Privacy
What we hold, and why.
This policy covers the Claybase platform and this website. It is written against the Australian Privacy Principles in the Privacy Act 1988 (Cth), in plain words rather than legal ones.
Who we are
Claybase is operated by R2G GROUP PTY LTD trading as Claybase, ABN 20 643 625 003, of Brisbane, Queensland, Australia. In this policy, we and us mean that company. You can reach us at hello@claybase.com.au.
Two groups of people
Claybase is used by a business, and that business uses it to serve its own customers. That makes two groups, and we treat them differently.
A business that uses Claybase
We hold that business’s information because it has an account with us, and we deal with it directly.
That business’s customers
When a business records its customers, jobs and invoices in its workspace, we hold that information on the business’s behalf. The relationship is with the business, so a request about that information normally goes to the business. If one comes to us, we pass it on and help the business answer it.
What we collect from a business that uses Claybase
- Contact and identity details: your name, your business name, your ABN, email address, phone number and postal or business address.
- Account details: the users you create, their roles, and the settings and branding you apply to your workspace.
- Billing details: what you are charged and whether it is paid. Card numbers are entered with our payment provider and are not stored by us.
- Technical records: sign-in times, IP address, browser and device information, and a log of significant actions taken inside your workspace.
- Anything you write to us: support emails and the attachments you send with them.
What a business records about its own customers
This is the information a business puts into its workspace, and what it contains is that business’s choice. In practice it usually includes:
- Names, phone numbers, email addresses and the addresses where work is done.
- Job details: what was asked for, when it is booked, who is doing it and what was done.
- Quotes, invoices, payment status and payment references.
- Calls and text messages made or received through the platform, including recordings and transcripts where the business turns those on.
- Notes staff write, and email sent to or received from the customer through the platform.
Why we hold it
- To provide the platform and do the things a business asks it to do.
- To take payments, issue documents, and carry calls, text messages and email.
- To answer support requests and fix faults.
- To keep the service secure, to detect misuse, and to reconstruct what happened when something goes wrong.
- To meet obligations under Australian tax, company and consumer law.
We do not sell personal information. We do not use it to build advertising profiles, and we do not use the contents of a workspace for anything other than running the service for that business.
Where it is stored
Claybase runs on cloud hosting and managed database services operated by third parties. Some of those providers store or process data outside Australia, including in the United States. Where we disclose personal information to an overseas recipient, we take reasonable steps to have it handled consistently with the Australian Privacy Principles.
Who else sees it
We share information with the service providers we need in order to run the platform, and only so far as each needs it to do its job:
- A cloud hosting and database provider, which stores the data.
- A payment provider, which processes card payments and payouts.
- A telephony provider, which carries phone calls and text messages.
- An email delivery provider, which sends the email the platform generates.
- Error and performance monitoring services, where they are in use.
- Our professional advisers, such as accountants and lawyers, where they need it.
We also disclose information where the law requires it, for example to a court, a regulator or a law enforcement agency acting under a proper authority. If the business is ever sold or restructured, information may pass to the new owner, and this policy would continue to apply to it.
This website
This website sets no cookies, runs no analytics, and carries no tracking scripts of any kind. Nothing here is loaded from a third party: the fonts, images and stylesheet all come from this site. Our web host keeps ordinary server logs, which include IP addresses, for security and troubleshooting. The platform itself, at app.claybase.com.au, does set a cookie so that you stay signed in; that is a working part of signing in, not tracking.
How long we keep it
We keep a workspace’s information for as long as the workspace is open. After it closes, we keep what we must in order to meet record-keeping obligations, which for business and tax records in Australia is generally five years, and then delete or de-identify it. Backups are kept on a rolling cycle and are overwritten in the ordinary course.
Keeping it safe
Access is limited to the people who need it, data is encrypted in transit, each workspace is separated from every other, and significant actions are logged. No system is perfect. If a data breach happens that is likely to cause serious harm, we will notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Getting a copy, or correcting something
Write to hello@claybase.com.au and ask. We will confirm who you are, then respond within 30 days. There is no charge for asking. If what you are asking about sits inside a business’s workspace and belongs to that business’s records, we will pass your request to that business, because they are the ones who hold the relationship with you. If we cannot give you what you ask for, we will tell you why in writing.
If you are unhappy with how we handled it
Write to hello@claybase.com.au with the word COMPLAINT in the subject line, and we will look at it and respond within 30 days. If you are not satisfied with our answer, you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
This is the first published version of this policy. When it changes, the new version is published on this page with a new date at the top of it. If a change is significant, we will tell the businesses using the platform directly.