Privacy Policy · In plain words

Privacy Policy

What we collect, why we collect it, who sees it and how you can ask us about it, written to be read, not skimmed past.

Last updated: 1 October 2026Applies to: easydone.work, easydone.studio and the EasyDone apps

The short version

  • Who we are. EASYDONE SOFTWARE PTY LTD, trading as EasyDone Work and EasyDone Studio, based in Western Australia.
  • Your business data is yours. If you use EasyDone to run your business, the information about your customers and staff is yours. We look after it for you and only use it to run your EasyDone.
  • We do not sell personal information, and we do not train AI models on it.
  • Live data stays in Sydney. Some connected services (AI, payments, email, network security) work overseas, and we tell you which ones and where.
  • You can ask us anything. Ask to see or fix the information we hold about you, or make a complaint, and we will answer within 30 days.

About this policy

This policy explains how EASYDONE SOFTWARE PTY LTD (ACN 702 804 420, ABN 24 702 804 420), a company registered in Western Australia, of 9D Regents Park Rd, Joondalup WA 6027, trading as EasyDone Work and EasyDone Studio (registered business names EASYDONE WORK and EASYDONE STUDIO) (EasyDone, we, us), handles personal information.

We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles, even where an exemption (such as the small business exemption) might otherwise apply to us.

Two different roles we play

When we decide how information is used (this policy applies)

This covers information about:

  • our customers' account holders, administrators, users and billing contacts;
  • prospects, including businesses we prepare a demo for, and people who contact us;
  • visitors to our websites; and
  • our suppliers, contractors and job applicants.

When we host information for our customers (their privacy policy applies)

Our customers use EasyDone to store information about their own customers, staff, suppliers and contacts. For that information, our customer decides what is collected and why. We handle it on their behalf, under our agreement with them.

If your information is in a business's EasyDone and you have a question about it, please contact that business first. If you contact us, we will pass your request to them where we can, and help them respond.

When a customer connects their own accounts (for example a Microsoft 365 mailbox or Xero), we reach into those accounts only with the permissions the customer approves, to run the features they turn on. They can withdraw that permission in the other service's settings at any time.

What we collect

Depending on how you deal with us, we may collect:

  • Identity and contact details: name, business name, role, ABN, email, phone and business address.
  • Account details: user names, sign-in records, roles and permissions, sign-in method (including Microsoft sign-in identifiers) and preferences.
  • Billing details: billing contact, plan, invoices and payment status. Card and bank details are collected by Stripe, not by us. We only receive limited details such as card type, expiry and the last four digits.
  • Signing records: when you sign our agreement online: the name, role and email you enter, your drawn or typed signature, the time, your internet (IP) address, device and browser details, and the version of the agreement.
  • Communications: emails, texts, calls, support requests, feedback and survey answers.
  • Usage and technical information: how our service and websites are used, pages viewed, features used, AI usage counts, errors, device and browser type, IP address, and approximate location based on IP address.
  • Public business information (for demos): when we prepare a demo for a business, we may collect publicly available information about it, such as its website content, logo, ABN details, public listings and social media pages, and the names and public contact details of its owners.
  • Job applicants and contractors: information in applications, references and contracts.

We do not intentionally collect sensitive information (such as health information) about you. If we ever need it, we will ask for your consent, unless the law allows otherwise.

How we collect it

  • From you: when you sign up, sign in, use the service, contact us or book a demo.
  • Automatically: through our websites, apps and servers (see cookies and analytics).
  • From others: from your employer or business (for example, when they add you as a user), from Stripe (payments), from Microsoft (sign-in), from public sources (such as the ABN Lookup, business websites and social media), and from people who introduce you to us, such as suppliers or partners.

If you do not give us information we ask for, we may not be able to provide the service, set up a demo or reply to you.

Why we use it

We use personal information to:

  • provide, set up, run, secure, support and improve EasyDone;
  • prepare and run demos and free trials for businesses interested in EasyDone;
  • create and manage accounts, check sign-ins and prevent fraud and misuse;
  • form, record and manage our agreements, including electronic signing;
  • bill, collect payments and keep financial and tax records;
  • communicate with you about the service, including service notices, changes to our terms and security alerts;
  • send marketing, where the law allows (see marketing);
  • meet our legal obligations and deal with disputes and legal claims; and
  • do anything else you agree to, or that is closely related to the above and that you would reasonably expect.

Sign-in records are used for billing

EasyDone is billed by the people who sign in each month. So we use sign-in records to count the people who signed in during each billing month, to work out your invoice, and to spot logins that look shared between several people. Your business's administrators can see which logins have signed in and are being counted on the Subscription page, and can ask us for the sign-in records behind an invoice.

How we use AI

In our product

EasyDone includes AI features. When someone uses one, the content they submit is sent to an AI provider (such as Anthropic or OpenAI) to produce a response. We use the business services of these providers, which say they do not use submitted content to train their models by default. The providers may keep data for a limited time for safety and legal reasons, under their own terms, and may process it outside Australia. We do not control how they handle it inside their own systems.

In running our business

We use AI-assisted tools, including AI agents, to build, run, monitor, support and improve EasyDone, and to help draft messages. These tools may handle personal information when a task needs it, for example when looking into a fault or drafting a support reply. Our people supervise them.

No training by us

We do not use personal information, or our customers' data, to train or fine-tune AI models.

Automated decisions

We do not make decisions about you that have a legal or similarly significant effect on you based only on automated processing.

We do use automated steps for routine matters, such as:

  • pausing AI features when an included allowance is used up;
  • retrying failed payments and sending reminders;
  • counting the logins that signed in during the month for billing; and
  • flagging unusual sign-in activity for review.

