Privacy Policy
Last updated: 14 February 2026
Agentive Group Co Pty Ltd (ABN 54 695 269 222) ("Agentive Group", "we", "us", "our") is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs"). This Privacy Policy describes how we collect, use, disclose, and store personal information through the Agentive Invoice Dashboard platform ("Service").
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, company name, and business details when you register for an account.
- Invoice data: Invoices, vendor information, financial amounts, line items, and related business documents you upload or process through the Service.
- Communication preferences: Notification settings, Slack webhook URLs, and other configuration preferences.
1.2 Information from Third-Party Services
When you connect third-party services, we may collect:
- Google (Gmail): Email metadata and invoice attachments from your connected Gmail account, accessed via OAuth with read-only permissions. We only access emails relevant to invoice processing.
- QuickBooks Online: Company information, chart of accounts, vendor records, and bill data, accessed via OAuth for the purpose of syncing approved invoices.
- Slack: We send notifications to your designated Slack channel via incoming webhook. We do not read or access your Slack messages or workspace data.
1.3 Information Collected Automatically
- Usage data: Pages visited, features used, timestamps, and general interaction patterns with the Service.
- Technical data: Browser type, device information, IP address, and similar technical information necessary for the operation of the Service.
2. How We Use Your Information
We use your personal information to:
- Provide, operate, and maintain the Service
- Process and classify invoices using AI-assisted extraction and validation
- Sync approved invoices with your connected accounting software
- Send notifications about invoice status via email or Slack
- Improve the accuracy and performance of the Service
- Respond to your enquiries and provide customer support
- Comply with legal obligations and enforce our terms
3. AI Processing
The Service uses artificial intelligence (OpenAI's GPT-4o) to classify, extract, and validate invoice data. When processing your invoices:
- Invoice content (email text, PDF documents) is sent to OpenAI's API for processing
- We use OpenAI's API with data processing agreements in place. As per OpenAI's API data usage policy, data sent via the API is not used to train their models
- Extracted data is stored in our secure database for your access and review
4. Disclosure of Information
We may disclose your personal information to:
- Service providers: Third-party providers who assist in operating the Service, including cloud hosting (Supabase, Netlify), AI processing (OpenAI), and workflow automation (n8n). These providers are bound by confidentiality obligations.
- Connected services: Third-party platforms you choose to integrate (Google, Intuit QuickBooks, Slack) as authorised by you.
- Legal requirements: When required by law, regulation, or legal process, or to protect the rights, property, or safety of Agentive Group or others.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
5. Data Storage and Security
Your data is stored on servers operated by Supabase (cloud infrastructure). While we endeavour to use service providers with data centres in Australia where available, some data may be processed or stored in overseas locations, including the United States, in connection with third-party service providers (e.g., OpenAI, Netlify).
In accordance with APP 8, where your data is disclosed to overseas recipients, we take reasonable steps to ensure that the overseas recipient handles your information in accordance with the APPs.
We protect your information using:
- Encryption in transit (TLS/SSL) and at rest
- Row-level security and tenant isolation in our database
- OAuth 2.0 for third-party service authentication (no passwords stored)
- API key hashing (SHA-256) for external integrations
- Role-based access controls
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Upon account termination:
- We will make your data available for export for 30 days
- After the export period, we will securely delete your data within 90 days
- We may retain certain data as required by law or for legitimate business purposes (e.g., audit logs, legal compliance)
7. Your Rights Under the Privacy Act
Under the APPs, you have the right to:
- Access: Request access to the personal information we hold about you (APP 12)
- Correction: Request correction of any inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information (APP 13)
- Complaint: Lodge a complaint about our handling of your personal information
To exercise any of these rights, contact us using the details in Section 11 below. We will respond to access and correction requests within 30 days.
8. Cookies and Tracking
The Service uses essential cookies and local storage for authentication and session management. We do not use third-party tracking cookies or advertising trackers. Authentication tokens are stored securely in your browser's local storage and are required for the Service to function.
9. Children's Privacy
The Service is designed for business use and is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes by email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.
11. Contact Us and Complaints
If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, please contact us at:
Privacy Officer
Agentive Group Co Pty Ltd
Email: doccubot@agentivegroup.ai
Website: https://doccubot.ai
We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
Post: GPO Box 5218, Sydney NSW 2001