Last updated: July 24, 2026
This is an initial version pending legal review before launch. It does not constitute legal advice.
This policy explains what personal data Aussiflow ([nombre del titular — por confirmar], operated from Australia, ABN [ABN — por confirmar]) processes, for what purposes, on what legal basis, and the rights you have. Aussiflow is an information and organisation tool to help you prepare Australian visa procedures; it is not a migration agent and does not provide legal advice.
[nombre del titular — por confirmar] (ABN [ABN — por confirmar]), Australia. For any privacy matter you can write to privacy@aussiflow.com.
Your data is stored in Australia (Supabase, region ap-southeast-2 (Sídney, Australia)). Aussiflow operates from Australia under the Australian Privacy Act. If you reside in the European Union, your data is transferred outside the EEA; we apply the safeguards required by the GDPR for such international transfers.
We work with providers that process data on our behalf, each with its own purpose:
We do not sell your data or share it with third parties for advertising purposes.
Our team may access your data to provide support and to review the quality of the analyses generated (quality control). Such access is restricted to authorised staff and is logged.
We apply reasonable security measures: encryption in transit and at rest, access control restricted by role (each user can only access their own data through row-level security policies on the database), and signed, time-limited URLs for your documents.
We retain your data while your account is active. If you request deletion of your account, we delete your profile, plans, tasks and uploaded documents immediately. Our infrastructure provider (Supabase) may retain backup copies for a limited period after deletion, in line with its standard backup policy.
If a security breach occurred that poses a risk to your data, we will notify you without undue delay. Our internal goal is to assess it and, where appropriate, notify it within 72 hours of becoming aware of it — a stricter standard than the Australian notifiable data breaches scheme (30 days), which we also comply with. If you reside in the European Union, we will notify the competent data protection authority(ies) of the Member State(s) where affected users reside, in accordance with Article 33 of the GDPR.
At any time you can exercise your rights of:
To exercise them, write to privacy@aussiflow.com. If you reside in the EU, you may also lodge a complaint with your data protection authority.
We may update this policy. The current version will be published on this page with its last updated date.
Controller: [nombre del titular — por confirmar], Australia. Privacy: privacy@aussiflow.com. General contact: hello@aussiflow.com.