How we handle your data
Last updated: 2026-04-30 · Engineering & privacy review in progress
This page describes the actual data flow and controls behind BuyersIQ. It is not legal advice; the formal Privacy Notice lives in our Privacy Notice. Every factual claim below links to a primary vendor or regulator source where possible — we do not display certification badges we have not earned.
Data flow
Uploaded property packs contain sensitive personal and commercial information (spec §12.1). In production we route browser traffic over TLS to application servers we operate ourselves, persist canonical copy and metadata in Supabase in ap-southeast-2, and send documents to our AI provider for inference per our architecture overview.
ap-southeast-2). AI inference processes your documents; retention follows our AI provider's published schedule — see the provider details table above for links.Region references: Supabase regions.
Where your data lives
Each provider processes the categories of data listed in our Privacy Notice. Operational status pages help verify independent availability claims.
Supabase
Postgres, Auth, encrypted object storage, Realtime — primary data region Sydney.
Anthropic
AI inference — documents are processed for report generation. We do not use customer data to train models.
Stripe
Payments, subscriptions, invoicing metadata (billing accounts only).
Resend
Transactional email (receipts, notifications).
Retention & deletion
Default retention targets roughly thirty days for AI provider-side processing artefacts, with buyer-configurable windows in account settings where the product exposes them. Hard-delete jobs run on a schedule plus on-demand export/deletion flows — see your account data tools.
| Data class | Typical location | Retention / deletion levers |
|---|---|---|
| Review jobs, findings, citations | Sydney Postgres (RLS-scoped) | Account retention preference + completion of deletion / export requests (Account data). |
| Original PDFs | Supabase Storage (encrypted at rest) | Aligned with job lifecycle; removed with account deletion pipeline. |
| AI provider — processed documents | AI provider infrastructure | Provider retention schedule; we schedule deletes aligned to project policy — see the provider's published data retention statement. |
| Billing records | Stripe (+ minimal copy in Postgres) | Tax / fraud / chargeback requirements per Stripe privacy notice. |
| Transactional email metadata | Resend | Provider logs per Resend privacy policy. |
Australian Privacy Principles (APP) alignment
We design controls around the APPs enforced by the OAIC (Privacy Act 1988). Below maps product practices to the obligations we most often touch; cite the official APP Guidelines and OAIC guidance on commercially available AI products.
- APP 1 / transparency — Privacy Notice, this security page, and in-product consents describe why we collect uploads.
- APP 3 / collection — We collect what buyers upload and the account profile needed to run reviews and comply with law (billing, audit).
- APP 6 / use — Data is used to perform the review, maintain security, and meet legal obligations — not for training foundation models.
- APP 8 / cross-border — AI inference may occur outside Australia; we document subprocessors and rely on transparency + contractual controls per our Privacy Notice.
- APP 11 / security — TLS in transit, encryption at rest via cloud providers, RLS, signed URLs, audit logging in product design.
- APP 12–13 / access & correction — Account profile editing, export, and deletion workflows (see Account data).
AI processing & data retention
AI processing of your documents is not covered by a Zero Data Retention guarantee; retention follows our AI provider's published policy. Our mitigations include explicit consent before AI processing, minimising unnecessary re-uploads, storing canonical copies in our own infrastructure for audit, scheduled provider-side deletes aligned to project policy, and the verifier layer that refuses uncited legal conclusions.
Verifier rules
The verifier agent downgrades or suppresses findings when evidence or policy guardrails fail (spec §8.3). Marketing claims about “AI certainty” must not contradict these rules.
- No supporting evidence exists.
- Evidence is ambiguous.
- The conclusion is legal advice rather than legal information.
- The report claims a right to terminate or rescind without human review.
- Jurisdiction is uncertain.
- The cited law source is stale or not versioned.
- OCR confidence is below threshold.
- Another document contradicts the finding.
Reporting concerns
Privacy Officer: privacy@buyersiq.com.au. General enquiries: Contact. You may also lodge a complaint with the Office of the Australian Information Commissioner: Lodge a privacy complaint.