Appearance
Privacy Policy
DRAFT — FOR LEGAL REVIEW. This document has not been reviewed by a lawyer and does not constitute legal advice. All [PLACEHOLDER] markers must be replaced before publication.
Effective date: [PLACEHOLDER — date] Version: 1.0
[PLACEHOLDER — entity name] Pty Ltd ("Frankfig", "we", "us") operates the Frankfig secure messaging and document-signing platform ("Service"). This Privacy Policy describes how we collect, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who this policy applies to
This policy applies to all users of the Service, including:
- Organisation administrators and team members who hold a Frankfig account;
- Guest counterparties who access a thread or sign a document via a guest link;
- Visitors to our help site and marketing site.
2. What personal information we collect
We collect personal information that is necessary to provide the Service:
| Category | Examples |
|---|---|
| Identity & contact | Full name, email address, phone number |
| Account credentials | Password hash (Argon2); TOTP secrets for MFA |
| Organisation details | Organisation name, industry, subscription tier |
| Professional credentials | Licence numbers, credential verification records (where applicable) |
| Communications content | Messages, documents, signing envelopes, and attachments transmitted through the Service |
| Usage and technical data | IP addresses, browser/device identifiers, access timestamps, audit event logs |
| Payment information | Stripe customer ID, subscription plan — card numbers are held by Stripe and are not stored by Frankfig |
| Support communications | Tickets, feedback, and correspondence with our support team |
We collect personal information directly from users when they register, use the Service, or contact us, and automatically through system logs.
3. Purposes for collection and use
We use personal information to:
- Create and manage your account and your organisation's subscription;
- Deliver the secure messaging and document-signing features you have requested;
- Verify the identity of parties to a transaction for evidentiary clarity;
- Process payments via our payment processor (Stripe);
- Send transactional notifications (via Sunsend);
- Provide support and respond to enquiries;
- Maintain the security and integrity of the Service, including fraud detection and audit logging;
- Comply with our legal obligations as a service operator;
- Improve the Service (aggregate, de-identified analytics only).
We do not use personal information for direct marketing without consent, and we do not sell personal information.
4. Disclosure to third parties
We disclose personal information to the following categories of third parties:
| Recipient | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage (S3), and encryption key management (KMS) | ap-southeast-2 (Sydney) |
| Sunsend | Transactional email and SMS delivery | AWS ap-southeast-2 (Sydney) |
| Stripe | Payment processing | [PLACEHOLDER — confirm Stripe data residency] |
| [PLACEHOLDER — other sub-processors] | [PLACEHOLDER] | [PLACEHOLDER] |
We require all sub-processors to maintain appropriate security measures and to process personal information only on our instructions.
We may disclose personal information to law enforcement or regulators where required by law.
5. Data residency and security
All customer data — messages, documents, audit logs, and personal information — is stored exclusively in the ap-southeast-2 (Sydney) AWS region. No customer data is routed to overseas servers.
We protect personal information using:
- TLS 1.2+ in transit;
- AES-256 server-side encryption at rest (AWS S3 SSE-KMS);
- Message content is encrypted in your browser to your organisation's key. Documents are stored encrypted at rest, Australian-hosted and access-controlled.
- Short-lived JWT access tokens (never in browser storage) with httpOnly refresh cookies;
- Argon2 password hashing;
- Role-based access control and comprehensive audit logging.
6. Retention and deletion
We retain personal information for as long as your account is active or as necessary to provide the Service, plus the following staged deletion windows:
| Stage | Period | What happens |
|---|---|---|
| Grace period | 30 days after account closure | Account data is inaccessible to team members but is recoverable by any organisation admin who logs in. |
| Archive | Up to 84 months (~7 years) after the grace period ends | Data is retained in an archived state accessible only to Frankfig platform administrators. It may be restored or exported on request. |
| Purge | After the archive window | All operational and personal data is permanently deleted or de-identified. |
Note. The 84-month archive period is a business choice, not a statutory requirement. Frankfig is a messaging and signing platform, not an AML/CTF reporting entity — record-keeping obligations rest with the customer (see the Org Admin Addendum). [PLACEHOLDER — legal confirmation of this retention period against APP 11.2 required before publication.]
Billing records. Frankfig retains its own invoices and payment history for tax purposes regardless of account closure. These are Frankfig's own business records, not customer content.
Export access log. Frankfig retains a log of who downloaded data exports (which user, from which IP, at what time) as a security record, separately from the account data retention window.
Personal export. Organisation administrators may export their organisation's full data at any time via the in-app export function.
7. Sensitive information
Some users may transmit sensitive information as defined by the Privacy Act (for example, health information in an aged-care context). Frankfig treats all transmitted content as confidential and applies the same security measures regardless of content type. We do not use message or document content for any purpose other than delivery and storage of the communication.
8. Your rights
Under the Australian Privacy Principles you have the right to:
- Access personal information we hold about you;
- Correct inaccurate or out-of-date personal information;
- Complain about a breach of the APPs.
To exercise these rights, contact us at: [PLACEHOLDER — privacy officer email]
Complaints. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Privacy officer
Our Privacy Officer can be contacted at:
[PLACEHOLDER — Privacy Officer name] [PLACEHOLDER — entity name] Pty Ltd [PLACEHOLDER — address] Email: [PLACEHOLDER — privacy officer email]
10. Changes to this policy
We will notify users within the application when a new version of this policy requires acceptance. Continued use of the Service after accepting an updated policy constitutes acceptance of the changes.
This document is a DRAFT. It must be reviewed by qualified Australian privacy counsel before publication. All [PLACEHOLDER] markers must be resolved.