Skip to content
OurCommonsOurCommons

Legal

Privacy Policy

How we collect, use, and protect information about you, your building, and the people you work with.

Version 0.1.0 · Effective 2026-08-23 · Prior versions

Draft

This document is in draft form. The final version is being reviewed by our legal team and will replace this text before launch.

The left column is the agreement. The right column (“What it means”) is a plain-English guide only and does not form part of the agreement.

1. What we collect

We collect and handle personal information using an Australian Privacy Principles (APP)-style baseline, whether or not every APP obligation applies to us in every circumstance. The information we collect depends on how you use OurCommons and may include:

  1. account and identity information, such as name, email address, authentication details, role, firm, building, lot, committee or office-bearer status, and invitation history;
  2. strata and building records, such as lot ownership and occupancy details, owner and tenant contact details, meeting agendas, motions, minutes, notices, by-laws, levy information, financial records, compliance documents, supplier records, correspondence, attachments, and documents uploaded by users;
  3. communications and recording information, such as emails, SMS messages, in-app messages, support requests, feedback, meeting recordings, transcripts, summaries and attendance metadata where those features are used;
  4. payment and subscription information, such as billing contacts, plan, lot count, invoice status, payment events, limited payment-method metadata and transaction identifiers provided by our payment provider. We do not ask you to enter full card numbers into OurCommons;
  5. usage, analytics and device information, such as pages viewed, features used, clicks or product events, browser and device type, IP address, approximate location, referral source, cookies and similar technologies used for sign-in, security, preferences and product analytics; and
  6. security and operational logs, such as sign-in attempts, session events, audit logs, access-control decisions, error reports, support diagnostics, fraud and abuse signals, and records needed to investigate security incidents.

We collect information directly from you when you create an account, use the platform, contact us, join a meeting, respond to a notice, or upload content. We may also collect information indirectly from the subscriber, strata manager, owners corporation or body corporate, committee members, other owners or occupiers, authorised users, suppliers, payment providers, communications providers, integrated services, publicly available property or strata records, and security or analytics tools.

OurCommons is not designed for users to place highly sensitive information, government identifiers, health information, or full payment-card details in free-text fields or general uploads unless a purpose-built feature expressly asks for it. If users include that information in strata records, meeting material, messages, recordings or support requests, we handle it consistently with this policy and the customer agreement.

2. How we use it

We use personal information to operate, secure, support and improve OurCommons. This includes creating and managing accounts, checking permissions, onboarding buildings, managing meetings and minutes, sending notices and service communications, supporting votes and approvals, processing levy and billing workflows, maintaining strata and compliance records, providing support, troubleshooting, preventing fraud or misuse, meeting legal obligations, and enforcing our agreements.

We use the content and context available in your account to provide product features, including the CoMo AI assistant and other AI-assisted drafting, search, summarisation, classification, extraction and recommendation tools. AI outputs may be incomplete or wrong and are not legal, financial, strata-management or other professional advice. Users and subscribers remain responsible for reviewing outputs before relying on them and for meeting their own statutory obligations.

We may use aggregated or de-identified information that does not reasonably identify a person, subscriber, scheme or building to understand usage, benchmark and improve the platform, test feature quality, configure AI-assisted features, and develop new functionality. We do not use customer content to train AI or machine-learning models and do not authorise third-party AI providers to train models on customer content unless the subscriber gives prior express written opt-in consent for that specified training.

We may use your contact details to send service communications, including security alerts, account notices, billing notices, meeting or building workflow messages, product-change notices, and support responses. We may also send marketing communications where permitted by law. You can opt out of marketing communications using the unsubscribe link or by emailing hello@ourcommons.co. Opting out of marketing does not stop service, security, legal, billing, or scheme-related communications.

Some platform rules are automated or partly automated. They may use account details, role and building relationships, subscription status, usage events, security signals, device information, payment metadata, content metadata and workflow state to grant or restrict access, flag security or fraud risk, prioritise support or compliance tasks, recommend next actions, and personalise product prompts. These rules support platform administration and recommendations; scheme governance decisions, statutory decisions, levy decisions, enforcement decisions and professional judgments remain the responsibility of the relevant subscriber, owners corporation, body corporate, strata manager or user.

We do not use AI features to make final scheme-governance, statutory, levy, enforcement or professional decisions. If we introduce or materially change a computer program that uses personal information to make, or substantially and directly support, a decision that could significantly affect an individual's rights or interests, we will update this policy to describe the kinds of personal information used and the kinds of decisions made or supported.

3. Data storage & security

We use technical, organisational and contractual safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include encryption in transit and at rest, role-based access controls, database access policies, server-side authorisation checks, audit logging, monitoring, vulnerability management, backups, incident response processes, and limits on staff and contractor access.

Primary application data and uploaded files are stored at rest using Australian-hosted infrastructure where our hosting, database and storage configuration supports that. Some processing, support, security, analytics, communications, payment, recording and AI features involve providers, personnel, infrastructure or subprocessors outside Australia, as described in clause 6.

No internet service can guarantee complete security. If we suspect a data breach, we assess the incident, take steps to contain it, and determine notification responsibilities with the relevant subscriber where scheme records are involved. Where required, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.

4. Building-level isolation

Customer access is scoped by organisation, building, lot, role and permission. Strata managers are assigned to portfolio buildings, committee members and owners receive access according to their building and role, and subscribers control which authorised users are invited or removed.

