MultiScene by MultiForge Privacy Policy
Version 2026-09-09.1 Effective date: 10 September 2026
1. About this policy
MultiScene by MultiForge (MultiScene, the Service) is operated by Multiforge Pty Ltd (ABN 11 676 186 244; ACN 676 186 244). This policy explains how we handle personal information. Contact us at contact.multiforge@gmail.com.
MultiScene is intended for workplace and business users aged 18 or older, including subscribed, invited, trial and beta users. Do not provide sensitive or specially regulated information unless a separately reviewed feature and agreement expressly permits it.
2. Information, sources and visibility
Depending on the features used, we may handle:
account and contact details, authentication state and account timestamps;
organisation, role, membership, invitation, entitlement and concurrent-seat information;
limited Paddle customer, transaction and subscription references and verified status, without receiving full payment-card details;
cloud scenarios, customer models and the names, metadata, ownership, quota, integrity and lifecycle records needed to protect them;
managed-model selections and short-lived delivery authority;
hosted-session roles, display names, participant position and orientation, interactions, scene messages and temporary session state;
security, network, error, audit and cleanup information needed to run and protect the Service; and
information supplied in a support, privacy, security, billing or legal request.
Information needed to use MultiScene. To create and use an account where registration is offered, a user must provide an email address and the password information marked as required. Organisation membership, permission and subscription records are needed to provide the corresponding organisation or paid features. Without the necessary information, we cannot provide the affected account or feature. Uploading Customer Content and joining hosted sessions are optional; when a user chooses those features, we process the associated information described in this policy. Optional marketing consent is not a condition of account or Service access.
We receive information directly from users; from a Customer's organisation owner or administrator through invitations, membership and role actions; from Paddle and other providers through verified service events; and automatically from the application, browser, device and infrastructure when the Service is used. Infrastructure providers may process ordinary network and security information such as IP address, request time, headers, browser or user-agent details and threat signals.
An organisation owner or administrator can see membership, role, invitation, plan and access information needed to administer that organisation. A trainer and other participants in the same hosted session can see the participant's display name, role, presence, shared position or orientation, interactions and session content needed for that session. Customer Content is shared only through available customer-authorised sharing or session controls. Organisation membership alone does not let every member read every private model. Service providers, advisers and authorities receive only the information described in section 5 for their applicable purpose.
3. Device, immersive and browser information
Local scenarios, preferences, recovery saves and local custom-model copies stay in browser storage on the device unless the user chooses a cloud action. Clearing browser data or losing the device may remove them.
MultiScene uses current headset, controller or device pose locally to render an immersive view. In hosted multiplayer, limited participant position, heading, display and interaction state is transmitted to operate the shared session. MultiScene does not request camera images, voice recordings, microphone audio, eye-tracking data, biometric templates or a stored scan of the user's room. A browser, headset or operating-system provider may process device information under its own terms when it provides WebXR or safety functions.
We use cookies, browser storage and similar technologies for authentication, security, local content, preferences and requested Service functions. MultiScene does not use advertising or behavioural analytics. If we introduce non-essential storage that requires consent, it will remain off until valid consent is recorded and will stop if consent is withdrawn or the consent control becomes unavailable. We may use iubenda to present and record that choice.
4. Purposes, roles and legal bases
We handle information as reasonably necessary to authenticate users; administer accounts, organisations, subscriptions, roles, seats, quotas and ownership; perform requested saves, uploads, downloads, exports and deletion; operate trainer-led multiplayer; secure, diagnose, monitor and improve MultiScene; reconcile verified Paddle events; respond to requests and disputes; and comply with law and enforce our agreements.
Multiforge acts as controller where it decides why and how personal information is handled, including account administration, platform security, billing reconciliation, support, legal compliance and product operation. Where a business Customer determines the purpose and essential means and Multiforge handles personal data on its behalf, Multiforge acts on the Customer's documented instructions under Annex A of the Terms or another applicable processing agreement. The Customer is responsible for establishing the lawful basis for that processing. For Multiforge's separate controller activities, we rely on an applicable lawful basis described below; an organisation's instruction alone is not that basis.
Where the UK or EU GDPR applies, the legal basis depends on the activity:
contract or steps requested before contract: providing an individual customer's requested account, subscription and Service functions where processing is necessary for that contract;
legitimate interests: administering business accounts and organisation users, securing the Service, preventing fraud and misuse, diagnosing faults, maintaining audit evidence, improving requested functions and handling ordinary business communications, balanced against the person's rights;
legal obligation: processing necessary to comply with an obligation grounded in applicable European Union or Member State law for EU GDPR purposes, or United Kingdom law for UK GDPR purposes. For requirements under other laws, including Australian company or tax laws, we identify another applicable GDPR basis, such as legitimate interests where its requirements are met. Foreign legal requirements do not automatically override applicable privacy rights or international-transfer safeguards; and
consent: optional marketing or non-essential browser storage where consent is required. Consent can be withdrawn at any time without affecting earlier lawful processing.
