User Tools

Site Tools


policy_-_privacy_policy

Privacy Policy

ACTION REQUIRED BEFORE PUBLICATION

This master policy is a legal and operational disclosure, not a substitute for discovering the facts. Replace every item marked [ACTION REQUIRED]. Delete every optional clause that does not match the real system. Do not publish statements about security, deletion, local processing, telemetry, cookies, hosting countries, encryption or third parties unless they have been technically verified. TBA

Document control Details
Policy owner SupportCALL Privacy Officer
Version 2.0 — master multi-service policy
Effective date 01 August 2026
Last reviewed (see the “Last modified:” at the base of the page)
Next review no later than 12 months after last review

1. The short version

We respect your privacy and limit personal information to what is reasonably necessary to provide, secure and improve the service you choose.

  • We do not sell personal information.
  • We do not use personal information for third-party behavioural advertising unless a service-specific notice clearly says so and you have the required choice or consent.
  • We do not ask for passwords, recovery codes, payment-card numbers, health records, identity documents or visa documents through ordinary email unless there is no safer approved channel.
  • Different SupportCALL services handle different information. A network diagnostic tool, help-desk portal, email service, clinical system and locally installed database do not have the same data flows. Section 5 explains each service.
  • Where a product is self-hosted, the customer normally controls the information stored in that installation. We do not automatically receive that customer content unless the customer enables an integration, telemetry or support access.
  • You may contact us to ask what personal information we hold about you, request correction, make a complaint, withdraw consent where processing relies on consent, or exercise another right that applies where you live.
  • Privacy requests: privacy@supportcall.com.au.

2. Who we are

This policy is issued by:

  • Australian entity or business: David H Maree Sole-Trader;
  • ABN: 21 498 105 915;
  • ACN, if applicable: (in progress…);
  • principal place of business: Launceston, Tasmania, Australia;
  • South African entity: **SupportCALL (Pty) Ltd Reg 2013/102719/07; and
  • product owner or licensor, where applicable: David H. Maree.

In this policy, “SupportCALL”, “we”, “us” and “our” mean the entity identified in the service-specific notice, order, licence, contract or collection form. If no entity is identified, contact us before submitting sensitive information.

For Australian privacy law, the relevant SupportCALL entity is the APP entity where the Privacy Act 1988 (Cth) applies. For South African privacy law, SupportCALL (Pty) Ltd is the responsible party where the Protection of Personal Information Act 4 of 2013 (POPIA) applies. Under the UK GDPR or EU GDPR, the relevant entity may be a controller or processor depending on the service and contract.

3. Scope

This policy applies to personal information handled through the following websites, subdomains, mobile applications, software, portals, communications and related services that link to this policy:

Service or domain Main function Privacy profile
supportcall.com.au ICT services, sales, support, consulting and enquiries Customer, prospect, billing, device, support and business-contact information
clientsitetest.supportcall.com.au and sites hosted beneath it Test, demonstration, staging or client websites Test and demonstration data; production personal information must not be used unless expressly authorised and protected
speedtest.supportcall-isp.co.za Internet speed testing IP address, test endpoint, network and performance measurements, device/browser metadata
tickets.supportcall.com.au Support and IT service-management portal Accounts, organisations, contacts, tickets, attachments, assets, configuration items, logs and support history
wanip.io IP, browser, privacy and network diagnostics Public IP, approximate geolocation, ISP/ASN, browser/device properties and diagnostic results
workflow4ai.com Workflow design and AI-assisted automation Prompts, workflow specifications, generated content, accounts, API/integration configuration and support data
sysadmin-ai.com AI-assisted system administration Prompts, scripts, technical environment details, diagnostics and generated output
sc-uscs.com Windows script generation and system-cleaning tools Selected options, generated scripts, device/browser metadata and technical diagnostics if submitted
sc-cloaked.com Security/privacy tool [ACTION REQUIRED: describe exact function, information processed, retention and whether processing is local]
pw-cloaked.com Encrypted secret or password exchange Encrypted payload, link/token metadata, expiry, access events and limited security logs; see section 5.7
sc-useo.com Website and SEO analysis Submitted URLs, site content, technical scan results, contact/account data and reports
seniormail.co.za Hosted email and user support Account, subscription, mailbox content and metadata, contacts, security logs and support records
maree-careflow.com.au and its application Self-hosted allied-health and NDIS practice management Health, disability, clinical, identity, funding, billing, staff, consent and audit information controlled mainly by the deploying practice
mareedb.com and Maree-DB software Database software, licensing, downloads and support Website enquiries, early-access registration, licensing, downloads and optional benchmark information; locally stored database content is controlled by the customer
immiassist2au.com General Australian immigration and settlement information Website usage and locally generated plans; any future account, assessment or document feature requires a separate just-in-time notice
Android applications published by us Mobile tools and companion applications The data and device permissions stated in this policy, the in-app notice and the applicable Google Play Data safety declaration

