1. Introduction
Build Standard Pty Ltd (Build Standard, we, us or our) provides website, software and compliance tools for participants in the Australian building and construction industry.
This Privacy Policy explains how we collect, hold, use and disclose Personal Information in connection with our business, including through:
- a. our Website;
- b. the Build Standard Web Application and related Services;
- c. customer support, product demos, onboarding and account management;
- d. public or shareable Trust Center profiles and links;
- e. marketing, events and business development activities; and
- f. other interactions you may have with us.
This Privacy Policy should be read together with our Master Subscription Agreement, which governs the provision of our subscription services to Customers.
2. Definitions
In this Privacy Policy:
APPs means the Australian Privacy Principles contained in Schedule 1 to the Privacy Act.
Build Standard, we, us or our means Build Standard Pty Ltd and, where the context requires, its officers, employees, contractors and service providers acting on its behalf.
Build Standard Web Application means the web application, platform, software, modules, dashboards, portals and related functionality made available by Build Standard to Customers and Users from time to time.
Customer means a person, company, partnership, trust, sole trader or other entity that has entered into, or is otherwise bound by, the MSA or another agreement with Build Standard for access to or use of the Services.
Customer Information means information, documents, records, data, files, images, photographs, policies, procedures, compliance materials, financial records, project records, licence information, construction site photos, Minimum Financial Requirements documentation, internal business records and other content uploaded to, generated in, stored in, submitted to, or processed through the Services by or on behalf of a Customer or User.
Information means Personal Information and Customer Information, collectively.
Master Subscription Agreement or MSA means the Build Standard Master Subscription Agreement, or other applicable customer agreement, that governs access to and use of the Services.
Minimum Financial Requirements or MFR means minimum financial requirements, financial reporting, compliance or licensing information relevant to builders or construction businesses, including requirements administered by a building regulator, licensing authority or other government body.
Personal Information has the meaning given in the Privacy Act and means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.
Privacy Act means the Privacy Act 1988 (Cth).
Services means the subscription services, software, modules, tools, Trust Center functionality, support services, websites, documentation, APIs, integrations and related services provided or made available by Build Standard from time to time, including through the Build Standard Web Application.
Trust Center means any Build Standard feature, profile, page, dashboard or module that allows a Customer to organise, display, publish, verify or share business identity, compliance, licence, financial, project, policy or other information with third parties.
Trust Link means a public, private, restricted, shareable or generated link, URL or access pathway that allows a Customer to share or make available information contained in, or generated through, a Trust Center.
User means any individual who accesses or uses the Website, Build Standard Web Application or Services, including employees, officers, contractors, consultants, administrators, authorised representatives or other personnel of a Customer.
Website means the Build Standard website located at buildstandard.com.au and any other website operated by Build Standard from time to time.
3. Customer Information and customer-uploaded content
Customers may upload, generate, store or process Customer Information through the Services. Customer Information may include Personal Information about directors, employees, contractors, site personnel, certifiers, consultants, subcontractors, suppliers, clients or other individuals.
Build Standard generally processes Customer Information on behalf of the relevant Customer and in accordance with the MSA and the Customer’s instructions.
This Privacy Policy applies to Personal Information we collect and handle for our own business purposes, including to manage our relationship with Customers and Users, provide and secure the Services, operate the Website, provide support, issue invoices, market our Services and comply with law.
Where you upload or provide Personal Information about another person, you must ensure that you are authorised to do so and that the person is aware that their information may be handled in accordance with this Privacy Policy, the MSA and any other applicable terms.
4. Anonymity and pseudonymity
Where practicable, you may deal with us anonymously or by using a pseudonym.
However, this may not be practicable where we need to identify you in order to provide our services, create or administer an account, verify a business or licence, provide support, process a payment, respond to a privacy request, investigate misuse, comply with law or manage a customer relationship.
5. Personal information we collect
The kinds of personal information we collect depend on how you interact with us.
