PTCorp Pty Ltd trading as PoweredByPTCorp (ABN 59 143 430 700)
Privacy Policy
At a glance
- We collect information you provide, account and authentication details, and usage/security data needed to run our Services.
- For ptNexus, PTRE and other platforms, Customers may upload information about workers, volunteers, contractors, clients and other people. They ordinarily determine the operational purpose for that information.
- We use personal information to provide the Services, secure accounts, provide support, comply with law, and improve reliability.
- We share information only with trusted providers (hosting, authentication, messaging, payments) and where required by law.
- You can request access/correction, and in some cases deletion. Complaints can be made to us and then the OAIC.
Our role: Customer data vs End User data
Our products include ptNexus Workforce and platforms used by business and community-service Customers. In these cases:
- Customer as controller: The Customer determines what personal information is collected and uploaded into the platform and how it is used for their business processes (e.g., tenancy management).
- PTCorp as service provider: We process that information on behalf of the Customer to provide and secure the platform, consistent with our contracts and this policy.
If you are an End User, worker, volunteer, contractor or client using a Customer-managed service, your first point of contact for an operational record will usually be the organisation that invited or supports you. You may always contact PTCorp about platform privacy or use our deletion request process.
Information we collect
A. Information you provide
- Account & contact details: name, email, phone, organisation, role/title, address (where relevant).
- Support content: messages, attachments, and information you provide when requesting help.
- Configuration content: settings, templates, workflow inputs and other material you upload or create within our Services.
B. Authentication & security information
- Authentication data: identity provider metadata (e.g., Google/Microsoft SSO), email verification status, multi-factor authentication status (if enabled).
- Security signals: login timestamps, IP addresses, device/browser characteristics, and event logs used for fraud prevention and service security.
- Bot/abuse protection: if enabled, we may use reCAPTCHA or similar tools to help detect abuse.
C. Usage, device, and analytics information
- Usage & device data: IP address, browser type, device type, pages viewed, timestamps, referring URLs, error logs and performance metrics.
- Location: approximate location may be derived from an IP address. ptNexus may also collect precise device location when an authorised user starts a location-sensitive function such as check-in or check-out.
- Cookies/local storage: for login sessions, security, and preferences (see “Cookies & analytics”).
D. Billing and transactions (if applicable)
- Billing details: billing contact, invoicing details, plan/entitlements, transaction references.
- Payments: processed by PCI-compliant payment processors; we do not store full payment card numbers.
E. Third-party personal information uploaded by Customers
Depending on the product (e.g., PTRE), Customers may upload or input personal information about third parties such as tenants, owners, landlords, buyers, sellers, applicants, emergency contacts, contractors, or staff. This content is controlled by the Customer.
F. ptNexus Workforce and client-support information
- Workforce records: roles, permissions, registrations, rosters, shifts, attendance, timesheets, training, assessments, qualifications, assigned tasks, maintenance activity and operational evidence.
- Device capabilities: camera input for barcode scanning and authorised evidence, selected photographs, microphone recordings and precise location only when the relevant feature is used and permission is granted.
- Client-support information: client profiles, contact details, service needs, intakes, notes, consent records, support sessions, referrals, safeguarding information, risk assessments and reports.
- Sensitive content: consented recordings, transcripts, summaries, client documents and face photographs. A face photograph may support a stated service or verification purpose; ptNexus does not create biometric templates or perform facial recognition.
How we use personal information
- Provide and operate Services: create accounts, deliver features, enable portal access, and maintain functionality.
- Security: authenticate users, protect accounts, detect and prevent fraud/abuse, and investigate security incidents.
- Support: respond to enquiries, troubleshoot issues, and provide customer support.
- Service communications: send operational emails/SMS such as verification, password reset, outages, policy updates, and billing notices.
- Improvement: monitor performance, fix bugs, and improve usability and reliability.
- Legal compliance: comply with legal obligations and enforce our Terms.
Where GDPR/UK GDPR applies, lawful bases may include contract performance, legitimate interests (e.g., security and fraud prevention), legal obligation, and consent where required.
AI and automated features
Some Services may include automation or AI-assisted transcription, drafting, summarisation, suggestions and decision support. Where enabled and authorised, relevant inputs may be sent to an approved provider to generate outputs. An authorised person must review outputs before use. AI output does not diagnose, replace professional judgment or make decisions about a client.
We do not use Customer Data to train public models unless you (or your organisation) have explicitly agreed to such use in writing. We may use de-identified, aggregated analytics to improve service performance and reliability.
Cookies & analytics
We use necessary cookies (and similar storage technologies) to keep you signed in, remember preferences, and deliver core functionality. Optional analytics is disabled unless you select “Allow analytics”. If enabled, it helps us understand website usage and improve reliability. We do not use advertising cookies on this website.
SSO flows (Google/Microsoft) may set cookies to support authentication. Security tooling may collect device and usage information to help prevent automated abuse.
You can change your choice through , your browser settings, or our Cookie Policy.
When we share information
We do not sell personal information. We share information only with:
- Service providers who help us deliver the Services (e.g., hosting, authentication, email/SMS, analytics, payment processing), subject to confidentiality and security obligations.
- Customers (where applicable) when you use an End User portal—your activity and submissions may be visible to the Customer that invited you.
- Legal and safety where required by law, court order, or to protect rights, property, or safety.
- Business transfers (e.g., merger, acquisition, restructure), subject to continued protections consistent with this policy.
Some providers may process data outside Australia. We take reasonable steps to ensure comparable protections (e.g., contracts, due diligence, and risk assessments).
International data transfers
Because we use global infrastructure providers, personal information may be stored or processed in Australia and other countries. We take reasonable steps to ensure overseas recipients handle information in a manner consistent with the APPs and this policy.
Security & retention
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information. No method of transmission or storage is 100% secure, but we work continuously to improve protections.
We retain personal information only as long as needed for the purposes described above, to comply with legal obligations, resolve disputes, safeguard people and enforce agreements. We then delete or de-identify it unless an approved exception applies. Default periods and deletion assurance for sensitive ptNexus records are in our Data Retention and Deletion Policy.
Your rights
- Access & correction: request access to and correction of your personal information.
- Deletion: use our account and data deletion process. Identity, authority and applicable retention requirements must be checked first.
- Marketing choices: opt out of marketing communications at any time.
- End Users: if you are a tenant/owner/portal user, the Customer (agency) may control your data—contact them first for most requests.
- Complaints: contact us first; if unresolved, you can contact the OAIC (Australia).
EU/UK residents may also have rights to object, restrict processing, and data portability, subject to law.
Children’s privacy
Our public commercial Services are not directed to children under 13. A Customer may lawfully support a child or engage a young volunteer through a controlled ptNexus workflow. The Customer must establish appropriate authority, notices, consent and access controls, and collect only information needed for that purpose. Contact us if you believe information was collected without appropriate authority.
Changes to this policy
We may update this policy from time to time. We will post updates here and change the “Effective date”. Material changes may also be communicated by email or in-product notice.
Contact
Email: privacy@poweredbyptcorp.com.au
Address: 8/5 Smiths Rd, Goodna QLD 4300, Australia
Privacy complaints
If you have a complaint, please contact us with details. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
OAIC website: oaic.gov.au