Privacy Policy

XBG Solutions Pty Ltd — ABN 31 688 945 913

Effective: 10 September 2026


1. Overview

XBG Solutions Pty Ltd is committed to protecting the privacy of individuals who interact with our websites and Services. This policy explains how we collect, use, hold and disclose personal information, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

It applies across every domain we operate, currently including xbg.solutions, my.xbg.solutions, build.xbg.solutions, collab.xbg.solutions, crm.xbg.solutions, input.xbg.solutions, morph.xbg.solutions, xbg.ventures and xbg.holdings. Where a particular practice applies only to a certain kind of Service, we say so.

Our Terms of Service govern your use of the Services. By using them, you consent to the collection and use of information as described here.

2. What Information We Collect

2.1 Information you provide directly

Depending on which Service you use, we may collect:

  • name, email address and job title
  • company name and ABN
  • login credentials (passwords are stored as a one-way cryptographic hash; plaintext passwords are never stored, logged, or transmitted in recoverable form)
  • billing name, email and postal address. Full payment card details are handled entirely by Stripe and are never transmitted to or stored on our systems
  • the content of messages, enquiries and support requests
  • questionnaire responses, including text, video and audio recordings
  • project material: briefs, documents, research inputs, discussion, artefacts and files you upload or create in a delivery workspace
  • where you connect a third-party account (for example email or calendar) to a Service, the material that account makes available, for the purposes you connected it for

2.2 Information collected automatically

When you access our Services we may collect IP address, browser and device information, pages visited and actions taken, and timestamps, for security, diagnostics and aggregate usage analysis.

3. How We Use Your Information

We use personal information to provide, operate and support the Services; to authenticate you and control access; to bill for the Services; to communicate with you about them; to detect, investigate and prevent security incidents, fraud and abuse; and to comply with legal and regulatory obligations.

We do not use personal information for direct marketing without your explicit consent, and we do not sell, trade or rent it. We do not engage in automated decision-making that produces legal or similarly significant effects without human review.

4. AI Processing

Our Services use third-party AI providers to transcribe, analyse, summarise and draft material. Sending your content to those providers is a disclosure of personal information to them, and it is fundamental to how the Services work.

We currently use Anthropic, PBC (Claude) for language processing and OpenAI, LLC (Whisper) for audio and video transcription. Both process API-submitted data under their published API terms, and neither uses API-submitted data to train its models by default.

Encryption at rest does not change this. Material we hold is encrypted when stored (Section 9), but to be processed it is decrypted and sent to the relevant provider.

You should not submit through our Services any personal information you are not authorised to process using third-party AI tools, including personal information about other people.

5. Disclosure of Personal Information

We may disclose personal information to:

  • Stripe, Inc. for payment processing (PCI DSS Level 1 certified)
  • Google LLC / Firebase for cloud hosting, authentication and storage (australia-southeast1, Sydney); see Section 6
  • Anthropic, PBC and OpenAI, LLC as described in Section 4
  • other sub-processors necessary to operate the Services, each bound by appropriate data processing terms
  • law enforcement, regulators or courts, where required or authorised by law
  • a successor entity in connection with a merger, acquisition or asset sale, subject to equivalent privacy protections being maintained

A current list of sub-processors is available on request from legal@xbg.solutions.

6. Data Storage and Cross-Border Transfers

Primary storage — Australia

Application data, accounts and uploaded files are stored in Firebase (Google Cloud Platform) in the australia-southeast1 region (Sydney). Your primary personal data is held in Australia.

AI processors — overseas

Where we use Anthropic or OpenAI to process content, that content is transmitted to servers operated by those providers in the United States. This is an overseas disclosure under APP 8. Before making it we take reasonable steps to ensure each provider handles personal information consistently with the APPs; both maintain privacy programs and contractual commitments consistent with international data protection standards.

Platform operations

Certain Firebase platform-level operations, such as authentication, may involve Google infrastructure outside Australia. Google participates in recognised cross-border data transfer frameworks.

7. Payments

All payment card transactions are processed entirely by Stripe, Inc. We do not store, process or transmit cardholder data and are not in scope for PCI DSS as a merchant. See stripe.com/au/privacy.

8. Cookies and Session Tokens

We use cookies and session tokens to maintain authenticated sessions, to hold access state for link-based Services, and to collect aggregate, anonymised usage analytics. You can disable cookies in your browser, though login and access-link features will not work without them. We do not use cookies for advertising, retargeting, or any sale of personal information.