We may collect the following categories of personal information.
4.1 Account and user information
When a customer subscribes to our services, creates an account or gives users access to the Build Standard application, we may collect:
- a. names;
- b. business email addresses;
- c. phone numbers;
- d. job titles, professional roles and permissions, such as director, administrator, site administrator, compliance manager or finance user;
- e. company or organisation details;
- f. account credentials, authentication information and user permissions; and
- records of account activity and access.
4.2 Business identity and verification information
To verify accounts, businesses or compliance records, we may collect:
- a. Australian Business Numbers (ABNs);
- b. Australian Company Numbers (ACNs);
- c. business names and trading names;
- d. builder licence numbers, including state or territory licence numbers such as Victorian Building Authority licence details;
- e. corporate entity details;
- f. director, officer or responsible person details;
- g. insurance, registration or accreditation information; and
- h. information obtained from public registers or commercial databases.
4.3 Billing and payment information
If a customer purchases paid services or modules, we may collect billing and transaction information, including:
- a. billing name and billing address;
- b. billing contact details;
- c. subscription, invoice and payment history;
- d. product or module purchased;
- e. payment status; and
- f. other information needed to administer accounts, invoices, payments, renewals and refunds.
Payment card details may be collected and processed by our third-party payment processor, such as Stripe. We do not intend to store full payment card numbers on our own systems.
4.4 Support and customer service information
When you contact us for support or customer service, we may collect:
- a. your contact details;
- b. details of your issue, request or question;
- c. screenshots, documents, examples or other materials you provide;
- d. correspondence and communication records; and
- e. information about your account, device, browser, system settings or usage where needed to investigate or resolve the issue.
4.5 Website, device, log and usage information
When you access our website or services, we may automatically collect:
- a. IP address;
- b. browser type and browser settings;
- c. device type, operating system and device settings;
- d. date and time of access;
- e. pages visited and features used;
- f. referring URLs;
- g. log-in, authentication and session information;
- h. crash data, error logs and diagnostic information;
- i. usage metadata relating to interactions with the services; and
- j. cookie and tracking information.
We use this information to operate, secure, troubleshoot, improve and monitor the performance of our website and services.
4.6 Marketing, lead and event information
We may collect personal information from marketing activities, including:
- a. contact details provided through website forms, event registrations, product demos or downloadable resources;
- b. business contact information received from business partners, analytics providers, event organisers or lead generation sources;
- c. communication preferences;
- d. email engagement information, such as whether you opened or clicked a marketing email; and
- e. information about your business needs or areas of interest.
4.7 Information from public and third-party sources
We may collect or verify information from public and third-party sources, including:
- a. the Australian Business Register;
- b. ASIC registers;
- c. state and territory builder or practitioner registers, including the Victorian Building Authority register;
- d. licensing, registration, accreditation or regulator databases;
- e. commercial databases;
- f. business partners;
- g. analytics providers;
- h. event organisers; and
- i. publicly available websites and business directories.
6. How we use personal information
We collect, hold, use and disclose personal information for the purposes for which it was collected and for related purposes permitted by law.
We may use personal information to:
- a. provide, operate, maintain, update and protect our services;
- b. create, administer and manage customer accounts and user access;
- c. authenticate users, including through secure log-in methods such as magic links;
- d. verify businesses, users, licences, registrations and compliance records;
- e. provide modules and features, including MFR, compliance, project execution and Trust Centre features;
- f. generate, display or maintain Trust Centre profiles where activated by a customer;
- g. administer billing, subscriptions, renewals, invoices, payments and account management;
- h. provide customer support and respond to requests, comments and questions;
- i. investigate, troubleshoot and resolve service issues, errors and security matters;
- j. monitor platform health, usage trends, performance and user experience;
- k. improve our website, services, modules and features;
- l. develop new tools, modules, products or services for the Australian building and construction industry;
- m. send administrative, transactional, service-related and security communications;
- n. send marketing communications, product updates, offers or promotional material, where permitted by law;
- o. conduct business development, analytics, reporting and customer relationship management;
- p. protect our rights, property, users, customers and services;
- q. prevent, detect and investigate fraud, misuse, unauthorised access, unlawful activity and security incidents;
- r. comply with applicable laws, regulations, legal processes and enforceable government requests; and
- s. enforce our agreements, including the MSA.
