Privacy Policy
Last updated: 18 September 2026
Flowzi (ABN 30 688 278 079) builds software for practices that carry statutory obligations over other people’s records. We would not ask a regulated practice to trust us with their client files if we were vague about our own handling, so this policy says plainly what we collect — through this website, and through the social and messaging accounts a practice connects to Pulse — why we hold it, where it lives, and how to have it removed. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
1. What this policy covers
Sections 3 onward cover flowzi.com.au — the Pulse waitlist, the product brief, Insights and Notes, and any email you send us from here. No client or case data is collected through this website.
Section 2 covers something different: the social and messaging accounts a practice can connect to Pulse. It is here because that feature reaches people who have no relationship with us at all — someone who messages a practice on Instagram has not agreed to anything of ours, and should still be able to find out what happens to that message.
The rest of what a practice holds inside Pulse is governed by our agreement with that practice, not by this page. The agency remains responsible for its clients’ information; we hold and process it on the agency’s instructions, including the retention, archive, redact and purge obligations a registered migration practice has to meet. Those terms sit in the agreement.
2. Social and messaging channels connected to Pulse
One part of Pulse is described here rather than left to the agreement, because it can affect people who have never visited this website or hired a migration agent — someone who sends a direct message or leaves a comment on a practice’s social account. This section is for them, and for practices deciding whether to connect an account.
Enquiries reach a practice through Messenger, Instagram, TikTok and WhatsApp, and a practitioner’s obligation to keep a record of client communications doesn’t stop at whichever channel the client happened to choose. Pulse can therefore connect to a practice’s own business accounts on those platforms, so that a conversation which starts there reaches the client’s file instead of living on one staff member’s phone.
- Which accounts: a Facebook Page and its Messenger inbox, the Instagram professional account linked to that Page, a TikTok Business account, and WhatsApp Business. Only accounts the practice itself owns and connects — never a personal account, and never yours.
- Who connects it: a staff member the practice has authorised to manage channels, through the platform’s own consent screen. Flowzi never asks for, sees or holds anyone’s social login credentials.
- What we receive: direct messages sent to the connected account and comments left on its posts — the text, any attached media, the platform’s own identifier for the sender, the display name or handle the platform supplies, timestamps, and where the platform provides one, a link back to the comment.
- What we don’t receive: anything about your activity away from the connected account. No friends or followers, no advertising or audience data, no browsing history, and nothing from accounts the practice has not connected.
Reading only, in one direction
The connection carries messages inward and nothing outward. Pulse does not send a message, post, comment or reply on a practice’s behalf, and does not ask the platforms for permission to — the write permissions were deliberately left out of what we request. Staff reply from the platform’s own app, exactly as they did before. If that ever changes, it will require a fresh consent from the practice and a change to this policy.
Messaging a practice does not create a client record
An incoming sender or commenter is held as an opaque platform identity — the id the platform issues, with whatever display name or handle it supplies. It is not matched to a person, and no client file is created from it. A staff member has to deliberately promote that identity onto a contact before it becomes part of anyone’s file, and that action is logged. Until then it sits in a triage queue, where staff can also dismiss, block or erase it.
How long it stays
Each practice sets a retention period for this staged material. The default is 90 days, and the software will not accept a value below 7 days or above 365 — the ceiling exists so that a message from someone who never became a client cannot sit there indefinitely. A daily job deletes staged identities, staged comments and the raw delivery records once they pass that period, whether or not anyone has looked at them.
Where a sender is promoted onto a client file, the conversation becomes part of that file and takes on the practice’s retention obligations instead — for a registered migration practice, generally seven years — along with the archive, redact and purge controls that apply to every other record in it.
Who is responsible for it
The practice that connected the account is responsible for the records that result. Flowzi receives and stores them on that practice’s instructions under our agreement with it. So if you have messaged a practice and want your message deleted, ask the practice — they can erase it directly. You can also write to us at founders@flowzi.com.au and we will pass it to them. Meta and TikTok handle your information on their side under their own policies, which we don’t control: see Meta’s Privacy Policy and TikTok’s Privacy Policy.
Where this is up to
WhatsApp Business capture is running in production. The Facebook, Instagram and TikTok connections are built but not yet enabled for any practice: each platform has to review our application before a real account can be connected, and this policy is part of what they review. We would rather say that plainly here than describe a capability as live before it is.
3. What this website collects
Deliberately little. There are no accounts on this site and nothing to log into.
- Waitlist signup: your email address, which form on the page you used, the time you signed up, the referring page, and any campaign tags (UTM parameters) in the link that brought you here.
