1. What Is Personal Information?
VendorVault is operated by Portfolioapp Pty Ltd (“VendorVault”, “we”, “us” or “our”). We respect the privacy of individuals who use VendorVault and individuals whose information is managed through the platform. This Privacy Policy explains how we collect, hold, use, disclose and protect personal information in connection with the VendorVault website, platform, applications and related services (collectively, the “Service”). We aim to handle personal information responsibly and in accordance with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply to us.
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. The types of personal information handled through VendorVault depend on how the Service is used and the individual's relationship with a VendorVault customer. Individuals whose information may be handled through VendorVault include:
- real estate agents and agency staff;
- property owners and vendors;
- prospective and actual buyers;
- conveyancers and solicitors;
- tradespeople and contractors;
- photographers, stylists and other property service providers;
- business contacts;
- prospective customers; and
- other individuals involved in a property transaction or workflow.
2. Information We Collect
We may collect or process the following categories of personal information.
Account Information
When a user creates or uses a VendorVault account, we may collect:
- name;
- email address;
- telephone number;
- agency or business name;
- job title or role;
- account credentials;
- profile information;
- subscription information; and
- account preferences and settings.
Property and Vendor Information
Information entered into a VendorVault property workspace or “Vault” may include:
- property address;
- property details;
- owner's or vendor's name;
- contact details;
- property documents;
- photographs;
- notes;
- appointment information;
- sale preparation information;
- marketing information;
- important dates;
- tasks and workflow information;
- conveyancer or solicitor details;
- contractor information; and
- other information relevant to the preparation, marketing or sale of a property.
Buyer Information
Where VendorVault functionality is used in connection with prospective or actual buyers, information may include:
- name;
- contact details;
- property interest;
- communications;
- inspection or enquiry information;
- documents;
- compliance information; and
- other information entered by an authorised VendorVault user.
Access to buyer information may be restricted depending on a user's role and permissions.
Identity and Compliance Information
Where VendorVault provides functionality relating to identity verification, regulatory compliance or transaction compliance, information processed through the Service may include:
- full name;
- date of birth;
- residential address;
- identity document information;
- verification status;
- compliance records;
- declarations;
- transaction-related information; and
- other information required for the relevant compliance process.
Depending on the features used, some identity or compliance information may be collected or processed by third-party verification or compliance providers rather than directly by VendorVault. We seek to limit the collection of identity and compliance information to information reasonably required for the relevant functionality.
Documents and Files
Users may upload documents and files to VendorVault. These documents may contain personal information about property owners, buyers or other individuals. The user or organisation uploading information is responsible for ensuring that it has appropriate authority to collect, use and provide that information through VendorVault.
Calendar and Workflow Information
Where calendar or workflow functionality is used, we may process:
- appointments;
- property-related dates;
- deadlines;
- tasks;
- reminders;
- event descriptions; and
- related property information.
If a user connects VendorVault to an external calendar provider, information may be exchanged with that provider as necessary to provide the integration.
Communications
We may collect information contained in communications with us, including:
- support requests;
- emails;
- feedback;
- enquiries;
- complaints;
- survey responses; and
- other correspondence.
Where VendorVault enables communications between users or other participants, we may process information necessary to facilitate those communications.
Payment and Subscription Information
If you purchase a VendorVault subscription, payments may be processed by a third-party payment provider. We may receive information including:
- subscription status;
- billing name;
- billing address;
- payment status;
- transaction identifiers;
- invoice information; and
- limited information about the payment method.
VendorVault does not ordinarily store complete credit or debit card details where payments are handled directly by our payment provider.
Technical and Usage Information
When you access VendorVault, we may automatically collect technical information including:
- IP address;
- browser type;
- device type;
- operating system;
- approximate location derived from technical information;
- login information;
- pages or features accessed;
- dates and times of access;
- referring pages;
- error information;
- application performance information; and
- security and audit information.