An employer's or organisation's contract is not automatically the contractual legal basis for every employee or invited user's personal data. Depending on the activity, legitimate interests, an applicable legal obligation or consent may apply instead.
We do not sell personal information or use Customer Content for advertising, resale or generative-model training without a separate express agreement. Optional marketing remains separate from the Service and requires its own clear choice and unsubscribe process.
5. Recipients, Paddle and international processing
We disclose information only as reasonably necessary to:
Supabase, for authentication, database, ownership and account services;
Cloudflare, for application delivery, server functions, temporary hosted sessions, private object storage and network security;
Paddle, when billing is enabled, for checkout, subscriptions, transaction taxes, invoices, payment administration, refunds, fraud prevention and verified events;
Esri and OpenStreetMap Foundation services, when a user opens the map picker or searches for a place, to provide map imagery, map tiles and place-search results;
iubenda, if its consent controls are enabled, to display and record cookie or similar-technology choices;
Google, for Multiforge's public business and privacy email route;
a Customer's authorised organisation owners, administrators, trainers and session participants, as described in section 2;
professional advisers, insurers, auditors, contractors and incident responders under appropriate confidentiality; and
courts, regulators, law enforcement or another party where authorised or required by law.
MultiScene's configured database and authentication service uses Supabase Pte Ltd under the Supabase Terms and Data Processing Addendum, which the Terms incorporate. Sydney, Australia (ap-southeast-2) is selected as the primary database region. Supabase states that processing may also occur where it and its subprocessors operate. Its current Addendum incorporates the European Commission's 2021 Standard Contractual Clauses, using Module 2 or 3 as applicable, and the United Kingdom Addendum for a covered restricted transfer.
MultiScene's application, server functions, hosted sessions and private-object storage use Cloudflare, Inc. under Cloudflare's Self-Serve Subscription Agreement and incorporated Customer Data Processing Addendum where it applies. The private-object bucket uses Cloudflare's best-effort Oceania (OC) location and is not public, while Cloudflare also operates a global network. Cloudflare's current Addendum uses the European Commission's 2021 Standard Contractual Clauses, Module 2 or 3 as applicable, and the United Kingdom Addendum for covered restricted transfers; it may also rely on a valid Data Privacy Framework certification where applicable.
Paddle provides checkout, payment, tax, invoice, subscription, refund and fraud-prevention services as Merchant of Record and authorised reseller. The relevant Paddle contracting entity is determined by the buyer's location and identified in Paddle's Buyer Terms and at checkout. Paddle acts as a separate controller for purchase and payment data under Paddle's Privacy Notice. Paddle publishes a Data Sharing Addendum for controller-to-controller sharing, including the European Commission's Standard Contractual Clauses and United Kingdom Addendum for covered restricted transfers. Any distinct activity for which Paddle acts on Multiforge's instructions is governed by its applicable Data Processing Addendum.
Multiforge's public contact route uses an ordinary Google email service. Google acts under its own consumer Privacy Policy and describes worldwide processing and use of standard contractual clauses where required in its international data transfer frameworks. Multiforge does not claim that a separate Google Workspace business data-processing addendum applies to this consumer email route.
When a user opens the map picker or searches for a place, the user's browser requests imagery or map tiles from Esri or OpenStreetMap services and may send a place-search query to Nominatim. Those providers receive ordinary network request information, such as the user's IP address, request metadata, requested tile area and any submitted search words, under the Esri Privacy Statement or OpenStreetMap Foundation Privacy Policy, as applicable.
A selected Sydney or Oceania location does not make the whole Service Australia-only. Any safeguard described above applies only to the parties, services, data and transfers within the effective agreement or other mechanism's actual scope. A provider's description of its own international transfers does not, by itself, establish a processing or transfer agreement between that provider and Multiforge. A business Customer's disclosure to Multiforge may be a separate restricted transfer. Where applicable law requires a transfer mechanism, the Customer and Multiforge must complete the applicable adequacy, exception, standard-clause, transfer-addendum or risk-assessment steps for that transfer. Contact us for information about the mechanism relevant to your data and how to obtain available details or a copy.
6. Retention, cancellation and deletion
We retain information only for as long as reasonably necessary for the purpose collected, considering account and subscription status, Customer instructions, security and dispute needs, provider capabilities and applicable legal, tax and financial duties.
