How we handle personal information — clearly, and in line with the Australian Privacy Principles.
Effective [EFFECTIVE DATE] · Last updated [EFFECTIVE DATE]
This Privacy Policy explains how [OPERATING ENTITY] (ABN [ABN]), trading as SMS365 (“SMS365”, “we”, “us”, “our”), collects, uses, holds, discloses and protects personal information. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our website at sms365.com.au or the SMS365 platform (the “Service”), you agree to the handling of personal information as described here.
SMS365 is a business messaging platform. Personal information reaches us in two different ways, and our responsibilities differ for each:
Your name, business name, email address, phone number, role, and login credentials (passwords are stored only as a secure hash — never in plain text).
Billing contact details, your prepaid credit balance and transaction history, and invoice records. Card payments are handled by our third-party payment processor; we do not store full card numbers on our systems.
Information generated as you use the Service: IP address, device and browser type, log and audit records, API request metadata, timestamps, and diagnostic data used to operate and secure the platform.
Recipient phone numbers, contact lists, sender IDs and message content that you submit for sending, together with delivery and usage records. See section 5.
Records of your correspondence with us, including support requests and their contents.
We collect personal information directly from you — when you register, configure your account, top up credit, contact support, or use the Service. We also collect it automatically as you interact with the website and platform (for example, through logs and cookies). Where practicable we collect personal information directly from the individual concerned; recipient data typically reaches us from our customer rather than from the recipient.
We use personal information to:
We only use personal information for the purposes for which it was collected, for a directly related purpose you would reasonably expect, or as permitted or required by law.
When you send through SMS365, we process the recipient numbers and message content you provide so we can deliver those messages and give you delivery and usage records. We act on your instructions as a processor for this data.
We do not sell personal information. We disclose it only as needed to run the Service, or where the law requires:
Some of our service providers may store or process data outside Australia — for example, in the United States or the European Union. Where personal information is disclosed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. By using the Service you acknowledge that, in some cases, we may not be able to guarantee an overseas recipient will not breach the APPs, and that Australian law may not apply to them. We will list the countries in which such recipients are likely to be located here on request.
We may send you information about the Service and related offers where you would reasonably expect it or where you have consented. Every marketing message from us includes a simple way to opt out, and you can also opt out at any time by contacting us. We do not use recipient data that you process through the Service for our own marketing.
Our website and platform use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Service is used so we can improve it. You can control cookies through your browser settings; disabling some cookies may affect how the Service works. Where we use analytics, we do so to measure and improve the Service, not to build advertising profiles.
We take security seriously and design for it. Our measures include:
No system is perfectly secure, but we work to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed.
We keep personal information only for as long as it is needed for the purposes described in this policy, or as required by law (for example, financial records we must retain for tax purposes). Message content and contact data are retained according to the controls available on your plan and your instructions. When information is no longer needed, we take reasonable steps to destroy or de-identify it.
We maintain procedures to detect, contain and assess data security incidents. If a data breach that is likely to result in serious harm to affected individuals occurs, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Much of this you can view and update yourself from your account settings. To make a request, contact our Privacy Officer using the details below. We will respond within a reasonable time, and will let you know if we cannot give access or make a correction and why.
The Service is intended for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will take appropriate steps to delete it.
We may update this Privacy Policy from time to time. The current version is always published here, with the “last updated” date shown at the top. Where changes are material, we will take reasonable steps to notify you. Your continued use of the Service after a change takes effect means you accept the updated policy.
If you have a question, an access or correction request, or a complaint about how we have handled your personal information, please contact our Privacy Officer:
Privacy Officer — SMS365
[OPERATING ENTITY] (ABN [ABN])
Email: [PRIVACY EMAIL]
Post: [POSTAL ADDRESS]
We will acknowledge your complaint and aim to resolve it promptly. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, by phone on 1300 363 992, or by post at GPO Box 5218, Sydney NSW 2001.