SimplyComply · controlled beta
Privacy Notice
This notice explains how SimplyComply handles information for its invite-only beta for selected Commonwealth and Western Australian businesses. It is written for the current controlled beta, not as a claim of complete legal coverage.
Last updated: 8 September 2026
1. Scope and important limits
SimplyComply provides a compliance register, tasks and evidence workflow for selected Commonwealth and WA businesses. Coverage is limited and may need follow-up. Regulatory content is general information, not legal advice, and does not determine what is legally required for your particular circumstances.
This notice and the beta product require legal review and owner approval before SimplyComply is offered as a broad public service. It does not claim certification, guaranteed compliance, or Australia-wide coverage.
2. Information we handle
Depending on how you use the beta, we may handle:
- Account and sign-in data: email address, name and a server-side account identifier. Magic-link sign-in uses a short-lived token; Google sign-in may provide the email, name and profile information you choose to share.
- Business profile answers: business name, optional ABN entered by you (shown as customer-confirmed and unverified), industry, state or jurisdiction, entity type, employee-count band and screening answers about GST, staff, licences, personal information and food activities. “Not sure” answers remain unresolved rather than being treated as no.
- Register and collaboration data: obligation status, tasks, dates, reminders, organisation membership, invitations and audit records needed to operate the tenant-scoped register.
- Evidence data: evidence metadata and, only if uploads are enabled for your account, the files you choose to upload. Evidence uploads are currently disabled in the production beta pending explicit beta and owner enablement; the scanner readiness gate has been separately proven.
- Support and operational data: messages you send to the beta team and ordinary request, security and service telemetry needed to operate and protect the service.
Please do not submit TFNs, banking credentials, full payroll records or unnecessary employee personal information. The beta is designed to store evidence that an obligation was met, not those sensitive data sets.
3. How information is used
- to authenticate invited users, maintain sessions and administer invitations;
- to scope register, task and evidence views to the authorised organisation;
- to evaluate the current deterministic register and show follow-up where information is unresolved;
- to send requested sign-in and, where enabled, task reminder emails;
- to provide support, maintain security, investigate failures and improve the controlled beta.
SimplyComply does not use your profile answers to create a public directory or sell them for advertising.
4. Hosting and service providers
The current implementation uses Google Cloud services for the application, Firestore operational data and Google Cloud Storage evidence objects. Transactional email is sent through Resend when configured. Google OAuth is available when you choose Google sign-in. Stripe is the billing provider if a signed user starts checkout and billing is enabled; SimplyComply does not receive or store card numbers.
These providers process information under their own service terms and privacy documentation. Provider processing locations and subprocessors can change; the beta should not be understood as a promise that every service remains in Australia.
5. Tenant isolation and security
Customer-owned records are scoped by the organisation selected and authorised on the server. The browser is not the authority for a tenant identifier. Sessions use signed, HTTP-only cookies, and evidence paths are tenant-bound. We apply the controls available in the beta architecture, including least-privilege service access, encrypted provider transport/storage, audit logging and bounded evidence scanning where enabled.
No online service can promise absolute security. If you believe an account or evidence object has been accessed improperly, contact the beta team promptly at support@simplycomply.app.
6. Retention, deletion and recovery
Operational data is retained while an account is active. Retention cleanup and account deletion jobs are disabled by default in production and are support-operated only after explicit approval and enablement. When enabled, the bounded retention procedure makes failed or quarantined upload objects and pending/orphan objects eligible only after their configured retention periods, while clean evidence is protected. It is not a blanket lifecycle rule for the quarantine prefix.
Account deletion is currently a dry-run-first, explicit support procedure with tenant checks and a resumable checkpoint. It removes customer documents and tenant operational data where approved, while preserving only justified operational or regulatory records. The procedure does not purge records held by third-party email or payment providers. Cloud Storage soft-delete and Firestore recovery features may retain recoverable copies for their configured windows; that is an operational recovery possibility, not a promise that deleted data can be restored.
7. Questions and requests
For access, correction, deletion, security or privacy questions, contact support@simplycomply.app. We may need to verify your authority before acting on a request, and some records may need to be retained for an approved hold, audit or other justified reason.
8. Changes and approval status
We may update this notice as the beta changes and will show a new “Last updated” date. This notice is a controlled-beta draft and requires legal review and owner approval before broad public launch.
Questions about the controlled beta?
Contact support@simplycomply.app. You can also sign in or use an invite.