Legal
Privacy policy
Not a finished document — do not publish this page as-is.
This is a structural outline of what the privacy policy needs to cover. It has not been drafted or reviewed by an Australian legal practitioner and it is not legal advice. Generate the real document with a compliant generator (Termly or Iubenda both handle Australian Privacy Principles), have a solicitor review it, then replace this file entirely.
See HANDOVER.md · Legal section
01Who we are and what this covers
- Legal entity name and ABN
- Contact point for privacy enquiries, including a postal address
- That the policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles
02What we collect
- Scan requests: business name, suburb, industry, contact name, email, optional phone
- Account data: billing contact, connected Google Business Profile identifiers
- Customer contact lists uploaded by clients for review requests — this is the sensitive one
- Review content, private feedback and video testimonials collected on a client's behalf
- Analytics and cookies — list every tool actually in use
03Why we collect it and the lawful basis
- Delivering the scan and the platform
- Sending review requests on behalf of the client, and the client's role as the party with the customer relationship
- Explicitly state we do not sell personal information
04Who we disclose it to
- Name the platform provider that processes review data
- SMS, email and WhatsApp delivery providers
- Payment processor
- Any overseas recipients and the countries involved — required under APP 8
05Data location and cross-border disclosure
- Where data is hosted and processed
- That the underlying review platform is operated outside Australia, and what that means
06Consent, opt-out and the Spam Act
- How consent for SMS and email review requests is established, and whose obligation it is
- Unsubscribe mechanism in every message, honoured within five business days
- Australian Spam Act 2003 compliance, including sender identification
07Retention and deletion
- How long contact lists, review data and video testimonials are kept
- Deletion on account closure, and the export available before that
08Access, correction and complaints
- How an individual requests access or correction under APP 12 and 13
- Complaint process and escalation to the OAIC
09Security and breach notification
- Security measures in plain language
- Notifiable Data Breaches scheme obligations and the notification process