Security Overview
Version 1.0 • Last updated: 9 June 2026 • Company: MACLOUD LABS PTY LTD
1. Executive summary
Bottlytics AI helps retailers, suppliers, and catalogue teams convert labels, images, files, and product evidence into validated alcohol product records.
This document describes how we protect Customer Data — including product catalogue data, capture images, user account information, and operational records — across our mobile application, web services, and supporting infrastructure.
Security highlights:
• Enterprise access controls: SSO (SAML 2.0 / OpenID Connect) and role-based access control (RBAC)
• Multi-tenant architecture with strict customer and branch-level isolation
• Encryption in transit and at rest
• Audit logging of key user and system activities
• Privacy and security governance aligned with SOC 2 Trust Services Criteria, GDPR, and the Australian Privacy Act (APPs)
• Documented incident response and data retention practices
For privacy-specific details, see our Privacy Policy. For contractual terms, see our Terms of Service. Enterprise customers may request a Data Processing Agreement (DPA) and sub-processor list.
Related: Privacy Policy · Terms of Service
2. Scope
This overview applies to:
• The Bottlytics mobile application
• Bottlytics web application and marketing site
• APIs and backend services that support capture, enrichment, search, and catalogue workflows
• Customer support and administrative tooling used to operate the Service
This document is intended for security, IT, legal, and procurement teams evaluating Bottlytics for enterprise use.
3. Security principles
We design and operate the Service around these principles:
• Least privilege — users receive only the access required for their role
• Tenant isolation — customer data is logically separated and access-controlled by organisation
• Defence in depth — layered controls across identity, network, application, and data layers
• Auditability — security-relevant actions are logged and reviewable
• Transparency — customers can request security documentation, sub-processor details, and DPAs
• Continuous improvement — regular reviews, monitoring, and control updates as the platform evolves
4. Architecture overview
Platform components:
• Mobile app — product capture, label scanning, and offline workflows
• Web services — authentication, catalogue management, enrichment, and search
• Cloud infrastructure — hosting, storage, compute, and backups
• AI / OCR services — label extraction and product intelligence
• Search and indexing — product discovery and catalogue search
Data flow (high level):
1. User captures a label image or uploads product evidence in the app
2. Data is transmitted securely to Bottlytics backend services
3. Extraction, enrichment, and validation workflows process the data
4. Structured product records are stored in the customer's tenant
5. Authorised users search, review, and publish records according to RBAC
Customer and user data is hosted on Google Cloud Platform (GCP) and related managed services (for example, Firebase). Where region configuration is available, data may be stored and processed in a designated geographic region (for example, Australia). Some supporting services and encrypted backups may operate in additional regions as part of high availability and disaster recovery.
5. Data we protect
Customer Data categories include:
• Account and billing — company name, contacts, subscription and billing details
• User identity — name, email, user IDs, roles, and permissions
• Operational and catalogue data — SKUs, attributes, inventory, pricing, notes, and product images
• Capture media — label photos, scans, and uploaded files
• Technical logs — access logs, error logs, security events, and usage diagnostics
Under GDPR, Bottlytics acts as a controller for account, billing, marketing, and our own operational data. Bottlytics acts as a processor for Customer Personal Data within Operational Data, processed on the Customer's instructions. Details are in our Privacy Policy.
6. Identity and access management
Authentication:
• Secure user authentication for mobile and web access
• Enterprise SSO via SAML 2.0 and OpenID Connect (where enabled for the customer)
• Session management and protection against unauthorised access
Role-based access control (RBAC):
• Permissions assigned by role and access group
• Administrators control which users can view, edit, review, or publish records
• Visibility can be scoped to team, branch, or catalogue context as configured
Administrative access:
• Internal administrative access is restricted, logged, and granted on a least-privilege basis
• Production access is limited to personnel with a legitimate operational need
7. Tenant isolation
Bottlytics uses a multi-tenant architecture designed to ensure:
• Customer data is associated with a unique tenant / organisation context
• Users cannot access another customer's data without explicit authorisation
• Branch- or team-level separation is enforced where configured
Isolation is enforced at the application and data access layers, not only in the user interface.
