HEXTrack

HexTrack — Privacy Policy

Effective date: 28 July 2026

Applies to: personal information handled by HexTrack in connection with accounts billed in Australia. This policy is written for the *Privacy Act 1988* (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs).

ÓRUS DIGITAL (CNPJ 38.084.946/0001-56) (HexTrack, we, us, our), is the entity responsible for handling personal information as described below. We are committed to handling personal information in accordance with the Privacy Act and the APPs.


1. Two kinds of data, two different roles

HexTrack handles personal information in two distinct capacities. Understanding which applies is important, because it determines who is responsible for it.

DataOur roleYour role
Your leads’ and customers’ data — conversation content, phone numbers, names, email addresses, deal values, pipeline stage, attribution identifiersProcessor — we handle it on your behalf and on your instructions, to run the serviceController — you decide the purpose and are the APP entity responsible for it
Your own account and billing data — name, business/tax number, email, address, payment method, usage logsController — we decide the purposeData subject

Australian privacy law does not use the words “controller” and “processor”; both parties are “APP entities” where the Act applies to them. We use those terms here for clarity and for customers who are familiar with them. In substance:

  • For your leads’ data, you are the entity that decides why it is collected and used; we act only on your instructions to deliver the service and do not use it for our own purposes. You are responsible for having any consents and notices your obligations require, including for AI-assisted processing and for sending conversion events to Meta and Google.
  • For your own account data, we decide the purpose and are directly responsible to you under this policy.

2. What we collect

As controller, about you (the account holder):

  • Registration: name, email, phone, company name, business or tax number.
  • Billing: payment details, billing address and transaction history, processed by Stripe.
  • Usage: access logs, IP address, date and time of access, browser and device data.
  • Support: the messages and information you exchange with us.

As processor, on your behalf (your leads’ data):

  • the content of WhatsApp and other channel conversations between your team and your leads;
  • phone numbers, names, email addresses and other contact details of your leads;
  • deal values and pipeline data;
  • attribution data (campaign, ad set, ad, trackable link, click identifiers such as gclid and fbclid, and UTM parameters).

We collect personal information by lawful and fair means, generally directly from you or from your use of the platform. Where practicable, you may deal with us anonymously or using a pseudonym (APP 2), although we cannot provide the service without the account information described above.

We do not intentionally collect sensitive information (as defined in the Privacy Act). If you choose to load sensitive information about your leads into the platform, you are responsible for obtaining the consent that APP 3 requires.


3. Purposes and basis for handling

We collect, hold, use and disclose your account data for the following purposes. The basis for each, under the Privacy Act, is that the handling is reasonably necessary for our functions or activities, is required by law, or is done with your consent.

HandlingPurposeBasis
Registration and accountCreate and administer your accessNecessary to provide the service you requested
Billing through StripeCharge the subscription and issue tax invoicesNecessary to provide the service; legal (tax) obligations
Running the productDeliver attribution, CRM, messaging, AI and reportingNecessary to provide the service
Access logs and fraud preventionProtect the platform and meet audit and security dutiesLegal obligations; our legitimate functions
Product improvement on de-identified dataImprove the service using aggregated, de-identified dataOur legitimate functions
Service communicationsSend you operational, billing and security noticesNecessary to provide the service
Direct marketingSend you product news and offersWith your consent / where permitted; you can opt out at any time (APP 7)

For your leads’ data, you determine the purpose and are the APP entity responsible — including for AI reading conversation content and for sending conversion events to Meta and Google. We handle it only to deliver the service to you.


4. AI features and your data

AI-assisted features read conversation content and CRM records to classify pipeline stages, qualify leads, summarise, and draft replies. To produce the requested output, excerpts of that content are sent to our AI sub-processors, currently OpenAI and Anthropic, whose processing takes place in the United States.

Accounts on the 14-day trial and in the public demo never reach any AI provider. The restriction is enforced technically at the point where the AI provider is resolved, so it also covers background jobs and webhooks — not only the screens a user sees.

AI processing is automated and probabilistic. Where an individual is subject to an AI-assisted decision relating to their lead data, the request for human review is directed to the customer who controls that data. Customers are responsible for informing their own leads about AI-assisted processing where their obligations require it.


