Privacy policy

Privacy policy

Last updated: October 6, 2026 · Effective as of the publication date

ReefBeacon is produced, operated, and maintained by Noviai Limited and serves users worldwide. This policy explains what personal data this system processes, why it is processed, the third-party services involved, retention principles, and how to submit rights requests. We process data as needed to provide monitoring services, manage accounts, and maintain security. This policy does not limit any rights you have under applicable law.

What we collect

The system serves institutional users and offers no public sign-up. Depending on how you sign in and use it, we may collect:

  • Account information: email address, securely processed password verification information (plain-text passwords are not stored), and account role. When an organization enables single sign-on, the identity provider may supply information such as email address, display name, avatar, or user group to verify identity and assign permissions. This system does not access the password used with that sign-in method.
  • Sign-in status: after you sign in, your browser stores the cookies needed to maintain your session. They become invalid when you sign out or when they expire.
  • Notification records: the sending status and delivery identifier for alert emails, and the read status of in-app notifications, to help review how notifications were handled. An email service accepting a sending request does not mean the recipient received or read the email.
  • Incident records: when error monitoring is enabled, the service collects error and performance information to diagnose problems. Sensitive values such as passwords, access credentials, and keys are redacted before they are sent.
  • Local preferences: your language and region selections are stored in your browser and can be deleted at any time. Deleting them restores the default settings.
  • Access security information: sign-in abuse prevention checks process request information such as source IP addresses to limit unusual requests and maintain service security.

How we use the data

We use the data only for the purposes below; we do not sell your data, and we do not use it for advertising, profiling, or any purpose unrelated to the service:

  • To authenticate sign-in and control access to features and data by role;
  • To send alert emails and in-app notifications to the registered recipient addresses when heat-stress thresholds are breached;
  • Generate auditable records of notification sending and read status; see “Data retention” for retention principles.
  • Diagnose problems, prevent unauthorized access and abuse, and maintain service stability.

AI and your data

This system uses Google’s analysis support service (Gemini) to process marine monitoring readings, authorized photos, historical records, and related questions submitted by users to help prepare assessment notes. The system does not automatically use account passwords or sign-in credentials as analysis input. Questions you enter or photos you upload may contain personal data; do not submit unrelated personal data, secrets, or content you are not authorized to share.

Cookies and local storage

  • Session cookie (essential): keeps you signed in; deleting it signs you out.
  • Language and region preferences: remembers the language and region you select in the dashboard and stores them only in your browser.
  • This system does not use advertising cookies or cross-site marketing tracking. See “Third-party services” for enabled diagnostic services and the information they process.

Third-party services

Third-party services may process relevant information outside your country or region. Any cross-border processing is subject to the legal basis and safeguards required by applicable law. For information about processing locations, service providers, and safeguards, contact [email protected].

  • Incident diagnosis service (Sentry, when enabled): receives redacted error and performance information.
  • Email delivery service (Resend, when enabled): processes alert recipient email addresses and email content to send alert notifications.
  • Institutional single-sign-on providers (Google / Microsoft): involved only when you choose SSO sign-in.
  • NOAA Coral Reef Watch, the AFCD and other data-source agencies are not data processors of this system — we consume their public data.

Data retention

  • To support alert traceability, audit records are generally retained for at least 1 year, subject to applicable legal retention and deletion requirements. Records containing personal data are retained only for as long as needed for service traceability, security response, or compliance with legal obligations; they are deleted or anonymized when no longer needed.
  • Account information is retained as needed for the service relationship, access management, and applicable legal obligations. Information that must be retained after an account is deactivated is subject to restricted use; it is deleted or anonymized when no longer needed. Deactivation does not automatically erase records that must be retained by law.

Your rights

You can request access to, correction of, or deletion of your personal data by contacting [email protected]. Other rights provided by applicable law are also unaffected, such as restricting or objecting to processing, obtaining a portable copy, withdrawing consent where processing is based on consent, or lodging a complaint with a supervisory authority. We will respond within the period required by applicable law and may verify your identity when necessary. If we cannot fulfill a request by law, we will explain why. Withdrawing consent does not affect lawful processing carried out before withdrawal.

Data security

  • Protect information during transmission and storage;
  • Do not store plain-text passwords and keep access credentials secure;
  • Give each account only the access needed to perform its duties;
  • Redact incident and activity records before storage or external transmission.

Minors

The system serves professional conservation and research institutions; it is not directed at minors, and we do not knowingly collect personal data from minors.

Changes to this policy

When this policy is updated, it will be posted on this page and the “Last updated” date will change. Significant changes will be communicated through a website notice or an appropriate contact channel. Updating this policy or continuing to use the service does not replace consent where consent is legally required. If a new processing purpose requires separate consent, that consent must be obtained first.