Privacy Policy
Last updated: 29 July 2026 (version 2026-07-29). This is a living document — updated as Redrock PM evolves.
Redrock Systems Pty Ltd (ABN 53 696 760 433) ("we", "us", "our") is committed to protecting the privacy of individuals whose personal information we collect and handle. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Australian Privacy Principles ("APPs") under the Privacy Act 1988 (Cth).
1. Information We Collect
We collect the following categories of personal information:
- Account information: Name, email address, phone number, job title, organisation details
- Authentication data: Encrypted passwords, multi-factor authentication secrets (TOTP), session tokens
- Client data: Information you enter about your clients, including names, addresses, tax file numbers, financial records, and compliance documentation
- Usage data: Login timestamps, feature usage, browser type, IP address
- Payment information: Billing details processed through Stripe (we do not store card numbers)
2. How We Collect Information
We collect personal information directly from you when you register, use the Platform, or communicate with us. We may also collect information automatically through cookies and server logs when you access the Platform.
3. Purpose of Collection
We collect and use personal information to:
- Provide, maintain, and improve the Platform
- Authenticate users and enforce access controls
- Process payments and manage subscriptions
- Send transactional emails (e.g. document requests, engagement letters, notifications)
- Comply with legal obligations, including AML/CTF record-keeping requirements
- Respond to support requests and enquiries
4. Data Hosting and Storage
All data is hosted in Sydney, Australia (ap-southeast-2) on infrastructure provided by Supabase (backed by AWS). Data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Database backups are retained in the same region.
5. Third-Party Service Providers
We use the following third-party services to operate the Platform. Each is engaged under appropriate data processing agreements:
- Supabase(Sydney) — Database hosting, authentication, file storage
- Vercel(Sydney) — Application hosting, edge functions
- Stripe— Payment processing (PCI DSS Level 1 certified)
- Resend— Transactional email delivery (fallback)
- Microsoft 365— Primary email delivery via Graph API
- Annature— Electronic signature services
- Sentry— Error monitoring and crash reporting. Error data is scrubbed of tax file numbers, emails, phone numbers, and ABNs before being sent.
6. Disclosure of Personal Information
We do not sell personal information. We may disclose personal information to:
- Third-party service providers listed above, solely for the purpose of operating the Platform
- Law enforcement or regulatory bodies where required by Australian law
- Your organisation's administrators, who manage user accounts and access permissions
7. Cross-Border Disclosure
Some of our third-party providers (Stripe, Resend, Sentry) may process data outside Australia. Where this occurs, we take reasonable steps to ensure compliance with the APPs and that the overseas recipient handles information in a manner consistent with Australian privacy law.
8. Government Identifiers — Tax File Numbers (APP 9)
Tax file numbers (TFNs) are government identifiers subject to additional protection under the Taxation Administration Act 1953 (Cth) and the Privacy (Tax File Number) Rule 2015, beyond the general protections that apply to other personal information under the APPs. We collect and use TFNs only to the extent necessary to deliver tax and compliance-related practice management services on your behalf. We do not use a TFN as a general account identifier, and we do not disclose TFNs to any party other than those listed in section 6 above. TFNs are subject to the same field-level encryption and access controls described in section 11.
9. Direct Marketing (APP 7)
We do not use your clients' personal information for direct marketing. We may send product update and marketing emails to your organisation's account holders. You can opt out of marketing emails at any time via the unsubscribe link in those emails, or by contacting privacy@redrocksystems.com.au. Opting out of marketing does not affect transactional emails necessary to operate your account (e.g. billing notices, security alerts).
10. Data Retention
We retain personal information for as long as your account is active or as needed to provide the Platform. AML/CTF compliance records are retained for a minimum of 7 years as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); other records may be subject to their own retention periods under tax agent or professional obligations applicable to your firm. Upon account termination, non-compliance data is deleted within 90 days.
11. Data Security
We implement technical and organisational measures to protect personal information, including:
- Encryption at rest and in transit
- Row-level security (RLS) ensuring tenant data isolation
- Multi-factor authentication enforcement
- Role-based access control (8 roles with granular permissions)
- HMAC-signed session tokens and hashed access credentials
- Regular security audits and vulnerability assessments
12. Notifiable Data Breaches (Part IIIC, Privacy Act)
If we become aware of an eligible data breach — one likely to result in serious harm to one or more individuals — we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) within 30 days of becoming aware of the breach, including a description of the breach, the information involved, and the steps we are taking in response. We maintain an internal data breach response plan.
13. Your Rights
Under the APPs, you have the right to:
- Access the personal information we hold about you
- Correct any inaccurate or out-of-date information
- Request deletion of your personal information (subject to legal retention requirements)
- Withdraw consent for marketing communications at any time
To exercise these rights, contact us at privacy@redrocksystems.com.au. We will respond within 30 days.
14. Complaints
If you believe we have breached the APPs, you may lodge a complaint with us at the email address above. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a notice on the Platform. The "last updated" date at the top of this page reflects the most recent revision.
16. Contact
For privacy enquiries, contact our Privacy Officer at: privacy@redrocksystems.com.au
Redrock Systems Pty Ltd
ABN 53 696 760 433
Perth, Western Australia
17. Trust Center
For the formal Data Processing Agreement, full sub-processor register, and data residency commitments that apply across all RedRock Systems products, see the RedRock Systems Trust Center.