Privacy policy
US-market edition · Draft of August 6, 2026 · Brolly Australasia Pty Ltd (ABN 66 633 439 577)
The short version
We collect what we need to run the website and platform, we use it only for that, and we never sell it. Customer records captured by the platform belong to our customers. You can ask what we hold about you, and you can ask us to delete it.
1. What we collect
Website visitors
Usage analytics (pages viewed, referrer, approximate location from IP), and any details you submit through forms — such as your name, work email, organization and role when you download a guide or book a call.
Platform users
Account details (name, work email, role), authentication and usage logs, and billing information processed by our payment providers.
Customer Data from connected platforms
When a customer connects social media accounts, the platform captures content from those accounts — posts, comments, replies, reactions, edits, deletions, media and metadata — through each platform's official APIs (Facebook, Instagram, Threads, X, YouTube, LinkedIn, TikTok). This data is captured on the customer's behalf, belongs to the customer, and is processed only to provide the service.
2. How we use information
- To provide, secure and support the website and platform
- To respond to inquiries and deliver resources you request
- To send service communications, and marketing you can opt out of at any time
- To meet legal obligations
We do not sell personal information, and we do not share it with third parties for their own marketing.
3. Platform API data
Data received from social media platform APIs is used solely to provide archiving, insights, monitoring and moderation to the customer whose accounts it comes from. It is not used for advertising, profiling or any purpose beyond the service, consistent with each platform's developer policies — including Meta's and Google's limited-use requirements. Disconnecting an account stops capture from it.
4. Cookies
The website uses necessary cookies and, with consent where required, analytics cookies. You can control cookies through your browser; the site works without non-essential ones.
5. Retention
Customer Data is retained per each customer's configured retention settings and applicable records schedules. Account and website data is kept only as long as needed for the purposes above or as law requires, then deleted.
6. Security
Records are encrypted in transit (TLS 1.2+) and at rest (AES-256), protected by multi-factor authentication, role-based access and audit trails, within an ISO/IEC 27001:2022-certified information security management system. Details live in the Trust & Security Center.
7. Your rights
Depending on where you live, you may have rights to know, access, correct and delete personal information we hold about you, and to opt out of sale or sharing — noting we sell nothing. California residents have these rights under the CCPA/CPRA; we honor equivalent rights under other US state privacy laws, the GDPR for European residents, and the Australian Privacy Act 1988. We do not discriminate against anyone for exercising privacy rights.
To exercise any right, contact us via the contact page. To delete data connected to social media platforms, see how to request data deletion.
8. Children
Our website and platform are for organizations and their staff, not children, and we do not knowingly collect children's personal information.
9. Changes and contact
Material changes to this policy are announced on this page with an updated date. Questions and requests: via the contact page.