Suiviro Legal
Privacy Policy
Last updated: 7 July 2026
Suiviro (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how Suiviro collects, uses, stores and discloses information when you use our software, website, mobile-web application and related services (“Services”). It is intended to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and, for visitors from those regions, incorporates the additional disclosures required by the EU / UK GDPR, the Swiss FADP and the California CCPA / CPRA.
1. Anonymity and Pseudonymity
Where lawful and practicable, individuals may deal with Suiviro anonymously or under a pseudonym. Anonymity is not practicable for account holders because we must identify the business responsible for the subscription and for communications sent through the Services.
2. Information We Collect
Account Information
- Name
- Email address
- Phone number
- Business name
- Business address
- Billing information
Client Information
Users may store information relating to their customers including:
- Customer names, phone numbers, email addresses and addresses
- Job history, notes and communications
- Uploaded files and photographs
Staff Information
- Name and contact details
- User permissions and assigned jobs
- Activity records
Technical Information
- IP address
- Device, browser and operating system information
- Login activity and usage analytics
3. How We Use Information
- Provide the Services
- Create and manage accounts
- Process subscriptions
- Deliver notifications
- Provide customer support
- Improve the Services
- Monitor security
- Comply with legal obligations
4. Communications
Suiviro may process email notifications, SMS notifications, customer portal communications and internal messaging. Messages may be stored as part of the job history and client record.
5. Client Data
Users control the client data they upload into Suiviro. Client data remains the property of the business that entered it. Suiviro processes client data only for the purpose of providing the Services.
End-customer personal information
Where an individual is a customer of a Suiviro account holder (for example, a homeowner whose plumber uses Suiviro to schedule a job), Suiviro acts as a processor on behalf of that account holder. We do not have a direct relationship with those end-customers. Requests to access, correct or delete end-customer information should be directed to the Suiviro account holder that collected it. If an end-customer contacts Suiviro directly, we will forward the request to the responsible account holder and confirm receipt to the individual.
6. Unsolicited Information
If we receive personal information we did not solicit, we will determine within a reasonable period whether we could have collected it under the Australian Privacy Principles. If not, we will destroy or de-identify the information as soon as practicable, unless we are required by law or a court order to retain it.
7. Data Quality
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date and complete. Account holders can review and update their business, staff and client details from within the Suiviro application at any time.
8. Government Identifiers
We do not use government-issued identifiers (such as Tax File Numbers, Medicare numbers or driver licence numbers) as our own identifier of individuals.
9. Xero, Google and Microsoft Integrations
Users may connect Xero, Google Calendar and Microsoft Outlook. When connected, Suiviro may access information necessary to provide integration functionality. Suiviro does not access more information than reasonably required for the Services. Use of third-party integrations is subject to the privacy policies of those providers.
10. Cookies
Suiviro uses cookies and similar technologies to maintain login sessions, remember preferences, improve performance and analyse usage. Additional information is available in our Cookie Policy.
11. Disclosure of Information
We do not sell personal information. We disclose personal information to the third-party service providers listed below (our "subprocessors") strictly to deliver the Suiviro Services, and to professional advisers or government authorities where required by law. Integration subprocessors only receive data if you enable the corresponding integration in your account.
Core platform subprocessors
Always active for every Suiviro account.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase (via AWS) | Managed Postgres, authentication, file storage, backups | All application data: businesses, users, clients, jobs, files, notifications | Australia (ap-southeast-2) |
| Cloudflare | Edge hosting, CDN, DDoS protection, TLS termination | Request metadata (IP, user-agent, URL); no database contents | Global edge; AU point-of-presence used for AU traffic |
| Lovable | Platform hosting, deployment and monitoring | Application code and configuration; runtime request metadata. Suiviro does not currently expose AI features that receive Xero, client or job data. | Global |
Optional integration subprocessors
Active only when the account owner connects the integration.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Xero | Accounting integration: import contacts, sync quotes and invoices | OAuth tokens; contact, quote and invoice data you choose to sync | Global (Xero-controlled) |
| ClickSend | SMS delivery for reminders, confirmations and staff notifications | Client and staff phone numbers, SMS body content, delivery receipts | Australia (primary), global routing |
| Microsoft 365 (Outlook / Exchange Online) | Transactional email; two-way Outlook calendar sync and inbound mail parsing when enabled | Recipient/sender email addresses, subject, body, delivery events; OAuth tokens and calendar/mail metadata | Global (Microsoft-controlled) |
| Google (Calendar, Sign-in) | Two-way calendar sync and Google OAuth sign-in when enabled | OAuth tokens; calendar event metadata you choose to sync | Global (Google-controlled) |
| Paddle | Merchant-of-record billing, card processing, tax handling, invoicing | Billing name, email, address, transaction amount, card token (never full card) | UK / EU / global |
Suiviro may add, remove or replace subprocessors as the product evolves. Material changes will be reflected in this list with an updated date at the top of this Privacy Policy. To request advance notification of subprocessor changes, email privacy@suiviro.com.
12. International Data Storage
Data is primarily stored in Australia. Certain service providers may process data in other jurisdictions, including the European Union, United Kingdom, United States, and New Zealand. Where personal information is disclosed to overseas recipients, we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles the information consistently with the Australian Privacy Principles, including through contractual safeguards.
