Privacy Policy
Last updated: 30 September 2026
1. Who we are and how this policy applies
DraftFlow Software, ABN 60 693 461 610 (DraftFlow, we, us) operates the DraftFlow website, application and related services (Services). This policy explains how we handle personal information.
DraftFlow is currently a small business. The Privacy Act 1988 (Cth) and every Australian Privacy Principle (APP) may not apply to every activity of every small business. We nevertheless use the APPs as our privacy standard where practicable and comply with privacy laws that apply to us. This policy is a notice about our current practices and does not create rights beyond applicable law or an agreed contract.
2. Personal information we collect
Information you or your organisation provide
- Account details such as name, business email, company, role, phone number where provided, and a hashed password.
- Workspace content such as projects, job numbers, drawing registers, RFIs, QA and ITP records, notes, comments and files.
- Sign-off evidence such as signer name, signature image or mark, acknowledgement, timestamp and related workflow record.
- Device location (latitude and longitude) attached to an inspection or ITP evidence record, only when you choose to capture it and your device permission allows it. It is stored with that record, visible to users who can access the project, and kept for as long as the evidence record is kept.
- Billing contact, billing address, subscription and invoice information. Stripe processes card details for web subscriptions and Google Play processes payment for subscriptions bought in the Android app; DraftFlow does not receive full card numbers. For a Google Play subscription we keep the order identifier, product, subscription state and expiry, the user who bought it, and a one-way hash of the purchase token.
- Support enquiries, feedback and other correspondence.
Information collected through use
- Account, audit and workflow events, including actions, timestamps and identifiers used for security and traceability.
- Device and connection information, including IP address, browser, operating system, URLs and request logs.
- Diagnostic events, which may include error details, page or route, device context, user identifier and email address.
- Cookies and browser storage for sign-in, security, preferences and consent choices.
- On the website only, Google Analytics page, device, approximate location and interaction data after analytics consent is given. Google Analytics does not run in the DraftFlow Android or iOS apps.
- Product usage events inside the signed-in application, only after analytics consent is given: which screens and features are opened, and whether actions succeed or fail, recorded against your user and company. These are stored in our own database, never sent to a third party, and hold no free text, names or document content.
Information from providers
We receive subscription and payment status from Stripe and, for subscriptions bought in the Android app, from Google Play (status updates are delivered through Google Cloud Pub/Sub), email delivery and suppression events from Resend, and diagnostic or service events from providers used to operate the Services.
3. Why we collect and use it
- Provide, administer, secure and support the Services.
- Authenticate users, enforce permissions and maintain tenant-separated business workspaces.
- Process subscriptions, payments, invoices and account changes.
- Send operational, workflow, security, billing and support communications.
- Diagnose faults, prevent abuse and improve the Services.
- Send marketing only where we have recorded a lawful basis or consent and provide a working unsubscribe method.
- Meet legal obligations and respond to lawful requests.
We do not sell or rent personal information and do not use Customer workspace content for advertising.
4. Collection from organisations and third parties
A Customer administrator or colleague may create your account, invite you, assign work or enter information about you. External signers may receive a link from a Customer. Where a Customer provides personal information, that Customer is responsible for having authority to provide it and giving any notice required by law. If we cannot collect information required for an account, subscription or workflow, we may be unable to provide that part of the Services.
5. When we disclose information
We disclose personal information to service providers only as reasonably needed for their function. Our Service Providers page names the current providers, purposes, data and locations. Provider terms and assurances differ; the register states known limitations rather than promising that every provider has a separately negotiated data-processing agreement.
We may also disclose information where reasonably necessary to comply with law or a binding legal process, enforce our terms, investigate fraud or abuse, protect people or property, or complete a sale or restructure of the relevant business. Where practicable, we will require a recipient in a business transfer to protect the information and give affected customers notice of a material change.
6. Storage and overseas processing
DraftFlow is based in Brisbane, Australia. Its selected Railway application, database and cache workload region is Singapore, while Railway states that its primary processing operations occur in the United States. Uploaded files use AWS S3 object storage configured for Sydney, Australia. A company logo and drawn or typed signature images are kept in the database instead. Vercel delivers the frontend through a global network and identifies the United States as its primary processing location. The Sentry organisation is configured for EU data storage in Germany, with other processing possible under Sentry's terms. Resend's primary processing occurs in the United States. Google Play subscription billing uses global Google infrastructure, including the United States. Stripe uses a global payment network, including processing in the United States and other countries. Google Analytics uses regional collection and global processing infrastructure. Provider support, security, resilience, corporate and subprocessor functions may occur in additional countries under the applicable terms.
DraftFlow's optional AI features are switched off, so no information is sent to an AI provider. If we switch them on, the files and text a user sends to an AI feature, and the response, are processed by Anthropic, either through Anthropic's API outside Australia, including in the United States, or through AWS Bedrock in the configured region. Our Australian AI setting accepts only AWS Bedrock in Sydney or Melbourne. Before these features are switched on, we will update the Service Providers page to name the provider and region in use.
Where APP 8 or another transfer rule applies, we take reasonable steps appropriate to the information and recipient. These may include reviewing provider terms and public assurance material, minimising data sent, limiting access, and using encryption in transit and managed storage protections. Overseas laws and provider arrangements may differ from those in Australia.
7. Security
We use measures appropriate to our size and the information we handle, including transport encryption, managed encryption at rest, one-way password hashing, role-based permissions, authenticated tenant-scoped queries, audit logging, optional user multi-factor authentication and monitoring. No internet service is completely secure. Report a suspected account or security incident to admin@draftflow.org.
8. Retention and deletion
We keep personal information for as long as reasonably needed to provide and secure the Services, administer the Customer relationship, resolve disputes and meet legal obligations. Retention varies by record and may be affected by active accounts, legal holds, backups and provider deletion cycles.
- Account and workspace records are generally retained while the Customer account is active and for a reasonable administration, recovery and deletion period afterwards.
- Application audit logs are normally configured for 18 months, unless an active configuration or written customer agreement sets another period.
- File access records, which note the user, time, IP address and browser when certain uploaded files, such as drawings, certificates and site photos, are opened or downloaded, are normally kept for 18 months and then deleted.
- An email that cannot be delivered on the first attempt is held in a retry queue with its recipient, subject and content. Once it has been delivered or has finally failed, it is normally deleted after 90 days.
- While a legal hold applies, for example during a security incident investigation or a legal claim, we suspend these scheduled deletions until the hold is released.
- Support and security records are kept as reasonably needed to document and resolve the matter.
- Australian business and tax records are generally retained for the period required by law, commonly five years measured from the later relevant event.
- Marketing suppression records may be retained so we continue to honour an unsubscribe request.
When information is no longer reasonably required, we delete or de-identify it where practicable, subject to legal and operational constraints.
9. Access, correction, account deletion and export requests
You may ask to access or correct personal information we hold about you. You may also request deletion of your DraftFlow account and associated personal information, or an available export. We will verify identity and authority, explain any data that must be retained for legal, security, backup or dispute purposes, and confirm when the request has been completed. Limits may apply where a Customer controls the workspace or another person's rights are affected.
Delete your account in DraftFlow. Signed-in users can delete their own account on the website or in the app from the account menu, under Delete account, after confirming their password. Deletion takes effect immediately. You are signed out on every device, and we remove from your account your name, email address, phone number, job title, preferences, personal notes and to-dos, multi-factor authentication settings, remembered devices and sessions, and copies of emails to you about your account or organisation that are held in our email retry queue. API keys you created are switched off. If you were the company's account owner, ownership passes to another Drafting Manager.
What your organisation keeps. Projects, RFIs, inspections, time entries, comments and files you took part in belong to your organisation and stay in its workspace, shown as “Deleted user”. Text you wrote and files you uploaded may still contain your name. Electronic sign-off records keep the signer name, email address, signature image, time and IP address, because they are evidence your organisation relies on. Share links you created for your organisation keep working until your organisation revokes them. Earlier security audit entries, file access records and error reports are kept for their stated periods and then deleted, and backups and provider deletion cycles may hold copies for a limited time.
Deleting your DraftFlow account does not cancel a Google Play subscription. Cancel it in Google Play under Payments and subscriptions.
Closing a company account. If you are your company's only Drafting Manager, make another user a Drafting Manager first, or request closure of the whole company account from the Delete account screen. We confirm the request by email when we receive it.
If you cannot sign in, email admin@draftflow.org from your DraftFlow account email address with the subject “DraftFlow account deletion request.” We verify the request and confirm when it is complete.
Closure is carried out by us, not by an automated purge. We aim to disable the workspace and remove its content within 30 days of a confirmed request. Some copies remain after that: provider backups expire on their own cycle, sign-off evidence another party relies on is retained as described above, and records we must keep by law are kept for their stated periods. We do not claim that every copy of every file is erased on day 30. If you need deletion by a fixed date, or written confirmation of what was deleted, email admin@draftflow.org and we will agree it in writing before you rely on it.
10. Cookies and analytics choices
Necessary cookies and browser storage support authentication, security, routing and consent records. Functional storage may remember interface preferences. On the website, Google Analytics is optional and is loaded only after you allow analytics through the cookie controls; it does not run in the DraftFlow apps. You can decline or change that choice without losing necessary account functions. Browser settings can also block storage, but blocking necessary storage may prevent sign-in or other functions.
11. Marketing and automated decisions
DraftFlow does not currently operate a general marketing-email campaign. Before doing so, we must record the consent or other lawful basis relied on, identify the sender and provide a working unsubscribe method. We may still send operational messages needed for an account or service. DraftFlow does not currently use personal information in a computer program to make a decision that significantly affects a person's rights or interests without meaningful human involvement. We will update this policy if that practice changes.
12. Children
The Services are for business users aged 18 or older and are not directed to children. Contact us if you believe a child has provided personal information so we can investigate and take appropriate action.
13. Data incidents and the NDB scheme
We maintain a process to contain, investigate and respond to data incidents. Where the Notifiable Data Breaches scheme applies, we will carry out a reasonable and expeditious assessment, taking reasonable steps to complete it within the statutory assessment period. If an eligible data breach is established, we will prepare the required statement, notify the OAIC and take reasonable steps to notify affected individuals as soon as practicable.
14. Complaints
Send a privacy complaint to admin@draftflow.org with enough detail for us to investigate. We aim to acknowledge complaints promptly and provide a substantive response within a reasonable period. If the Privacy Act applies to the matter and you are not satisfied, you may contact the Office of the Australian Information Commissioner.
15. Changes to this policy
We may update this policy as our practices, providers or legal obligations change. We will update the date above and give direct notice to active customers where a change is material or notice is required by law.
16. Contact
Privacy contact
DraftFlow Software
ABN 60 693 461 610
Brisbane, Queensland, Australia
Email: admin@draftflow.org