8. Encryption and data protection
Encryption in transit:
• Data in transit is protected using TLS (HTTPS) between clients, services, and third-party integrations where supported
Encryption at rest:
• Customer data at rest is protected using cloud provider default encryption and platform security controls
Key management:
• Encryption keys are managed using cloud provider key management services and platform best practices
9. Application and infrastructure security
We implement technical and organisational measures including:
• Network and application security controls
• Secure software development practices
• Vulnerability assessments and security reviews
• Monitoring, logging, and alerting for suspicious or anomalous activity
• Protection against abuse, fraud, and unauthorised access attempts
No system can be guaranteed 100% secure. We continuously work to protect information in line with industry best practice and our internal security framework.
10. Audit logging and monitoring
Security-relevant events may include:
• User authentication and session activity
• Administrative configuration changes
• API access and integration activity
• Capture, review, and publish workflow actions (as configured)
• System errors and security alerts
Logs support security investigations, incident response, compliance, and operational troubleshooting. Log retention may exceed general customer data retention where necessary for security, fraud prevention, or legal purposes.
11. AI and data use for service improvement
• Customer Data is used to provide and operate the Service
• We may use aggregated and/or de-identified data to improve extraction quality, accuracy, and product performance
• Service-improvement use of Customer Data is restricted to what is necessary (for example, user corrections and confidence metrics), with access controls as described in our Terms and Privacy Policy
• We do not sell personal information
Customers requiring contractual restrictions on model training or data use should discuss requirements during enterprise onboarding.
12. Sub-processors
We use carefully selected third-party providers ("Sub-processors") to deliver the Service. Examples include:
• Cloud infrastructure and storage — Google Cloud Platform, Firebase
• AI and search — Google AI / Gemini, Algolia
• Logging, monitoring, and analytics — operational tooling as configured
• Payment and billing — payment providers as applicable
• Customer support — support platforms as applicable
Each Sub-processor is engaged under agreements requiring appropriate security and confidentiality obligations. A current Sub-processor list is available on request. Material changes are communicated where contractually required.
13. Compliance and governance
Our privacy and security governance is designed to align with:
• SOC 2 Trust Services Criteria (Security, Availability, Confidentiality, and related controls)
• GDPR (where applicable)
• Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
Supporting policies and agreements include our Privacy Policy, Terms of Service, Data Processing Agreement (DPA) for enterprise customers, Data Retention Schedule, and Incident Response Process.
14. Data retention and deletion
General approach:
• Customer account data is retained for the subscription term and as required for legal and accounting purposes
• Customer Personal Data in the Service is retained while the account is active
• After account closure, Customer Personal Data is deleted or de-identified within a reasonable period, subject to legal requirements and backup or archive limitations
• Security and audit logs may be retained longer where necessary
Standard retention for Customer Personal Data in the Service is commonly the contract term plus a limited post-termination period (commonly up to 90 days), unless otherwise agreed. Customers may request export or deletion subject to applicable law and contract terms.
15. Incident response and breach notification
We maintain a documented Incident Response Process. In the event of a data breach involving personal information, we will:
• Contain and assess the incident
• Notify affected customers without undue delay, per law and contract
• Notify regulators where required (for example, OAIC or EU/UK authorities under GDPR)
• Inform affected individuals where required or appropriate
• Remediate root cause and improve controls
Details are in our Privacy Policy (Data Breach Notification section).
16. Business continuity and availability
Production services are designed for reliability using cloud-native infrastructure. Backups and high-availability patterns may span multiple regions for resilience. Specific recovery objectives, if any, are defined in enterprise agreements.
17. Customer responsibilities
Customers are responsible for:
• Managing user accounts, roles, and permissions
• Ensuring lawful collection and upload of data into the Service
• Configuring SSO and access policies appropriately
• Promptly reporting suspected security issues
• Maintaining security of devices used to access the Service
Bottlytics is responsible for securing the platform, infrastructure, and services under our control.
18. Security reviews and documentation requests
Enterprise prospects and customers may request:
• This Security Overview
• Sub-processor list
• DPA / SCCs for international transfers
• Completed security questionnaires (SIG, CAIQ, custom RFP forms)
Use Contact Sales on the website or email us using the details below.
19. Contact
For security and privacy enquiries, or to request additional documentation:
Security and privacy enquiries
Email: support@bottlytics.ai
Bottlytics AI is a product of MACLOUD LABS PTY LTD ACN 634 982 157, 2/56 Brandon Park Drive, Wheelers Hill VIC 3150. All Rights Reserved.