Privacy Policy
Last updated: June 2026
1. Overview
Registrum Pty Ltd ("we", "us", "our") operates the Registrum platform. This Privacy Policy explains how we collect, hold, use, and disclose your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where applicable, we also comply with the EU General Data Protection Regulation (GDPR).
2. Information We Collect
We may collect the following categories of personal information:
- Account information — name, email address, and password when you register.
- Business data — invoices, expenses, payroll records, inventory, contacts, and financial documents you create within the platform.
- Payment details — billing information processed securely through our third-party payment provider. We do not store full card numbers.
- Usage data — browser type, device information, IP address, pages visited, and feature usage to improve our service.
- Cookies and analytics — we use essential cookies for session management and optional analytics cookies to understand how the platform is used. You can manage cookie preferences via your browser settings.
3. Lawful Basis for Processing
Under the APPs and GDPR, we process your data on the following bases:
- Contractual necessity — to provide and maintain the Registrum service you have signed up for.
- Legitimate interest — to improve our platform, prevent fraud, and ensure security.
- Consent — for optional analytics and marketing communications, which you may withdraw at any time.
- Legal obligation — to comply with Australian tax, financial reporting, and record-keeping requirements.
4. How We Use Your Information
- To operate, maintain, and improve the Registrum platform.
- To process transactions and send related notices (e.g., invoice reminders).
- To provide customer support and respond to enquiries.
- To send service updates and, with your consent, promotional communications.
- To detect, prevent, and address technical issues or security threats.
- To comply with legal obligations, including ATO record-keeping requirements.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. Data Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest (AES-256), Row-Level Security for strict data isolation between accounts, multi-factor authentication options, and regular security audits. While no system is completely secure, we take reasonable steps to protect your data from unauthorised access, modification, or disclosure.
6. Third-Party Integrations & Disclosure
We may share your information with:
- Service providers — hosting, payment processing, email delivery, and analytics providers who assist us in operating the platform under strict confidentiality agreements.
- Connected integrations — when you choose to connect third-party services (e.g., banking, e-commerce platforms), we access those APIs solely on your behalf and only as you have configured.
- Legal requirements — if required by law, regulation, legal process, or government request.
- Authorised users — accountants or team members you have explicitly granted access to your data.
Current sub-processors:
- Supabase / AWS (Dublin, Ireland) — primary application database, authentication, file storage and edge functions.
- Basiq Pty Ltd (Sydney/Melbourne, Australia) — ACCC-accredited CDR Data Recipient used to retrieve bank feed data on your behalf.
- Stripe Payments Australia Pty Ltd — subscription billing and Stripe Connect for accepting customer payments.
- Resend — transactional email delivery (invoices, receipts, system notifications).
- Telegram FZ-LLC — optional document delivery channel where you have enabled and authorised it.
- Google (Gemini) and OpenAI — AI providers accessed via the Lovable AI Gateway, used to power the Reggie assistant. Prompts and the records you reference are processed transiently to generate a response; we do not allow them to train on your data.
- Mapbox — address autocomplete on document and contact forms.
- Frankfurter / Open Exchange Rates — public FX reference rates for multi-currency revaluation.
- Cloudflare, Inc. (USA) — provides the Turnstile bot-protection challenge on our sign-up and public lead-capture forms. Cloudflare processes your IP address, user-agent string, browser characteristics, interaction signals and an ephemeral challenge token to distinguish humans from automated traffic and prevent abusive account creation. Data may be transferred to the United States under Standard Contractual Clauses. See Cloudflare's Privacy Policy and the Turnstile Privacy Addendum.
We review this list whenever a new sub-processor is added. Material changes will be communicated as set out in section 15.
7. Cross-Border Data Transfers
Your data is stored on Amazon Web Services (AWS) infrastructure located in Dublin, Ireland (eu-west-1 region). Ireland is subject to the EU General Data Protection Regulation (GDPR), which the Australian Privacy Commissioner recognises as providing protections substantially similar to the Australian Privacy Principles under APP 8.
In the event of a breach by AWS Dublin, Registrum's accountability under APP 8.1 is reduced because our sub-processor operates under a framework equivalent to or stronger than the Privacy Act 1988 (Cth). We do not market to EU residents, and hosting in Ireland does not subject Registrum customers to GDPR obligations.
