The short version
- Who we are. EASYDONE SOFTWARE PTY LTD, trading as EasyDone Work and EasyDone Studio, based in Western Australia.
- Your business data is yours. If you use EasyDone to run your business, the information about your customers and staff is yours. We look after it for you and only use it to run your EasyDone.
- We do not sell personal information, and we do not train AI models on it.
- Live data stays in Sydney. Some connected services (AI, payments, email, network security) work overseas, and we tell you which ones and where.
- You can ask us anything. Ask to see or fix the information we hold about you, or make a complaint, and we will answer within 30 days.
About this policy
This policy explains how EASYDONE SOFTWARE PTY LTD (ACN 702 804 420, ABN 24 702 804 420), a company registered in Western Australia, of 9D Regents Park Rd, Joondalup WA 6027, trading as EasyDone Work and EasyDone Studio (registered business names EASYDONE WORK and EASYDONE STUDIO) (EasyDone, we, us), handles personal information.
We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles, even where an exemption (such as the small business exemption) might otherwise apply to us.
Two different roles we play
When we decide how information is used (this policy applies)
This covers information about:
- our customers' account holders, administrators, users and billing contacts;
- prospects, including businesses we prepare a demo for, and people who contact us;
- visitors to our websites; and
- our suppliers, contractors and job applicants.
When we host information for our customers (their privacy policy applies)
Our customers use EasyDone to store information about their own customers, staff, suppliers and contacts. For that information, our customer decides what is collected and why. We handle it on their behalf, under our agreement with them.
If your information is in a business's EasyDone and you have a question about it, please contact that business first. If you contact us, we will pass your request to them where we can, and help them respond.
When a customer connects their own accounts (for example a Microsoft 365 mailbox or Xero), we reach into those accounts only with the permissions the customer approves, to run the features they turn on. They can withdraw that permission in the other service's settings at any time.
What we collect
Depending on how you deal with us, we may collect:
- Identity and contact details: name, business name, role, ABN, email, phone and business address.
- Account details: user names, sign-in records, roles and permissions, sign-in method (including Microsoft sign-in identifiers) and preferences.
- Billing details: billing contact, plan, invoices and payment status. Card and bank details are collected by Stripe, not by us. We only receive limited details such as card type, expiry and the last four digits.
- Signing records: when you sign our agreement online: the name, role and email you enter, your drawn or typed signature, the time, your internet (IP) address, device and browser details, and the version of the agreement.
- Communications: emails, texts, calls, support requests, feedback and survey answers.
- Usage and technical information: how our service and websites are used, pages viewed, features used, AI usage counts, errors, device and browser type, IP address, and approximate location based on IP address.
- Public business information (for demos): when we prepare a demo for a business, we may collect publicly available information about it, such as its website content, logo, ABN details, public listings and social media pages, and the names and public contact details of its owners.
- Job applicants and contractors: information in applications, references and contracts.
We do not intentionally collect sensitive information (such as health information) about you. If we ever need it, we will ask for your consent, unless the law allows otherwise.
How we collect it
- From you: when you sign up, sign in, use the service, contact us or book a demo.
- Automatically: through our websites, apps and servers (see cookies and analytics).
- From others: from your employer or business (for example, when they add you as a user), from Stripe (payments), from Microsoft (sign-in), from public sources (such as the ABN Lookup, business websites and social media), and from people who introduce you to us, such as suppliers or partners.
If you do not give us information we ask for, we may not be able to provide the service, set up a demo or reply to you.
Why we use it
We use personal information to:
- provide, set up, run, secure, support and improve EasyDone;
- prepare and run demos and free trials for businesses interested in EasyDone;
- create and manage accounts, check sign-ins and prevent fraud and misuse;
- form, record and manage our agreements, including electronic signing;
- bill, collect payments and keep financial and tax records;
- communicate with you about the service, including service notices, changes to our terms and security alerts;
- send marketing, where the law allows (see marketing);
- meet our legal obligations and deal with disputes and legal claims; and
- do anything else you agree to, or that is closely related to the above and that you would reasonably expect.
Sign-in records are used for billing
EasyDone is billed by the people who sign in each month. So we use sign-in records to count the people who signed in during each billing month, to work out your invoice, and to spot logins that look shared between several people. Your business's administrators can see which logins have signed in and are being counted on the Subscription page, and can ask us for the sign-in records behind an invoice.
How we use AI
In our product
EasyDone includes AI features. When someone uses one, the content they submit is sent to an AI provider (such as Anthropic or OpenAI) to produce a response. We use the business services of these providers, which say they do not use submitted content to train their models by default. The providers may keep data for a limited time for safety and legal reasons, under their own terms, and may process it outside Australia. We do not control how they handle it inside their own systems.
In running our business
We use AI-assisted tools, including AI agents, to build, run, monitor, support and improve EasyDone, and to help draft messages. These tools may handle personal information when a task needs it, for example when looking into a fault or drafting a support reply. Our people supervise them.
No training by us
We do not use personal information, or our customers' data, to train or fine-tune AI models.
Automated decisions
We do not make decisions about you that have a legal or similarly significant effect on you based only on automated processing.
We do use automated steps for routine matters, such as:
- pausing AI features when an included allowance is used up;
- retrying failed payments and sending reminders;
- counting the logins that signed in during the month for billing; and
- flagging unusual sign-in activity for review.
If this changes, we will update this section first. New Privacy Act rules about automated decisions start on 10 December 2026, and we will review this section against them before then.
