// Legal

Privacy Policy

Last updated · 24 July 2026

Plain-English summary: SubSync AI Pty Ltd, trading as ConsultSync AI ("ConsultSync", "we", "us"), respects your privacy and protects personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, hold, use and disclose personal information when you use the ConsultSync platform, website and related services ("Services"), and how we handle uploaded documents and commercially sensitive information.

1. Collection of Personal Information (APP 3)

We collect personal information that is reasonably necessary for providing and operating the ConsultSync platform and related services. Types of personal information we may collect include:

  • Account and billing details such as name, email address, business name, practice details and payment information. Payment card information is processed by Stripe and is not stored by ConsultSync.
  • Inputs submitted to the Services, which may include consultancy agreements and other materials that contain personal information about individuals, and any standard terms and exclusions you save to your account.
  • Technical and usage data including IP address, device information, browser type, system logs and analytics information.
  • Support requests, contact form submissions, communications and feedback.

We generally collect personal information directly from you when you create an account, use the Services, contact support or communicate with us. We may also collect information automatically through cookies and system logs.

User responsibility for uploaded information

Users are responsible for ensuring they have the legal right to upload any document or information to the Services, including personal information relating to third parties (such as individuals named in consultancy agreements), commercially sensitive or confidential information belonging to principals, developers, head contractors or other parties, and documents subject to confidentiality obligations. By submitting information to the Services, you represent that you have obtained any required consents or authorisations. ConsultSync does not independently verify whether users have obtained the required permissions.

2. Handling of Uploaded Contract Documents

Consultancy agreements and related documents uploaded to the Platform are treated as Confidential Information. In addition to the protections described in this Privacy Policy, uploaded contract documents are subject to the following safeguards.

Storage location

Uploaded documents and review records are stored encrypted at rest in the Sydney, Australia region.

Retention of uploaded documents

Uploaded contract documents and associated Inputs are retained for the duration of your subscription and for 12 months following account closure, after which they are deleted or de-identified unless retention is required by law. You may delete a review and its stored contract file from your dashboard at any time, or request deletion by contacting privacy@consultsync.com.au.

Use of uploaded documents

Uploaded contract documents are used solely to:

  • generate Outputs for you as part of the Services
  • operate, maintain and improve the technical performance of the Platform
  • comply with legal obligations

ConsultSync does not use uploaded contract documents or their contents to train, fine-tune or improve public or shared AI models. De-identified, aggregated or statistical data may be used to improve system performance and reliability.

Access by ConsultSync personnel

Access to uploaded contract documents by ConsultSync personnel is restricted to authorised personnel with a legitimate business need, such as security investigation, technical support or legal compliance. All personnel are subject to confidentiality obligations.

AI sub-processors

The Platform uses third-party AI model providers to process Inputs and generate Outputs. These providers operate as data sub-processors and are contractually required to handle uploaded content as confidential and not to use it for model training. Our current sub-processors are: Supabase (database and file storage, Sydney), Vercel (application hosting), Stripe (payments), n8n (workflow orchestration), Mistral (document OCR), OpenAI and Anthropic (AI review models), Google Workspace (report delivery and schedule generation), Tavily (legislative reference lookups) and Resend (transactional email). Further details are available on request from privacy@consultsync.com.au.

3. Anonymity and Pseudonymity (APP 2)

Where lawful and practicable, you may interact with us anonymously or using a pseudonym. However, this may limit our ability to provide certain Services including account creation, billing or customer support.

4. Notification of Collection (APP 5)

At or before the time we collect personal information, we take reasonable steps to notify you of the identity and contact details of ConsultSync, the purposes for which information is collected, the entities to which it may be disclosed, whether it may be disclosed overseas, the consequences of non-collection, and how you may access, correct or complain about handling of your information. This Privacy Policy and notices provided during sign-up serve as our collection notice. If you do not provide certain personal information, we may be unable to create your account, provide the Services, process payments or respond to support requests.

5. Use and Disclosure of Personal Information (APPs 6–7)

We use and disclose personal information only for the primary purpose of providing, operating, securing, billing, supporting and improving the Services, purposes reasonably related to that primary purpose, and purposes authorised or required by law.