12A. Your Rights in the EEA, UK and Switzerland (GDPR)
If you are located in the European Economic Area, the United Kingdom or Switzerland, the EU General Data Protection Regulation, the UK GDPR and the Swiss FADP grant you the following rights in respect of the personal information Suiviro holds about you as a data controller (typically account and billing information): the right to access, rectify, erase, restrict or object to processing, and the right to data portability. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
Legal bases we rely on
- Performance of a contract — to create your account, deliver the Services and provide support.
- Legitimate interests — to secure the platform, prevent abuse, and improve the product, provided those interests are not overridden by your rights.
- Legal obligation — to retain financial records and to respond to lawful requests from regulators.
- Consent — for optional marketing communications and non-essential cookies where applicable.
International transfers
Where personal information is transferred out of the EEA, UK or Switzerland, Suiviro relies on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and equivalent safeguards implemented by our subprocessors (see the tables above). Data is primarily stored in Australia, which does not have an EU adequacy decision; the SCCs provide the required safeguard for that transfer.
Where end-customer data is involved
Where Suiviro processes end-customer information on behalf of an account holder (for example, a homeowner's contact details entered by a plumber), Suiviro acts as a data processor. The account holder is the data controller and is the primary point of contact for GDPR requests. See our Data Processing Agreement for the processor terms.
EEA / UK representative
Suiviro is established in Australia and does not currently offer goods or services to, or systematically monitor, individuals in the EEA or the UK at a scale that requires the appointment of a representative under Article 27 of the GDPR or Article 27 of the UK GDPR. If our processing later meets those thresholds, we will appoint a representative and publish their contact details in this section within 30 days.
Complaints and contact
To exercise any of these rights, contact privacy@suiviro.com. You may also lodge a complaint with your local supervisory authority — for example, the Irish Data Protection Commission, the UK Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.
12B. Your Rights in California (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the following rights in respect of the personal information Suiviro holds about you as a business: the right to know what categories of personal information we collect and the purposes we use it for; the right to request a copy or deletion of that information; the right to correct inaccurate information; and the right to opt out of the "sale" or "sharing" of personal information, and to limit the use of sensitive personal information.
Do Not Sell or Share My Personal Information
Suiviro does not sell your personal information, and does not share it for cross-context behavioural advertising, in the sense used by California Civil Code §1798.140(ad) and §1798.140(ah). We have not sold or shared personal information in the preceding 12 months and do not intend to do so. Because we do not engage in these activities, we do not provide a separate "Do Not Sell or Share" web form; if that changes, we will publish one at this URL. We do not collect sensitive personal information for the purposes of inferring characteristics about you, and there is nothing to opt out of under the "limit use of sensitive personal information" right.
To exercise a right, email privacy@suiviro.com. We will verify your identity using information already associated with your account. You may authorise an agent to make a request on your behalf; we may require written authorisation and identity verification before we act on the request. We will not discriminate against you for exercising a right under the CCPA/CPRA.
Where an end-customer of a Suiviro account holder is a California resident, the account holder is generally the "business" under the CCPA/CPRA and Suiviro acts as a "service provider" under a written contract that limits our use of that data to providing the Services.
13. Data Security
We implement reasonable security measures including encrypted connections (HTTPS), access controls, authentication systems, role-based permissions, monitoring and logging, and secure cloud infrastructure. No system can be guaranteed completely secure.
Where an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
14. Data Retention
Account and client data is retained while the account remains active. Following account termination, data is deleted within 30 days, and backups containing that data are overwritten in the normal backup rotation within a further 30 days.
Financial records (invoices, subscription payments and related information) may be retained for up to 7 years as required by the Corporations Act 2001 (Cth) and the A New Tax System (Goods and Services Tax) Act 1999 (Cth).
15. Access and Correction
You may request access to personal information we hold about you, and request correction of inaccurate information. Requests can be made through admin@suiviro.com. We will respond within 30 days.
16. Marketing Communications
We may send service-related communications. Marketing communications will only be sent where permitted by law and may be unsubscribed from at any time.
Customers and end-users of Suiviro account holders are not marketed to by Suiviro. Communications sent to those customers through the Services (email, SMS or portal messages) are sent by the Suiviro account holder, not by Suiviro.
17. Children's Privacy
Suiviro accounts are not intended for use by children under 18 years of age. We do not knowingly collect information from children for account creation.
The Suiviro customer portal may be used by end-consumers of an account holder's business. Account holders are responsible for ensuring that any collection or use of information relating to minors through the Services complies with applicable law.
18. Complaints
If you believe we have breached your privacy rights, please contact our Privacy Officer at privacy@suiviro.com. We will acknowledge your complaint within 7 days and respond substantively within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
19. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Services or website. Continued use of the Services constitutes acceptance of the updated Privacy Policy.
20. Availability and Contact
A copy of this Privacy Policy will be provided in an alternative format on request. Privacy enquiries can be directed to our Privacy Officer at privacy@suiviro.com. Security enquiries: security@suiviro.com. Postal notices: Suiviro Pty Ltd, PO Box 2060, Marmion WA 6020, Australia. Data controller: Suiviro Pty Ltd (ACN 699 266 987, ABN 30 699 266 987).
Questions about this document? Email admin@suiviro.com.