3. How We Collect Personal Information
We may collect personal information:
- directly from you;
- when you create or update an account;
- when you use VendorVault;
- when information is entered into a Vault;
- when documents or files are uploaded;
- when you communicate with us;
- when you purchase a subscription;
- when you connect a third-party integration;
- automatically through cookies and similar technologies;
- from an agency, employer or team administrator;
- from another authorised VendorVault user;
- from third-party services you choose to connect to VendorVault; or
- from third-party service providers that collect or process information on our behalf or in connection with functionality requested through VendorVault.
Because VendorVault is a collaborative real estate platform, we may receive information about individuals who do not personally have a VendorVault account. For example, a real estate agent may enter information about a property owner, prospective buyer, conveyancer or contractor as part of a property workflow.
4. Information Provided by Our Customers
VendorVault customers may upload or enter personal information about other individuals. In these circumstances, the customer is responsible for ensuring it has appropriate authority to collect, use and provide that information through VendorVault. VendorVault generally processes that information for the purpose of providing the Service requested by the customer. If you believe your personal information has been entered into VendorVault without appropriate authority, you may contact us using the details at the end of this Privacy Policy.
5. Why We Collect and Use Personal Information
We may collect, hold, use and disclose personal information where reasonably necessary to:
- provide and operate VendorVault;
- create and administer accounts;
- provide property Vaults and workflow functionality;
- facilitate collaboration between authorised users;
- provide seller, buyer and property-related functionality;
- provide calendar, timeline and reminder functionality;
- provide compliance-related functionality;
- process subscriptions and payments;
- provide customer support;
- respond to enquiries;
- communicate important service information;
- authenticate users;
- maintain security;
- detect or prevent fraud and misuse;
- troubleshoot technical issues;
- monitor and improve performance;
- develop and improve VendorVault;
- understand how the Service is used;
- maintain appropriate business records;
- enforce our Terms of Service;
- protect our legal rights and those of our users;
- comply with applicable laws and regulatory requirements; and
- carry out other purposes disclosed at the time information is collected.
6. Marketing Communications
We may use contact information to communicate with existing or prospective customers about VendorVault where permitted by law. Marketing communications may include information about:
- VendorVault features;
- product updates;
- offers;
- promotions;
- educational material; and
- other information relating to VendorVault.
Where required, we will obtain appropriate consent before sending electronic marketing communications. You may unsubscribe from marketing emails using the unsubscribe link contained in those communications or by contacting us. Unsubscribing from marketing communications does not prevent us from sending essential communications relating to your account, subscription, security or use of VendorVault.
7. How We Disclose Personal Information
We do not sell personal information. We may disclose or make personal information available to third parties where reasonably necessary to operate VendorVault or where authorised or required by law. These third parties may include:
- cloud hosting and infrastructure providers;
- database and storage providers;
- authentication providers;
- payment processors;
- email delivery providers;
- SMS or communications providers;
- analytics and monitoring providers;
- customer support providers;
- identity verification or compliance providers;
- artificial intelligence, machine learning and automated processing providers;
- calendar and productivity providers;
- professional advisers including lawyers and accountants;
- insurers;
- regulators, law enforcement agencies or government authorities where required or authorised by law; and
- other service providers that assist us in operating VendorVault.
We seek to provide service providers only with information reasonably necessary for them to perform their functions.
8. Sharing Within VendorVault
VendorVault is designed to allow authorised users to collaborate. Information may therefore be visible to other users depending on:
- the relevant Vault;
- the user's organisation;
- invitations;
- account permissions;
- user roles; and
- functionality selected by the customer.
Users are responsible for managing access appropriately. VendorVault may implement technical permissions designed to restrict certain categories of information to appropriate users.
9. Third-Party Integrations
VendorVault may allow users to connect third-party services such as calendar, email, identity, property, payment or productivity platforms. When you connect an integration, VendorVault may exchange information with that service as reasonably necessary to provide the requested functionality. The third-party provider's handling of information is also governed by its own privacy policy and terms. Users should review those policies before connecting a third-party service.