This policy also applies to telephone calls, email, messaging, remote support, onsite work, contracts, quotations, invoices, events, surveys, job applications and business administration associated with those services.

Third-party websites and services linked from our services have their own privacy practices. A link does not make us responsible for the third party's handling of information.

4. Our roles when handling information

4.1 When we decide why and how information is used

We act as the privacy principal, controller or responsible party for our own websites, sales, account administration, billing, licensing, security, marketing choices, recruitment and direct support relationships.

4.2 When we handle a customer's information for them

For managed ICT, hosted services, ticketing, backups, remote monitoring, Maree-CareFlow deployments and other customer-controlled systems, we may act only as a service provider, operator or processor. The customer determines why its end-user, employee, patient, participant or client information is processed. The customer's privacy notice applies to that information. We process it under the contract, documented instructions, confidentiality duties and applicable law.

We will not use customer-controlled content for our independent marketing, sell it, or train a general-purpose AI model on it unless a separate written agreement and all legally required notices and consents expressly permit that use.

4.3 Customer responsibilities

Customers must have a lawful basis and give all required notices before placing personal or sensitive information in a SupportCALL-managed or SupportCALL-licensed system. Customers must configure permissions, retention, integrations, AI providers, backups, exports and user accounts appropriately. A self-hosted product does not by itself make the customer's deployment legally compliant.

5. Service-specific information

5.1 SupportCALL ICT services and ticket portal

We may collect names, business names, roles, contact details, customer identifiers, service addresses, contracts, quotations, invoices, payment status, communications, appointment details and feedback.

Support records may contain usernames, device identifiers, serial numbers, IP and MAC addresses, operating-system and software details, configuration information, screenshots, recordings approved for the support session, event logs, security alerts, backup status, diagnostic data, ticket descriptions and attachments. Remote access may make information visible on a customer device. Support staff must access only what is reasonably necessary for the authorised task.

Do not place passwords, private keys, seed phrases, one-time codes, full payment-card data, health records or identity documents in an ordinary ticket. Use the approved secure exchange method. If unnecessary sensitive information is submitted, we may redact, isolate or delete it.

If call or screen recording is enabled, we will notify participants before recording unless recording is legally authorised without notice. [ACTION REQUIRED: confirm whether any calls, remote sessions or screens are recorded and state retention].

5.2 Test and demonstration websites

The clientsitetest.supportcall.com.au environment and sites beneath it may be unfinished, temporary, experimental or configured for demonstration. Do not enter real personal information, production credentials, health information, payment-card details, identity documents or confidential business information unless the page expressly states that production use is authorised.

We may reset or delete test environments without notice. Test data must be synthetic, masked or properly authorised. If a customer asks us to host production information in that environment, the parties must first document security, backups, retention, access, hosting location and controller/processor responsibilities.

5.3 Speed test and WANIP diagnostics

To provide network results, the service necessarily receives a public IP address and may process timestamps, test server, upload/download speed, latency, jitter, packet loss, protocol, ISP, ASN, approximate IP-derived location, referrer, user agent, browser, operating system, language, screen properties, connection attributes, WebRTC exposure, DNS results, HTTP headers and other values displayed in the diagnostic report.

