PRIVACY POLICY
Supply’d Pty Ltd (ABN 17 636 457 817)
Effective Date: 1st October 2026
1. Introduction
Supply’d Pty Ltd (“Supply’d”, “we”, “our”, or “us”) is committed to protecting the privacy of our customers, authorised users, and visitors. This Privacy Policy sets out how we collect, use, store, process, and disclose personal information in connection with our software platforms, websites, applications, and related services (the “Services”).
We comply with applicable privacy and data protection laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, international privacy and data protection laws.
By creating a User Account, accessing our website, or using our Services, you acknowledge that your personal information will be handled in accordance with this Privacy Policy and our Terms of Service.
2. Information We Collect
We collect personal information reasonably necessary to deliver, maintain, secure, and improve our Services. This may include:
- Account & Identity Information: Names, job titles, business email addresses, phone numbers, login credentials, account information, and billing or payment details.
- Customer Data & Content: Business communications, customer and supplier information, transaction records, documents, inventory data, operational workflows, employee information, and other data uploaded, created, imported, or processed through the Services by or on behalf of a Customer.
- Technical & Usage Information: IP addresses, browser types, device identifiers, system activity logs, feature usage, integration performance, diagnostic data, and information about how the Services are accessed and used.
- Third-Party Integration Information: Account tokens, credentials, identifiers, and operational information exchanged when you connect Third-Party Services, such as accounting, payment, point-of-sale, ecommerce, shipping, logistics, or other platforms, to Supply’d.
- Website, Marketing & Enquiry Information: Information you provide when booking a demonstration, submitting an enquiry, subscribing to communications, attending an event, downloading a resource, or otherwise interacting with Supply’d, together with information about how you interact with our website and communications.
3. How We Collect Information
We collect personal information in a number of ways, including:
- directly from you when you create an account, contact us, book a demonstration, subscribe to communications, submit information through our website, or use the Services;
- from Customers where they provide information about their employees, customers, suppliers, contractors, or other individuals in connection with their use of the Services;
- through Third-Party Services and integrations that you or a Customer authorise to connect with Supply’d;
- automatically when you access or use our websites or Services, including through server logs, cookies, device information, system activity, and usage data; and
- from publicly available sources, business directories, referral partners, and other lawful sources where relevant to our business activities.
We generally hold personal information electronically within the systems and infrastructure used to provide and operate the Services.
Customers are responsible for ensuring that they have the necessary rights, permissions, notices, and lawful basis to provide personal information to Supply’d through their use of the Services.
4. How We Use Personal Information
We collect and use personal information for purposes including:
- Service Delivery: To establish and manage User Accounts, process transactions, facilitate orders, manage subscriptions, and provide the Services.
- Platform Operations & Support: To maintain platform performance, perform system updates, provide customer support, investigate issues, conduct diagnostic analysis, and maintain data integrity.
- Integrations: To exchange Customer Data with authorised Third-Party Services at the Customer’s request.
- Security & Compliance: To prevent unauthorised access, detect and investigate security incidents or fraudulent activity, maintain audit records, enforce our agreements, and comply with legal obligations.
- Communications & Marketing: To respond to enquiries, arrange demonstrations, communicate service and product updates, provide information about Supply’d products and services, and send marketing communications where permitted by law. You may opt out of marketing communications at any time.
- Improvement & Analytics: To understand how our Services are used, improve functionality and usability, develop new features, troubleshoot issues, and analyse service performance.
5. Artificial Intelligence & Machine Learning
Supply’d uses artificial intelligence (AI), machine learning (ML), and other automated technologies to provide features such as document extraction, forecasting, classification, operational analysis, recommendations, and conversational assistance.
- Use of Customer Data: Customer Data may be processed by AI or ML systems where necessary to provide features requested or enabled by the Customer. This may include analysing information, generating responses or recommendations, extracting information from documents, forecasting demand, and supporting operational workflows.
- Customer-Specific Configuration: Supply’d may use Customer Data to configure, adapt, or improve customer-specific rules, workflows, models, or functionality solely for that Customer’s use of the Services. Customer-specific configurations remain isolated from other customers.
- No General AI Model Training: Customer Data will not be used to train, develop, or improve general-purpose AI or machine learning models for the benefit of other customers or third parties unless the Customer has provided express prior authorisation.
- Third-Party AI Providers: Supply’d may use third-party AI or cloud service providers to process Customer Data when delivering AI-enabled functionality. Where we do so, we take reasonable steps to ensure those providers handle Customer Data consistently with applicable privacy obligations and our contractual requirements.
- Document Processing: Where requested or expressly authorised by the Customer, documents and associated corrections or feedback may be used to improve Supply’d document scanning, OCR, classification, or extraction models across the platform.
6. Automated Decision-Making Systems
Our Services include automated systems that may analyse data, generate forecasts, recommend purchasing or production requirements, classify information, identify exceptions, suggest actions, or trigger workflows configured by a Customer.
These systems are primarily designed to assist Customers with operational and business decisions, such as inventory management, purchasing, production planning, forecasting, document processing, and logistics. These activities do not generally involve automated decisions that significantly affect the rights or interests of an individual.
Unless a Customer has expressly configured the Services to take an automated action, automated recommendations and AI-generated outputs are generally provided as decision-support tools and may be reviewed or adjusted by an authorised user.
If Supply’d introduces or operates functionality that uses personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, this Privacy Policy will be updated to describe:
- the kinds of personal information used by those automated systems;
- the kinds of decisions made solely by those automated systems; and
- the kinds of decisions for which an automated system performs something substantially and directly related to making the decision.
Customers are responsible for determining whether automated workflows they independently configure through the Services are appropriate for their business and for complying with laws applicable to their use of those workflows.
Customers are responsible for determining whether automated workflows they configure through the Services are appropriate for their business and for complying with laws applicable to their use of those workflows.
7. Disclosure & Overseas Data Transfers
We do not sell, rent, or trade personal information to third parties for marketing purposes. We may disclose personal information in circumstances including:
- Service Providers & Sub-processors: To trusted third-party providers that support the operation of our Services, including cloud infrastructure, hosting, communications, analytics, payment processing, security, support, and technology providers.
- Third-Party Integrations: Where a Customer enables an integration with another platform, data may be exchanged with that provider as authorised by the Customer and as necessary to provide the integration.
- Professional Advisers: To professional advisers such as legal, accounting, insurance, or security providers where reasonably necessary.
- Corporate Transactions: Where reasonably necessary in connection with a proposed or completed merger, acquisition, financing, restructuring, or sale of all or part of our business or assets.
- Legal Requirements: Where required or authorised by law, court order, regulatory body, or law enforcement agency, or where reasonably necessary to protect the rights, safety, security, or property of Supply’d, our Customers, users, or others.
Overseas Transfers: Some of our service providers and sub-processors may store or process personal information outside Australia. The countries in which personal information is likely to be stored or processed include Australia, Singapore, and the United States.
Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles that information consistently with applicable privacy requirements, including through appropriate contractual, technical, and organisational safeguards.
Personal information may also be transferred to other countries where a Customer enables a Third-Party Service that operates or stores information outside Australia. The handling of information by that Third-Party Service may also be subject to the third party’s own privacy policy and terms.
8. Data Retention, Export & Deletion Lifecycle
We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, provide the Services, manage active accounts, maintain appropriate business and security records, or comply with legal requirements.
- Active Accounts: While your User Account is active, Customers may export Customer Data using standard self-service tools available within the platform.
- Post-Termination Retention Window: Following the effective date of account termination, Customer Data will remain recoverable and available for requested export for up to ninety (90) days.
- Permanent Deletion: After the 90-day post-termination period, Customer Data will be permanently deleted or de-identified from active operational databases, except where retention is required by law or reasonably necessary for security, fraud prevention, dispute resolution, enforcement of contractual rights, or other legitimate legal purposes.
