted hash by our authentication provider.
  • Two-step sign-in: if you set up an authenticator app, our authentication provider stores the shared secret needed to check your codes. When you choose to remember a device we store a random identifier for it (as a hash), the browser and operating system family, and when it was last used, so that device is not asked for a code again for a limited time. You can see and remove remembered devices under Account security; an administrator can reset your authenticator if you lose access to it.
  • Work you record: inspection results, sign-offs, comments, redlines, findings, shift entries, procurement and issue entries, and the attribution of each of these to you (who did what, when). Sign-offs also store a content hash of what was signed so later edits can be detected.
  • Photographs and files you upload as inspection evidence. These are of equipment only; no record requires photographs of people. ROTOR never requests your device location.
  • Bug reports you choose to send: your description, an optional screenshot, the page you were on, and basic device and browser details.

Why we use it

  • To operate the service: authenticate you, show you the projects you are a member of, and let you create and sign records.
  • To keep a complete quality record: sign-offs, comments and audit entries are attributed and time-stamped because the record is only useful if it is traceable. Audit tables are append-only.
  • To notify people who need to act: for example, an email to a customer representative when a witness or hold point is scheduled.
  • To keep the service secure and working: reviewing sign-in problems, investigating bug reports, and monitoring for misuse.

We collect only what is reasonably necessary for these purposes. We do not use your data for marketing, profiling, or advertising, and we do not sell it. Notification emails contain no open or click tracking.

Who can see it

  • Members of a project see that project only. Customer representatives see only the projects their organisation is party to, and only the customer-facing parts of those records (for example, they do not see internal hold points or internal comments). This is enforced in the database with row-level security, not only in the user interface.
  • Siemens Energy field-service staff see the projects they are assigned to; a small number of platform administrators can see all projects for support and administration. Some of these staff are employed by other Siemens Energy group companies and work from outside Australia — see the overseas-disclosure paragraph below.
  • Your name appears against the records you create and sign, to everyone who can see those records. That is inherent to a quality record and cannot be switched off.

Where it is stored and who processes it for us

Your data is held by the following service providers. Each acts only on our instructions and is bound by contractual confidentiality and data-processing obligations (their published data-processing agreements):

  • Supabase — PostgreSQL database, file storage and authentication. Data at rest is in Sydney, Australia (AWS ap-southeast-2).
  • Vercel — application hosting. The application runs in Sydney (Vercel syd1) and encrypted nightly backups are kept in a private Vercel store in Sydney. Vercel’s global edge network handles requests in transit over TLS, so a request may pass through a Vercel edge location outside Australia before reaching Sydney; no application data is stored at those locations.
  • SendGrid (Twilio) — sends notification emails from infrastructure in the United States. It receives only the recipient address and the message content (for example, the project name and the date of a scheduled inspection).
  • Cloudflare R2 — a second, independent copy of each nightly backup (database and evidence files, encrypted) is kept in a private Cloudflare storage bucket so that a failure at Vercel or Supabase cannot take the backup with it. The bucket is configured to be placed in the Oceania region; Cloudflare treats this placement as best-effort rather than a contractual residency guarantee, so we disclose it here as a possible overseas storage location. Cloudflare holds only the encrypted backup objects and has no access to the live application.
  • Google Maps — the project summary page embeds a map of the site location. When that page loads, your browser requests the map directly from Google, which therefore receives your IP address and the site address being displayed. No account or record data is sent to Google.

Overseas disclosure. Your data is stored only in Australia, but Siemens Energy engineers, technical specialists and administrators assigned to a project may view its records from outside Australia. These people are employed by other companies in the Siemens Energy group and may be located in any of the countries in which the Siemens Energy group operates, most commonly Germany, the United Kingdom, the United States and countries in the Asia-Pacific region. It is not practicable to list the countries for a particular project in advance, because who is assigned depends on where the required specialists are; if you want to know which countries apply to your project, ask our privacy contact. Access is limited to the projects they are assigned to, is subject to the same database-level access controls as everyone else, and is covered by Siemens Energy’s intra-group data-protection agreements, which require the recipient to handle personal information in a way consistent with the Australian Privacy Principles. Other than this, the email delivery, the edge transit and the Cloudflare backup copy described above, we do not disclose your personal information overseas.

We may also disclose personal information, in each case only to the extent necessary: to the customer organisation a project belongs to, as part of the inspection records for that project; to our professional advisers, insurers and auditors; to a successor if the ROTOR service is transferred within Siemens Energy; and where the law requires or permits it. We do not sell or rent personal information.

How long we keep it

  • Quality records, sign-offs, comments and audit entries are kept for as long as the inspection record itself must be kept under the contract for that work and Siemens Energy’s records-retention requirements — they are part of the evidence that the work was done and checked. When the retention period ends the record, including the personal information in it, is deleted or de-identified.
  • Deleted files are held in a recoverable trash area for 90 days, then permanently removed.
  • Backups are kept for 30 days (daily) and 12 months (weekly), then rotated out.
  • When your account is no longer needed it is deactivated rather than deleted, so the records attributed to you stay traceable. Deactivation immediately blocks sign-in and ends open sessions. If you ask us to, we will remove personal details that are not part of a quality record.

Cookies and local storage

ROTOR uses only strictly necessary cookies: the session cookies set by our authentication provider to keep you signed in, and small preference cookies for the sidebar state and view mode. The browser’s local storage holds draft work you have not yet saved and interface preferences. There are no advertising or third-party analytics cookies, so no consent banner is shown.

Access, correction and complaints

You can ask to see the personal information we hold about you, to have inaccurate or out-of-date details corrected, or to have details removed where they are not part of a quality record. Contact our privacy contact (Mitchell Schram, ROTOR Product Owner, Siemens Energy field service) through the sign-in page; if you are a customer user, your organisation’s Siemens Energy project lead can also raise it for you. We will respond within 30 days. If we refuse a request we will tell you why in writing and how to complain about the refusal.

If you believe we have handled your personal information in a way that breaches the Australian Privacy Principles, complain to our privacy contact first. We will acknowledge your complaint, investigate it and reply in writing, normally within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are outside Australia you may also contact the privacy regulator in your own country.

Security and data breaches

Access is limited to invited accounts, every request is checked against project membership in the database, audit records are append-only, data is encrypted in transit and at rest, and backups are taken nightly to a separate encrypted store. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the OAIC as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.

Changes to this notice

We will update this notice when the service or our providers change. The version and date appear at the top of the page; material changes are also announced in the release notes on the sign-in page.