Some browser tests may calculate a canvas or similar device/browser value. Such a value is used only to display or calculate the requested privacy/security result [ACTION REQUIRED: verify; if retained or used to recognise users, disclose exact purpose and retention].

The public IP address must reach our server for the webpage to work. “Zero tracking” or “zero data collection” does not mean the server never receives an IP address. It means, only if technically true, that diagnostic values are processed transiently and are not retained or used to follow the person across services. Standard security logs may still contain an IP address for a limited period.

We do not claim that IP geolocation, VPN, proxy, DNS leak, WebRTC or security results are exact. Do not use them as the sole basis for a legal, employment, credit, insurance, housing, healthcare or other high-impact decision.

5.4 Workflow4AI, SysAdmin AI, SC-USCS and SC-USeo

These tools may process prompts, instructions, selected settings, submitted URLs, public webpage content, system descriptions, error messages, configuration excerpts, scripts, workflow definitions, generated outputs and user feedback.

Do not submit credentials, secrets, private keys, access tokens, personal records, health information or confidential customer data unless the interface expressly supports that information and explains the safeguards. Remove or mask unnecessary identifiers before submission.

Where an external AI model or scanning provider is offered:

  • the interface must identify the provider or provider category before information is sent;
  • the user or customer chooses whether to enable it;
  • the provider may process information in another country under its own or our contracted terms;
  • output may be inaccurate or insecure and requires human review; and
  • we do not use submitted customer content to train a general-purpose model unless this is separately disclosed and lawfully agreed.

[ACTION REQUIRED: list every supported AI provider, search/scanning API, hosting provider and the destination country for each.]

5.5 SeniorMail

SeniorMail may process account names, email addresses, recovery details, billing records, mailbox quotas, login and security events, device and IP information, contacts, message metadata, message content, attachments, spam indicators and support communications.

Email content is private to the account holder and authorised recipients. It may be automatically processed to route mail, detect malware, filter spam, maintain backups, troubleshoot delivery and comply with law. Authorised staff may access mailbox information only where necessary, legally permitted and appropriately logged, such as at the account holder's verified request or to investigate abuse or security incidents.

Because the service is designed for seniors, we use identity-verification steps before account recovery, remote support, disclosure or deletion. A family member does not automatically have authority to access another adult's mailbox. We require verified consent, legal authority or another lawful basis.

[ACTION REQUIRED: state mail-server country, backup country, spam-filter providers, payment provider, message/back-up retention after account closure, and whether administrators can decrypt stored mail.]

5.6 Maree-CareFlow and health/NDIS information

Maree-CareFlow can process sensitive and health information including participant and patient identifiers, contact and emergency-contact details, date of birth, diagnoses, disability, functional information, clinical notes, assessments, risks, incidents, recordings or transcripts, documents, goals, appointments, practitioner records, AHPRA details, NDIS numbers and plans, funding, claims, invoices, insurer and case-manager details, legal proceeding indicators, audit logs and consent records.

For a self-hosted deployment, the allied-health practice or other deploying customer normally controls this information and chooses the server, users, retention, integrations, backups and optional AI. SupportCALL does not automatically receive clinical or participant content merely because it licenses the software.

Local AI processing may keep content within the customer's infrastructure. If the customer connects a cloud AI provider, calendar, accounting platform, payment provider, object-storage service, telehealth platform, government portal or other integration, data will flow to that provider as configured by the customer. The customer must complete a privacy, security, clinical-safety and overseas-disclosure assessment and obtain any required consent before enabling it.

AI-generated clinical content is a draft. A qualified human practitioner remains responsible for checking accuracy, clinical appropriateness, bias, attribution and compliance before use. AI must not be treated as a clinician, migration agent, lawyer or autonomous decision maker.

For hosted, enterprise-support or migration work, our access to health information must be limited by contract, role-based access, confidentiality, logging and a defined deletion schedule. [ACTION REQUIRED: create a separate Maree-CareFlow collection notice and data-processing agreement before production use.]

