Skip to main content
Legal

Privacy Policy

Last updated: 18 September 2026

Flowzi (ABN 30 688 278 079) builds software for practices that carry statutory obligations over other people’s records. We would not ask a regulated practice to trust us with their client files if we were vague about our own handling, so this policy says plainly what we collect — through this website, and through the social and messaging accounts a practice connects to Pulse — why we hold it, where it lives, and how to have it removed. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

1. What this policy covers

Sections 3 onward cover flowzi.com.au — the Pulse waitlist, the product brief, Insights and Notes, and any email you send us from here. No client or case data is collected through this website.

Section 2 covers something different: the social and messaging accounts a practice can connect to Pulse. It is here because that feature reaches people who have no relationship with us at all — someone who messages a practice on Instagram has not agreed to anything of ours, and should still be able to find out what happens to that message.

The rest of what a practice holds inside Pulse is governed by our agreement with that practice, not by this page. The agency remains responsible for its clients’ information; we hold and process it on the agency’s instructions, including the retention, archive, redact and purge obligations a registered migration practice has to meet. Those terms sit in the agreement.

2. Social and messaging channels connected to Pulse

One part of Pulse is described here rather than left to the agreement, because it can affect people who have never visited this website or hired a migration agent — someone who sends a direct message or leaves a comment on a practice’s social account. This section is for them, and for practices deciding whether to connect an account.

Enquiries reach a practice through Messenger, Instagram, TikTok and WhatsApp, and a practitioner’s obligation to keep a record of client communications doesn’t stop at whichever channel the client happened to choose. Pulse can therefore connect to a practice’s own business accounts on those platforms, so that a conversation which starts there reaches the client’s file instead of living on one staff member’s phone.

Reading only, in one direction

The connection carries messages inward and nothing outward. Pulse does not send a message, post, comment or reply on a practice’s behalf, and does not ask the platforms for permission to — the write permissions were deliberately left out of what we request. Staff reply from the platform’s own app, exactly as they did before. If that ever changes, it will require a fresh consent from the practice and a change to this policy.

Messaging a practice does not create a client record

An incoming sender or commenter is held as an opaque platform identity — the id the platform issues, with whatever display name or handle it supplies. It is not matched to a person, and no client file is created from it. A staff member has to deliberately promote that identity onto a contact before it becomes part of anyone’s file, and that action is logged. Until then it sits in a triage queue, where staff can also dismiss, block or erase it.

How long it stays

Each practice sets a retention period for this staged material. The default is 90 days, and the software will not accept a value below 7 days or above 365 — the ceiling exists so that a message from someone who never became a client cannot sit there indefinitely. A daily job deletes staged identities, staged comments and the raw delivery records once they pass that period, whether or not anyone has looked at them.

Where a sender is promoted onto a client file, the conversation becomes part of that file and takes on the practice’s retention obligations instead — for a registered migration practice, generally seven years — along with the archive, redact and purge controls that apply to every other record in it.

Who is responsible for it

The practice that connected the account is responsible for the records that result. Flowzi receives and stores them on that practice’s instructions under our agreement with it. So if you have messaged a practice and want your message deleted, ask the practice — they can erase it directly. You can also write to us at founders@flowzi.com.au and we will pass it to them. Meta and TikTok handle your information on their side under their own policies, which we don’t control: see Meta’s Privacy Policy and TikTok’s Privacy Policy.

Where this is up to

WhatsApp Business capture is running in production. The Facebook, Instagram and TikTok connections are built but not yet enabled for any practice: each platform has to review our application before a real account can be connected, and this policy is part of what they review. We would rather say that plainly here than describe a capability as live before it is.

3. What this website collects

Deliberately little. There are no accounts on this site and nothing to log into.

We do not collect payment details, government identifiers, or any of the sensitive information defined in the Privacy Act through this site. Please don’t send us client names, visa details or case documents by email or through the waitlist form — this site is not the place for them, and we will delete anything of that kind we receive.

4. How we use it

We do not use your information to build a profile of you, and we do not run advertising on this site.

5. Where it lives and how we protect it

Waitlist records are stored in Amazon Web Services in the Sydney region (ap-southeast-2), and confirmation email is sent from the same region. The specifics:

No transmission or storage method is completely secure, and we won’t claim otherwise. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

6. Who else sees it

We do not sell, rent or trade personal information, here or in Pulse. For this website, we share it only with the providers that run the site, and only to the extent they need it (for the platforms behind a connected social account, see section 2):

Some of these providers operate infrastructure outside Australia, so your information may be handled overseas by them, including in the United States and the European Union. We take reasonable steps to ensure any overseas recipient handles it consistently with the Australian Privacy Principles.

7. Cookies and analytics

This site sets no cookies of its own. Where Google Analytics 4 is enabled, it sets its own cookies to distinguish one visit from another and reports to us in aggregate — page views, referrers, approximate location. We never see individual browsing histories through it.

You can block or clear cookies in your browser settings, or install Google’s opt-out browser add-on. Everything on this site — including the waitlist form — works with cookies disabled.

8. How long we keep it

Those periods are about this website only. Material captured from a connected social account keeps its own clock, described in section 2, and the seven-year retention Pulse applies to client files is an obligation owed to the practice under its agreement with us. Neither has anything to do with the email address you give this website, and neither stops us deleting it on request.

9. Your rights

Email founders@flowzi.com.au and we’ll respond within 30 days. We don’t charge for access requests. If you’re not satisfied with how we’ve handled a privacy complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Our Insights and Notes link out to legislation, regulator guidance and other sources. We don’t control those sites and aren’t responsible for their privacy practices — their policies apply once you leave ours.

11. Children

This site is for practitioners and the people who run practices. It isn’t directed at children, and we don’t knowingly collect personal information from anyone under 16. If we find we have, we’ll delete it.

12. Changes to this policy

We’ll update this policy as our practices change — most obviously when Pulse moves from waitlist to pilot. The current version always lives at this address, with the date it last changed at the top. If a change materially affects people already on the waitlist, we’ll email them rather than rely on you noticing.

Questions about this policy

Write to us at founders@flowzi.com.au. A person reads that inbox.