Privacy Policy

Effective Date: March 23, 2026

  1. About This Policy

IONYX Pty Ltd (ABN 22 605 061 327) and its controlled entities (“IONYX”, “we”, “us”, or “our”) are committed to protecting the privacy and personal information of individuals with whom we interact.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in connection with:

  • Our SaaS platforms (including Local Suppliers Portal, Cost Tracker, and other hosted systems)
  • Our digital and professional services
  • Our websites and related business activities

This policy applies to clients, users, employees, contractors, suppliers, and other stakeholders.

  1. Legal Framework

IONYX handles personal information in accordance with:

  • The Privacy Act 1988 (Cth) and the Australian Privacy Principles
  • The General Data Protection Regulation (GDPR) where applicable
  • Other relevant international privacy and data protection laws where services are provided globally
  1. What Information We Collect

We may collect personal information including:

  • Name
  • Company name
  • Contact details (email, phone, address)
  • Billing information
  • Account login details
  • Professional information
  • IP address and usage data
  • Location data (where enabled)
  • Any information voluntarily submitted through our platforms

We collect only information necessary to provide our services or meet legal obligations.

We do not sell personal information.

  1. Sensitive Information

We do not intentionally collect sensitive information unless required for specific client configurations or legal obligations.

  1. How We Use Personal Information

We use personal information to:

  • Provide and manage our SaaS and digital services
  • Process subscriptions and payments
  • Deliver client projects
  • Communicate with users and clients
  • Provide customer support
  • Improve system performance and security
  • Comply with legal obligations
  • Manage internal business operations

We process personal information only for legitimate business purposes.

  1. Disclosure of Information

We may disclose personal information:

  • To our controlled entities where required for service delivery
  • To subcontractors and service providers under confidentiality obligations
  • To cloud hosting and infrastructure providers
  • Where required by law or regulatory authority
  • In connection with legal claims or enforcement

Disclosure is limited to the minimum necessary information.

  1. Data Storage and Security

IONYX implements technical and organisational security controls to protect personal information, including:

  • Role-based access controls
  • Encryption in transit and at rest where supported
  • Multi-factor authentication
  • Secure cloud hosting environments
  • Regular security monitoring and updates

Information may be stored electronically, including on cloud servers that may be located outside Australia.

Despite reasonable safeguards, no system is completely secure.

  1. Data Retention

Personal information is retained only as long as necessary for:

  • Contractual obligations
  • Legal requirements
  • Legitimate business purposes

Information that is no longer required is securely destroyed or de-identified in accordance with our internal data protection controls.

  1. International Data Transfers

Where personal information is transferred outside Australia (including to cloud providers), IONYX takes reasonable steps to ensure appropriate safeguards are in place in accordance with applicable law.

  1. Cookies and Analytics

We use cookies and similar technologies to:

  • Improve user experience
  • Monitor service performance
  • Analyse usage patterns

Users may manage cookie preferences through browser settings.

Third-party tools (such as Google Analytics or reCAPTCHA) may collect limited technical information as described in their respective privacy policies.

  1. Your Rights

Depending on applicable law, individuals may have the right to:

  • Access personal information held about them
  • Request correction of inaccurate information
  • Request deletion where legally permissible
  • Object to certain processing activities
  • Withdraw consent (where processing is consent-based)

Requests may be submitted to the contact details below.

  1. Complaints

If you believe we have breached privacy obligations, you may contact us. We aim to respond within 30 days.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

  1. Changes to This Policy

IONYX may update this Privacy Policy from time to time. The current version will always be available on our website.

  1. Contact Us

For privacy enquiries or requests:

Email: privacy@ionyx.com.au

Address: Level 6/200 Adelaide St, Brisbane City QLD 4000