5.7 PW-Cloaked and SC-Cloaked

PW-Cloaked is intended to exchange a secret through an encrypted payload. Depending on its verified design, the system may process encrypted ciphertext, a random link or token identifier, creation and expiry time, retrieval count/status and limited IP/security logs. The sender and recipient remain responsible for using a separate secure channel to exchange any required decryption secret.

We do not need to know the plaintext to operate a correctly designed zero-knowledge service. [ACTION REQUIRED: cryptographically verify whether encryption and decryption occur only in the user's browser, whether the key appears in a URL fragment that is never sent to the server, whether server logs exclude secrets, and whether any administrator can decrypt payloads. Amend this paragraph to the verified design.]

Secrets must expire and be irreversibly deleted according to the displayed expiry or after the permitted retrieval count. Backups, replicas, caches and logs must follow a documented deletion process. Never use the service for unlawful content. No online secret-sharing system can guarantee that a recipient will not copy a secret or that a compromised device is safe.

SC-Cloaked's exact handling must be inserted here before that service links to this policy: [ACTION REQUIRED: function, collected data, local/server processing, encryption, retention, sharing, cookies and deletion method].

5.8 Maree-DB

The Maree-DB website may process enquiry and early-access details, business contact information, careers submissions, licensing and activation records, support records and standard download/security logs.

The locally installed Maree-DB product is designed so that customer database content remains under the customer's control. We do not receive stored tables, documents, vectors, graphs, queries, schemas or logs unless the customer deliberately sends them for support or enables a clearly disclosed feature.

Any optional benchmark sharing must be off by default and administrator initiated. The interface and documentation must show the exact payload before upload. Technical data can still be personal information when it can reasonably identify or be linked to a person or organisation. We therefore do not label data “anonymous” unless re-identification risk has been assessed; otherwise we describe it as pseudonymised or technical information and protect it accordingly.

The current service-specific Maree-DB policy and this master policy must not contradict each other. The more specific notice applies to the specific interaction, but this does not reduce legal rights.

5.9 ImmiAssist2AU

ImmiAssist2AU provides general information, not personal migration, legal, tax or financial advice. Its current interactive starting-point questions, target-date plan, checklist state and downloads are represented as operating on the user's device without upload.

Browsing the site still exposes ordinary web-request data such as IP address, timestamp, requested page and user agent to the host and security systems.

Do not upload passports, visas, birth or marriage certificates, police certificates, health documents, financial records, addresses, employment evidence or relationship evidence unless a future feature expressly requests them through an approved secure channel and presents a separate collection notice first. Any future personalised visa assessment, account, document vault, appointment, referral or paid-advice feature requires a privacy impact assessment before release.

We are not the Australian Department of Home Affairs and are not a registered migration agent merely because we publish general information.

5.10 Android applications

This policy applies to Android applications only where the Google Play listing and in-app privacy notice identify SupportCALL or one of the entities in section 2 as the developer.

An app may process account details, user-entered content, app settings, crash and diagnostic information, device/app identifiers, network information, files selected by the user and data required for the app's stated function. An app must not access a permission merely because Android makes it available.

Android permission or data Permitted reason Required control
Camera Scan a code, capture an authorised image or attach evidence Ask at the point of use; allow refusal where practical
Microphone User-initiated voice note, call or transcription Visible recording state; separate consent where required
Photos, video, audio or files User selects content to upload, process or back up Use system picker where possible; do not scan unrelated files
Contacts User expressly chooses a contact-related feature Do not upload the whole address book unless essential and clearly disclosed
Location A feature expressly requiring location Prefer approximate/background-free access; explain any background access
Notifications Service, security, reminder or status alerts User-controlled; not required for unrelated functionality
Device/network information Compatibility, diagnostics, fraud/security or the core network tool Minimise and retain only as stated
Cloud-storage account User-authorised backup/restore to the user's provider account OAuth; least privilege; no collection of the user's provider password

Each app must publish an accurate Google Play Data safety declaration consistent with the app's code, SDKs and this policy. If an app permits account creation, it must provide an in-app account-deletion path and a publicly accessible web method to request deletion of the account and associated data, subject only to disclosed lawful retention.

