Legal

Privacy Policy

FlexiPL — How we collect, use, store, disclose and protect personal information when you use our application and related services.

Last Updated

12/11/2025

Company

GET IT NOW PTY LTD (ABN 73 643 410 191) ("we", "us", or "our")

Section 01

Purpose of this Policy

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when:

  • Your organisation or you as an individual ("Customer") use our application and related services (the "Service"); and
  • Individual users authorised by a Customer ("Users") access or interact with the Service.

This Policy is designed to comply with:

  • The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs); and
  • (Where applicable) the EU/UK General Data Protection Regulation (GDPR).

This Privacy Policy forms a key part of our information security and SOC 2 compliance framework.

If you do not agree with this Policy, you should not use the Service.

Section 02

Scope

This Policy applies to:

  • Customers: Business entities and individual customers that subscribe to, license or trial the Service.
  • Users: Individuals who access the Service under a Customer account (for example, employees, contractors, or the Customer themselves where they are an individual).
  • Website visitors and others who interact with us (for example, via support channels or marketing pages).

This Policy does not apply to:

  • Third-party websites, apps or services that we do not own or control; or
  • Personal information collected by Customers outside the Service.

Customers (including individual Customers) remain responsible for ensuring that their own collection and use of personal information (including what they upload into the Service) complies with applicable laws.

Section 03

Definitions

For the purposes of this Policy:

01

"Customer"

means any business entity or individual that enters into an agreement with us to use the Service (including on a trial basis).

02

"Personal Information" / "Personal Data"

means information about an identifiable individual or an individual who is reasonably identifiable (as defined under the Privacy Act and/or GDPR).

03

"Customer Personal Data"

means Personal Information that Customers or Users submit to, or generate in, the Service.

04

"Operational Data"

means the data you capture, store or manage in the Service about your products, inventory, pricing, transactions, or other business or personal operations. Some Operational Data may include Personal Information (for example, a person's name in a note or label).

05

"Processing"

means any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.

06

"Sub-processor"

means a third-party service provider that processes Customer Personal Data on our behalf.

Section 04

Our Role: Controller vs Processor (GDPR)

Depending on the context, we act as:

1

Data Controller

or "APP entity"

for:

  • Customer account details (for both business and individual Customers);
  • Contact details for Customer representatives and prospective customers;
  • Our own marketing, analytics and operational data about use of the Service; and
  • Records required to meet our legal and regulatory obligations.
2

Data Processor

under GDPR

for Customer Personal Data within Operational Data, where:

  • The Customer decides what data to collect and upload;
  • We process that data only on the Customer's documented instructions (for example, via configuration, API calls, and in-app actions); and
  • We implement technical and organisational measures to protect that data as required by Article 28 GDPR and the APPs.

If there is any inconsistency between this Policy and a signed Data Processing Agreement (DPA) with a Customer, the DPA will prevail to the extent of the inconsistency.

Section 05

Information We Collect

We only collect information that is reasonably necessary to operate, secure, and improve the Service.

5.1 Customer Information

Information provided when a Customer (business or individual) signs up or manages their account, for example:

  • Legal entity or individual name (and, where relevant, trading name and ABN/ACN);
  • Business or mailing address and billing details;
  • Primary and secondary contacts (name, role, email, phone);
  • Subscription, billing and payment information.

5.2 User Information

Information about individual Users authorised by a Customer, such as:

  • Name and contact details (for example, email address);
  • Usernames, user IDs, and authentication identifiers;
  • Role, permissions, and access groups;
  • Activity and audit logs relating to use of the Service.

5.3 Product & Operational Data

Data entered or ingested into the Service by or on behalf of a Customer, which may include (depending on configuration):

  • Product catalogue data (for example, product names, SKUs, categories, attributes);
  • Inventory, stock movements, counts, and valuation data;
  • Pricing, promotions, and transactional or order-related information;
  • Tags, notes, comments, labels, or other metadata created by Users.

This data is generally business or operational data. However, it may occasionally contain Personal Information (for example, a person's name or email address in a note). Where it does, we treat it as Customer Personal Data.

5.4 PII within Operational Data

To the extent Operational Data contains Personal Information (for example, a person's name on a label):

  • The Customer is the controller of that Personal Information (under GDPR); and
  • We act as the processor, handling it only as directed by the Customer and in accordance with this Policy and any applicable DPA.

5.5 Technical & Usage Data

We automatically collect limited technical data when you use the Service, such as:

  • IP address, device and browser type, operating system;
  • Access times, pages viewed, and actions taken in the Service;
  • System performance metrics, error logs and diagnostic information;
  • Identifiers associated with cookies, SDKs or other tracking technologies.

We use this information primarily to operate, secure, and improve the Service (see Section 7).

Section 06

Legal Bases for Processing (GDPR)

Where the GDPR applies, we rely on one or more of the following legal bases:

  • Performance of a contract (Art. 6(1)(b)) — To provide, maintain and support the Service under our agreement with the Customer.
  • Compliance with legal obligations (Art. 6(1)(c)) — To meet our obligations under tax, accounting, privacy, security and other laws.
  • Legitimate interests (Art. 6(1)(f)) — To operate and improve the Service, secure our systems, prevent fraud and abuse, respond to enquiries, and conduct internal analytics.
  • Consent (Art. 6(1)(a)) — Where required by law (for example, certain marketing communications or non-essential cookies), we will rely on your consent.

When we act as a processor on behalf of a Customer, the Customer is responsible for identifying and documenting the appropriate legal basis for processing Customer Personal Data.

