Privacy Policy
CoreConverge Pty Ltd (ABN 60 669 440 331) ("CoreConverge", "we", "us") operates the CoreConverge platform. This policy explains how we handle personal information, and applies to our website, our platform, and the services we provide to business customers.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. What we collect
Account information — name, business email address, business phone number, job title, and the name and ABN of the organisation you represent.
Authentication data — credentials and session tokens necessary to operate your account, and OAuth tokens issued by third-party services you choose to connect.
Customer business data — where you connect a third-party system such as Xero, we access and store business records from that system. These may include contact records, invoices, bills, bank account balances and transaction records, and financial reports. Contact records may contain personal information about your customers and suppliers.
Usage data — log records, IP address, browser and device information, and records of actions taken within the platform.
2. How we collect it
We collect information directly from you when you create an account or use the platform, and from third-party systems that you explicitly authorise us to connect to on your behalf. We do not purchase personal information from data brokers and we do not collect personal information from publicly available sources for the purpose of building profiles.
3. Why we collect it
We use personal information to provide and operate the platform, authenticate users, generate the financial and operational insights you have asked us to produce, provide support, meet our legal obligations, and improve the reliability and security of our services.
4. Automated processing and AI
The platform uses large language models to analyse business data and generate summaries, insights and recommendations. Business data — which may include personal information contained within contact and transaction records — is transmitted to the model providers listed in our sub-processor list for this purpose.
We contract with these providers on terms that prohibit the use of your data to train their models. Outputs generated by these models are advisory. Material actions within the platform require human approval before execution.
5. Who we share it with
We share personal information with the service providers listed in our sub-processor list, each of whom is engaged to perform a specific function on our behalf and is bound by confidentiality and data protection obligations.
We do not sell personal information. We do not disclose personal information for the purpose of direct marketing by third parties.
We may disclose personal information where required by law, to enforce our terms, or to protect the rights or safety of any person.
6. Overseas disclosure
Some of our service providers are located outside Australia. Personal information may be disclosed to recipients in Australia and the United States, and may be processed through global edge infrastructure where that is required to deliver the service. The current provider locations and any remaining verification notes are listed in our sub-processor list. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
Our primary application infrastructure is hosted in Australia (Google Cloud, australia-southeast1).
7. Security
We protect personal information using encryption in transit and at rest, tenant isolation enforced at the database layer, least-privilege access controls for our personnel, and logging of access to customer data. Further detail is available in our security overview.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
8. Retention and deletion
We retain personal information for as long as your account is active and for 30 days afterwards, unless a longer period is required by law. You may request deletion of your data at any time by contacting us. Disconnecting a third-party integration stops further collection but does not by itself delete data already held; contact us if you require deletion.
9. Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate. Contact us using the details below. We will respond within a reasonable period. If we refuse a request we will tell you why in writing.
10. Cookies
We use cookies that are strictly necessary to operate the platform and keep you signed in. We also use optional analytics cookies to understand how the platform is used. PostHog analytics is loaded only after you choose to allow analytics; it records page views and selected product events for the identified workspace user. We disable PostHog autocapture and session recording in the platform configuration.
11. Complaints
If you believe we have mishandled your personal information, contact us at kalyan@coreconverge.com.au. We will acknowledge your complaint and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
12. Changes
We may update this policy. We will post the updated version here with a new effective date, and where changes are material we will notify account holders directly.
13. Contact
CoreConverge Pty Ltd, ABN 60 669 440 331 [POSTAL ADDRESS] kalyan@coreconverge.com.au