5. Who we share data with (sub-processors)

We disclose personal information only to the extent necessary to run the service, and to the sub-processors listed below. Each is bound by contract to handle the data only on our instructions and to protect it to a standard consistent with this policy and the APPs.

Sub-processorPurposeData involvedLocation
Stripe, Inc.Payment processing and tax calculation (AUD)Billing data (name, address, payment method, transaction history)United States and worldwide
OpenAI, L.L.C.AI classification, qualification, summaries, assisted repliesConversation excerpts and CRM contextUnited States
Anthropic, PBCAI classification, summaries and assisted repliesConversation excerpts and CRM contextUnited States
Meta Platforms, Inc.WhatsApp Business channel and delivery of conversion eventsPhone numbers, message delivery data, conversion identifiersUnited States and worldwide
Google LLCUpload of conversions to Google AdsClick identifiers (gclid) and conversion eventsUnited States and worldwide
Transactional email providerTransactional email (verification, billing, invitations, support)Names, email addresses, message contentUnited States and worldwide
Cloud hosting providerApplication and database hostingAll hosted data, encrypted at restUnited States and worldwide

We may also disclose personal information where required or authorised by law, in response to a lawful request from an authority, to establish or defend our legal rights, or in connection with a corporate transaction — in which case the protections in this policy carry over to the recipient.

We do not sell personal information.


6. Cross-border disclosure

The platform runs on a single encrypted database rather than per-country data residency, so your data — and your leads’ data — may be handled outside Australia, including in the United States, by the sub-processors listed in section 5.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, principally through contractual data-protection obligations with each sub-processor. Under APP 8.1 we remain accountable for that information. Our hosting sub-processor is identified in section 5.


7. How long we keep data

DataRetention period
Account and CRM dataWhile the account is active
Application access logsAt least 6 months
Tax and billing recordsFor the periods required by Australian law (generally 5 years)
After the account closes30-day export grace window, then deletion, except records we must keep by law

We take reasonable steps to destroy or de-identify personal information we no longer need for any purpose for which it may be used or disclosed, and that we are not required by law to retain (APP 11.2).


8. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11). These steps include encryption in transit (TLS/HTTPS), encryption at rest, additional field-level encryption for sensitive credentials, role-based access control, separation between accounts and environments, logging and backups.

No system is completely secure. If we become aware of an eligible data breach that is likely to result in serious harm, we will act on it and, where required, notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act). Where the breach affects your leads’ data, we will notify you as the responsible party so that you can meet your own obligations.


9. Your rights

Under the Privacy Act and the APPs you may:

  • Access the personal information we hold about you (APP 12);
  • Correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13);
  • Deal with us anonymously or by pseudonym where practicable (APP 2);
  • Opt out of direct marketing at any time (APP 7);
  • Ask us to stop handling your information based on consent, and withdraw that consent; and
  • Complain about how we have handled your personal information (see section 11).

We will respond to access and correction requests within a reasonable time (generally within 30 days). Access is normally free; if a cost applies to a more involved request, we will tell you first. We may decline access or correction where the Privacy Act permits, and we will give you reasons if we do.

Where the request relates to a customer’s lead: the request is directed to that customer, who is the responsible party, and we support them as processor. Where the request relates to your own account data: send it to our Privacy Officer at contato@hextrack.com.br.


10. Cookies

Our website and app use cookies and similar technologies. How we use them, and your choices, are described in our Cookie Policy.


11. Complaints

If you believe we have breached the APPs or mishandled your personal information, please contact our Privacy Officer at contato@hextrack.com.br. We will acknowledge your complaint and aim to resolve it within a reasonable time, generally 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au, phone 1300 363 992, or GPO Box 5288, Sydney NSW 2001.


12. Changes and contact

We may update this policy from time to time. We will notify you of material changes by email and/or in-app notice. The version in force is always the one published here, with its effective date.

Privacy Officer
ÓRUS DIGITAL (CNPJ 38.084.946/0001-56)
Email: contato@hextrack.com.br
General enquiries: contato@hextrack.com.br