[ACTION REQUIRED: add an appendix listing every app name, package ID, purpose, minimum age, permissions, SDKs, data collected/shared, encryption, deletion URL and retention period. A generic policy alone is not enough if apps differ.]

6. Personal information we may collect

Depending on the service, we may collect:

  • identity and contact information;
  • account, authentication and preference information;
  • business, employment, practitioner and professional information;
  • contracts, orders, subscriptions, invoices and transaction records;
  • communications, enquiries, tickets, feedback and attachments;
  • device, browser, network, usage, log and security information;
  • service configuration, assets, licences and technical diagnostics;
  • location information, usually approximate and derived from an IP address;
  • content deliberately submitted to a tool, AI feature or support channel;
  • recruitment information; and
  • sensitive, special or health information only where the service legitimately requires it, the law permits it, and additional protections apply.

We may derive information, such as a fraud signal, device category, support priority, network/privacy result or aggregated service metric. We identify automated inferences that materially affect a person and provide human review where required by law.

7. How we collect information

We collect information:

  • directly from you when you browse, register, buy, subscribe, contact us, submit a ticket, use a tool, apply for work or request support;
  • automatically from your device and our servers as reasonably required to deliver and secure the service;
  • from your employer, practice, service provider, authorised representative, family member or customer where they are authorised to provide it;
  • from integrations you or a customer enables;
  • from payment, identity, fraud-prevention, hosting and support providers;
  • from public sources where lawful and reasonably expected; and
  • from regulators, courts, law enforcement or other authorities where permitted or required.

Where lawful and practical, you may deal with us anonymously or using a pseudonym. This may not be possible where we must verify identity, contract with you, invoice you, secure an account, provide remote support or comply with law.

8. Why we use information

We use information to:

  • provide, configure, maintain, secure and support products and services;
  • create and administer accounts, licences, subscriptions and customer relationships;
  • respond to enquiries, tickets, incidents and complaints;
  • process transactions and maintain accounting, tax and legal records;
  • detect spam, fraud, misuse, malware, security threats and technical failures;
  • diagnose performance and improve reliability, accessibility and usability;
  • communicate service, security, legal and operational notices;
  • send marketing only where permitted and honour opt-outs;
  • manage suppliers, staff, contractors and recruitment;
  • establish, exercise or defend legal claims;
  • comply with law, court orders, lawful government requests and professional obligations; and
  • create aggregated or de-identified statistics where re-identification is not reasonably likely and contractual controls prevent re-identification.

We do not use information for a materially incompatible purpose without a lawful basis and any required notice or consent.

Where Australian privacy law applies, we collect, use and disclose personal information for the notified primary purpose, a reasonably expected related purpose, with consent, or as otherwise authorised by law. Sensitive information receives the additional protections required by the Australian Privacy Principles.

Where POPIA applies, processing must be lawful, reasonable, minimal, purpose-specific, accurate, secure and appropriately retained. We rely on consent, contract, legal obligation, legitimate interests recognised by POPIA, protection of a legitimate interest, or another permitted ground. Special personal information and children's information are processed only where a statutory authorisation applies.

Where the UK GDPR or EU GDPR applies, the lawful basis may be performance of a contract, steps requested before a contract, compliance with law, legitimate interests balanced against individual rights, consent, protection of vital interests or another lawful basis. Special-category information requires an additional legal condition. Consent may be withdrawn prospectively at any time.

10. When we disclose information

We may disclose the minimum necessary information to:

  • personnel and contractors who need it and are bound by confidentiality;
  • a customer controlling the relevant account or system;
  • hosting, infrastructure, email, security, backup, communications, support, payment, accounting and professional-service providers;
  • AI, cloud, calendar, storage or other integration providers selected or enabled by the user or customer;
  • regulators, courts, law-enforcement bodies and other parties where legally authorised or required;
  • professional advisers and insurers;
  • a prospective buyer, investor or successor under confidentiality and lawful due diligence; and
  • another party with your direction or consent.

We do not sell personal information. We do not share it for cross-context behavioural advertising. If either practice changes, we will update the policy and provide all required notices and opt-outs before the change applies.

