Last updated: 20 September 2026
BizzMate is operated from Darwin, Northern Territory, Australia. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). For anything in this policy — a copy of your data, a correction, a deletion, or a complaint — write to rxalphatech@gmail.com and we will answer within 30 days.
Account information. Your name, email address, mobile number, business name, ABN and trade type, given when you register.
Mailbox content, when you connect a mailbox. This is the significant one. If you connect Gmail, Outlook or an IMAP account, we read unread messages and store the sender, subject, date, message body and any attachments. We do this so we can turn enquiries into jobs. We read only unread mail, and we do not delete anything.
Chat messages. If you connect a WhatsApp Business number or a Facebook Page, we store the messages customers send you and the sender's provider-assigned identifier.
Business records you create. Customers, jobs, quotes, invoices, payments, photos and documents.
Mailbox credentials. Either an OAuth token issued by your provider, or an app password you supply. These are encrypted at rest and are never displayed back to you or to our staff.
To run the product: to identify enquiries, create jobs, match them to customers, and produce quotes and invoices. We do not sell your data, and we do not use the contents of your mailbox for advertising.
To identify a job in an email, we send the message content to Google's Gemini API, which returns structured details such as a title, a due date and a priority. This means the content of emails in a connected mailbox is transmitted to and processed by Google. We use the paid tier, whose terms state that Google does not use prompts or responses to improve its products; Google retains them for a limited period only, to detect abuse of the service.
When we process an email, we send Gemini that message and nothing else: not your customer list, not your invoices, and never your mailbox credentials. Mailbox content is never used to train or improve any AI model, ours or anyone else's.
The AI Business Coach is the one place we send Gemini more than a single message. When an administrator asks it a question, it answers by querying your own records, and the results of those queries go to Google's Gemini API as part of the question: customer names with their job counts, invoiced totals and outstanding balances; invoice and quote numbers with the customer they belong to; job titles; and the names of your team members. It is read-only — it can look things up but never change them — it is restricted to administrators, and nothing is sent unless somebody asks it a question. The same paid-tier terms apply, so none of it trains a model. If you would rather these records never left your account, do not use the Coach; every other part of BizzMate works without it.
Messages that reach you through a connected Facebook Messenger or WhatsApp channel are read the same way, by the same paid Gemini API and on the same terms, to turn an enquiry into a job. The model's output is a job record inside your account; it never writes a reply to your customer.
Google's Gemini API is the only AI provider we use. Until 20 September 2026 chat messages were processed by DeepSeek, an AI provider operated from the People's Republic of China whose terms permit training on submitted content; mailbox content was never sent there. That arrangement has ended, DeepSeek is no longer part of BizzMate, and no message of any kind is sent to it. Every call we make records which provider served it, so this is auditable rather than asserted.
If you would rather no message content left our systems at all, do not connect a mailbox or a chat channel; every other part of BizzMate works without one.
Where you connect a Gmail account, BizzMate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We ask for three things and no more: permission to read your Gmail messages, so we can identify enquiries and create jobs from them; permission to send email from that mailbox, so quotes and invoices reach your customers from the address they already know; and, where your connection grants it, permission to mark a message as read once BizzMate has filed it. We never delete your mail. You can revoke our access at any time from your Google Account.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In particular, we do not transfer that data — raw, aggregated or anonymised — to any third party that uses it to create, train or improve generalised artificial intelligence or machine learning models, and we do not use it to train models of our own. The AI provider that processes mailbox content, and anything derived from it, is Google's Gemini API on its paid tier, whose terms forbid training on what we send. It is the only provider that receives this data. Our chat-channel provider is a separate service that never receives it — see Automated processing above.
The app for Android and iPhone shows you the same jobs as the website and is covered by everything above. Three things are specific to it.
What it asks permission for. The camera and your photo library, and only so you can attach a photo to a job. It asks the first time you try, and declining leaves every other part of the app working. The app does not ask for your location and never reads it. Where a job appears on a map, that comes from the site address someone typed in, converted to coordinates on our server — not from your phone.
What it keeps on your phone. A sign-in token, held in the Android Keystore or the iOS Keychain, so you are not asked to sign in every morning. Signing out or deleting the app removes it. Job details you have opened are held only for as long as the app is running.
What it does not do. There is no analytics SDK, no advertising, no third-party tracker and no cross-app identifier in the BizzMate app. We do not sell your data and we do not share it with data brokers. The one outside service the app contacts on its own is OpenStreetMap, which serves the map tiles and necessarily sees your device's IP address when a map is drawn.
In Sydney, Australia, on a virtual private server operated by Contabo Asia. Your jobs, customers, quotes, invoices, uploaded photos and the contents of any connected mailbox are stored here, onshore. This changed on 4 September 2026; until then the server was in Lauterbourg, France, and this page said so.
Storing it here does not mean none of it ever leaves. Mailbox content is processed by Google's Gemini API, as described above, and that remains an overseas disclosure under Australian Privacy Principle 8 — so we still tell you plainly rather than in a footnote. What has changed is where your data lives; what has not changed is that the AI processing it happens outside Australia.
Mailbox credentials are encrypted at rest with a key held separately from the database. Uploaded files are served only to signed-in members of the organisation that owns them, never from a public URL.
For as long as your account is open. When you delete your account we delete it immediately — not after a grace period, and not as a flag on a row we keep. What survives, and why, is set out in full in our data deletion policy. In short: if you were the last person in your business's workspace, the workspace and everything in it goes with you; records that Australian tax law requires to be kept — those supporting an issued invoice, for five years — may outlive the account, and are kept only for that purpose.
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it, by writing to rxalphatech@gmail.com. You can delete your account yourself at any time — in the app under Settings, or on the web under Settings → Your account. You can disconnect a mailbox at any time from Settings, which stops any further reading immediately. If you are unhappy with how we handle a request you can complain to the Office of the Australian Information Commissioner.
If a breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme.