NerraFlow — Privacy Policy
Effective date: [INSERT DATE]
Last updated: [INSERT DATE]
[LEGAL ENTITY NAME] (ABN [INSERT ABN]) trading as NerraFlow ("NerraFlow", "we", "us", "our") is committed to protecting your privacy. This Policy explains how we handle personal information in connection with the NerraFlow websites, applications and services (the "Service"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
Template only — not legal advice. Confirm the details (entity, hosting locations, sub-processors, retention periods) match your actual setup and have it reviewed by a qualified Australian legal practitioner before publishing.
1. Scope
This Policy covers personal information we collect as a business — for example, from account holders and their team members. Separately, our business customers (pool-service companies) may upload information about their own customers and sites into the Service (for example, a pool's name, address, or contact details). For that uploaded content, our customer is the entity responsible for its collection and use, and we handle it on their behalf under our Terms of Service and this Policy. See clause 12.
2. The personal information we collect
Depending on how you use the Service, we may collect:
- Account information — your name, work email address, password (stored only in hashed form by our authentication provider), organisation/company name, and role.
- Team information — the email addresses of people you invite to your organisation.
- Content you enter — pool and site records (which may include names, addresses and notes), device identifiers, and manual water-test entries. This content may include personal information about your own customers (see clause 12).
- Device & sensor data — water-chemistry readings and related telemetry (this is generally not personal information).
- Technical & usage information — IP address, device and browser type, log and diagnostic data, and information about how you use the Service, collected automatically by us and our infrastructure providers.
- Communications — records of your correspondence with us (for example, support requests).
We do not intentionally collect sensitive information (as defined in the Privacy Act). Please do not submit sensitive information through the Service.
3. How we collect it
We collect personal information directly from you when you register, use, or contact us about the Service, and automatically through your use of the Service. Where reasonable and practicable, we collect personal information directly from the individual concerned. If you provide us with personal information about another person, you must ensure you are authorised to do so and have made them aware of this Policy.
4. Why we use personal information
We use personal information to:
- provide, operate, secure, maintain and support the Service;
- create and manage accounts and organisations, and authenticate users;
- generate readings, alerts and indicative dosing recommendations you request;
- communicate with you about the Service, including service and security notices;
- analyse and improve the Service (including using aggregated or de-identified data);
- comply with our legal obligations and enforce our Terms; and
- with your consent or as otherwise permitted by law, send you product updates.
We only use personal information for the purposes for which it was collected, related secondary purposes you would reasonably expect, or as otherwise permitted by law.
5. Automated processing
The Service generates automated, indicative water-chemistry statuses and dosing recommendations from sensor and manual-test data. These outputs are decision-support estimates about pool and spa water — they are not decisions about individuals and do not by themselves determine any right or entitlement of any person. If in the future we introduce automated decision-making that could significantly affect an individual's rights or interests, we will update this Policy to describe it, consistent with the transparency requirements commencing on 10 December 2026 under the Privacy and Other Legislation Amendment Act 2024 (Cth).
6. When we disclose personal information
We may disclose personal information to:
- Service providers / sub-processors who help us run the Service — including cloud hosting, database and edge-infrastructure providers (for example, Supabase and Cloudflare) — who are authorised to use it only to provide services to us;
- Professional advisers (such as lawyers and accountants) under confidentiality;
- Authorities or others where required or authorised by law, or to protect safety, rights or property; and
- A successor in connection with a sale, merger or restructure of our business (subject to this Policy).
We do not sell personal information.
7. Overseas disclosure (APP 8)
We host the primary database for the Service in Australia (Sydney / ap-southeast-2). However, some of our service providers, and their personnel or sub-processors, may be located or store or process limited data outside Australia (for example, in the United States). Where we disclose personal information to overseas recipients, we take reasonable steps to ensure they handle it consistently with the APPs. By using the Service, you acknowledge that some processing may occur overseas and that Australian Privacy Principle 8.1 may not apply to those recipients. [Confirm the actual locations of your providers and update this clause.]
8. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure — including encryption in transit, hashed credentials, row-level access controls that separate each organisation's data, and access restrictions. No system is completely secure, and we cannot guarantee absolute security.
9. Data breaches
We maintain procedures to detect and respond to data breaches and will comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals of any eligible data breach that is likely to result in serious harm.
10. Retention
We keep personal information only for as long as needed for the purposes described in this Policy, to provide the Service, and to meet legal, accounting or reporting requirements. When information is no longer needed, we take reasonable steps to delete or de-identify it. On account closure, Customer Data is handled as described in our Terms of Service.
11. Cookies & local storage
The Service uses browser local storage to keep you signed in and to operate core features. We and our infrastructure providers may use essential cookies and similar technologies for security, load-balancing and diagnostics. We do not use the Service to serve advertising. You can control storage and cookies through your browser settings, though disabling them may affect functionality.
12. Content you upload about your own customers
If you are a pool-service business using the Service, information you enter about your customers and their sites (such as names and addresses) is your responsibility. You are responsible for having a lawful basis to collect it and for your own privacy compliance, including your own privacy notices to those individuals. We process that content on your behalf to provide the Service, and will not use it except as permitted by our Terms and this Policy, or as required by law.
13. Access and correction (APP 12 & 13)
You may request access to, or correction of, the personal information we hold about you by contacting us (see clause 16). We will respond within a reasonable time and in accordance with the APPs. We may need to verify your identity, and in limited circumstances permitted by law we may decline a request (we will tell you why). Much of your account and content can also be viewed and corrected directly within the Service.
14. Direct marketing
If we send you marketing communications, you can opt out at any time using the unsubscribe link or by contacting us, and we will stop within a reasonable time. Service and security communications are not marketing and may still be sent.
15. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal information from children.
16. Complaints & contact
If you have a question, an access/correction request, or a complaint about how we handle personal information, contact our Privacy Officer:
- Email: [privacy@nerraflow.com.au]
- Post: [LEGAL ENTITY NAME], [registered address]
We will acknowledge and investigate your complaint and respond within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.
17. Changes to this Policy
We may update this Policy from time to time. The current version will always be available in the Service, and material changes will take effect on the "Effective date" shown above. Please review it periodically.
Template only — not legal advice. Complete the bracketed placeholders, verify your actual data flows, hosting locations and sub-processors, and have a qualified Australian legal practitioner review this Policy before you publish or rely on it.