9. Security

We apply technical and organisational measures appropriate to the material we hold:

  • all data encrypted in transit using TLS 1.2 or higher
  • data at rest encrypted by Google Cloud infrastructure in australia-southeast1
  • passwords hashed with a strong one-way algorithm; never logged or stored in plaintext
  • security rules and server-side access control enforcing per-account and per-project access
  • API keys you supply stored encrypted and used only to make calls on your behalf
  • access to production systems limited to authorised personnel on a need-to-know basis, with cross-account access by our staff restricted, deliberate and logged

Per-client encryption

In addition to infrastructure-level encryption, material you create in our delivery workspaces is encrypted under a key unique to your account, held separately from the data it protects. We are progressively extending this across our Services; where it applies, it lets us render your material permanently unreadable at your request — including in backups and historical copies, not only in the live systems (Section 11).

This is not end-to-end encryption and we do not claim it is. We hold the keys, because we must be able to process your material to provide the Services and to maintain them over time. You should assume that XBG Solutions can read material you store with us, and that our staff may access it where necessary to operate or support the Services.

Breach notification

In the event of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC).

10. Shared Workspaces and Community Areas

Some of our Services are collaborative by design, and it matters that you know which is which.

  • Delivery workspaces — projects, engagements and their contents are visible to the people invited to them, which may include people from more than one organisation where a project is run jointly.
  • Community and support forums — where a Service provides a shared forum, posts are visible to other customers of that Service. The interface says so at the point of posting.

Account-specific or project-specific support, and anything requiring disclosure of sensitive or confidential material, should be raised with us directly rather than in a shared forum. Contact us at legal@xbg.solutions or through your usual engagement contact.

11. Access, Correction and Deletion

Under the Privacy Act you may access personal information we hold about you and request correction of inaccuracies. You may also ask us to delete your material. To make a request, contact legal@xbg.solutions; we will respond within 30 days.

What deletion means

Where per-client encryption applies (Section 9), deletion means we destroy the key that protects your material and then remove the material itself. Destroying the key is what makes the deletion reach copies that ordinary deletion cannot — backups and historical copies included.

Three limits apply, and we would rather state them plainly than have them assumed away.

  • Commercial records survive. Invoices, contracts, charge history and our audit trail are retained — by design, and in several cases because the law requires it (Section 12).
  • Shared material survives for the other participants. Where you contributed material into a workspace or engagement shared with another organisation, it remains available to them, because it is also their record. Depending on the arrangement it is either handed over to a remaining participant or your attribution to it is anonymised. The material itself is not altered.
  • Individuals are de-identified, not deleted. If you ask us to remove you as an individual, we remove your name and contact details and you appear as a former user. Work you contributed remains with the account that owns it, because it is generally that organisation’s record and other people’s as well.

Erasure removes what was yours alone. What you contributed to something shared remains, because it is also somebody else’s record.

If you need something broader than this — for example a specific handling or destruction obligation for an engagement — it can be agreed in writing as part of that engagement.

12. Retention

We retain personal information while it is needed for the purposes described in this policy, and then destroy or de-identify it.

  • Account and project material: retained while your account is active. On request, deleted within 30 days.
  • Financial records (invoices, transaction records): 7 years, as required by the Tax Administration Act 1953 (Cth).
  • Questionnaire responses, video files and transcriptions: the duration of the engagement plus 12 months, unless earlier deletion is requested or a different period is agreed in writing.
  • Marketing site contact form submissions: up to 24 months, or until the enquiry is resolved.

We do not currently operate an automatic deletion process triggered by account closure. If you close an account and want your material removed, ask us and we will do it within 30 days. We would rather tell you that than imply a process we have not built.

13. Complaints

If you believe we have breached the APPs, contact legal@xbg.solutions. We will acknowledge within 5 business days and aim to resolve within 30 days.

If you are unsatisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au.

14. Changes to This Policy

We may update this policy from time to time. We will post an updated version with a revised effective date and, for material changes, notify you by email where appropriate. Continued use of the Services after notification constitutes acceptance.

15. Contact Us

XBG Solutions Pty Ltd
ABN 31 688 945 913
legal@xbg.solutions

This is an interim document and has not been reviewed by a qualified legal practitioner. XBG Solutions intends to replace it with a solicitor-drafted version. Priority items for legal review: (1) Privacy Act applicability given the annual turnover threshold; (2) data processing agreements for engagements involving third-party end-user data; (3) the treatment of jointly-held material in shared workspaces on erasure; (4) customer-supplied API key terms and liability allocation.