7. Direct marketing
We may use your personal information to send marketing communications about Build Standard products, services, updates, events, offers or content that may be relevant to you or your business.
You may opt out of marketing communications at any time by using the unsubscribe link in the relevant communication or by contacting us at privacy@buildstandard.com.au.
Even if you opt out of marketing communications, we may still send administrative, transactional, security, account, billing and service-related communications.
8. Trust Center profiles and Trust Links
Build Standard may allow customers to create, activate, publish or share Trust Centre profiles, Trust Links or similar compliance profiles.
If a customer chooses to activate a public Trust Centre profile or generate a Trust Link, the business identity, licence, compliance and other information the customer chooses to include may be visible to third parties, such as banks, regulators, counterparties, clients, insurers, consultants or other persons with access to the profile or link.
Customers are responsible for deciding what information they upload to, include in, publish through or share via a Trust Centre profile or Trust Link.
If a customer shares a Trust Link with another person, information made available through that link may be accessible to anyone with the link, subject to any access controls available within the service.
Customers should not publish or share personal information through a Trust Centre profile or Trust Link unless they are authorised to do so.
9. How we disclose personal information
We may disclose personal information in the following ways.
8.1 Service providers and business partners
We may disclose personal information to third-party service providers and business partners who help us operate our business and provide our services, including:
- a. cloud hosting providers, including Supabase and AWS;
- b. payment processors, including Stripe;
- c. email delivery providers, including Resend;
- d. analytics, logging, monitoring and security providers;
- e. customer support and CRM providers;
- f. professional advisers, including lawyers, accountants, auditors and insurers;
- g. contractors and consultants who assist us to provide, support, secure or improve our services; and
- h. other technology, infrastructure and operational service providers.
We take reasonable steps to ensure that service providers handle personal information consistently with applicable privacy obligations and appropriate confidentiality and security requirements.
8.2 Trust Centre and customer-directed sharing
We may disclose or make available information through Trust Centre profiles, Trust Links or similar features where a customer chooses to activate, publish or share that information.
8.3 Aggregated or de-identified information
We may use or disclose aggregated or de-identified information for analytics, benchmarking, industry research, product improvement, reporting, marketing or other business purposes.
We will take reasonable steps to ensure that aggregated or de-identified information cannot reasonably be used to identify an individual.
8.4 Legal, regulatory and enforcement matters
We may disclose personal information where required or authorised by law, including to:
- a. courts, tribunals and dispute resolution bodies;
- b. law enforcement agencies;
- c. regulators and government authorities;
- d. building, construction or licensing bodies, including the Building and Plumbing Commission, Victorian Building Authority or equivalent bodies in other jurisdictions;
- e. tax authorities; and
- f. other persons where disclosure is required or permitted by law.
Where a request relates to Customer Information, and where legally permitted and commercially practicable, we may give the relevant customer notice of the request so that the customer may seek legal advice or protective orders.
8.5 Business transactions
If Build Standard is involved in an actual or proposed merger, acquisition, financing, restructure, insolvency, sale of assets or transfer of all or part of our business, we may disclose or transfer information to persons involved in that transaction, subject to appropriate confidentiality arrangements where practicable.
10. Data sovereignty and overseas disclosure
Build Standard is committed to Australian data sovereignty for core customer data.
The core databases used to store Customer Information, including sensitive business compliance records such as financial records, policies and site execution photos, are hosted onshore in Australia.