Current operational periods include:
private download authority lasting no more than five minutes;
an empty recoverable hosted session expiring after ten minutes, while final Host closure removes retained session state and discovery promptly;
a seven-day recovery period for a user-deleted private file or replaced private-file version;
a 30-day export or resubscription period for eligible cloud Customer Content after ordinary paid or cardless-trial entitlement expiry, followed by scheduled cleanup; and
billing, tax, legal, acceptance, complaint and security records retained only for the applicable legal, accountability or genuine documented-hold period.
Eligible Customer Content means the Customer's own cloud scenarios and private uploads in an available export format. It excludes raw Managed Content and material the requester is not authorised to export. Managed Content is not available for extraction and may be used inside MultiScene only while the applicable entitlement remains active.
Subscription cancellation, commercial account closure, erasure of an individual's personal data and deletion of organisation-owned content are separate actions. Cancellation ordinarily stops future renewal and leaves paid access until the end of the paid period. If an account-closure request requires renewal to stop, we will arrange that promptly rather than wait for the data-deletion work to finish. A valid earlier erasure request overrides the routine 30-day content period for the affected personal data unless the person asks us to defer or a lawful reason requires retention. Organisation content will not be deleted without appropriate authority, and ownership coordination will not be used to delay an individual's valid request unnecessarily.
Deletion from the active Service does not erase an independent copy on a user's device. Provider backups, replicas, fraud-prevention records and security records may remain through their documented normal rotation or a required legal period, protected from ordinary use. If a backup is restored, applicable deletions must be reapplied before normal service resumes. MultiScene does not promise a provider's physical-erasure time where that provider does not publish or support one.
7. Individual rights and complaints
Contact contact.multiforge@gmail.com to request access to or correction of personal information, ask for deletion or account closure, object to or request restriction of processing, request applicable data portability, withdraw consent, or make a privacy complaint. A subscription is not required. Ordinary rights requests are free; a fee is charged only where applicable law expressly permits it and after we explain the basis.
Your right to object. Where applicable privacy law gives you this right, you may object at any time, for reasons relating to your particular situation, to processing based on legitimate interests. We will stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. You may object to direct marketing at any time, and we will stop using your information for that purpose. Contact contact.multiforge@gmail.com or use the unsubscribe option where provided.
We verify authority using a method proportionate to the request, preferring a current signed-in account or confirmed account email. A sensitive or high-impact request may require fresh account-bound authentication. Do not send passwords, authentication codes, private keys, payment-card details or identity documents unless we have separately explained why particular evidence is necessary and how it will be protected.
We act without undue delay. We aim to respond to ordinary requests within 30 calendar days, but an applicable one-calendar-month or shorter legal deadline controls. We acknowledge privacy complaints within any applicable legal deadline, including within 30 days where the United Kingdom requirement applies, investigate them appropriately and communicate the outcome without undue delay. A lawful extension, refusal, limitation or fee will be explained together with the reason and available complaint route. Another person's rights, a legal obligation or a genuine scoped hold may limit what can be disclosed or deleted.
Nothing in this policy restricts a complaint to a competent regulator where applicable law permits it. The regulator's own jurisdiction and complaint-admissibility rules apply; some regulators normally require you to raise the matter with us first. Depending on the matter and applicable law, this may be the Office of the Australian Information Commissioner, the UK Information Commissioner's Office or the appropriate European Economic Area supervisory authority.
8. Security, recovery and data incidents
We use authenticated access, server-controlled ownership and entitlement checks, row-level security, private object storage, short-lived delivery authority, validated uploads, environment separation, minimised monitoring, transport protections supplied by configured services and guarded deployment and recovery procedures.
Backups are limited to workflows that are specifically configured and tested. When private cloud asset recovery is enabled, its narrow recovery workflow uses encrypted backup material for the covered private assets. It does not provide a general backup of every account, organisation, billing record, cloud scenario or local browser file. Customers must keep independent copies of important material.
No service is perfectly secure. Protect your credentials and report suspected compromise to contact.multiforge@gmail.com without sending credentials, payment details or unnecessary Customer Content.
We assess suspected data incidents, contain and investigate them, preserve only necessary evidence and notify affected people or regulators where required.
9. International users, children and changes
Mandatory privacy rights in a user's location continue to apply where they cannot be excluded. International availability may be restricted where lawful processing or required local arrangements are not reasonably available.
Multiforge is established in Australia and has not appointed a representative in the European Economic Area or United Kingdom. Whether a representative is required depends on the territorial scope and circumstances of the processing. We do not claim an exemption or that MultiScene complies with every country's laws. If applicable law requires Multiforge to appoint a representative for processing covered by this policy, the effective policy and relevant collection notice will identify that representative and provide its contact details.
MultiScene is not designed for children and is limited to workplace and business users aged 18 or older.
The effective policy will display its publication date and version. We will give appropriate notice of a material change and seek consent where required. Historical versions and applicable acceptance or collection-notice evidence may be retained for accountability.