10. Artificial Intelligence and Automated Features
VendorVault may use artificial intelligence (“AI”), machine learning and other automated technologies to provide, support and improve certain features of the Service.
Depending on the functionality used, AI features may process information entered into, uploaded to or generated through VendorVault, including property information, documents, notes, workflow information, communications and other information relevant to the requested feature.
VendorVault may use third-party AI and technology providers to provide some of these capabilities. Where information is provided to such providers, we seek to limit the information shared to what is reasonably necessary to provide, maintain and secure the relevant functionality.
VendorVault does not use personal information, customer content or other user data to train artificial intelligence models, and we do not permit third-party AI providers to use VendorVault user data to train their general-purpose AI models.
AI-generated outputs may not always be complete, accurate or appropriate for a particular purpose. Users are responsible for reviewing AI-generated outputs before relying on them for business, legal, compliance, property or other decisions.
We do not sell personal information to AI providers.
11. Google and Microsoft Integrations
If VendorVault allows you to connect a Google or Microsoft account, we will request access only to permissions reasonably necessary to provide the selected functionality. Depending on the integration, this may include access required to create, update, synchronise or display property-related calendar information. Information obtained through these integrations will be used to provide and maintain the requested VendorVault functionality and for related security and operational purposes. Users may revoke access through their Google or Microsoft account settings or through VendorVault where that functionality is available.
12. Overseas Disclosure and Processing
Some third-party technology providers used to operate VendorVault may be located outside Australia or may use infrastructure located outside Australia. As a result, personal information may in some circumstances be disclosed to overseas recipients. Where practicable, and where required by applicable Australian privacy law, we will identify the countries in which overseas recipients are likely to be located. We take reasonable steps as required by applicable law in relation to overseas disclosures of personal information. The locations used by third-party providers may change as their infrastructure and services develop.
13. Data Hosting and Storage
Personal information may be stored electronically using VendorVault's infrastructure and third-party cloud service providers. Information may be stored in databases, file storage systems, backups, logs and other systems reasonably required to operate and secure the Service. We seek to select reputable service providers and implement safeguards appropriate to the nature of the information being handled.
14. Security
We take reasonable technical and organisational measures designed to protect personal information against:
- misuse;
- interference;
- loss;
- unauthorised access;
- unauthorised modification; and
- unauthorised disclosure.
Depending on the circumstances, these measures may include:
- encrypted connections;
- access controls;
- authentication controls;
- restricted administrative access;
- secure cloud infrastructure;
- monitoring and logging;
- software and infrastructure maintenance;
- backups; and
- security procedures.
No internet-based service or electronic storage system can be guaranteed to be completely secure. Users also have an important role in protecting information and should maintain secure passwords, protect account credentials and devices, and promptly notify us of suspected unauthorised access.
15. Data Breaches
We maintain processes designed to identify and respond to suspected data breaches. If we become aware of a data breach involving personal information, we will assess the incident and take appropriate steps to contain, investigate and remediate it. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify affected individuals and the relevant regulator as required by law.
16. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected or as required or permitted by law. Retention periods may depend on:
- the nature of the information;
- whether an account remains active;
- contractual obligations;
- legal and regulatory requirements;
- security requirements;
- fraud prevention;
- dispute resolution; and
- legitimate business record-keeping requirements.
When personal information is no longer required, we will take reasonable steps to delete, destroy or de-identify it where required by applicable law. Some information may remain temporarily in secure backups before being deleted or overwritten through normal backup processes.
17. Account Closure and Deletion
Users may request closure of their VendorVault account. Account closure does not necessarily result in immediate deletion of every piece of information associated with the account. We may retain information where reasonably necessary to:
- comply with law;
- maintain financial or business records;
- resolve disputes;
- investigate fraud or security incidents;
- enforce agreements; or
- protect legal rights.
