Terms of use

Last updated: 10 August 2026

1. Purpose and scope

Mission Control is Citra's internal enterprise resource planning system. It supports Citra's construction and property development operations and contains commercially sensitive business information.

This policy applies to every Citra employee who is granted access to Mission Control, in any role, on any device. It supplements — and does not replace — your employment agreement, any non-disclosure agreement you have signed, and Citra's other IT and information security policies. Where this policy and another Citra policy differ, the stricter requirement applies.

Access to Mission Control is a privilege granted for the performance of your role. It is not a personal entitlement and may be modified or revoked by Citra at any time.

2. Confidentiality and proprietary rights

All data and information on Mission Control is proprietary to Citra. This includes, without limitation:

  • Data — project records, unit and inventory data, pricing, feasibility and scenario models, financial figures, milestone and schedule information, partner, vendor, contractor and customer records, personnel data, audit logs, and any report, extract, or derivative work produced from them.
  • Interface — the design, layout, navigation structure, screens, visual identity, and user experience of Mission Control.
  • Processes — the business logic, workflows, approval chains, calculation methods, data models, integrations, and operating procedures that Mission Control implements or embodies.
  • Software — the source code, configuration, infrastructure, architecture, documentation, and technical specifications of the system.

All of the above is the confidential and proprietary property of Citra. Citra retains all right, title, and interest in it, including all intellectual property rights. Nothing in your access to Mission Control grants you any ownership, licence, or right to use this information outside your work for Citra.

You must:

  • Treat everything you access in Mission Control as confidential;
  • Not disclose it to anyone — inside or outside Citra — who is not authorised to receive it and does not need it for their work;
  • Not publish, post, discuss, or reproduce it publicly, including on social media, in professional portfolios, in job applications or interviews, or in any AI or third-party tool that is not approved by Citra;
  • Not photograph, screen-record, or screenshot Mission Control screens except where required for Citra business.

These obligations continue after your employment with Citra ends, for as long as the information remains confidential.

3. Authorised use

Use Mission Control only for legitimate Citra business, and only within the permissions assigned to your role. You must not:

  • Access, or attempt to access, data or functions outside your granted permissions;
  • Use another person's account, share your account, or allow anyone to use a session opened under your account;
  • Circumvent, disable, or test authentication, authorisation, or audit controls without prior written authorisation from [ROLE];
  • Introduce malicious code, scrape or bulk-extract data by automated means, or connect unapproved software, scripts, browser extensions, or integrations to Mission Control;
  • Enter false, misleading, or deliberately incomplete information into the system;
  • Use Mission Control for personal gain, for the benefit of a competitor, or for any unlawful purpose.

If you are granted access to data you do not need, or believe your permissions are broader than your role requires, report it to [EMAIL].

4. Account security

  • Access Mission Control only through your assigned Citra account and approved sign-in method.
  • Never share your credentials or authentication factors with anyone, including colleagues, managers, or IT staff.
  • Lock or sign out of unattended devices. Do not leave Mission Control open on shared or public screens.
  • Access Mission Control only from devices that meet Citra's security requirements, and avoid untrusted public networks.
  • Report a lost or stolen device, a suspected credential compromise, or any unauthorised access immediately to [EMAIL].

5. Data handling and export

  • Keep Mission Control data inside Mission Control and other approved Citra systems. Do not copy it into personal email, personal cloud storage, personal devices, messaging apps, or unapproved third-party tools.
  • Export data only where your work requires it. Exports are logged.
  • Store any export in an approved Citra location, share it only with authorised recipients, and delete it once it is no longer needed.
  • Apply the same care to printed material. Do not leave printouts unattended; dispose of them securely.
  • Mission Control contains personal information about employees, partners, and customers. Handle it in accordance with [APPLICABLE DATA PROTECTION LAW / CITRA PRIVACY POLICY] and collect, use, and disclose it only as your role requires.

6. Monitoring and audit logging

You have no expectation of privacy in your use of Mission Control.

Citra logs and may review activity in Mission Control, including sign-ins, records viewed and changed, searches, exports, permission changes, and administrative actions. Logs are retained for [RETENTION PERIOD] and may be used to:

  • Investigate suspected policy violations, security incidents, or data loss;
  • Meet audit, regulatory, or legal obligations;
  • Maintain and improve the security and reliability of the system.

Citra may disclose log data to auditors, regulators, or law enforcement where required or permitted by law.

7. Reporting

Report the following to [EMAIL] without delay:

  • Suspected or actual unauthorised access, disclosure, or loss of Mission Control data;
  • Security vulnerabilities or defects you discover;
  • Accidental access to information you should not be able to see;
  • Any request from outside Citra for Mission Control data.

Report promptly and in good faith. Citra will not penalise anyone for a good-faith report, including a report of their own mistake.

8. When your access ends

When you leave Citra, change roles, or are asked to do so, you must:

  • Stop using Mission Control immediately upon revocation of access;
  • Return or securely destroy all Mission Control data, exports, and printouts in your possession, in whatever form and on whatever device;
  • Confirm to [ROLE] that you have done so, if asked.

Your confidentiality obligations under Section 2 survive the end of your access and the end of your employment.

9. Violations

Violating this policy may result in suspension or revocation of access, disciplinary action up to and including termination of employment, and civil or criminal proceedings. Citra reserves all rights and remedies available to it.

10. Changes to this policy

Citra may update this policy at any time. Material changes will be notified through Mission Control, and continued use after the effective date of a new version constitutes acceptance of it. The current version is always available at [LINK].