Legal

Privacy Policy

Last updated 21 July 2026

This Privacy Policy explains how [ENTITY NAME] (ABN [ABN]) (AskFrankie, we, us) collects, holds, uses, and discloses personal information in connection with the AskFrankie platform and the askfrankie.com.au website (the Service).

We are committed to complying with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This policy is structured around the APPs.

1. Who we are and the two roles we play

AskFrankie is an AI operations platform for Australian real-estate agencies. It’s important to understand that we handle personal information in two different capacities:

  1. Information about our customers and website visitors (agency principals, staff accounts, billing contacts, enquiries). For this information we decide how and why it is collected — we are the primary handler.
  2. Information inside a customer agency’s instance (their vendors, buyers, prospects, property records, emails, transcripts). This information is collected by the agency, which controls it. We handle it on the agency’s behalf, under their instructions and our agreement with them, solely to provide the Service. The agency remains responsible for its own Privacy Act obligations to its clients, including collection notices and consents. If you are a vendor, buyer, or prospect of an agency that uses AskFrankie, your first point of contact about your personal information should generally be that agency — but you can also contact us (see section 12) and we will help.

2. What personal information we collect (APPs 3–5)

From our customers and website visitors:

  • name, role, agency name, business contact details;
  • account credentials (passwords are stored hashed, never in plain text);
  • billing and subscription details;
  • support requests and correspondence;
  • technical logs (IP address, browser/device information, usage events) for security and troubleshooting.

Within a customer agency’s instance (held on the agency’s behalf):

  • contact records for vendors, buyers, and prospects (names, phone numbers, emails, addresses, notes);
  • property, listing, and appraisal records;
  • tasks, reminders, and internal notes;
  • staff account details for the agency’s team;
  • emails, if the agency connects Microsoft Outlook;
  • voice recordings and transcripts, if the agency uses voice features;
  • data synced from the agency’s CRM (for example Rex Software), if the agency connects it.

We do not seek to collect sensitive information (such as health information or racial or ethnic origin). Agencies should not enter sensitive information into free-text fields unless they have a lawful basis to hold it.

We collect information directly from you, from your agency (if it creates an account for you), and from integrations the agency chooses to connect. You can browse our website without identifying yourself; anonymity is generally not practicable for using the platform itself, because accounts are tied to an agency.

3. Why we collect and use it (APP 6)

We collect, hold, and use personal information to:

  • provide, operate, secure, and support the Service;
  • power AI features (see section 4);
  • run integrations the agency has connected (CRM sync, email, voice);
  • manage accounts, billing, and communications with customers;
  • monitor performance, debug faults, and improve the Service;
  • comply with our legal obligations.

We do not sell personal information. We do not use the contents of a customer agency’s instance to train our own AI models or third-party foundation models, and our agreements with LLM providers are selected on the basis that customer content is not used for provider model training.

We only send marketing communications about AskFrankie to business contacts who would reasonably expect them, and every marketing email includes an unsubscribe option (consistent with the Spam Act 2003 (Cth)).

4. AI and large language model processing

The Frankie assistant processes data in an agency’s instance using large language models (LLMs) operated by third-party providers. In practical terms:

  • when a staff member asks Frankie something, relevant snippets of agency data (for example a contact record, listing details, or an email thread) may be sent to an LLM provider to generate the response;
  • voice features, if enabled, send audio to a speech-to-text provider (Deepgram) for transcription;
  • embedding (search-index) computations run on infrastructure we control in the European Union.

LLM providers may include Ollama Cloud, DeepSeek, OpenAI, Anthropic, or xAI depending on configuration; the current list for each deployment is maintained in the subprocessor annexure to our customer agreement. Data is sent to these providers only to generate the requested output, not for their own purposes.

AI outputs can be inaccurate. Agencies are responsible for reviewing outputs before acting on them.

5. Per-tenant isolation and where data is held

Each customer agency has its own isolated database instance — a single-tenant deployment. One agency’s data is never stored in the same database as another agency’s, which materially reduces the risk of cross-customer data exposure.

Data is hosted with the infrastructure providers listed in section 6.

6. Overseas disclosure (APP 8)

Because we use international cloud infrastructure, personal information handled by the Service is disclosed to (stored or processed by) providers located overseas. The countries are:

ProviderFunctionLocation
ConvexDatabase hosting (each agency’s isolated instance)United States
VercelWeb application hostingUnited States
ResendTransactional email deliveryUnited States
LLM providers (per deployment configuration — e.g. Ollama Cloud, DeepSeek, OpenAI, Anthropic, xAI)AI text generationUnited States and/or other jurisdictions depending on provider (DeepSeek may process data in the People’s Republic of China)
DeepgramVoice transcription (only if voice features are enabled)United States
OVH (self-managed virtual server)Embeddings computation and document renderingEuropean Union (France/EU region)

Before disclosing personal information overseas, we take reasonable steps to ensure recipients handle it consistently with the APPs, including contractual protections, and we select providers with appropriate security practices. By using the Service, customer agencies authorise these disclosures for the purpose of providing the Service.

7. Security (APP 11)

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure, including:

  • single-tenant database isolation per agency;
  • encryption of data in transit (TLS) and encryption at rest on our hosting providers;
  • role-based access within each agency’s instance (agents see their own records; administrators see agency-wide records);
  • credentialed, least-privilege access to production systems, limited to the personnel who operate the Service;
  • storage of integration credentials (e.g. CRM tokens) in protected configuration, not in application code;
  • logging and monitoring of system faults and anomalies.

No system is perfectly secure, but we treat security as a core product requirement, not an afterthought.

8. Retention and deletion

  • We keep personal information only as long as needed for the purposes above or as required by law.
  • When a customer agency’s subscription ends, the agency has a 30-day window to export its data, after which we delete the instance’s data from production systems. Residual copies in backups are deleted as backups age out on our standard cycle.
  • Technical logs are retained for a limited period for security and debugging, then deleted or de-identified.

9. Data breaches

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act. If a data breach occurs that is likely to result in serious harm to individuals, we will:

  • act promptly to contain and assess the breach;
  • notify affected customer agencies without undue delay so they can meet their own obligations; and
  • notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where the Privacy Act requires it.

10. Access and correction (APPs 12–13)

You may request access to, or correction of, the personal information we hold about you. We will respond within a reasonable period (usually 30 days). We do not charge for making a request and will only charge reasonable costs, if any, for giving access.

If the information relates to a customer agency’s instance (for example, you are a vendor or buyer whose details an agency holds in AskFrankie), we may refer your request to that agency, since the information is theirs to control — but we will assist them to action it.

If we refuse a request, we will tell you why in writing and how you can complain.

11. Cookies and website analytics

The askfrankie.com.au website uses only the cookies necessary for the site and product to function (such as login sessions). If we later add analytics cookies, we will update this policy first.

12. Complaints and contact

If you have a question or complaint about how we have handled your personal information:

  1. Contact us at [privacy@askfrankie.com.au] (or by mail to [ENTITY NAME], [address], Victoria, Australia). Please include enough detail for us to investigate.
  2. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
  3. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au | 1300 363 992 | GPO Box 5288, Sydney NSW 2001.

13. Changes to this policy

We may update this policy from time to time. The current version will always be available at askfrankie.com.au, with the “last updated” date shown at the top. Material changes will be notified to customer agencies by email or in-app notice.