If this changes, we will update this section first. New Privacy Act rules about automated decisions start on 10 December 2026, and we will review this section against them before then.

Marketing

We may send you information about EasyDone and related services if you have agreed to receive it, or where the law otherwise allows (for example, if you are an existing customer and would reasonably expect it).

Every marketing email or text has a way to unsubscribe, and we action unsubscribes within 5 business days. You will still get the service and account messages we need to send you.

We do not sell personal information, and we do not give it to others for their own marketing.

Who we share it with

We share personal information only as needed with:

  • our service providers, who help us run EasyDone and our business (listed below);
  • the business you work for or with, where you are a user of its EasyDone;
  • our professional advisers, insurers, auditors and financiers;
  • a buyer or potential buyer of our business, under confidentiality obligations; and
  • government bodies, courts and regulators, where the law requires or allows it.

Our service providers

Locations come from each provider's published information at the date of this draft, and providers can change where they process data. This table is our published list of providers, at easydone.work/privacy/#providers. We give paying customers 30 days' notice before a new provider starts handling personal information in their data.

ProviderWhat it does for usWhere it processes data
DigitalOceanHosts each paying customer's private server and its daily backupsSydney, Australia. Provider support and account systems: United States and other countries
CloudflareNetwork security, encrypted connections, delivery of web traffic, and hosting of Studio websitesGlobal network, including Australia and the United States
AnthropicAI features; AI tools we use to build and support EasyDoneUnited States, and other regions where Anthropic operates, as it publishes
OpenAIAI features; AI tools we use to build and support EasyDoneUnited States, and other regions where OpenAI operates, as it publishes
OpenRouterRoutes some Studio AI requests to a range of AI modelsUnited States and the countries of the underlying model providers (Studio, when enabled)
GoogleAddress lookup and place details (Google Maps Platform)United States and globally
StripeTakes subscription payments and runs the billing portalAustralia, United States and other countries
ClickSendSends SMS messages from EasyDoneAustralia and other countries, as ClickSend publishes; messages pass through Australian and international carriers
MicrosoftOur own email and business systems (sign-up emails, signed agreements, support)Australia and other countries, under Microsoft's terms
GitHubStores and builds the EasyDone software and Studio website codeUnited States
OVHOur operations server: monitoring, deployments, routing AI requests, demo hosting, the shared free-trial server, and final backups when a customer leaves (kept up to 90 days)OVH data centre in Sydney, Australia
TailscalePrivate network for our administrative access to servers. Connection details only, not customer data (where we use it)United States and global

Services a customer connects with their own account (for example their own Microsoft 365, Xero or Stripe) are not our providers. They act for that customer, under the customer's own agreement with them.

Cookies and analytics

Our websites and apps use cookies and similar technologies to keep you signed in, remember your settings, keep the service secure and understand how the websites are used.

If we use analytics tools or advertising pixels on our websites or in the app, we will describe them here and offer a way to opt out.

You can block or delete cookies in your browser, but some parts of the service may then stop working.

Overseas disclosure

Our customers' live EasyDone data is hosted on servers in Sydney, Australia. During a free trial, a customer's data sits on a shared trial server hosted by us in Australia.

Some of our service providers store or process personal information outside Australia. Based on their published information, the countries include the United States, Ireland and other countries in the European Union, and other countries where global providers (such as Cloudflare, Microsoft and Google) operate. Our operations server and the shared trial server are with OVH, in a data centre in Sydney, Australia.

We take reasonable steps to make sure these providers handle personal information in a way that is consistent with the Australian Privacy Principles. We choose reputable providers with published security and privacy commitments, and we send them only what they need. We cannot control how a provider handles data inside its own systems, and the laws of other countries may not protect personal information in the same way Australian law does.

How we keep it safe

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, change or disclosure. These include: separate servers for each paying customer; encrypted connections; firewalls; restricted, key-based access to servers; role-based access controls; security updates; and logging.

No system is completely secure. If we become aware of a data breach that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner, as the law requires.

How long we keep it

We keep personal information only as long as we need it for the purposes in this policy, or as the law requires. For example:

  • Account and signing records: for the life of the account and 7 years after, for legal and tax purposes.
  • Customer data we host: after an agreement ends, the customer has 30 days to export it. We then delete it from live systems within 30 days, and backup copies expire within a further 90 days.
  • Free trial data: if a trial ends without a paid subscription, the customer has the same 30 days to export it, and we then delete it from the trial server.
  • Demos: deleted when the demo ends, with one final backup kept for up to 90 days.
  • Marketing lists: until you unsubscribe. We then keep a note that you unsubscribed so we do not contact you again.

When we no longer need personal information, we destroy it or remove anything that identifies you.

Seeing and correcting your information

You can ask to see, or to correct, the personal information we hold about you by contacting us (see contact us). We will reply within 30 days. We may need to check who you are first.

There is no charge to ask. In some cases we may charge a reasonable fee for providing access, and we will tell you first. If we refuse, we will tell you why and how to complain.

Complaints

If you are unhappy with how we have handled your personal information, please contact us first. We will confirm we have your complaint within 5 business days and aim to sort it out within 30 days.

If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner: www.oaic.gov.au, phone 1300 363 992.

Contact us

Privacy Officer, EasyDone Software Pty Ltd

Email: support@easydone.work (please put “Privacy” in the subject line)

Post: 9D Regents Park Rd, Joondalup WA 6027

Changes to this policy

We may update this policy from time to time. We will publish the new version on our website with its date. If a change is significant, we will also email our customers.

Questions about EasyDone? Ask here, and a person from our team will reply.