Legal
Privacy policy
Last updated 25 September 2026
byAUTO Pty Ltd operates BidNomy and handles personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This page says what we collect, why, and what you can ask us to do about it.
What we collect
- Account information — your name, work email address, organisation name and role. Provided by you at sign-up.
- Authentication data — a hashed credential or an OAuth identifier, held by our authentication provider, not by us in readable form.
- Organisation and team — the organisation name, who is in it, each person’s role, and who invited whom. An invitation holds the invitee’s email address and who sent it for 14 days.
- Workspace content — saved searches, pursuits, tasks, tags, custom fields, notes, saved prompts and their runs, notification channels, and the files you upload with the text extracted from them.
- Billing — a Stripe customer id and subscription id, the billing email, the plan and its status, and a log of the events Stripe sends us. Never card numbers: those go to Stripe and never reach us.
- Usage records — pages viewed, searches run, exports taken and AI requests made, kept for security, billing accuracy and product decisions.
- Records you open — which published records you opened and when, so Explore can show your Recently viewed list and what your organisation follows. Your organisation sees these only as totals (“opened by 3 people on your team”), never who opened what, and never another organisation’s. You can turn it off, or clear it, on your account page; when you leave an organisation your opens stay in its totals without your name.
What we do not collect
We do not build profiles of individual public servants. Where a published record names a contact officer, that name stays inside the record as its publisher released it; it is not extracted into a person-level database, and there is no people-search feature.
Why we hold it
- to give you access to the service and keep the account secure;
- to run your organisation, its seats and its invitations;
- to send the alerts and reports you asked for;
- to apply the limits of your plan and to take payment;
- to answer support requests;
- to decide what to build next, using aggregate figures.
Government records are not personal information about you
The procurement records in the product are published by Australian Government agencies as open data. They are subject to their publishers’ terms, not this policy. This policy covers information about you as a user of the service.
Who else sees it
These are the processors we use. Each is bound by contract to use the data only to provide its service.
| Processor | What it does | Where |
|---|---|---|
| Cloudflare | Delivers the website and the portal | Edge, worldwide |
| Amazon Web Services | Hosts the API and the AI agents | Sydney |
| Supabase | Database, uploaded files and sign-in | Sydney |
| Microsoft Azure | Holds the government records | Sydney |
| Anthropic | Runs the AI models | United States |
| OpenAI | Runs the AI models if the fallback is switched on | United States |
| Stripe | Takes payments and holds card details | United States, Australia |
| Microsoft 365 | Sends alerts, invitations and reports | Australia |
Your workspace is held in Sydney. Two disclosures leave Australia: the text of an AI request goes to a model provider in the United States, and payment goes through Stripe, which also operates in the United States. Under Australian Privacy Principle 8 we take reasonable steps to see that an overseas recipient handles the information consistently with the Australian Privacy Principles. We do not sell personal information and we do not share it for advertising.
Data you send elsewhere
Some features send workspace data wherever you point them. A notification channel posts pursuit and task details to a webhook, a Slack workspace, an email address or a Jira project of your choosing. An API key lets your own script or AI client read what you can read, through the API or the Model Context Protocol server. Those are disclosures you have directed, to a destination you control, and we cannot see what happens to the data once it arrives. Revoke the key or switch the channel off to stop it.
AI features
The question you ask, the records the agent reads to answer it and any document you attached are sent to the model provider to generate the answer. Prompts and uploaded documents are not used to train models. AI and your data sets out exactly what is sent, what is never sent, and where your words are kept.
How long we keep it
| What | How long |
|---|---|
| AI conversations | Until you delete them |
| Saved-prompt runs and their reports | Kept, with the prompt that was sent |
| Uploaded documents and their extracted text | Until you delete the file |
| Invitation records | 14 days, when the link expires |
| Stripe event log | 7 years, with the tax records |
| Usage records | 12 months |
| Records you open | 12 months after you last opened it; shared with your organisation as totals, never by name |
| Account, organisation and workspace data | While the account is open, then 30 days |
Deleting a conversation, a file or a pursuit removes it when you press delete. Closing the account removes the rest within 30 days, except where a record must be kept by law.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to admin@byauto.com and we will respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner.
Cookies
Signing in sets one cookie, the Supabase authentication session, so you stay signed in from page to page. If you pick a light or dark theme, that choice is kept in your own browser under govai-theme, which is local storage rather than a cookie and is never sent to us. There is nothing else: no analytics, no advertising and no cross-site tracking.
Changes
If this policy changes materially we will tell account holders by email before the change takes effect. The current version always sits at /legal/privacy.