Pre-launch notice: this operational privacy summary must be reviewed for the final operator, hosting regions, subprocessors and Australian Privacy Act applicability before production. It is not legal advice.
Privacy
How private telecom records are handled
Draft status · no effective date set
1. Operator and contact
The configured operator is IzyBoard. Privacy enquiries can be sent to info@izyboard.com. Placeholder operator details mean the service is not ready for a production launch.
2. What this beta collects
- Account name, email address, password hash, verification time and session records.
- Case declarations: Australian microbusiness scope, authority to upload, service-type and line-count bands, and whether the agreement set is complete.
- Private contract, Critical Information Summary, order and invoice files. These can contain names, addresses, account/service identifiers, ABN, phone lines, employee information, usage and payment-reference fragments.
- Extracted values with original source text, source document, page, text span, extraction method and technical extraction score.
- Deterministic findings, report entitlement, review state, PII-safe operational events and short-lived user-requested exports.
- Stripe customer/session references in test checkout mode. Card details are entered in Stripe interfaces and are not stored in this application database.
3. Why the data is used
Data is used to authenticate the account, store and process user-requested cases, compare supplied agreement and bill records, provide aggregate free results, enforce detailed-report access, respond to support or review needs, prevent abuse, fulfil exports/deletion and maintain security. Final lawful-basis language must be confirmed by the operator's counsel.
4. Extraction and human review
The credential-free MVP recognises only exact, clearly labelled synthetic fixture PDFs. General OCR or LLM extraction is not configured. Other valid uploads are encrypted and moved to review required without a billing conclusion. Reviewer/admin status changes require a reason and create an audit event; this MVP does not expose a raw-file download in the review interface. If OCR or AI providers are added, this notice, processor terms, regions, no-training settings and redaction controls must be updated first.
5. Storage and security boundary
Source files use generated tenant/case/document keys in the private Supabase Storage bucket. Server-only service-role access follows an authenticated owner check; the bucket is non-public and has tenant-folder policies, an 8 MiB limit, TLS and provider encryption at rest. Uploads are checked against PDF/JPEG/PNG signatures; only byte-exact repository fixtures are marked known-safe. Other files remain quarantined because no antivirus service is wired. Production still requires malware scanning, access monitoring, backup-deletion verification and a reviewed deployment region.
6. Retention defaults
- Incomplete uploads: source bytes become eligible for deletion after 24 hours.
- Processed source files: source bytes become eligible for deletion after 30 days.
- Cases, extracted provenance and report snapshots: eligible for deletion after 90 days.
- User-requested JSON exports: expire after 24 hours.
- Unverified accounts: eligible for cleanup after 7 days.
- Delete-now removes source objects before cascading local database records. Stripe test records are controlled by Stripe and are not deleted by the local account endpoint.
- If private-object deletion fails, the local record is retained rather than silently orphaned.
These are configurable product defaults, not statutory retention conclusions. Scheduled cleanup must be deployed and monitored for them to operate.
7. Processors and transfers
Depending on deployment, services can include Supabase Postgres and private Storage, Netlify hosting/background functions, Resend transactional email, Stripe test billing and consent-gated Google Analytics. The final operator must publish the services actually used, their regions, processing agreements and cross-border safeguards. No source-document content is intentionally sent to analytics.
8. Analytics choice
Optional analytics is currently disabled. Enabling analytics or advertising tooling requires an updated consent and privacy review.
9. Your controls
The dashboard provides structured export, case deletion and account deletion. Contact the configured operator for access, correction or privacy enquiries. Rights and complaint language must be finalised for the operator's circumstances and applicable law. Only upload records you are authorised to process.
10. Independence and changes
The service is independent and is not affiliated with Telstra, ACMA or the Telecommunications Industry Ombudsman. The operator must publish an effective date, change-notice process and incident contact before production use.