Information relating to a property Vault may also be associated with an agency or other authorised users and may not necessarily be deleted solely because one user leaves an organisation. Where information is no longer required, it may be deleted or de-identified in accordance with our retention practices and applicable law.
18. Access to Personal Information
You may request access to personal information we hold about you. We may need to verify your identity before providing access. In some circumstances, applicable law may permit or require us to refuse access to certain information. Where required by law, we will provide reasons for refusing an access request.
19. Correction of Personal Information
We take reasonable steps to maintain accurate, complete and up-to-date personal information where appropriate. You may request correction of personal information you believe is inaccurate, out of date, incomplete, irrelevant or misleading. Some account information may be corrected directly through VendorVault. For other corrections, you may contact us.
20. Privacy Requests Relating to an Agency
Where VendorVault holds information in connection with services provided to a real estate agency or another customer, we may need to refer an access, correction or deletion request to that organisation. This is because the organisation may control the relevant property or client records and may have independent legal or professional obligations regarding those records. We will seek to assist with legitimate privacy requests where reasonably possible.
21. Cookies and Similar Technologies
VendorVault may use cookies and similar technologies to:
- maintain login sessions;
- provide essential functionality;
- remember preferences;
- protect account security;
- understand how the Service is used;
- diagnose technical problems; and
- improve performance.
Some cookies may be necessary for VendorVault to function correctly. Browser settings may allow users to block or delete cookies, although doing so may affect certain features of the Service.
22. Analytics
We may use analytics and monitoring tools to understand how VendorVault is used and improve reliability, performance and user experience. Analytics information may include technical and usage information such as device information, browser information, pages accessed, feature usage and error information. Where reasonably possible, we seek to minimise the personal information used for analytics purposes.
23. Children
VendorVault is a business platform and is not directed at children. We do not knowingly seek to collect personal information directly from children for the purpose of creating VendorVault accounts. If we become aware that personal information about a child has been collected inappropriately, we will take reasonable steps to address the situation.
24. Business Transfers
If VendorVault or Portfolioapp Pty Ltd is involved in a merger, acquisition, financing, corporate restructure or sale of some or all of its business or assets, personal information may be disclosed to relevant advisers, prospective purchasers or other parties involved in the transaction where appropriate and lawful. Where such a transaction occurs, we will seek to ensure personal information continues to be handled appropriately and in accordance with applicable law.
25. Legal Disclosure
We may disclose personal information where disclosure is required or authorised by law, including in response to:
- court orders;
- subpoenas;
- regulatory requirements;
- law enforcement requests; or
- other lawful government requests.
We may also use or disclose information where reasonably necessary to establish, exercise or defend legal claims or protect the rights, safety or security of VendorVault, our users or others, subject to applicable law.
26. Privacy Complaints
If you believe we have mishandled your personal information or breached an applicable privacy obligation, please contact us using the details below. Please provide sufficient information for us to understand and investigate your concern. We will seek to: 1. acknowledge your complaint within a reasonable period; 2. investigate the circumstances; 3. request additional information where necessary; and 4. provide a response or proposed resolution within a reasonable timeframe. If you are not satisfied with our response and the Privacy Act applies to the matter, you may have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
27. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to VendorVault;
- new functionality;
- changes to our service providers;
- changes to our information-handling practices;
- legal or regulatory developments; or
- security and operational requirements.
The current version will be published on the VendorVault website. The “Last Updated” date at the top of this Privacy Policy will indicate when it was most recently revised. Where changes materially affect how we handle personal information, we may provide additional notice where appropriate.
28. Contact Us
Questions, requests or complaints regarding privacy can be directed to:
VendorVault
Operated by Portfolioapp Pty Ltd Email: connect@vendorvault.com.au Website: vendorvault.com.au Please include sufficient information for us to identify and respond to your request.