Privacy Policy
Last updated: 1 August 2026
This Privacy Policy explains how Apsis ("Apsis", "we", "us") collects, uses, discloses, and protects personal information when you visit this website or use the Apsis application (together, the "Service"). We handle personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles ("APPs").
The Privacy Act currently exempts many businesses with an annual turnover of $3 million or less. We do not rely on that exemption. We comply with the Australian Privacy Principles as though they applied to us in full, and we treat the commitments in this policy as binding regardless of whether the exemption is later removed.
Apsis is a business-management tool. That means we hold two quite different kinds of information: information about you, our customer, and information you enter aboutyour clients. This policy covers both, and section 3 explains the distinction, because it changes who is responsible for what.
1. Information we collect
We collect the following categories of personal information:
- Account information - your name, email address, password (stored only as a salted hash, never in readable form), and, if you enable two-factor authentication, an encrypted authenticator secret.
- Business details - your business or trading name, ABN, address, contact details, logo, and tax settings. Where you use the ABN lookup feature, we query the Australian Business Register to retrieve publicly available details for the ABN you enter.
- Content you create - clients, quotes, invoices, expenses, receipts, tasks, timesheets, calendar entries, and the documents generated from them. This content frequently contains personal information about third parties, such as your clients' names and contact details.
- Billing information - your subscription plan, billing status, and payment history. Card numbers are collected and stored by Stripe, our payment processor. Apsis never receives or stores full card numbers.
- Support correspondence - the name, email address, and message you submit through our contact form, along with the IP address and browser user agent of the submission, which we retain to detect and block abuse of that form.
- Technical and usage data - server logs (including IP address, request path, and timestamp) kept for security and diagnostics; aggregate, non-identifying analytics about how the marketing site is used; and, only if you accept the cookie banner, session-replay analytics recording how you move through and interact with pages (see section 5).
2. How we use information
We use personal information only for the following purposes:
- to provide, operate, maintain, and improve the Service;
- to authenticate you and keep your account secure;
- to process payments, manage subscriptions, and administer the referral programme;
- to send you service communications - invoice and quote notifications, reminders about documents you have issued, security alerts, and changes to these terms;
- to respond to your support requests;
- to detect, investigate, and prevent fraud, abuse, and security incidents;
- to comply with our legal and record-keeping obligations.
We do not use the content you create - your clients, invoices, expenses, or documents - to build advertising profiles, and we do not sell personal information to anyone.
3. Information about your clients
When you enter details about your own clients, you remain responsible for that information: you decide what to collect, you are the party with the relationship to those individuals, and any privacy obligations you owe them remain yours. Apsis holds and processes that information on your behalf and under your instructions, in order to provide the Service to you. We do not contact your clients for our own purposes, and we do not use their details for marketing.
Some features send email directly to your clients on your instruction - for example, issuing an invoice or a payment reminder. Those messages are sent because you asked us to send them.
4. Artificial intelligence features
Some optional features use a third-party AI model to draft text for you, such as generating a description for a quote. These features run only when you explicitly invoke them. When you do, the text needed to produce that draft - which may include business and client details from the record you are working on - is sent to our AI provider for processing and returned as a suggestion for you to accept, edit, or discard. We do not enable these features in the background, and your content is not used to train third-party models.
We do not use automated decision-making. No decision that could significantly affect your rights or interests - including whether you may hold an account, what you are charged, or whether access is suspended - is made by a computer program without a person deciding it. The AI features described above draft text for you to review; they do not decide anything. If this ever changes, we will set out here the kinds of personal information involved and the kinds of decisions made, as required by the transparency obligations commencing 10 December 2026.
5. Cookies, analytics and similar technologies
The Apsis application uses cookies that are strictly necessary to operate it - principally to keep you signed in and to protect against cross-site request forgery. These cannot be disabled without breaking the Service.
This marketing website uses Plausible, a privacy-friendly, self-hosted analytics tool that measures aggregate traffic. It sets no cookies, stores no personal identifiers, and does not track visitors across other websites. Web fonts are self-hosted, so no font request leaves this website to a third party.
This marketing website also offers Microsoft Clarity, which records session replays - how you move through and interact with pages - so we can find and fix usability problems. Clarity sets its own cookies and sends what it records to Microsoft in the United States. It only runs if you accept the cookie banner shown on your first visit; you can change your decision at any time using "Cookie preferences" in the site footer.
6. Who we share information with
We disclose personal information only to the service providers that help us operate the Service, and only to the extent they need it to perform their function:
- Stripe - Subscription billing and card payments. Card details are entered directly with Stripe and are never stored by Apsis.
- Google (Gemini API) - Powers the optional AI drafting features. Only the text needed to generate a draft is sent, and only when you invoke an AI feature.
- Cloudflare - Turnstile bot protection on public forms. Sees the request metadata needed to score whether a submission is automated, including your IP address, for contact form submissions.
- Microsoft (Clarity) - Session-replay analytics on the marketing website. Only runs if you accept the cookie banner. Records how you move through and interact with pages, and sends that data to Microsoft in the United States.
- Amazon Web Services - File and document storage. Stores logos, attachments, and generated PDF documents.
We may also disclose personal information where we are required or authorised to do so by law, to enforce our Terms of Service, or to protect the rights and safety of our users or the public. If Apsis is ever involved in a merger, acquisition, or sale of assets, personal information may be transferred as part of that transaction; we will notify you before your information becomes subject to a materially different privacy policy.
7. Overseas disclosure
Customer data is stored in Australia. Some of the service providers listed above operate infrastructure or support functions outside Australia, principally in the United States and the European Union. Before disclosing personal information to an overseas recipient we take reasonable steps, as required by APP 8, to ensure it is handled consistently with the Australian Privacy Principles.
For visitors in the European Union and United Kingdom, transfers of personal information to the United States rely on the recipient's certification under the EU-U.S. Data Privacy Framework and its UK Extension, which the European Commission and UK Government recognise as providing an adequate level of protection. Stripe, Cloudflare, Microsoft, Amazon Web Services, and Google are each certified under this framework.
8. Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These include encryption of traffic in transit, hashing of passwords, encryption of two-factor authentication secrets at rest, strict separation of data between customer accounts, role-based access controls, rate limiting on sensitive endpoints, and regular backups.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, following our documented breach response process.
9. How long we keep information
We retain the content in your account for as long as your account remains active. When you close your account:
- Account content - your clients, quotes, invoices, expenses, and documents remain available for export for 30 days, and are then deleted or de-identified within a further 90 days.
- Billing and transaction records - retained for 7 years, to meet our own financial record-keeping obligations under the Corporations Act 2001 (Cth) and taxation law. This is a legal obligation we cannot waive at your request.
- Support correspondence - retained for 2 years, then deleted.
- Server and security logs - retained for 12 months.
- Backups - retained on a rolling basis and overwritten in the ordinary course, so deleted data may persist in backups for a short period after deletion from the live system.
Separately, you have your own record-keeping obligations: the ATO generally requires business records to be kept for five years. Export anything you need before closing your account, because the retention periods above are ours, not a substitute for your own records.
10. Your rights
Under the Australian Privacy Principles you may:
- request access to the personal information we hold about you;
- ask us to correct information that is inaccurate, out of date, or incomplete;
- request deletion of your personal information, subject to our legal retention obligations;
- export the content in your account in a portable format;
- opt out of non-essential communications at any time, using the unsubscribe link or your notification settings.
Much of this can be done directly in the application. For anything else, contact us atsupport@apsis.com.au and we will respond within 30 days. We do not charge for access requests, and if we refuse one we will tell you why in writing.
11. Marketing and email
Most email we send you is service email - an invoice notification, a payment reminder, a security alert, or a change to these terms. These relate directly to your account and to documents you have chosen to issue, and you cannot opt out of them while your account is open, because they are part of the Service.
We send marketing email only where you have consented to it, and every marketing message includes a working unsubscribe link that we honour promptly, consistent with the Spam Act 2003 (Cth). We do not use your information for third-party marketing, and we do not provide your contact details to anyone else for marketing purposes. You may ask us at any time to stop using your personal information for direct marketing, or to tell you where we obtained it.
Where the Service sends email to your clients on your instruction - issuing an invoice, sending a reminder - you are the sender for practical purposes, and you are responsible for having a proper basis to contact them. See clause 6 of theTerms of Service.
12. Children
The Service is intended for use by businesses and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
13. Complaints
If you believe we have breached the Australian Privacy Principles, contact us first atsupport@apsis.com.au. We will investigate and respond in writing, normally within 30 days. If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner atoaic.gov.au.
14. Changes to this policy
We may update this Privacy Policy from time to time. The "last updated" date at the top of this page always reflects the current version. Where a change materially affects how we handle your personal information, we will notify you through the Service or by email before it takes effect.
15. Contact us
For any privacy question, request, or complaint, contact us atsupport@apsis.com.au, or use ourcontact form.
Apsis.