1. Who we are
This policy applies to Strongpoint (ABN 34 093 188 820), including the website at www.strongpoint.com.au, our software services, client portals and integrations (together, the “Services”). In this policy, “we”, “us” and “our” mean Strongpoint.
We handle personal information in accordance with applicable Australian privacy law, including the Australian Privacy Principles where they apply.
2. Information we collect
Depending on how you use the Services, we may collect:
- identity and contact details, such as your name, business name, email address, telephone number and postal address;
- account and authentication information, including usernames, roles and secure authentication tokens;
- project, support and commercial information you provide when requesting or using our Services;
- technical and usage information, such as IP address, browser type, device information, logs and interactions with the Services;
- billing and transaction information, although payment card details may be processed directly by our payment providers; and
- data you authorise us to access from third-party services, including accounting platforms such as Xero.
Please do not provide personal information about another person unless you are authorised to do so.
3. How we collect information
We collect information directly from you when you contact us, create an account, submit a form, engage us or use the Services. We may also collect information automatically through service logs and cookies, from your organisation, or from a third-party service that you choose to connect.
4. Why we use information
We use information where reasonably necessary to:
- provide, operate, secure and improve the Services;
- authenticate users and administer accounts and permissions;
- deliver projects, integrations, support and requested communications;
- process transactions and maintain business and legal records;
- detect misuse, investigate incidents and protect our users and systems;
- comply with legal obligations and enforce our agreements; and
- send relevant business communications where permitted, with an option to unsubscribe from marketing.
5. Connected services and Xero data
If you connect a third-party service, you authorise us to access and process the information permitted by the scopes you approve. For a Xero connection, this may include organisation details, contacts, accounts, invoices, payments, bank transactions and financial reports, depending on the permissions selected.
We use connected-service data only to provide the integration and features you request. We do not sell Xero data and do not use data obtained through Xero’s API to train, fine-tune, adapt or enhance artificial intelligence or machine-learning models. You can revoke a Xero connection through Xero or ask us to disconnect it.
6. Automated and AI-assisted features
Some Services may use third-party artificial intelligence providers to process information and generate requested outputs. Where enabled, we limit the information supplied to what is reasonably necessary for the feature, apply appropriate access controls and configure providers in accordance with our contractual and privacy obligations. AI-generated output should be reviewed by a person before it is relied upon for financial, legal or other consequential decisions.
7. Disclosure and service providers
We may disclose information to personnel and contractors who need it to perform their work, and to service providers supporting hosting, storage, authentication, communications, analytics, payments, support and software functionality. We may also disclose information with your direction or consent, as part of a business restructure, or where required or permitted by law.
Some providers may process information outside Australia. Where this occurs, we take reasonable steps to select reputable providers and apply appropriate contractual and technical safeguards.
8. Security and retention
We use reasonable administrative, technical and physical safeguards appropriate to the nature of the information, including access controls, encrypted transport and secure credential storage. No internet-connected system is completely secure, and we cannot guarantee absolute security.
We retain information only for as long as reasonably needed for the purposes described in this policy, to provide the Services, resolve disputes, maintain backups and meet legal, accounting or reporting obligations. We then delete, destroy or de-identify it where practicable.
9. Cookies and links
Our website may use essential cookies and similar technologies for security, authentication and functionality. If we use non-essential analytics or marketing cookies, we will provide any notice or choice required by law. Our Services may link to third-party websites whose privacy practices we do not control.
10. Access, correction and complaints
You may request access to or correction of personal information we hold about you. You may also ask a privacy question or make a complaint by emailing privacy@strongpoint.com.au. We may need to verify your identity and may decline a request where permitted by law. We will investigate complaints and respond within a reasonable period.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
11. Changes to this policy
We may update this policy as our Services or legal obligations change. The current version will be published on this page with its effective date. Material changes may also be communicated through the Services or directly to affected users.
12. Contact
Strongpoint31 Cordova Street
Milton QLD 4064, Australia
privacy@strongpoint.com.au
07 3876 2925