Privacy Policy

    Effective Date: January 1, 2025 · Last Updated: March 2026

    EntityFlo Pty Ltd ("EntityFlo", "we", "our", "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy outlines how we collect, use, store, and disclose your personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR") and UK GDPR.

    Data Controller: EntityFlo Pty Ltd, ABN 12 692 755 614, 1150 Gold Coast Hwy, Palm Beach 4221, Queensland, Australia.

    1. Information We Collect

    We may collect the following types of personal information:

    • • Name, contact details (email, phone number, address)
    • • Business details (company name, role, ABN)
    • • Account login credentials
    • • Payment and billing information
    • • Communications with us (emails, phone calls, messages)
    • • Usage data when you interact with our website, products, or services
    • • Technical data including IP address, browser type, device identifiers, and cookie identifiers

    2. How We Collect Information

    We collect information directly from you when you:

    • • Register for or use our services
    • • Contact us by phone, email, or through our website
    • • Subscribe to newsletters or marketing communications
    • • Participate in surveys, feedback, or promotions

    We may also collect information indirectly through:

    • • Cookies, analytics, and tracking technologies (see our Cookie Policy)
    • • Publicly available sources
    • • Third-party service providers

    Where the GDPR or UK GDPR applies, we process your personal data on the following legal bases:

    Data CategoryPurposeLegal Basis
    Account and contact detailsProviding and managing our servicesContractual necessity
    Payment and billing informationProcessing paymentsContractual necessity
    Usage and technical dataImproving our platform and servicesLegitimate interest
    Marketing communicationsSending promotional contentConsent
    Communications and enquiriesResponding to your requestsLegitimate interest
    Legal and compliance dataMeeting regulatory obligationsLegal obligation

    Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

    4. Use of Personal Information

    We use your personal information to:

    • • Provide and manage our products and services
    • • Communicate with you about your account or enquiries
    • • Process payments and billing
    • • Improve our website, services, and customer experience
    • • Send marketing and promotional communications (you can opt out at any time)
    • • Comply with legal and regulatory requirements
    • • Detect, prevent, and address technical issues or fraudulent activity

    5. Disclosure of Personal Information

    We may share your information with:

    • • Our employees, contractors, and service providers
    • • Payment processors, IT and cloud hosting providers
    • • Regulatory bodies or government authorities (where legally required)
    • • Other parties with your explicit consent

    We do not sell or rent your personal information to third parties.

    6. Data Retention

    We retain your personal information only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law.

    Data CategoryRetention Period
    Account and profile dataDuration of account plus 7 years
    Payment and billing records7 years (legal/tax requirement)
    Marketing consent recordsUntil consent is withdrawn plus 3 years
    Usage and analytics data26 months
    Communications and support records3 years from last interaction

    After the applicable retention period, data is securely deleted or anonymised.

    7. Data Storage & Security

    We take reasonable steps to protect your personal information from misuse, loss, and unauthorised access. This includes secure servers, encryption in transit and at rest, role-based access controls, and regular security reviews.

    8. Overseas Disclosure

    Some service providers we use may store or process personal information outside Australia or, where GDPR applies, outside the EEA or UK. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, or equivalent mechanisms required under applicable law.

    9. Your Rights

    Australian residents have the right to request access to and correction of their personal information held by us.

    EEA and UK residents have the following additional rights under the GDPR and UK GDPR:

    • Right of access — Request a copy of the personal data we hold about you
    • Right to rectification — Request correction of inaccurate or incomplete data
    • Right to erasure — Request deletion of your personal data in certain circumstances
    • Right to restrict processing — Request that we limit how we use your data
    • Right to data portability — Request your data in a structured, machine-readable format
    • Right to object — Object to processing based on legitimate interest or for direct marketing
    • Right to withdraw consent — Withdraw consent at any time where processing is based on consent

    To exercise any of these rights, contact us at privacy@entityflo.com. We will respond within 30 days.

    10. Right to Lodge a Complaint

    If you are located in the EEA or UK and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In Ireland, this is the Data Protection Commission (DPC) at dataprotection.ie.

    Australian residents may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

    11. Cookies & Website Tracking

    Our website uses cookies and similar technologies. Analytics and non-essential cookies are only placed with your prior consent, which you can manage through our cookie consent banner. For full details, see our Cookie Policy.

    12. Marketing Communications

    We may send you marketing communications about our products and services where you have given consent or where we have a legitimate interest in doing so. You may opt out at any time by clicking the unsubscribe link in any email or contacting us at hello@entityflo.com.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised effective date. We encourage you to review this policy periodically.

    14. Contact Us

    EntityFlo Pty Ltd

    ABN: 12 692 755 614

    1150 Gold Coast Hwy, Palm Beach 4221, Queensland, Australia

    Email: hello@entityflo.com

    Privacy enquiries: privacy@entityflo.com

    Phone: 02 4406 4934

    We use cookies to improve your experience. Essential cookies are always active. You can accept all cookies or choose essential only.