- Technical information: a one-way salted hash of your IP address — not the address itself — used to rate-limit the signup form; your browser’s user-agent string; and the two-letter country our hosting provider derives from your connection.
- Correspondence: whatever you choose to put in an email to us, and our reply.
- Analytics: if analytics is enabled on the site, Google Analytics 4 records aggregate page views, referrers and approximate location. See section 7.
We do not collect payment details, government identifiers, or any of the sensitive information defined in the Privacy Act through this site. Please don’t send us client names, visa details or case documents by email or through the waitlist form — this site is not the place for them, and we will delete anything of that kind we receive.
4. How we use it
- To confirm your signup — one automated email acknowledging that you’re on the list.
- To tell you when pilots open, and to send occasional updates about Pulse. Nothing else. Every email we send comes from a real address you can reply to, and you can ask us to stop at any time.
- To answer you when you get in touch, and to arrange pilot or design-partner conversations.
- To keep the site working — the hashed IP exists solely to stop one source flooding the signup form, and the aggregate analytics tell us which channels actually reach practitioners.
- To meet our legal obligations where we are required to.
We do not use your information to build a profile of you, and we do not run advertising on this site.
5. Where it lives and how we protect it
Waitlist records are stored in Amazon Web Services in the Sydney region (ap-southeast-2), and confirmation email is sent from the same region. The specifics:
- The site is served over HTTPS; data is encrypted in transit and at rest.
- Your IP address is hashed with a secret salt before it is written anywhere, so the raw address is never stored and the hash can’t be reversed back to it.
- Rate-limiting records expire automatically one hour after they are written.
- Access to the waitlist is restricted to named Flowzi people, behind single sign-on with an explicit allowlist.
No transmission or storage method is completely secure, and we won’t claim otherwise. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
6. Who else sees it
We do not sell, rent or trade personal information, here or in Pulse. For this website, we share it only with the providers that run the site, and only to the extent they need it (for the platforms behind a connected social account, see section 2):
- Amazon Web Services — waitlist storage and outbound email, in the Sydney region.
- Vercel — hosting and content delivery. Its edge network handles your request and supplies the country code described above.
- Google — web fonts, which means your browser discloses its IP address to Google when a page loads; and Google Analytics where enabled.
- Microsoft — the identity provider for our own staff sign-in.
- Legal disclosure — where we are required by law, or in response to a valid request from a court or public authority.
Some of these providers operate infrastructure outside Australia, so your information may be handled overseas by them, including in the United States and the European Union. We take reasonable steps to ensure any overseas recipient handles it consistently with the Australian Privacy Principles.
7. Cookies and analytics
This site sets no cookies of its own. Where Google Analytics 4 is enabled, it sets its own cookies to distinguish one visit from another and reports to us in aggregate — page views, referrers, approximate location. We never see individual browsing histories through it.
You can block or clear cookies in your browser settings, or install Google’s opt-out browser add-on. Everything on this site — including the waitlist form — works with cookies disabled.
8. How long we keep it
- Waitlist records: until our pilot programme concludes, or until you ask us to delete them — whichever comes first.
- Rate-limiting records: one hour.
- Email correspondence: as long as the matter is live, then archived.
- Analytics: per Google’s retention settings for the property.
Those periods are about this website only. Material captured from a connected social account keeps its own clock, described in section 2, and the seven-year retention Pulse applies to client files is an obligation owed to the practice under its agreement with us. Neither has anything to do with the email address you give this website, and neither stops us deleting it on request.
9. Your rights
- Access — ask what we hold about you, and we’ll tell you.
- Correction — have anything inaccurate or out of date fixed.
- Deletion — have your record removed, subject to anything we’re legally required to keep.
- Opt out — stop the emails, by replying to any of them or writing to us.
Email founders@flowzi.com.au and we’ll respond within 30 days. We don’t charge for access requests. If you’re not satisfied with how we’ve handled a privacy complaint, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
10. Links to other sites
Our Insights and Notes link out to legislation, regulator guidance and other sources. We don’t control those sites and aren’t responsible for their privacy practices — their policies apply once you leave ours.
11. Children
This site is for practitioners and the people who run practices. It isn’t directed at children, and we don’t knowingly collect personal information from anyone under 16. If we find we have, we’ll delete it.
12. Changes to this policy
We’ll update this policy as our practices change — most obviously when Pulse moves from waitlist to pilot. The current version always lives at this address, with the date it last changed at the top. If a change materially affects people already on the waitlist, we’ll email them rather than rely on you noticing.
Questions about this policy
Write to us at founders@flowzi.com.au. A person reads that inbox.