1.1 Rev-Raise Group Pty Ltd (ABN 45 691 400 594) handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We apply the APPs to everything we do, and we hold ourselves to them whether or not the small business exemption in section 6D applies to us in a given year. Section 5.6 explains that position.
1.2 This policy explains what we collect, why, who we share it with, and what you can do about it.
1.3 We handle personal information in two different roles, and the obligations are different in each. Section 3 explains both.
About you, when you deal with us directly:
About your customers, when we operate systems for you: whatever your systems collect. That is your data and section 3.2 explains how we treat it.
We do not intentionally collect sensitive information, as defined in the Privacy Act, for our own marketing or general business operations, and we ask you not to send it to us. A system we operate for a client may process sensitive information only where that is expressly agreed in writing with the client and subject to the additional privacy and security requirements in Schedule J.
You are a visitor, an enquirer, a course member, an event attendee or a client. We decide what to collect and why, and this policy governs it.
Where we build and run systems for a client, those systems hold that client's customers' personal information.
If you are a customer of one of our clients and you want your information accessed, corrected or deleted, contact that business. They control it. We will help them action your request.
The full terms on which we handle a client's data are published at rev-raise.com/terms-data, Schedule J.
This section exists because we use AI in how we work, and you are entitled to know what that means.
We use artificial intelligence and automation tools to:
Name, email address, phone number, business name and business information, the answers you give in forms, scorecards and applications, and the content of your communications with us.
Automated tools may make, or do something substantially and directly related to making, the following decisions:
A person reviews every application before anyone is declined. No decision to decline to work with someone is made by a computer alone.
Australian Privacy Principles 1.7 to 1.9, which require covered entities to disclose automated decision-making in their privacy policy, commence on 10 December 2026. They are not yet in force.
We have written this section to that standard now rather than waiting for the date, because we think you are entitled to know how automated tools are used in decisions about you regardless of what the commencement table says.
Rev-Raise may fall below the $3 million small business threshold in section 6D of the Privacy Act in a given year. We apply the Australian Privacy Principles regardless. We do that because our clients are covered entities, because some of them are health service providers who are covered at any size, and because it is the right way to handle other people's information.
6.1 We record training sessions, review sessions and some client calls, for delivery, quality, internal reference and to develop our materials.
6.2 Everyone in the room is told beforehand and asked to consent at the start, on the recording. Our clients circulate a written notice we provide before the session, within the period their employees are entitled to under the law of their state and at least one business day before. Anyone who does not want to be recorded can say so: they remain outside the recording area and the recording is paused before they speak.
6.2A We ask for consent rather than just giving notice because recording law differs by state. In Queensland, section 45 of the Invasion of Privacy Act 1971 makes it a separate offence to communicate or publish a conversation you lawfully recorded, unless an exception applies, and consent of all parties is that exception. In New South Wales, consent is needed at the point of recording where the purpose is to share it.
6.3 We do not record a conversation with a client's own customer unless that customer has consented and the client has confirmed it to us in writing.
6.4 Recordings are stored on secure cloud infrastructure, are used internally, and are not published externally without written consent.
6.5 Retention is in section 10.
8.1 We use third-party providers in the following categories:
| Category | What they do | Where they process |
|---|---|---|
| Cloud hosting and infrastructure | Store data and run our systems | Australia, United States |
| CRM and marketing automation | Run our own and our clients' systems | United States |
| Email and SMS delivery | Send messages | Australia, United States |
| Payment processing | Take payments (Stripe) | United States, Australia |
| AI and automation tools | The uses in section 5 | United States |
| Analytics and performance monitoring | Understand site usage | United States |
| Video and course hosting | Host courses and communities | United States |
| Accounting and bookkeeping | Run the business | Australia |
8.2 A current list of named providers is available on request. Clients can request it at any time and we will provide it within 10 business days.
8.3 All providers are subject to confidentiality obligations.
8.4 Overseas disclosure. Some providers are located outside Australia, principally in the United States. We take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, including through contractual commitments, and we remain accountable for that information under APP 8 unless an exception in the Privacy Act applies. We do not ask you to waive that accountability.
8.5 We do not sell personal information.
8.6 We may disclose information where required by law, to enforce our terms, or to protect the rights and safety of any person.
9.1 Data is stored on secure cloud infrastructure with access controls, encryption in transit, and multi-factor authentication on administrative accounts.
9.2 Access is limited to people who need it for their role.
9.3 Data breaches. We will assess any suspected eligible data breach and notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme.
9.4 Where a breach involves personal information held in systems we operate for a client, we will notify that client without undue delay and within 72 hours of becoming aware, so that they can meet their own obligations.
| What | How long |
|---|---|
| Enquiry and prospect data, where you never became a client | 24 months from last contact |
| Free course and community accounts | While active, then 12 months after last login |
| Client records and engagement documents | 7 years after the engagement ends |
| Financial and tax records | 7 years, as required by law |
| Session and call recordings | 24 months, unless the client asks us to keep them longer |
| Recordings of a client's own customer | 90 days, unless the client asks otherwise |
| Client customer data in systems we operate | Returned and deleted under Schedule B clause 12. 90 days after access ends |
| Website analytics | 26 months |
When information is no longer required we securely delete or de-identify it.
11.1 You may:
11.2 Email [email protected]. We will respond within 30 days.
11.3 There is no charge for making a request. We may charge a reasonable cost for providing access where the request is substantial, and we will tell you before we do.
12.1 We send marketing only where you have opted in, or where consent can reasonably be inferred from the relationship, your role, the nature of our prior dealings and the relevance of the message, such that you would reasonably expect to receive it. A one-off enquiry or purchase does not by itself establish ongoing marketing consent. We keep separate records of service messages, requested downloads, sales follow-up, ongoing marketing and telephone marketing consent.
12.2 Every message has an unsubscribe link and we honour it within 5 business days, as required by the Spam Act 2003 (Cth).
12.3 You can also unsubscribe by emailing [email protected].
12.4 Consent to receive marketing is separate from engaging our services. Declining marketing does not affect any service you buy from us.
See our Cookie and Tracking Policy at rev-raise.com/cookies.
Our website, courses, events and services are not directed at anyone under 18 and we do not knowingly collect personal information from anyone under 18. If you believe we have, contact us and we will delete it.
Our website links to third-party sites and uses third-party platforms for courses, communities and video. This policy does not apply to them. Their own policies do.
If we merge, are acquired, or sell assets, personal information we hold may transfer as part of that transaction. We will take reasonable steps to ensure any transferee handles it consistently with this policy.
17.1 Contact us first at [email protected]. We will acknowledge within 5 business days and respond within 30 days.
17.2 If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
We may update this policy. The current version is always at rev-raise.com/privacy, with the date it was last updated at the top. Where a change is material and affects current clients, we will tell them.
Privacy enquiries: [email protected]
Rev-Raise Group Pty Ltd ABN 45 691 400 594 Brisbane, QLD, Australia
© 2026 Rev-Raise Group Pty Ltd (ABN 45 691 400 594). All rights reserved.