Marketing
We may send you information about EasyDone and related services if you have agreed to receive it, or where the law otherwise allows (for example, if you are an existing customer and would reasonably expect it).
Every marketing email or text has a way to unsubscribe, and we action unsubscribes within 5 business days. You will still get the service and account messages we need to send you.
We do not sell personal information, and we do not give it to others for their own marketing.
Who we share it with
We share personal information only as needed with:
- our service providers, who help us run EasyDone and our business (listed below);
- the business you work for or with, where you are a user of its EasyDone;
- our professional advisers, insurers, auditors and financiers;
- a buyer or potential buyer of our business, under confidentiality obligations; and
- government bodies, courts and regulators, where the law requires or allows it.
Our service providers
Locations come from each provider's published information at the date of this draft, and providers can change where they process data. This table is our published list of providers, at easydone.work/privacy/#providers. We give paying customers 30 days' notice before a new provider starts handling personal information in their data.
| Provider | What it does for us | Where it processes data |
|---|---|---|
| DigitalOcean | Hosts each paying customer's private server and its daily backups | Sydney, Australia. Provider support and account systems: United States and other countries |
| Cloudflare | Network security, encrypted connections, delivery of web traffic, and hosting of Studio websites | Global network, including Australia and the United States |
| Anthropic | AI features; AI tools we use to build and support EasyDone | United States, and other regions where Anthropic operates, as it publishes |
| OpenAI | AI features; AI tools we use to build and support EasyDone | United States, and other regions where OpenAI operates, as it publishes |
| OpenRouter | Routes some Studio AI requests to a range of AI models | United States and the countries of the underlying model providers (Studio, when enabled) |
| Address lookup and place details (Google Maps Platform) | United States and globally | |
| Stripe | Takes subscription payments and runs the billing portal | Australia, United States and other countries |
| ClickSend | Sends SMS messages from EasyDone | Australia and other countries, as ClickSend publishes; messages pass through Australian and international carriers |
| Microsoft | Our own email and business systems (sign-up emails, signed agreements, support) | Australia and other countries, under Microsoft's terms |
| GitHub | Stores and builds the EasyDone software and Studio website code | United States |
| OVH | Our operations server: monitoring, deployments, routing AI requests, demo hosting, the shared free-trial server, and final backups when a customer leaves (kept up to 90 days) | OVH data centre in Sydney, Australia |
| Tailscale | Private network for our administrative access to servers. Connection details only, not customer data (where we use it) | United States and global |
Services a customer connects with their own account (for example their own Microsoft 365, Xero or Stripe) are not our providers. They act for that customer, under the customer's own agreement with them.
Cookies and analytics
Our websites and apps use cookies and similar technologies to keep you signed in, remember your settings, keep the service secure and understand how the websites are used.
If we use analytics tools or advertising pixels on our websites or in the app, we will describe them here and offer a way to opt out.
You can block or delete cookies in your browser, but some parts of the service may then stop working.
Overseas disclosure
Our customers' live EasyDone data is hosted on servers in Sydney, Australia. During a free trial, a customer's data sits on a shared trial server hosted by us in Australia.
Some of our service providers store or process personal information outside Australia. Based on their published information, the countries include the United States, Ireland and other countries in the European Union, and other countries where global providers (such as Cloudflare, Microsoft and Google) operate. Our operations server and the shared trial server are with OVH, in a data centre in Sydney, Australia.
We take reasonable steps to make sure these providers handle personal information in a way that is consistent with the Australian Privacy Principles. We choose reputable providers with published security and privacy commitments, and we send them only what they need. We cannot control how a provider handles data inside its own systems, and the laws of other countries may not protect personal information in the same way Australian law does.
How we keep it safe
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure. These include: separate servers for each paying customer; encrypted connections; firewalls; restricted, key-based access to servers; role-based access controls; security updates; and logging.
No system is completely secure. If we become aware of a data breach that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner, as the law requires.
How long we keep it
We keep personal information only as long as we need it for the purposes in this policy, or as the law requires. For example:
- Account and signing records: for the life of the account and 7 years after, for legal and tax purposes.
- Customer data we host: after an agreement ends, the customer has 30 days to export it. We then delete it from live systems within 30 days, and backup copies expire within a further 90 days.
- Free trial data: if a trial ends without a paid subscription, the customer has the same 30 days to export it, and we then delete it from the trial server.
- Demos: deleted when the demo ends, with one final backup kept for up to 90 days.
- Marketing lists: until you unsubscribe. We then keep a note that you unsubscribed so we do not contact you again.
When we no longer need personal information, we destroy it or remove anything that identifies you.
Seeing and correcting your information
You can ask to see, or to correct, the personal information we hold about you by contacting us (see contact us). We will reply within 30 days. We may need to check who you are first.
There is no charge to ask. In some cases we may charge a reasonable fee for providing access, and we will tell you first. If we refuse, we will tell you why and how to complain.
Complaints
If you are unhappy with how we have handled your personal information, please contact us first. We will confirm we have your complaint within 5 business days and aim to sort it out within 30 days.
If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner: www.oaic.gov.au, phone 1300 363 992.
Contact us
Privacy Officer, EasyDone Software Pty Ltd
Email: support@easydone.work (please put “Privacy” in the subject line)
Post: 9D Regents Park Rd, Joondalup WA 6027
Changes to this policy
We may update this policy from time to time. We will publish the new version on our website with its date. If a change is significant, we will also email our customers.