However, in operating our business and providing our services, some personal information may be accessed from, disclosed to, stored in or processed by service providers located outside Australia. This may include personal information used for log-in routing, email delivery, customer support, monitoring, analytics, billing, security, communications and other operational functions.
The countries in which overseas recipients are likely to be located may include the United States, Japan and any other countries in which our service providers or their sub-processors operate.
Where we disclose personal information to an overseas recipient, we will take reasonable steps to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information, unless an exception under the Privacy Act applies.
11. Cookies and similar technologies
We use cookies and similar technologies on our website and services.
These technologies may be used to:
- a. operate the website and services;
- b. authenticate users and manage sessions;
- c. remember preferences;
- d. support security and fraud prevention;
- e. analyse website and service usage;
- f. measure performance and diagnose errors;
- g. understand marketing effectiveness; and
- h. improve user experience.
You can manage cookies through your browser settings. If you disable cookies, some features of our website or services may not function properly.
We may use third-party analytics, security, hosting, email, customer support, payment and marketing tools. Those providers may collect or process information in accordance with their own privacy policies and contractual arrangements with us.
12. Security
Build Standard takes security seriously.
We use technical, organisational and administrative safeguards designed to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
These safeguards may include:
- a. access controls and permission settings;
- b. authentication controls;
- c. secure cloud hosting arrangements;
- d. tenant isolation controls;
- e. Row Level Security database architecture;
- f. encryption or secure transmission protocols where appropriate;
- g. logging, monitoring and audit processes;
- h. security testing and vulnerability management;
- i. confidentiality obligations for personnel and service providers; and
- j. incident response processes.
However, no internet transmission, cloud service or electronic storage method is completely secure. We cannot guarantee absolute security.
13. Data breaches
If we become aware of a privacy or data security incident involving personal information, we will assess the incident and take appropriate steps to contain, investigate and remediate it.
Where we are required by law to notify affected individuals, customers, the Office of the Australian Information Commissioner or another regulator, we will do so in accordance with applicable law.
If you believe there has been unauthorised access to, or disclosure of, personal information in connection with Build Standard, please contact us promptly at privacy@buildstandard.com.au.
14. Data retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide our services, manage customer accounts, comply with legal obligations, resolve disputes, maintain business records and enforce our agreements.
The retention of Customer Information may also be governed by the MSA and any applicable customer instructions, legal requirements or technical retention settings within the services.
When personal information is no longer required for a lawful purpose, we will take reasonable steps to destroy or de-identify it in accordance with applicable law.
15. Age limitations
Our services are designed for business and commercial use in the building and construction industry.
We do not knowingly collect personal information from anyone under 18 years old. If we become aware that we have collected personal information from a person under 18 without lawful basis, we will take reasonable steps to delete that information.
16. Access and correction
You may request access to personal information we hold about you.
You may also request that we correct personal information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
You can update some account and profile information directly within the Build Standard application.
For other access or correction requests, please contact us at privacy@buildstandard.com.au.
We may need to verify your identity before responding to your request. We will respond within a reasonable period and will provide access in the manner requested if it is reasonable and practicable to do so.
In some circumstances, we may refuse or limit access or correction where permitted by law. If we refuse a request, we will generally provide written reasons where it is reasonable and lawful to do so.
17. Complaints
If you believe that Build Standard has breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer in writing using the contact details below.
Please include enough information for us to understand and investigate your complaint.
We will consider your complaint and may contact you if we need further information. We will aim to respond in writing within 30 days.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, services, service providers or legal requirements.
We will publish the updated version on our website with an updated effective date.
If we make material changes, we may provide additional notice, such as by email, in-app notification or website notice.
19. Contact us
If you have any questions about this Privacy Policy or Build Standard’s privacy practices, please contact us at:
Build Standard Pty Ltd
Email: privacy@buildstandard.com.au
Address: SE 119, 87 Turner St, Port Melbourne VIC 3207
Contact our team at privacy@buildstandard.com.au