We do not transfer your data to any country without adequate safeguards in place.
7b. Bank Feeds & Open Banking Data
When you connect a bank account, Registrum uses Basiq Pty Ltd, an ACCC-accredited Data Recipient under Australia's Consumer Data Right (CDR) framework, to retrieve your transaction data. Basiq stores bank feed data in AWS data centres in Sydney and Melbourne. Your bank data is never stored outside Australia by Basiq except where you select a financial institution that uses Basiq's secure web connector (non-CDR), in which case Basiq's standard data handling terms apply. Bank feed consent is valid for 12 months and will expire automatically. You will receive a reminder in Registrum before expiry. You can withdraw consent at any time from Banking → Bank Feeds → Disconnect. For Basiq's full CDR Policy, visit basiq.io.
8. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Financial records are retained for a minimum of five (5) years to comply with ATO requirements. You may request deletion of your account and associated personal data by contacting support; requests are actioned within a reasonable period, except where retention is required by law.
We retain integration traffic metadata (e.g., webhook delivery logs, API call timestamps, status codes, and redacted request headers) for up to two (2) years for security, reliability, and partner-billing purposes. Full request and response payloads are redacted after 30 days.
9. Your Rights
You have the right to:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct inaccurate or incomplete information.
- Deletion — request deletion of your account and personal data by contacting support@registrum.com.au; requests are actioned within a reasonable period, subject to legal retention obligations.
- Portability — receive your data in a structured, commonly used format (e.g., CSV export).
- Withdraw consent — opt out of marketing communications or analytics at any time.
- Object — object to processing based on legitimate interests (GDPR).
To exercise any of these rights, contact us at support@registrum.com.au. We will respond within 30 days.
10. Data Breach Notification
In line with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth), if we have reasonable grounds to suspect an eligible data breach we will carry out an assessment within 30 days. If the assessment confirms a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable after that determination. For EU residents, we will notify the relevant supervisory authority within 72 hours as required by Article 33 of the GDPR.
11. Cookies & Tracking
We use the following types of cookies:
- Essential cookies — required for authentication and session management. These cannot be disabled.
- Analytics cookies — help us understand usage patterns. These are optional and can be managed through your browser settings.
We do not use advertising or tracking cookies.
12. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us at support@registrum.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC). EU residents may also contact their local supervisory authority.
13. Not a Tax or BAS Agent
Registrum is record-keeping software. We are not a registered tax agent, BAS agent, or SBR-enabled lodgement provider under the Tax Agent Services Act 2009 (Cth). Reports and files generated by Registrum — including BAS summaries and STP files — are for your records only. Lodgement to the ATO must be performed by you or your registered tax/BAS agent via the ATO Business Portal or SBR-enabled software.
14. Smart Notes & Knowledge Base
The Smart Notes module lets you create markdown notes, organise them with tags and folders, link them to your records (invoices, jobs, contacts, etc.), and use templates. The following applies specifically to Smart Notes data:
- Content ownership. You retain full ownership of all note content, tags, folders, and links you create. Registrum holds them solely to provide the service to you.
- Storage and limits. Each plan has a maximum number of notes and total storage size. We measure note count and storage in bytes solely to enforce your plan's limits — this usage data is not shared with third parties or used for marketing.
- No automatic overage charges. When you reach 100% of your plan's notes or storage limit, new notes are blocked and you are shown an upgrade option. We never automatically bill you above your chosen plan price. Any plan change requires your explicit confirmation.
- Visibility. Notes marked "Private" are visible only to you. Notes marked "Shared" are visible to other authenticated members of your organisation.
- Linked records. When you link a note to a record (e.g. an invoice or contact), only the link reference is stored — no additional copy of that record is created.
- Export and deletion. You can export all your notes as Markdown or CSV at any time, and delete individual notes. Deletion of your entire account can be requested by contacting support, in line with the rights set out in section 9.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. Your continued use of Registrum after changes are posted constitutes acceptance of the updated policy.
16. Contact Us
For privacy-related enquiries, contact our Privacy Officer at:
support@registrum.com.au