[ACTION REQUIRED: insert a current subprocessor/service-provider register with provider, purpose, data, country and applicable service. At minimum verify web hosting/CDN/DNS, email, ticketing, RMM, remote access, security monitoring, analytics, payment, accounting, backups, AI, error reporting, messaging, app SDKs and app-store services.]

11. Overseas handling

Our services operate across Australia, South Africa and potentially other countries. Personal information may be stored in or accessible from Australia and South Africa and from countries used by a selected hosting, email, payment, cloud, AI, support or app-platform provider.

Australian law requires an APP privacy policy to identify likely overseas disclosures and, where practicable, the countries involved. [ACTION REQUIRED: replace this paragraph with the verified country list. “Global cloud” is not sufficient.]

Before an overseas disclosure, we take reasonable steps required by applicable law, such as due diligence, contractual safeguards, access controls, data minimisation and transfer mechanisms. A user choosing an external provider does not automatically remove our duties.

12. Cookies, local storage and similar technologies

Our sites and apps may use:

  • essential session, authentication, security, load-balancing and preference storage;
  • local browser storage for user-controlled settings or on-device tools;
  • measurement or error-reporting technology only where actually deployed and lawfully configured; and
  • third-party content or integrations that may receive request metadata when loaded.

Non-essential analytics, advertising or similar technologies must not load before any consent required by applicable law. Rejecting non-essential cookies must be as easy as accepting them. Essential storage cannot always be disabled without breaking the requested feature.

[ACTION REQUIRED: run a cookie/storage and network scan on every production domain and Android app. Insert a cookie table containing name, provider, purpose, data, duration and essential/non-essential status.]

Global Privacy Control or browser “Do Not Track” signals will be honoured where legally required. Because there is no universally binding interpretation of “Do Not Track”, its treatment may differ where law does not require a response.

13. Direct marketing

We may send marketing where you have consented or where another lawful permission applies. Service and security messages are not marketing. You can opt out through the message mechanism or by contacting us. We will retain the minimum suppression record needed to honour the opt-out. We do not require agreement to unrelated marketing as a condition of receiving a service.

14. Security

We use risk-based administrative, technical and physical safeguards appropriate to the nature of the information. These may include access control, least privilege, multi-factor authentication, encryption in transit, encryption at rest where appropriate, logging, monitoring, patching, backups, recovery testing, staff confidentiality, supplier review, vulnerability management, secure development and incident response.

No system is completely secure. Security claims describe controls, not a guarantee that unauthorised access, loss or misuse can never occur. Users must protect credentials, use strong unique passwords and multi-factor authentication where available, keep recovery details current, update devices and report suspected compromise promptly.

Do not send vulnerability details through a public form. Security reports: [ACTION REQUIRED: security@ address or responsible-disclosure URL].

15. Data breaches

We maintain an incident-response process to contain, investigate, remediate and document suspected data breaches. Where required, we notify affected individuals, the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, South Africa's Information Regulator, customers acting as controllers/responsible parties, and other regulators or authorities within the applicable timeframe.

If we process information for a customer, we notify that customer without undue delay as required by contract and law so the customer can meet its own obligations.

16. Retention and deletion

We retain personal information only as long as reasonably necessary for the stated purpose, security, dispute resolution, enforcement and legal, tax, accounting or professional obligations. We then delete it, destroy it securely or de-identify it where lawful and technically feasible. Backup copies may remain until the protected backup cycle expires and are not restored for ordinary use after an approved deletion.

Information Default target retention
Web/security access logs [ACTION REQUIRED: e.g. 30–90 days unless investigating an incident]
Network and speed-test results [ACTION REQUIRED: transient only, or exact period]
Contact and sales enquiries [ACTION REQUIRED: e.g. 24 months after last contact]
Customer contracts, invoices and tax records Required statutory period plus any lawful dispute period
Support tickets and attachments [ACTION REQUIRED: e.g. contract term plus 24 months; sensitive attachments shorter]
Remote support recordings [ACTION REQUIRED: state “not recorded” or exact period]
Unsuccessful job applications [ACTION REQUIRED: commonly 6–12 months with consent for longer talent-pool use]
SeniorMail mailbox after closure [ACTION REQUIRED: active grace period, backup expiry and legal holds]
PW-Cloaked encrypted payloads Displayed expiry/retrieval rule plus [ACTION REQUIRED: backup/cache maximum]
Maree-DB download/security logs [ACTION REQUIRED: verify current policy and system]
App account and associated data Until deletion request/account closure plus specifically disclosed lawful retention
Customer-controlled or self-hosted content Set by the customer; SupportCALL copies deleted when support/migration purpose ends, subject to contract and backups
Privacy requests and consent/opt-out records Long enough to prove and honour the request and meet legal obligations

