Legal
Privacy Policy
How Surepayd collects, uses, stores and discloses personal information, and how to reach us about it.
Who we are
SurePayd Services Pty Ltd (ABN 92 617 873 935), trading as Surepayd, provides Working Capital Infrastructure to businesses in Australia and New Zealand. This policy covers both this website and the platform we operate for our clients.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we hold information about people in New Zealand, we also act in accordance with the Privacy Act 2020 (NZ).
Privacy enquiries, requests to access or correct your information, and privacy complaints should be sent to enquiries@surepayd.com.
Information we collect
What we hold about you depends on how you came to us. There are three relationships and they are genuinely different, so they are set out separately.
- If you use this website
- Almost nothing, unless you contact us. The site sets no cookies. It counts visits using privacy-preserving analytics that cannot identify you and cannot follow you to another site. If you submit the contact form we collect your name, work email address, company and your message. Your role and the ERP you run are optional.
- If you use Surepayd for your employer
- Your name, work contact details, role and permissions, and a record of the actions you take in the platform. The audit trail is a product feature your employer relies on, so it is not optional.
- If you owe money to a business that uses Surepayd
- We hold what that business gave us: typically your name and contact details, your account and invoice history, payment records, and any disputes or payment arrangements. We collected it from them, not from you, and we hold it on their behalf.
Where a client uses our onboarding and credit modules, we also obtain credit information from credit reporting bodies and carry out PPSR searches. We do that on the client's behalf, under the authority they obtained from the applicant.
The contact form carries one hidden field and a timestamp. They exist to detect automated submissions and are discarded with the rest of the submission. They record nothing about you.
How we use your information
- To answer your enquiry and arrange a conversation.
- To provide the platform to the client who engaged us: presenting invoices, taking payments, sending reminders, recording disputes and maintaining account history.
- To contact our clients' customers on their behalf, by email, SMS, voice or through the customer portal.
- To assess credit applications and monitor credit risk, where a client uses those modules.
- To keep the platform secure, investigate misuse and meet our legal obligations.
We do not sell personal information, and we do not use it for advertising.
We do not train models on one client's data and then use them to serve another. Models are trained per client, on that client's own data, and nothing crosses the boundary between clients. Your transactions do not teach a model that someone else uses, and no model we run for you has learned anything from anyone else's.
Who we share it with
We share personal information with the providers that make the platform work, and with nobody else, unless the law requires it of us.
| Who | What for | Where they hold it |
|---|---|---|
| The client who engaged us | Their own customer, account and payment data | Australia and New Zealand |
| Payment providers | Processing a payment you choose to make | Australia and New Zealand |
| Credit reporting bodies | Credit assessment and monitoring, on a client's authority | Australia and New Zealand |
| Communications providers | Sending email, SMS and voice messages | Varies by provider |
| Resend | Delivering enquiries submitted through this website | United States |
| Plausible Analytics | Counting visits to this website, without identifying you | European Union |
Platform data is stored and processed within Australia and New Zealand. Enquiries submitted through this website are different: they are delivered by Resend, which operates from the United States, so a website enquiry does leave Australia. If you would rather not send personal information offshore, email us at enquiries@surepayd.com instead.
Storage, security and retention
Platform data is held in Australia and New Zealand. It is encrypted with AES-256 at rest and TLS 1.3 in transit. Access is role-based, with single sign-on and multi-factor authentication enforced, and every action is written to an immutable audit log that can be exported on request.
Surepayd holds SOC 2 Type II certification, and our information security management is aligned to the ISO 27001 standard. The platform is penetration tested annually by an independent security firm.
An enquiry submitted through this website is kept for 24 months and is then deleted.
Client data is kept for 90 days after an agreement ends, which leaves time to export it and to settle any final reconciliation, and is then deleted. Where the law requires us to keep something for longer, we keep only what it requires, for only as long as it requires.
Accessing and correcting your information
You can ask what personal information we hold about you, ask us to correct it, and ask us to delete it where we are not required to keep it. Write to us and we will respond within 30 days.
If you are a customer of a business that uses Surepayd, that business controls the information and we hold it for them. Ask them first, because they can act on it immediately where we would have to seek their instruction. If you cannot reach them, or they do not respond, contact us and we will help.
We will not charge you for making a request. If we refuse one we will tell you why, in writing.
Complaints about privacy
If you think we have mishandled your personal information, tell us. Our complaints process sets out how to raise it and what happens next, and a privacy complaint follows the same path.
If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner, or, in New Zealand, to the Office of the Privacy Commissioner. You do not need our agreement to do that.
Changes to this policy
We update this policy when what we do changes. The date at the top of this page is the date of the current version.
Where a change materially affects how we handle information we already hold, we will tell affected clients directly rather than relying on you noticing the date.