Privacy policy
IntraWork is a strategic advisory and operations platform business based in Australia. We take your privacy seriously, and this policy describes what personal information we collect, why we collect it, who we share it with, and the rights you have under Australian privacy law.
This policy is written for two audiences. If your organisation is a customer of the IntraWork Platform, sections 1 through 7 describe how we handle the information that flows through your deployment. If you are an individual whose information is held inside an IntraWork Platform deployment — for example, because you are a contact of one of our customers — sections 6 and 7 describe the rights available to you.
1. Who we are
IntraWork Group Pty Ltd (ABN 35 661 220 748), registered office 15 Napier St, Warragul, VIC 3820. Operated by Jessica O'Donnell, Principal. We are governed by the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Our contact details for privacy enquiries are at the end of this document.
2. What personal information we collect
We collect personal information directly from you when you engage IntraWork as a client, complete an intake form, send us an email, accept a meeting, or sign a proposal. The categories of personal information we collect include:
- Contact details. Names, business email addresses, phone numbers, organisation names, position titles, postal addresses where provided.
- Communication content. The substance of emails, calendar invitations, meeting notes, and intake form responses you exchange with us.
- Engagement records. Proposals, agreements, project documents, deliverables, invoices, and the operational record of work we have done for you.
- Calendar metadata. Meeting times, attendees, locations, and meeting titles drawn from the calendar systems we have authorisation to access.
- Document metadata. File names, modification timestamps, and shared access permissions for documents stored in OneDrive folders we have authorisation to access.
We do not knowingly collect sensitive information as defined under the Privacy Act (information about health, racial origin, political opinions, religious beliefs, and similar categories) unless it is voluntarily provided in the course of advisory work where its relevance has been agreed.
3. How we collect it
Most personal information is collected directly from you, through normal business channels — email, scheduled meetings, intake forms, signed agreements. Where IntraWork operates a platform deployment on your organisation's behalf, the platform also collects information through:
- Microsoft Graph. With your explicit OAuth authorisation, the platform reads mail, calendar, and OneDrive metadata from your Microsoft 365 tenant. We use minimum-necessary scopes and access the data on-demand rather than copying mailboxes wholesale.
- Inbound webhooks. If you operate a marketing site, contact form, or email automation tool that we have integrated into your deployment, those tools send submissions to the platform via secured webhook endpoints.
If we collect personal information about you from a third party (for example, a referrer who recommends a contact), we will tell you about that collection at the first reasonable opportunity.
4. Why we collect it
We collect personal information for the purposes of:
- Delivering the advisory and platform services your organisation has agreed to receive from us.
- Managing the business relationship — invoicing, agreement administration, support, scheduling.
- Maintaining the operational record of work performed, including for tax, audit, and professional indemnity purposes.
- Improving our services, including through anonymous analysis of how the platform is used.
- Complying with our legal obligations under Australian law.
We do not collect personal information for marketing purposes beyond the specific business relationship, and we do not sell personal information to any third party.
5. Who we disclose it to
We use a small set of carefully selected sub-processors to deliver our services. The current list, with each sub-processor's purpose, the categories of data they handle, and their location, is maintained at /legal/sub-processors.md.
In summary, the sub-processors are:
- Supabase Inc. — database hosting for your operational data (Sydney by default for Australian customers).
- Microsoft Corporation — Graph API access to your existing Microsoft 365 tenant (your selected region).
- Anthropic, PBC — large language model inference for the agent runtime (United States).
- Microsoft Azure (Static Web Apps) — compute hosting for the application (Australia East).
- Wix.com Ltd. — only if your deployment uses the Wix integration (United States).
We will notify you by email at least 30 days before adding or replacing any sub-processor.
We may disclose personal information to professional advisers (accountants, lawyers, auditors) bound by their own confidentiality obligations, or where required by Australian law.
6. Overseas disclosure (Australian Privacy Principle 8)
Two of our sub-processors operate outside Australia:
- Anthropic, PBC, United States. Required to provide the agent runtime that drives the platform's intelligent features. Anthropic's Commercial Terms apply to this transfer and explicitly prohibit the use of customer data submitted via the API for model training. Anthropic's published security posture is available at their trust centre.
- Wix.com Ltd., United States (only if your deployment uses the Wix integration). Webhook traffic from Wix-hosted forms to your deployment travels through Wix infrastructure before reaching the application.
By accepting an IntraWork engagement, you acknowledge that personal information will be disclosed to these overseas recipients for the purposes described above. We take reasonable steps to ensure that overseas recipients handle personal information consistently with the Australian Privacy Principles, including through contractual terms.
7. Automated decisions and AI-assisted work
The IntraWork Platform uses large language models (Claude, supplied by Anthropic) to assist in drafting client-facing content, triaging inbound communications, summarising documents, and surfacing patterns in your business operations. We treat the following points as binding:
- No fully automated decisions affecting clients without human approval. Every client-facing action produced by an AI agent — emails, proposals, scheduled posts, decision recommendations — routes through an approval queue where a human operator reviews, edits, and either approves or rejects the action before it is sent. This is an architectural primitive of the platform, not a feature setting.
- No model training on your data. Anthropic's Commercial Terms prohibit training on customer data submitted via the API. We do not fine-tune models on customer data.
- Personal information used in AI-assisted work. The agents process personal information from contacts, organisations, communications, calendar metadata, and document metadata as part of generating drafts. The categories of personal information used in substantially automated decisions are: contact identifiers (names, email addresses, organisation details), communication content drawn from authorised channels, and engagement history.
In line with the Australian Privacy Act amendments commencing in December 2026, we have drafted this section to disclose the categories of personal information used in substantially automated decisions. We will update this section as the amendment commences and as our use of AI evolves.
8. Security and retention
The technical and organisational measures we apply to protect personal information are described in our Information Security Policy. Highlights:
- TLS 1.2 or higher on every external connection.
- AES-256 encryption at rest on operational data.
- Multi-factor authentication on operator accounts.
- A documented incident response runbook with a 72-hour customer notification commitment.
We retain personal information for the life of the engagement plus a 30-day grace period after termination, during which we will provide a data export on request. After the grace period, your operational data is permanently deleted from the deployment we operate. Personal information held for legal, tax, or professional indemnity reasons may be retained for the period required by Australian law.
9. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you.
- Correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Complain if you believe we have breached our obligations under the Privacy Act.
To exercise any of these rights, contact us at privacy@intrawork.com.au. We will respond within 30 days. Access requests are currently fulfilled by the operator on a per-request basis; an automated export workflow is in development. There is no fee for an access request, though in exceptional cases (e.g. very large requests) we may discuss a reasonable cost-recovery arrangement before proceeding.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by phone on 1300 363 992.
10. Cookies and tracking on our marketing site
Our public marketing site uses a small set of essential and analytics cookies. The marketing site's cookie policy is published separately on the site itself. The IntraWork Platform (the client portal and admin application) does not use third-party tracking cookies — only the session cookies required for authentication.
11. Children
The IntraWork Platform is a B2B product not directed at children. We do not knowingly collect personal information from children under the age of 16.
12. Changes to this policy
We will update this policy from time to time as our services, sub-processors, or legal obligations change. Material changes will be notified to active customers by email at least 30 days before they take effect. The current version's effective date is at the top of this document.
13. Contact
For any privacy enquiry, including access and correction requests:
Email: privacy@intrawork.com.au
Postal address: IntraWork Group Pty Ltd, 15 Napier St, Warragul, VIC 3820, Australia.
Response time: within 30 days of receipt.
This document was last updated on 2026-05-18. It is a draft pending legal review.