Supply'd - A revolutionary ERP

PRIVACY POLICY
Supply’d Pty Ltd (ABN 17 636 457 817)
Effective Date: 1st October 2026

1. Introduction

Supply’d Pty Ltd (“Supply’d”, “we”, “our”, or “us”) is committed to protecting the privacy of our customers, authorised users, and visitors. This Privacy Policy sets out how we collect, use, store, process, and disclose personal information in connection with our software platforms, websites, applications, and related services (the “Services”).

We comply with applicable privacy and data protection laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, international privacy and data protection laws.

By creating a User Account, accessing our website, or using our Services, you acknowledge that your personal information will be handled in accordance with this Privacy Policy and our Terms of Service.

2. Information We Collect

We collect personal information reasonably necessary to deliver, maintain, secure, and improve our Services. This may include:

3. How We Collect Information

We collect personal information in a number of ways, including:

We generally hold personal information electronically within the systems and infrastructure used to provide and operate the Services.

Customers are responsible for ensuring that they have the necessary rights, permissions, notices, and lawful basis to provide personal information to Supply’d through their use of the Services.

4. How We Use Personal Information

We collect and use personal information for purposes including:

5. Artificial Intelligence & Machine Learning

Supply’d uses artificial intelligence (AI), machine learning (ML), and other automated technologies to provide features such as document extraction, forecasting, classification, operational analysis, recommendations, and conversational assistance.

6. Automated Decision-Making Systems

Our Services include automated systems that may analyse data, generate forecasts, recommend purchasing or production requirements, classify information, identify exceptions, suggest actions, or trigger workflows configured by a Customer.

These systems are primarily designed to assist Customers with operational and business decisions, such as inventory management, purchasing, production planning, forecasting, document processing, and logistics. These activities do not generally involve automated decisions that significantly affect the rights or interests of an individual.

Unless a Customer has expressly configured the Services to take an automated action, automated recommendations and AI-generated outputs are generally provided as decision-support tools and may be reviewed or adjusted by an authorised user.

If Supply’d introduces or operates functionality that uses personal information to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, this Privacy Policy will be updated to describe:

Customers are responsible for determining whether automated workflows they independently configure through the Services are appropriate for their business and for complying with laws applicable to their use of those workflows.

Customers are responsible for determining whether automated workflows they configure through the Services are appropriate for their business and for complying with laws applicable to their use of those workflows.

7. Disclosure & Overseas Data Transfers

We do not sell, rent, or trade personal information to third parties for marketing purposes. We may disclose personal information in circumstances including:

Overseas Transfers: Some of our service providers and sub-processors may store or process personal information outside Australia. The countries in which personal information is likely to be stored or processed include Australia, Singapore, and the United States.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles that information consistently with applicable privacy requirements, including through appropriate contractual, technical, and organisational safeguards.

Personal information may also be transferred to other countries where a Customer enables a Third-Party Service that operates or stores information outside Australia. The handling of information by that Third-Party Service may also be subject to the third party’s own privacy policy and terms.

8. Data Retention, Export & Deletion Lifecycle

We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, provide the Services, manage active accounts, maintain appropriate business and security records, or comply with legal requirements.

Residual encrypted copies of Customer Data contained in routine system backups will be overwritten according to our standard backup cycle, currently up to 30 days following deletion from active operational systems, and will remain securely protected until destroyed.

Certain records, including billing, accounting, security, audit, and legal records, may be retained for longer periods where reasonably necessary or required by law.

9. Data Security

We implement technical and organisational security measures designed to protect personal information against unauthorised access, disclosure, loss, misuse, alteration, or destruction.

These safeguards may include encryption in transit using TLS/HTTPS, encryption of stored data where appropriate, role-based access controls, authentication controls, network security measures, system logging and monitoring, backup procedures, and regular security reviews.

While we take reasonable steps to protect personal information, no electronic transmission, system, or method of storage can be guaranteed to be completely secure.

Users are responsible for maintaining the confidentiality of their login credentials and for taking reasonable steps to protect access to their User Account. We recommend using strong, unique passwords and enabling two-factor authentication where available.

10. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve our websites and Services, understand how they are used, remember preferences, measure website performance, and support marketing and advertising activities.

These technologies may collect information including IP addresses, browser and device information, pages viewed, interactions with our website, referring websites, and other usage information.

We may use both first-party technologies operated by Supply’d and third-party technologies provided by trusted analytics, advertising, and technology providers. Where required by applicable law, we will obtain consent before using non-essential cookies or similar technologies.

You may be able to control or disable cookies through your browser or device settings. Disabling certain cookies may affect the functionality of some parts of our websites or Services.

11. Third-Party Services & Links

Our Services may contain links to, or integrate with, websites and services operated by third parties. Supply’d does not control the privacy, security, or data-handling practices of those third parties.

Where you choose to access or connect a Third-Party Service, the third party’s own privacy policy and terms may apply to information it receives or processes. We recommend reviewing those policies before providing personal information or enabling an integration.

12. Your Rights & Access

Subject to applicable law, you may have the right to:

Some rights may be subject to legal, regulatory, contractual, security, or record-keeping requirements.

To exercise any of these rights, please contact our Privacy Officer using the details below. We may need to verify your identity before responding to a request.

13. Children’s Privacy

Supply’d is primarily designed for use by businesses and their authorised users and is not directed towards children.

The Privacy Act 1988 (Cth) protects personal information regardless of an individual’s age. Where consent is required in relation to a child’s personal information, whether the child is capable of providing that consent will depend on whether they have sufficient understanding and capacity in the circumstances.

If we become aware that personal information relating to a child has been provided to Supply’d in circumstances where appropriate consent or authority was required but not obtained, we may take reasonable steps to restrict processing or delete the information.

If you believe that a child’s personal information has been provided to us inappropriately, please contact our Privacy Officer.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes to our Services, legal requirements, security practices, or business operations.

Where appropriate, we will notify Customers of material changes by email, in-app notification, website notice, or another reasonable method before those changes take effect. The current version of this Privacy Policy will be made available through our website.

15. Contact Us & Complaints

If you have questions or concerns about our privacy practices, wish to exercise your privacy rights, or wish to lodge a privacy complaint, please contact:

The Privacy Officer / Company Secretary
Supply’d Pty Ltd
Level 2, 66 Victor Crescent
Narre Warren VIC 3805
Australia

Phone: +61 3 9068 7812
Email: [email protected]

If you lodge a privacy complaint with us, we will acknowledge the complaint, investigate the matter, and aim to provide a substantive response within 30 days. If we require additional time, we will let you know.

If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or another relevant privacy regulator in your jurisdiction.

Information about the OAIC and its complaints process is available at www.oaic.gov.au.