Database access policies, server-side checks and audit logs help enforce these boundaries. Our support, security and operations personnel may access customer information where reasonably required to provide support, investigate an issue, maintain the platform, comply with law, protect security, or enforce our agreements. Administrative access is separately controlled and logged where practicable.

Where a user belongs to multiple firms, buildings, lots or roles, the information available to them may change depending on the context they select and the permissions set by the relevant subscriber or scheme.

5. Data retention

We retain personal information for as long as reasonably needed to provide the platform, support the relevant subscriber or scheme, meet legal and accounting obligations, resolve disputes, maintain security, enforce agreements, and preserve records that must be kept.

Strata and body corporate records are statutory scheme records of the relevant owners corporation, body corporate or scheme, as set out in the customer agreement and applicable strata legislation. The customer, acting for itself and the relevant schemes, not OurCommons, remains responsible for deciding what scheme records must be created, kept, corrected, exported, handed over to an incoming manager, or retained for statutory periods. OurCommons provides tools to assist with those tasks and does not provide legal advice about a scheme's record-keeping obligations.

When a subscription ends, the customer agreement governs export, retrieval, handover and deletion of building data. The current subscription terms contemplate a 30-day data-retrieval window after termination. After that window, we may delete or de-identify platform copies of customer data in accordance with our deletion processes, subject to backups, audit logs, security records, unresolved support issues, disputes, legal holds, accounting records, and obligations that require or justify longer retention.

If an individual asks us to delete personal information, we assess the request against our role and the relevant customer's obligations. Deleting an individual account or profile may not delete scheme records, minutes, financial records, notices, audit logs or other records that the customer or platform must retain. Where appropriate, we may refer the request to the relevant subscriber, owners corporation, body corporate or strata manager because they control the underlying scheme record.

6. Third parties

We use third-party service providers to host, operate, secure, communicate through, analyse, bill for and improve OurCommons. Principal provider categories include:

  1. infrastructure, database, authentication, storage and application hosting providers, including Supabase and Vercel;
  2. payment and subscription providers, including Stripe;
  3. email, SMS, push-notification and communications providers, including Resend, MessageMedia, Expo and Apple or Google push-notification services;
  4. product analytics, diagnostics, monitoring, security and error-reporting providers, including PostHog and Sentry;
  5. meeting recording, transcription or processing providers, including Recall.ai where recording features are enabled;
  6. AI, embedding, search and language-model providers, including Anthropic and OpenAI for selected AI-assisted features; and
  7. mapping, address lookup, support, administration, legal, accounting and professional advisers where needed to operate the business.

The personal information shared with a provider depends on the feature used and the provider's role. For example, billing providers may receive billing contacts, payment metadata and invoice events; communications providers may receive names, contact details and message content; AI or recording providers may process meeting content, transcripts, documents, prompts or outputs when those features are used; analytics and monitoring providers may receive usage events, device information, IP addresses and error diagnostics.

Some providers, their personnel, infrastructure or subprocessors may be located outside Australia. Likely overseas processing locations or regions include the United States, the United Kingdom, the European Union or European Economic Area, Singapore, other Asia-Pacific locations, and other countries where our providers operate or engage subprocessors. We take reasonable steps to assess and manage overseas processing and provider access, including contractual protections, data minimisation, security controls and vendor review appropriate to the service.

We are not in the business of selling personal information or sharing it with data brokers. We may disclose information where required or authorised by law, to protect security or safety, to investigate suspected unlawful activity or serious misconduct, to complete a business restructure or transfer, or with consent.

7. Your rights

You can ask us to give you access to personal information we hold about you, correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading, or delete personal information where deletion is available. Please email hello@ourcommons.co with enough detail for us to identify the information and the request.

We may need to verify your identity, authority, role, building relationship or lot relationship before acting on a request. We may also ask for clarification if the request is broad or unclear. We aim to respond to privacy access and correction requests within 30 days, or within another reasonable period where a request is complex.

Access, correction or deletion may be limited where the law allows or requires a different outcome, including where giving access would affect another person's privacy, reveal confidential or commercially sensitive information, compromise security, interfere with legal proceedings or investigations, or conflict with statutory scheme-record, accounting, audit, backup, dispute or legal-hold obligations. If we refuse or limit a request, we will explain the reason where it is reasonable and lawful to do so.

Some information in OurCommons is controlled by the relevant subscriber, owners corporation, body corporate, strata management firm or building operator rather than by us alone. If your request concerns scheme records, meeting records, notices, lot ownership records, financial records or communications sent on behalf of a scheme, we may refer you to the relevant customer or work with them to handle the request.

8. Contact

For privacy questions, access or correction requests, deletion requests, marketing opt-outs, or complaints, email hello@ourcommons.co.

If you make a privacy complaint, please include the relevant account, building or scheme details, what happened, and what outcome you are seeking. We will acknowledge the complaint, investigate it, and aim to respond within 30 days. If we need more time because the issue is complex or requires input from a subscriber, provider or adviser, we will let you know.

If you are not satisfied with our response, or we do not respond within a reasonable time, you may escalate the complaint to the Office of the Australian Information Commissioner (OAIC) using the process described at oaic.gov.au/privacy/privacy-complaints.