A legal hold, active security investigation or binding recordkeeping rule may temporarily override ordinary deletion. We disclose the reason where legally permitted.

17. Your choices and rights

Depending on the law that applies, you may have rights to:

  • know whether and how we process your information;
  • access or receive a copy;
  • correct inaccurate, incomplete, out-of-date or misleading information;
  • request deletion or destruction;
  • restrict or object to processing;
  • withdraw consent prospectively;
  • receive portable data in a structured format;
  • opt out of direct marketing, sale, sharing, targeted advertising or qualifying profiling;
  • request human review of a qualifying automated decision;
  • complain to us and an applicable regulator; and
  • receive equal service and pricing when exercising a right, except where the information is genuinely required for the service.

Rights are not absolute. We may retain or refuse information where law permits or requires, including to protect another person's privacy, preserve legal privilege, prevent fraud, maintain security or comply with recordkeeping duties. We will explain a refusal where required.

17.1 How to make a request

Email privacy@supportcall.com.au with the subject Privacy Request and state:

  1. your name and preferred contact method;
  2. the service, domain or Android app involved;
  3. the account/email or other identifier needed to locate the information; and
  4. the right you want to exercise.

Do not email identity documents initially. We will request proportionate verification through an appropriate channel if needed. An authorised agent must prove authority. We respond within the period required by applicable law and ordinarily aim to acknowledge a complaint or request promptly.

Android account deletion page: [ACTION REQUIRED: public HTTPS URL usable without app login].

18. Complaints

Send a complaint to:

  • Privacy Officer: David Maree Owner
  • Email: privacy@supportcall.com.au
  • Postal address: 10 Pedder St; Lanunceston; 7249; TAS
  • Telephone: +61 (0)4 99 33 5679

Describe the service, event, date, people involved and outcome sought. We will acknowledge, investigate and respond fairly. We will not retaliate because you made a privacy complaint.

If you remain dissatisfied, you may contact the regulator that applies, including:

19. Children and vulnerable people

Our general business, systems-administration, database and security services are not directed to children. A service designed for families, schools, health, NDIS or accessibility may legitimately process a child's information under the direction of an authorised adult or organisation and with the protections required by law.

We do not knowingly use children's information for behavioural advertising, sell it, or use it to train a general-purpose AI model. We use age-appropriate explanations, minimise collection, apply stricter defaults and verify the authority of a parent, guardian, competent person or service provider where required.

SeniorMail users and people receiving disability, health, settlement or migration information may be vulnerable to impersonation or coercion. We use proportionate verification and do not give another person access merely because they claim to be family, a carer or a support worker.

20. Automated systems and artificial intelligence

AI features may generate scripts, workflows, summaries, clinical drafts, classifications, recommendations or other content. AI output can be wrong, biased, incomplete or insecure. A competent human must review output before it affects a system, person, patient, participant, visa matter, payment, entitlement or legal right.

We disclose when personal information is sent to an external AI provider. We minimise prompts, restrict retention where the provider permits, prohibit provider training where contractually available, and require customers to configure their own provider consistently with law. Sensitive or health information must not be sent to an external AI provider without a documented lawful basis, required consent, security assessment and overseas-disclosure assessment.

We do not make a solely automated decision producing legal or similarly significant effects about an individual unless lawfully authorised, necessary safeguards exist and the person receives required information and review rights.

21. Payments

Payments may be handled by a third-party payment provider or financial institution. We aim not to store full payment-card numbers or card security codes. The payment provider's privacy policy applies to its independent handling. We may retain transaction identifiers, payer name, amount, status, billing contact and accounting records.

[ACTION REQUIRED: name every payment provider by service and country; confirm PCI scope and whether any site directly receives card data.]

22. Business changes

If a service or business is sold, merged, reorganised or transferred, relevant information may transfer under confidentiality and applicable law. We will provide notice and choices where required. We will not treat a business transfer as permission to use information for unrelated purposes.

23. Changes to this policy

We review this policy when services, laws, suppliers, countries, data practices or risks change and at least annually. The current version is posted with its effective date. For a material change, we provide prominent notice and seek consent where required. We do not silently convert previously collected information to a materially incompatible use.

24. Contact

SupportCALL Privacy Officer
Email: privacy@supportcall.com.au
Postal address: 10 Pedder St; Launceston; 7429; TAS
Telephone: +64 (0)4 99 33 5679
Security reports: [TBA]
Android account/data deletion: [TBA: URL]

Appendix A — Required service-provider register

Complete this table from contracts, hosting dashboards, DNS, source code, tag scans, Android dependency reports and production configuration. Do not guess.

Provider Service(s) Purpose Personal information Storage/access country Retention Contract/safeguard
[ACTION REQUIRED] [ACTION REQUIRED] Web hosting/CDN/DNS IP, logs, hosted submissions [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]
[ACTION REQUIRED] Ticket portal ITSM/help desk Accounts, tickets, attachments, assets [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]
[ACTION REQUIRED] Relevant services Email delivery/hosting Addresses, metadata, content as applicable [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]
[ACTION REQUIRED] Relevant services Payments Billing and transaction data [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]
[ACTION REQUIRED] Workflow4AI/SysAdmin AI/Maree-CareFlow Optional AI Prompts and generated output [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]
Google Android apps Play distribution, integrity and platform services Per Data safety declaration [ACTION REQUIRED] Provider controlled Google terms

Appendix B — Android application register

App name Package ID Function Minimum age Data collected Data shared Permissions/SDKs Retention Deletion URL
[ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED] [ACTION REQUIRED]

Appendix C — Pre-publication verification

  1. [ ] Confirm the exact contracting legal entity for every domain, app and service.
  2. [ ] Insert ABN/ACN, South African registration number and publishable addresses.
  3. [ ] Verify that privacy@supportcall.com.au is monitored and tested.
  4. [ ] Inventory all domains, subdomains, APIs, mobile apps and discontinued services.
  5. [ ] Scan cookies, local storage, scripts, pixels, fonts, embeds, SDKs and outbound network calls.
  6. [ ] Map data from collection to storage, access, sharing, backup and deletion.
  7. [ ] List all provider countries and cross-border safeguards.
  8. [ ] Verify every “local”, “self-hosted”, “zero telemetry”, “zero tracking”, “encrypted” and “not retained” claim against production code and logs.
  9. [ ] Set and technically enforce every retention period.
  10. [ ] Create a separate just-in-time collection notice for health, immigration documents, recruitment, remote recording and external AI.
  11. [ ] Create customer data-processing agreements for processor/operator services.
  12. [ ] Create a public Android account/data-deletion page and an in-app deletion path for every app with accounts.
  13. [ ] Reconcile every Google Play Data safety form with actual code and SDK behaviour.
  14. [ ] Complete a privacy impact assessment for Maree-CareFlow, AI features, children's information, biometrics, high-risk monitoring and any future ImmiAssist2AU document feature.
  15. [ ] Test access, correction, deletion, complaint and breach-response procedures.
  16. [ ] Obtain Australian and South African privacy-law review before publication; obtain EU/UK advice if intentionally offering regulated services there.

Appendix D — Authoritative references

Status: Comprehensive master draft. Not approved for publication until all [ACTION REQUIRED] fields are completed, the statements are checked against production systems, and qualified privacy counsel reviews the final version. A privacy policy must describe what actually happens; broad protective wording cannot cure an undisclosed or non-compliant data practice.

policy_-_privacy_policy.txt · Last modified: by thesaint

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki