// LEGAL

Privacy Policy

Effective 3 October 2026 · Last reviewed 3 October 2026

Boers Systems Pty Ltd (ABN 62 700 224 399) ("Boers Systems", "we", "us", "our") builds reporting and analytics software for the property industry. This policy explains how we collect, hold, use and disclose personal information and other data in the course of operating our business. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and with the developer and platform policies of the third-party services our products connect to, including LinkedIn, Meta, Google, HubSpot and Salesforce.

Where this policy refers to "personal information" it means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. Where it refers to "data" it means any information we process, whether or not it is personal information.

Contents

  1. Who this policy covers
  2. What we collect
  3. Data from connected platforms
  4. How we use information
  5. Platform-specific commitments
  6. Who we share information with
  7. Where information is stored and processed
  8. Cookies, analytics and tracking
  9. How we protect information
  10. How long we keep information
  11. Your rights and choices
  12. Requesting deletion of your data
  13. Our role when processing data for clients
  14. Children
  15. Other jurisdictions
  16. Changes to this policy
  17. Contact

1. Who this policy covers

This policy applies to all of the websites, web applications, dashboards, integrations, application programming interfaces, data connectors, mobile or desktop software, demonstration environments, documentation, communications and other services that Boers Systems operates now or in the future (together, the "Services"). This includes, without limitation:

It applies to everyone whose information we handle, including visitors to our websites, prospective and current clients and their staff, users of our Services, people whose information our clients provide to us or authorise us to access, suppliers, partners, job applicants and anyone who contacts us.

2. What we collect

We collect information in several ways. The categories below are intended to be broad and are not exhaustive; we may collect other information of a similar kind where it is reasonably necessary for one or more of our functions or activities.

2.1 Information you give us

2.2 Information collected automatically

2.3 Information from third-party platforms you or our clients connect

Our Services exist to bring a client's marketing, sales and development data together in one place. When a client, or a person acting for a client, authorises us to connect a third-party platform, we collect the data that platform makes available under that authorisation. This is described in detail in section 3.

2.4 Information our clients give us about other people

Our clients may provide us with, or authorise us to access, information about their own customers, prospects, leads, enquirers, purchasers, tenants, agents, contractors and staff. Where we hold this information we do so as a service provider to the client. Section 13 explains how this works.

2.5 Information from other sources

2.6 Sensitive information

We do not seek to collect sensitive information (such as health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or biometric information). If sensitive information is contained in data a client provides or a platform returns, we handle it only as necessary to provide the Services and in accordance with this policy and the law.

3. Data from connected platforms

With the authorisation of the relevant account holder, our Services read data from third-party platforms through their official application programming interfaces, exports or feeds. The platforms we connect to, or may connect to in future, include:

The data returned by these platforms is mostly aggregate and relates to businesses, campaigns and content rather than to individuals. It can however include personal information, for example:

We collect only the permissions, scopes and fields reasonably required to provide the Services the client has asked for, and we describe them to the authorising user on the platform's own consent screen. Authorisation can be withdrawn at any time, as described in section 11.

4. How we use information

We use the information we collect for the following purposes, and for other purposes that you would reasonably expect or that are related to them:

We may combine information from different sources described in this policy where doing so is necessary for one of these purposes, including matching a platform's campaign names to a client's projects and estates and matching website page paths to the same.

5. Platform-specific commitments

In addition to the general commitments in this policy, we make the following commitments in respect of data obtained from particular platforms. Where a platform's developer terms impose a stricter requirement than this policy, the stricter requirement applies to data from that platform.

5.1 LinkedIn

Our use of data obtained through the LinkedIn Marketing API Program complies with the LinkedIn Marketing API Terms and LinkedIn's developer documentation. Data about a LinkedIn ad account or page is used only to provide reporting to the client that owns or administers that account or page and that authorised our access. We do not use one client's LinkedIn data for the benefit of another client, and we do not use LinkedIn data for advertising targeting, member profiling, recruitment, sale or resale. Where our Services receive personal information about LinkedIn members, we do not store it beyond what is required to display the client's own content and engagement to the client, and we delete it when the client disconnects LinkedIn or on LinkedIn's instruction.

5.2 Meta (Facebook and Instagram)

Our use of data obtained through Meta's Marketing API and Graph API complies with Meta's Platform Terms and Developer Policies. Data is used only to provide reporting to the client that owns the connected ad account, Facebook Page or Instagram account. We do not sell Meta platform data, do not use it to build or augment user profiles, and do not transfer it to any advertising network, data broker or other monetisation service. If you wish to delete data that our Services obtained from Meta in connection with your account, follow the instructions in section 12.

5.3 Google

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve user-facing features of the Services that are prominent to the user, is not transferred to third parties except as necessary to provide those features, to comply with law or as part of a merger or acquisition with notice, is not used for serving advertisements, and is not read by humans except with the user's affirmative agreement, for security purposes, to comply with law, or in aggregated and anonymised form for internal operations.

5.4 HubSpot, Salesforce and other CRM and email platforms

Data from a client's CRM or email platform is used only to report to that client on their own campaigns and contacts. We do not send email through these connections unless a client has engaged us to do so, and we do not use a client's contact lists for our own marketing.

5.5 Property portals

Data from property listing portals is used only for the exclusive benefit of the client to which it relates and is attributed to its source where the portal's terms require it. Where a portal's terms require data to be stored in a particular country, we store it there. Personal information about enquirers and leads is de-identified or omitted where the portal's terms require.

6. Who we share information with

We do not sell personal information. We may disclose information to:

Our service providers are bound by contract to handle information only for the purpose of providing their services to us and in a manner consistent with this policy.

7. Where information is stored and processed

We are based in Australia and store client reporting data in Australia by default. Some of our service providers and all of the connected platforms are located, or process data, in other countries, including the United States, the European Union, Singapore and other locations where those providers operate. Information may therefore be transferred to, stored in and accessed from countries other than Australia. Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles, or we rely on your consent or another lawful basis. Where a data source's terms require that its data remain in Australia, we comply with that requirement.

8. Cookies, analytics and tracking

Our websites and Services use cookies, browser storage and similar technologies to:

Analytics providers may set their own cookies and collect information about your use of our sites and other sites over time. You can control cookies through your browser settings and can opt out of Google Analytics using Google's browser add-on. Disabling cookies may limit the functionality of the Services. Our dashboards store view state in your browser's local storage; this information stays on your device and is not transmitted to us.

9. How we protect information

We take reasonable steps to protect the information we hold from misuse, interference, loss and from unauthorised access, modification or disclosure. These steps include encryption of data in transit, access controls and role-based permissions, credential and token storage separate from application code, logging and monitoring, secure development practices, and contractual obligations on our service providers. Platform credentials and access tokens are stored encrypted and are never published or committed to source code. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.

10. How long we keep information

We keep information for as long as it is needed for the purposes described in this policy, which generally means for the duration of our relationship with the relevant client or user and for a reasonable period afterwards to meet legal, accounting, reporting and dispute-resolution obligations. In particular:

When information is no longer needed we delete it or de-identify it. De-identified and aggregated information may be retained indefinitely.

11. Your rights and choices

You may:

We will respond to requests within a reasonable time, usually within 30 days. We may need to verify your identity before acting on a request. We will not charge for making a request but may charge a reasonable fee for providing access where permitted by law. If we refuse a request we will tell you why, unless it would be unreasonable to do so.

12. Requesting deletion of your data

You can ask us to delete data we hold about you, including data our Services obtained from LinkedIn, Meta, Google, HubSpot, Salesforce or any other connected platform, in any of the following ways:

  1. Email contact@boers.com.au with the subject line "Data deletion request", telling us which platform account, page or ad account the request relates to and the email address or profile associated with it.
  2. If you are a client user, ask your account administrator to disconnect the platform in the Services, which deletes the stored tokens and schedules the associated personal information for deletion.
  3. Remove our application from the platform's own settings. Where the platform notifies us of the removal we treat it as a deletion request.

We will confirm receipt, action the request within 30 days, and confirm when deletion is complete. Aggregate metrics that do not identify any individual may be retained. Where the data belongs to a client rather than to you personally, we may need to refer the request to that client, and we will tell you if we do.

13. Our role when processing data for clients

Much of the data in our Services belongs to our clients and is processed on their instructions. In those cases the client decides what is collected, how it is used and how long it is kept, and we act as the client's service provider (or "processor"). Requests about that data should be directed to the client in the first instance, and we will help the client respond. Our agreements with clients require them to have a lawful basis for the data they provide or authorise us to access, and to have given any notices and obtained any consents the law requires.

14. Children

Our Services are business tools and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

15. Other jurisdictions

If you are located in the European Economic Area, the United Kingdom or another jurisdiction with its own privacy law, you may have additional rights, including rights to object to or restrict processing, to data portability and to lodge a complaint with your local supervisory authority. Where those laws apply, our lawful bases for processing are performance of a contract, our legitimate interests in operating and improving our business, compliance with legal obligations and, where we rely on it, your consent. You may exercise any of these rights by contacting us.

16. Changes to this policy

We may update this policy from time to time to reflect changes in our Services, the platforms we connect to, our practices or the law. The current version is always published at this address with its effective date. Where a change is material we will take reasonable steps to bring it to your attention, such as a notice in the Services or an email to account holders. Continued use of the Services after a change takes effect indicates acceptance of the updated policy.

17. Contact

Questions and requests about privacy can be sent to:

Boers Systems Pty Ltd
ABN 62 700 224 399 · ACN 700 224 399
Attention: Privacy Officer
Email: contact@boers.com.au

© 2026 Boers Systems Pty Ltd. Boers Systems and the Boers Systems logo are trademarks of Boers Systems Pty Ltd. LinkedIn is a trademark of LinkedIn Corporation. Facebook, Instagram and Meta are trademarks of Meta Platforms, Inc. Google, Google Ads and Google Analytics are trademarks of Google LLC. HubSpot is a trademark of HubSpot, Inc. Salesforce is a trademark of Salesforce, Inc. Use of these names does not imply endorsement.