PIA governance
Privacy Policy
How Property Intelligence Assistant handles account, research and portfolio information.
Draft for legal review · Updated 4 August 2026
Information we handle
We may process account and contact details, billing references, searches, watchlists, support correspondence, usage/security events and portfolio information entered by an authorised user. Portfolio information can include property addresses, ownership structures, values, rents, expenses, insurers or managers, lender names, balances, rates, offsets and loan dates. The portfolio editor can read a selected lease, management or loan PDF/image on the user's device to suggest supported fields; the raw file is not uploaded or stored and suggestions must be checked before saving. PIA does not request passwords, banking credentials, BSBs, full or partial bank or loan account numbers, tax file numbers, tenant identities or identity documents for portfolio monitoring.
Why we use it
Information is used to provide and secure the service, calculate portfolio indicators, generate requested reports, process purchases, maintain evidence and audit history, personalise research, detect abuse, respond to support requests and meet legal obligations. Customer and organisation information must be isolated by authenticated identity, membership and role.
Finance referrals
PIA does not share a finance enquiry with Tactical Finance Australia merely because a user views a calculator or link. A referral submission must use a separate, explicit and versioned consent describing the contact and indicative financial information to be shared and the purpose of contact.
AI processing
AI functionality remains disabled until an approved provider, permitted data flow and privacy assessment are in place. If enabled, the service must explain what information is sent, minimise and redact the request, prevent provider training where contractually available, and disclose relevant processing locations and retention before use.
Service providers and overseas processing
Approved infrastructure, authentication, payment, communications, monitoring, mapping, AI and licensed-data providers may process only the information required for their contracted function. The provider register, processing locations, contractual safeguards and cross-border disclosures must be finalised before real customer data or the relevant integration is activated.
Security, retention and breach response
PIA uses layered access controls, tenant isolation, private storage, encryption supplied by approved infrastructure, rate limits, audit records, monitoring and tested recovery controls. No service can promise absolute security. A record-class retention and deletion schedule, production backup policy and eligible-data-breach response process must be approved before beta.
Your choices and complaints
Authenticated users can download a structured copy of account data, request correction or request permanent deletion after re-authentication. Billing, legal and organisation-owner safeguards may require a handover or limited lawful retention. A monitored privacy contact and complaint process, including escalation to the OAIC where applicable, must be published before beta invitations.
This is a product-ready draft, not a substitute for review by an Australian privacy and technology lawyer before public launch.
