FireFlow Studio for FDS Back to site

Privacy Statement

Effective 28 July 2026

This statement explains what happens to your information when you use FireFlow Studio for FDS, visit fireflowstudio.com.au, or buy a licence from us. It is written in plain English, because you should not need a lawyer to work out what happens to your data.

1. Who we are and how to contact us

FireFlow Studios for FDS (ABN 38 592 552 472) is a registered business name of the Van der Walt Investments Trust, based in Queensland, Australia. In this statement, "we", "us" and "our" mean that business, and we are responsible for the personal information described here.

The software publisher named on the code signing certificate is Van der Walt Investments Pty Ltd (ACN 659 714 995). FireFlow Studio for FDS is developed by Dirk van der Walt, a practising fire safety engineer.

You can reach us about anything in this statement, including access, correction or a complaint, at info@fireflowstudio.com.au.

We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).

2. The short version

3. What the desktop application does and does not collect

What it does not do

Licences

Your licence key is an Ed25519 signed key that is verified locally on your own machine. The check happens entirely on your computer and sends nothing to us or to anyone else. Because there is no account and no activation server, we do not know when, where or how often you use the software.

The one outbound connection

The application can optionally check GitHub's public API (api.github.com) for the latest release of the NIST FDS solver, and can optionally download that solver for you. That request asks GitHub for public release information. It does not include your licence key, your name, your email address, your models or anything else about you or your work. As with any internet request, GitHub will see the connection itself, including your IP address, under its own privacy terms. Apart from that, the only other time the application reaches the internet is when you deliberately click a link, which opens in your own browser.

Your files

Models, results, input files, output files and anything else you open or save remain on your own device or on storage you control. We have no access to them.

4. Bug reports and model files

Nothing is ever transmitted automatically when something goes wrong. If you use the in-app "Report a Problem" dialog, the application composes a report and opens it in your own email client. You can read it, edit it, decide whether to send it, and cancel at any point. Nothing is uploaded to us or to any server of ours.

The dialog includes a tick box for attaching the model you currently have open. When a model is open, that box is ticked for you, so please check it. If you do not want to send your model, untick the box before continuing. If the box is ticked, the model is written to a file on your own computer, which you then attach and send yourself. You always see what is being sent before it leaves your machine.

Our commitment if you do send us a model

If you choose to send a model file with a bug report, we will use it only to reproduce and diagnose the issue you reported, and only if doing that is necessary. We will not use it for any other purpose, we will not share it with anyone else, we will not use it to build new features, and we will not use it to train any system.

Once the issue is resolved, we delete the file. Bug reports reach us by email, not by upload, so deletion means removing the file and any working copies we made from the mailbox it arrived in, including any copy in sent items if we replied with it attached, and then clearing it from deleted items. We do this as soon as the issue is resolved. To be honest about how email works: after we delete an item, our mail provider may hold it in a trash or recovery folder for a short time under its own settings before it is permanently purged. Beyond that, we do not retain the file and we do not keep it in any archive or backup of our own.

If you would prefer not to send a model at all, please untick the box and describe the problem instead. We will always try to help without it.

5. The website: trial signups, purchases and emails

Trial download

The trial download form collects your email address and nothing else. The form is submitted through Netlify Forms and your address is then added as a contact in Brevo, our email service. Brevo sends you a short automated sequence of trial emails. Every one of those emails has an unsubscribe link, and you can use it at any time without contacting us.

Buying a licence

Purchases are handled by Stripe Checkout. Stripe collects and processes your payment details directly. We never see or hold your full card number. What we receive from Stripe is your name and email address, plus the record of the transaction.

After your purchase we generate your licence key and email it to you. That email is delivered using Brevo's SMTP service. We also mark your contact in Brevo as a purchaser so the trial email sequence stops.

Other emails

If you email us at info@fireflowstudio.com.au, we will have whatever you put in that email, and we will use it to answer you.

If you are a customer, we may also email you about the software itself, for example a new release or a fix that affects you. Tell us if you would rather not receive those and we will stop.

Dealing with us anonymously

You can browse the website and use the software without telling us who you are. We need an email address to send you the trial, and Stripe needs your name and email to sell you a licence and issue your key. We do not ask for sensitive information such as health details, biometrics or government identifiers, and we have no use for it.

6. Cookies, tracking and embedded content

We do not use analytics, tracking cookies or advertising pixels. There is no Google Analytics, no tag manager, no Meta pixel, no Plausible and no Hotjar. We do not build a profile of visitors and we do not know who you are when you browse the site. That is also why you do not see a cookie consent banner: we are not setting anything that would need one.

The site does load two things from other companies, and we would rather tell you than let you find them in your network tab:

The video player itself is not loaded until you choose to play it. The preview is a click to load facade: only when you press play do we load the player, from youtube-nocookie.com, and from that point YouTube's own terms and privacy practices apply to the playback.

Our hosting provider, Netlify, may keep standard server logs, such as IP addresses and requested pages, for delivering and securing the site. Installer downloads are served from GitHub Releases, so GitHub sees those download requests.

7. Who else processes your information

We keep the list of third parties short on purpose. These are the only ones involved:

We do not sell your personal information, and we do not disclose it to anyone for advertising or marketing by others. We may disclose information if we are required to by law.

Overseas processing

Netlify, Stripe, Brevo, GitHub, Google and YouTube are based overseas and may process or store your information outside Australia, including in the United States and in Europe. Our email provider may also handle your email outside Australia. If you buy a licence, download the trial or use the website, some of your information will be handled outside Australia by these providers under their own privacy terms.

8. How long we keep information

9. Keeping your information secure

The strongest protection we can offer is to hold very little. The application sends us nothing, so almost everything you do in FireFlow Studio for FDS never reaches us at all. What we do hold is your name, your email address, your licence record and our correspondence with you.

That information sits in our email account and in the accounts we hold with Stripe, Brevo, Netlify and GitHub. We protect those accounts with strong, unique passwords and, where the provider offers it, multi-factor authentication, and access is limited to the people who run the business. Those providers apply their own security measures, which you can read about in their privacy terms.

No system is completely secure and we will not pretend otherwise. If personal information we hold is lost or disclosed without authorisation and it is likely to cause you serious harm, we will tell you as soon as we reasonably can, and we will notify the Office of the Australian Information Commissioner where the Notifiable Data Breaches scheme requires it.

10. Your rights

You can ask us to:

Email info@fireflowstudio.com.au and we will respond as quickly as we reasonably can, and in any case within 30 days. There is no charge for making a request. We may need to confirm your identity first, usually by replying from the email address we hold for you. In the limited situations where the Australian Privacy Principles allow us to refuse a request, we will tell you why.

Complaints

If you think we have mishandled your personal information, please tell us first at info@fireflowstudio.com.au. We will look into it and let you know the outcome. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Customers in the EU and the UK

If you are in the European Union or the United Kingdom, you may exercise equivalent rights over your personal information, including access, correction, erasure, restriction, objection and data portability, and you may withdraw consent to marketing emails at any time. Use the same address, info@fireflowstudio.com.au, and we will deal with your request. You may also lodge a complaint with your local supervisory authority.

11. Changes to this statement

If we change how we handle personal information, we will update this statement and change the effective date at the top. If a change is significant, and we hold an email address for you, we will tell you by email. The current version is always published at fireflowstudio.com.au. This statement covers our own site, software and emails, not any third party website you reach from a link.

Effective 28 July 2026. See also the End-user licence agreement and Third-party notices.