Residual encrypted copies of Customer Data contained in routine system backups will be overwritten according to our standard backup cycle, currently up to 30 days following deletion from active operational systems, and will remain securely protected until destroyed.
Certain records, including billing, accounting, security, audit, and legal records, may be retained for longer periods where reasonably necessary or required by law.
9. Data Security
We implement technical and organisational security measures designed to protect personal information against unauthorised access, disclosure, loss, misuse, alteration, or destruction.
These safeguards may include encryption in transit using TLS/HTTPS, encryption of stored data where appropriate, role-based access controls, authentication controls, network security measures, system logging and monitoring, backup procedures, and regular security reviews.
While we take reasonable steps to protect personal information, no electronic transmission, system, or method of storage can be guaranteed to be completely secure.
Users are responsible for maintaining the confidentiality of their login credentials and for taking reasonable steps to protect access to their User Account. We recommend using strong, unique passwords and enabling two-factor authentication where available.
10. Cookies & Tracking Technologies
We use cookies and similar technologies to operate and improve our websites and Services, understand how they are used, remember preferences, measure website performance, and support marketing and advertising activities.
These technologies may collect information including IP addresses, browser and device information, pages viewed, interactions with our website, referring websites, and other usage information.
We may use both first-party technologies operated by Supply’d and third-party technologies provided by trusted analytics, advertising, and technology providers. Where required by applicable law, we will obtain consent before using non-essential cookies or similar technologies.
You may be able to control or disable cookies through your browser or device settings. Disabling certain cookies may affect the functionality of some parts of our websites or Services.
11. Third-Party Services & Links
Our Services may contain links to, or integrate with, websites and services operated by third parties. Supply’d does not control the privacy, security, or data-handling practices of those third parties.
Where you choose to access or connect a Third-Party Service, the third party’s own privacy policy and terms may apply to information it receives or processes. We recommend reviewing those policies before providing personal information or enabling an integration.
12. Your Rights & Access
Subject to applicable law, you may have the right to:
- access the personal information we hold about you;
- request correction of inaccurate, incomplete, or out-of-date personal information;
- request deletion or restriction of your personal information where applicable;
- withdraw consent where processing is based on your consent;
- opt out of non-essential marketing communications; and
- exercise any additional rights available to you under applicable privacy laws.
Some rights may be subject to legal, regulatory, contractual, security, or record-keeping requirements.
To exercise any of these rights, please contact our Privacy Officer using the details below. We may need to verify your identity before responding to a request.
13. Children’s Privacy
Supply’d is primarily designed for use by businesses and their authorised users and is not directed towards children.
The Privacy Act 1988 (Cth) protects personal information regardless of an individual’s age. Where consent is required in relation to a child’s personal information, whether the child is capable of providing that consent will depend on whether they have sufficient understanding and capacity in the circumstances.
If we become aware that personal information relating to a child has been provided to Supply’d in circumstances where appropriate consent or authority was required but not obtained, we may take reasonable steps to restrict processing or delete the information.
If you believe that a child’s personal information has been provided to us inappropriately, please contact our Privacy Officer.
14. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes to our Services, legal requirements, security practices, or business operations.
Where appropriate, we will notify Customers of material changes by email, in-app notification, website notice, or another reasonable method before those changes take effect. The current version of this Privacy Policy will be made available through our website.
15. Contact Us & Complaints
If you have questions or concerns about our privacy practices, wish to exercise your privacy rights, or wish to lodge a privacy complaint, please contact:
The Privacy Officer / Company Secretary
Supply’d Pty Ltd
Level 2, 66 Victor Crescent
Narre Warren VIC 3805
Australia
Phone: +61 3 9068 7812
Email: [email protected]
If you lodge a privacy complaint with us, we will acknowledge the complaint, investigate the matter, and aim to provide a substantive response within 30 days. If we require additional time, we will let you know.
If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or another relevant privacy regulator in your jurisdiction.
Information about the OAIC and its complaints process is available at www.oaic.gov.au.