Privacy Policy
Last updated June 2026
This policy describes how DM360 collects, uses and protects information when you use our platform. It is our current baseline; for project- or contract-specific data-processing terms, contact us.
Information we collect
Account information you provide (name, email, organisation and role); project and delivery data you and your collaborators enter; and technical usage data needed to operate and secure the service (such as log and device information).
How we use it
To provide and improve the platform, authenticate users, enforce access controls between organisations, support you, and meet legal obligations. We do not sell your personal information or your project data.
Storage and access
Data is stored with reputable cloud infrastructure providers and is logically separated by organisation. Access is restricted to authorised users and to our personnel who need it to operate the service.
Sharing
Project data is visible only to the parties you grant access to (for example, a lender or consultant you invite). We use a limited set of service providers (for example, hosting and payment processing) under confidentiality obligations.
AI processing
Some features use artificial intelligence to process content you or your counterparties provide — for example summarising and filing emails sent to a project address, extracting details from uploaded invoices, and drafting meeting minutes from transcripts. This content is processed by our AI service provider under commercial terms that prohibit it from training on your data. AI outputs are suggestions: a person in your organisation reviews and approves them before they affect records of account.
Aggregated benchmarks
Where an organisation opts in, we derive anonymised, aggregated statistics (such as cost rates per square metre) across projects to power benchmarking features. These aggregates do not identify any person, organisation, project or counterparty.
Overseas disclosure
Our infrastructure and service providers (including hosting, database, email and AI providers) may store or process data in countries outside Australia, including the United States, under contractual safeguards. We take reasonable steps consistent with the Australian Privacy Principles when personal information is handled overseas.
Retention and breach response
We retain data while your subscription is active and for a limited export window after it ends, then delete or de-identify it unless the law requires longer retention. If a data breach involving personal information is likely to result in serious harm, we will notify affected users and the OAIC in line with the Notifiable Data Breaches scheme.
Your rights
You may request access to, correction of, or deletion of your personal information, subject to legal and contractual retention requirements. Australian users are covered by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Contact
Privacy questions: support@dm360.com.au.