Privacy policy
How Consuite collects, uses and protects your information.
Effective Date: 4 August 2026
Consuite Pty Ltd (ABN 43 679 312 540) ("Consuite", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction management platform and related services.
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, phone number, company name, and role.
Organisation Data: Information you and your team enter into the platform, including projects, tenders, contacts, financial data, documents, and communications.
Usage Data: We automatically collect information about how you interact with our platform, including pages visited, features used, timestamps, device information, and IP addresses.
Payment Information: When you subscribe, payment details are processed securely by our payment provider (Stripe). We do not store your full credit card details.
Cookies & Analytics: We use cookies and analytics tools (PostHog) to understand usage patterns and improve our service.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Consuite platform
- Process transactions and manage your subscription
- Send transactional emails (account confirmations, notifications, invoices)
- Provide customer support and respond to enquiries
- Improve our platform through usage analytics
- Power AI-assisted features using your organisation data (routed through a gateway configured for zero data retention; not retained by the AI provider after the request, and not used to train its models)
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
3. How We Share Your Information
We do not sell your personal information. We may share information with:
- Service Providers: Third-party services that help us operate our platform (e.g., Supabase for database hosting, Vercel for application hosting, Stripe for payments, Postmark for email)
- AI Providers: Data sent to AI models for AI-assisted features is routed through a gateway configured for zero data retention — it is processed to generate a response and is not retained by the provider afterwards, nor used to train its models
- Integration Partners: When you connect third-party integrations (e.g., Xero), we share relevant data as authorised by you
- Legal Requirements: When required by law, regulation, or legal process
- Organisation Members: Data within your organisation is accessible to members according to your configured permissions
Xero Accounting Integration
If you connect your Xero organisation, you authorise Consuite to access it via Xero's API using OAuth 2.0. We never see or store your Xero password. With your authorisation we access and synchronise the following Xero data to keep your accounting records aligned with your projects:
- Contacts (your clients and suppliers), invoices and bills, payments, the chart of accounts, and tax rates
- Requested only under the minimum scopes needed for these features (
accounting.contacts,accounting.invoices,accounting.payments,accounting.settings)
Access and refresh tokens are stored encrypted, server-side only, and are never exposed to your browser. This data is used solely to provide the integration's sync features and is retained under the same terms as your other organisation data (see Data Retention below). You can disconnect Xero at any time from Settings → Xero; on disconnect we revoke the token with Xero and delete the stored tokens. You may also revoke Consuite's access directly in your Xero account.
4. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS/SSL) and at rest
- Row-level security policies on our database
- Role-based access controls within organisations
- Regular security audits and monitoring
- Secure authentication with password requirements and optional multi-factor authentication
Overseas Disclosure
Consuite is an Australian company and we host your organisation data in Australia where our providers offer it. Some of the service providers listed above operate infrastructure or support functions outside Australia — principally in the United States and the European Union. Using Consuite means your information may be stored or accessed in those countries.
Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual data protection terms with each provider.
Data About Third Parties in Your Workspace
Much of the information in a Consuite workspace is about other people — your clients, staff, subcontractors and suppliers. Your organisation decides what to collect and why; we hold and process it on your instructions in order to provide the platform.
That means your organisation is responsible for having the right to enter that information and for meeting its own privacy obligations to those people. If someone asks us to access, correct or delete information held in your workspace, we will generally refer them to your organisation and support you in responding.
Data Breaches
If we become aware of unauthorised access to, or disclosure or loss of, personal information that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will tell the affected organisation promptly so it can meet its own obligations.
5. Data Retention & Deletion
We retain your data for as long as your account is active or as needed to provide our services. We do not keep organisation data indefinitely after you leave — the Privacy Act requires us to destroy or de-identify personal information once we no longer need it, and holding dormant data is a risk to you and to us.
When a paid subscription ends, your workspace becomes read-only for 90 days so you can sign in and export everything. If you have not resubscribed or taken up a paid data vault by the end of that window, the workspace is scheduled for permanent deletion. You can ask us to delete it immediately instead. Our Refund & Cancellation Policy describes this lifecycle in full.
After deletion, data may persist in encrypted backups for up to a further 35 days before those backups are cycled out; it is not restorable to your account during that time.
We retain billing and tax records — invoices, payments and refunds, not your project content — for 7 years, as Australian tax law requires. Where an individual asks us to delete their personal information, we will do so unless we are required by law to keep it, in which case we will tell you what we are keeping and why.
Within an active workspace, organisation data follows a soft-delete model — deleted records are marked as deleted and excluded from active use, with permanent deletion occurring during scheduled data purges.
6. Cookies
We use cookies for:
- Essential Cookies: Required for authentication and cross-subdomain sessions
- Analytics Cookies: Help us understand how you use our platform (PostHog)
- Preference Cookies: Remember your settings and preferences
You can control cookie preferences through your browser settings. Disabling essential cookies may affect platform functionality.
7. Your Rights
Under the Australian Privacy Act 1988 and applicable laws, you have the right to:
- Access and obtain a copy of your personal data
- Correct inaccurate or incomplete personal data
- Request deletion of your personal data
- Object to or restrict processing of your personal data
- Export your data in a portable format
- Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at the details below. We will respond within 30 days. We do not charge for making a request, and we will not ask you to give a reason for wanting a copy of your own information.
Complaints: if you think we have mishandled your personal information, email us and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Automated Decision-Making & AI Features
Our platform includes AI-assisted features (for example, drafting text, summarising records, and suggesting budgets or scopes). These features are decision-support tools: their outputs are suggestions for a person to review, and we do not use them to make decisions that produce legal or similarly significant effects about you without human involvement. Relevant organisation data may be sent to our AI provider to generate a response, routed through a gateway configured for zero data retention as described above. You remain responsible for reviewing and validating AI-assisted outputs before relying on them.
8. Children's Privacy
Our platform is not intended for use by anyone under 18 years of age. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through our platform. Your continued use of the platform after such changes constitutes acceptance of the updated policy.
10. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
Consuite Pty Ltd
ACN 679 312 540 · ABN 43 679 312 540
Level 5, 447 Collins Street, Melbourne VIC 3000
Email: support@consuite.app