Section 07

How We Use Information

We use the information described above for the following purposes:

7.1 To Provide and Operate the Service

  • Authenticating Users and managing access control;
  • Hosting, processing and analysing Customer and Operational Data as configured by the Customer;
  • Managing accounts, subscriptions, billing and Customer support;
  • Providing integrations and features requested by the Customer.

7.2 To Maintain Security and Integrity

  • Monitoring for suspicious or unauthorised activity;
  • Preventing, detecting and investigating fraud, abuse or security incidents;
  • Enforcing our acceptable use, security and access policies;
  • Supporting our SOC 2 controls and internal governance.

7.3 To Communicate with You

  • Sending administrative notifications (for example, login alerts, security notices, system updates);
  • Responding to enquiries and support requests;
  • Providing important information about changes to the Service or this Policy.

7.4 To Improve the Service

  • Analysing aggregated and de-identified usage trends;
  • Developing new features and enhancements;
  • Conducting product research and performance tuning.

We use aggregated and/or de-identified data where possible so that individuals cannot reasonably be identified.

7.5 Marketing (Optional)

Where permitted by law, we may use your contact details to send you product updates, newsletters or invitations to events. You can opt-out at any time via the unsubscribe link in our emails or by contacting us (see Section 16).

Section 08

Data Sharing, Sub-Processors & Disclosures

We do not sell, rent or trade Personal Information. We may disclose Personal Information only in the circumstances set out below.

8.1 Sub-Processors

We use carefully selected third-party service providers ("Sub-processors") to help us deliver the Service, including cloud infrastructure, AI services, logging tools, payment providers, and support platforms. Each Sub-processor is engaged under a written agreement requiring appropriate security measures.

8.2 Other Disclosures

We may also disclose Personal Information:

  • To professional advisers (for example, lawyers, auditors, insurers) under confidentiality obligations;
  • Where required by law, court order, or regulatory authority;
  • To investigate suspected fraud, security incidents or violations of our Terms of Use;
  • In connection with a merger, acquisition, financing or sale of all or part of our business.

Section 09

Overseas Disclosure & International Transfers

Our Sub-processors and infrastructure providers may process Personal Information in countries other than the one in which it was collected, including the United States, European Union, United Kingdom and other regions where our providers operate data centres.

9.1 Australian Privacy Principles (APP 8)

Where we disclose Personal Information to overseas recipients, we take reasonable steps to ensure they handle the information consistently with the APPs, including entering into contracts that require overseas recipients to handle Personal Information in accordance with Australian privacy requirements.

9.2 GDPR International Transfers (Articles 44–49)

For Personal Data subject to the GDPR transferred outside the EEA/UK, we only transfer to countries with adequate protection or implement appropriate safeguards such as Standard Contractual Clauses (SCCs).

Section 10

Data Security, Storage & Residency

10.1 Security Measures

We implement appropriate technical and organisational measures to protect Personal Information, including:

Security Measures
  • Data encryption in transit (TLS) and at rest;
  • Access controls and role-based permissions;
  • Network and application security measures;
  • Logging, monitoring and alerting;
  • Regular security reviews and vulnerability assessments.

10.2 Data Storage & Residency

To the extent commercially and technically feasible, Customer and User data is stored and processed within a designated geographic region (for example, Australia). Some supporting services and backups may operate in multiple regions as part of our high-availability and disaster recovery design.

Section 11

Data Retention

We retain Personal Information only for as long as reasonably necessary to provide and support the Service, comply with our legal and regulatory obligations, resolve disputes and enforce our agreements, and maintain appropriate business and financial records.

Section 12

Cookies & Tracking Technologies

We use cookies and similar technologies in connection with the Service and our website, including strictly necessary cookies, performance and analytics cookies, and preference cookies. We do not use cookies for interest-based advertising within the Service unless explicitly stated and consented to.

Some features of the Service may not function properly if cookies are disabled.

Section 13

Children's Privacy

The Service is intended for use by adults. It is not directed to children.

We do not knowingly collect Personal Information from individuals under the age of 16. If you believe your child has provided us with Personal Information, please contact us and we will promptly delete it.

Section 14

Your Rights (GDPR & Australian Privacy Act)

14.1 Access & Correction (APP 12 & 13)

You may request confirmation of whether we hold Personal Information about you, and access to or correction of that information.

14.2 GDPR Rights (Where Applicable)

Individual Rights
  • Data portability — to receive Personal Data in a structured, commonly used, machine-readable format.
  • Erasure ("right to be forgotten") — to request deletion of Personal Data in certain circumstances.
  • Restriction of processing — to request that we restrict processing of your Personal Data in certain circumstances.
  • Object to processing — to object to our processing of your Personal Data where we rely on legitimate interests.
  • Withdraw consent — where processing is based on consent, to withdraw that consent at any time.

14.3 Exercising Your Rights & Complaints

To exercise any of the above rights or to make a complaint, please contact us using the details in Section 17. If you are not satisfied with our response, you may contact the OAIC or the relevant EU/UK data protection authority.

Section 15

Data Breach Notification

In the event of a data breach involving Personal Information likely to result in serious harm, we will take immediate steps to contain and assess the breach, notify affected Customers without undue delay, and where required notify relevant regulatory authorities.

Section 16

Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated Policy with a new "Last Updated" date. For material changes, we will provide additional notice to Customers by email or in-app notification.

Section 17

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact:

Data Privacy Officer

support@flexipl.com.au