We may disclose personal information to:

  • cloud hosting providers
  • AI and data processing sub-processors
  • payment processors
  • professional advisors including lawyers and accountants
  • regulators or government authorities where required by law
  • entities involved in a corporate transaction such as a merger, acquisition or asset sale

We will comply with APP 7 for any direct marketing communications. You may opt out of marketing at any time.

6. Business Customer and Team Data

Where an organisation creates a company on the Platform and invites employees, contractors or authorised users, ConsultSync may process personal information associated with those users on behalf of that organisation. Team members within the same company can see the company's reviews and uploaded documents. The organisation is responsible for providing required privacy notices to its personnel and ensuring it has a lawful basis for providing that information to ConsultSync.

7. Cross-Border Disclosure (APP 8)

Account data and uploaded documents are stored in Australia (Sydney region). Some service providers we use — in particular AI model providers used to generate Outputs — are located outside Australia, and document content may be processed by recipients located in countries including the United States and Europe during review processing. We take reasonable steps to ensure overseas recipients handle personal information and Confidential Information in a manner consistent with the Australian Privacy Principles, including through contractual safeguards, data processing agreements and vendor due diligence.

8. Government Related Identifiers (APP 9)

We do not adopt, use or disclose government-related identifiers such as tax file numbers or passport numbers as our own identifiers unless permitted by law.

9. Quality of Personal Information (APP 10)

We take reasonable steps to ensure personal information we collect, use or disclose is accurate, up-to-date and complete.

10. Security of Personal Information (APP 11)

We take reasonable technical and organisational measures to protect personal information and uploaded documents from misuse, interference, loss, unauthorised access, modification or disclosure. These measures include encryption of data in transit and at rest, row-level access controls, private storage buckets with signed time-limited access, monitoring and audit logging.

Personal information and uploaded documents are destroyed or de-identified when they are no longer required for the purpose for which they were collected, subject to the retention periods described in clause 2 and any legal retention requirements. Despite these measures, no system can guarantee absolute security. If you become aware of a suspected security issue, please notify us immediately at security@consultsync.com.au.

11. Cookies and Analytics

Our website and Services use cookies and similar technologies to operate and secure the platform (authentication session cookies) and understand usage. No third-party advertising cookies are used, and no third-party analytics run on authenticated pages. You may adjust your browser settings to refuse cookies, although the authenticated parts of the Services will not function without them.

12. Automated Decision-Making and AI Outputs

Outputs generated by AI systems are probabilistic and may contain errors, biases or inaccuracies. Any personal information appearing in or inferred from AI Outputs is handled in accordance with this Privacy Policy. ConsultSync does not use personal information to make or support automated decisions that are reasonably expected to significantly affect individuals' legal rights or interests. The Platform generates analytical tools to assist human decision-making; all significant decisions remain with the user.

13. Prohibited or High-Risk Data

Unless expressly authorised in writing, users must not submit to the Services:

  • health information
  • biometric information
  • government identifiers
  • financial account credentials
  • personal information relating to children under 16 years of age

ConsultSync is not designed to process high-risk or regulated categories of personal information.

14. Access and Correction (APPs 12–13)

You may request access to personal information we hold about you and request corrections if it is inaccurate, out-of-date, incomplete, irrelevant or misleading. Requests can be made to the Privacy Officer, SubSync AI Pty Ltd, at privacy@consultsync.com.au. We will respond within a reasonable period and may charge a reasonable administrative fee where permitted by law.

15. Notifiable Data Breaches

We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If an eligible data breach occurs, we will assess the breach promptly, notify affected individuals where required, and notify the Office of the Australian Information Commissioner (OAIC). If you become aware of a suspected breach involving data processed via our Services, please notify us immediately at privacy@consultsync.com.au.

16. Complaints

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you may contact our Privacy Officer at privacy@consultsync.com.au. We will acknowledge and investigate complaints promptly. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Where practicable, material changes will be notified by email or prominent website notice at least 30 days before they take effect. Continued use of the Services after updates take effect constitutes acceptance of the updated policy.

18. Governing Law

This Privacy Policy is governed by the laws of Victoria, Australia.

Contact

Privacy Officer
SubSync AI Pty Ltd trading as ConsultSync AI
Melbourne, Victoria, Australia
Email: privacy@consultsync.com.au
Website: consultsync.com.au

© SubSync AI Pty Ltd 2026 · ACN 695 835 539 · ABN 68 695 835 539 · Melbourne, Victoria, Australia