Privacy Policy
Last updated: 11 March 2026
1. About This Policy
This privacy policy explains how Advisa ("we", "us", "our") collects, uses, stores, and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Advisa is a practice management platform for Australian financial advisers. We provide client relationship management, compliance tools, scheduling, and communication services to financial advisory firms operating under Australian Financial Services Licences (AFSLs).
Entity: [Entity name placeholder]
ABN: [ABN placeholder]
Contact: privacy@advisa.app
2. Information We Collect
2.1 Information provided by financial advisers (our customers)
- Account registration details: name, email address, firm name, AFSL number
- Client records entered by advisers: names, contact details, financial information, notes, and documents as required for their advisory practice
- Communication content: emails and SMS messages sent through the platform
- Booking and calendar information
2.2 Information collected automatically
- Log data: IP address, browser type, pages visited, timestamps
- Device information: operating system, screen resolution
- Usage analytics: feature usage patterns, session duration
2.3 Information from third-party integrations
When advisers connect their work accounts, we access limited data through OAuth integrations as described in Section 5.
2.4 Early access submissions
- Email addresses submitted through the early access form on our website
3. How We Use Your Information
We use personal information to:
- Provide and maintain the Advisa platform and its features
- Send emails and SMS messages on behalf of advisers to their clients
- Synchronise calendar events for booking and scheduling
- Process payments for platform services (e.g., SMS credits)
- Communicate with advisers about their account, service updates, and support
- Monitor and improve platform security, performance, and reliability
- Comply with legal obligations including the Privacy Act 1988
We do not sell personal information to third parties. We do not use client data entered by advisers for any purpose other than providing the platform service.
4. Data Storage and Security
All data is hosted entirely within Australia in the Sydney region (AWS ap-southeast-2) through our infrastructure providers. Your data never leaves Australia.
Security measures
- Data is encrypted at rest and in transit (TLS 1.2+)
- OAuth tokens are encrypted using AES-256-GCM before storage
- Row-level security (RLS) enforced at the database layer, ensuring each firm's data is completely isolated from other firms
- Authentication via secure, HTTP-only session tokens
- All API endpoints require authentication and are scoped to the requesting adviser's firm
- Administrative access is restricted and audited
5. Third-Party Integrations and OAuth
Advisa allows financial advisers to connect their existing work email and calendar accounts. These integrations use industry-standard OAuth 2.0. We never see or store your email or calendar passwords.
5.1 Google Workspace Integration
When an adviser connects their Google account, we request the following permissions:
- openid, email, profile: To identify which Google account is connected and display the adviser's name and email address within Advisa
- gmail.send: To send emails on behalf of the adviser (e.g., appointment confirmations, review reminders) from their real business email address. We can only send emails. We cannot and do not read, access, or store the contents of the adviser's inbox or any received emails.
- calendar (read/write): To read the adviser's calendar availability and create/update calendar events for client bookings and appointments
5.2 Microsoft 365 Integration
When an adviser connects their Microsoft account, we request the following permissions:
- User.Read: To identify which Microsoft account is connected
- Mail.Send: To send emails on behalf of the adviser from their Outlook/Microsoft 365 email address. We can only send emails. We cannot and do not read, access, or store the contents of the adviser's mailbox.
- Calendars.ReadWrite: To read calendar availability and create/update events for client bookings
- offline_access: To maintain the connection without requiring the adviser to re-authenticate each session
5.3 Purpose of Email and Calendar Integrations
Financial advisers connect their work accounts so that all client communications (appointment confirmations, review reminders, follow-ups) are sent from their real business email address, not from the Advisa platform domain. This ensures clients receive communications from a trusted, recognised address.
Calendar sync allows Advisa to manage bookings against the adviser's real calendar, preventing double-bookings and ensuring clients can only book available times.
5.4 OAuth Token Storage
OAuth access and refresh tokens are encrypted using AES-256-GCM before being stored. Tokens are scoped to the minimum required permissions. Advisers can disconnect their accounts at any time, which immediately revokes and deletes stored tokens.
5.5 SMS (Twilio)
SMS messages are sent via Twilio's API. Each firm is assigned a dedicated Australian mobile number. Message content and recipient numbers are transmitted to Twilio for delivery. Twilio's privacy policy applies to their processing of message data.
6. Data Retention
- Active accounts: Data is retained for as long as the adviser's account is active and as required for platform operation
- Closed accounts: Upon account closure, adviser and client data is deleted within 90 days, except where retention is required by law
- Communication logs: Records of sent emails and SMS messages are retained as part of the adviser's compliance trail
- Early access submissions: Email addresses are retained until the submitter requests removal or the early access programme concludes
7. Disclosure of Personal Information
We may disclose personal information to:
- Infrastructure providers: Our hosting and database services are provided by Vercel (compute) and Supabase (database), both operating in the Sydney, Australia region
- Communication providers: Twilio (SMS delivery), and email delivery via the adviser's own connected email account (Google or Microsoft)
- Payment processors: Stripe processes payments for SMS credit top-ups. Stripe's privacy policy applies to payment data.
- Law enforcement: Where required by Australian law, court order, or regulatory requirement
We do not disclose adviser client data to any third party except as required to deliver the platform service (as described above) or as required by law.
8. Your Rights Under the Australian Privacy Principles
Under the APPs, you have the right to:
- Access personal information we hold about you
- Request correction of inaccurate or outdated information
- Request deletion of your personal information (subject to legal retention requirements)
- Withdraw consent for specific data processing activities
- Lodge a complaint about our handling of your personal information
To exercise any of these rights, contact us at privacy@advisa.app.
9. Complaints
If you believe we have breached the Australian Privacy Principles, please contact us at privacy@advisa.app. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
10. Changes to This Policy
We may update this privacy policy from time to time. Where changes are material, we will notify affected users via email or in-platform notification. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact Us
For any questions about this privacy policy or our data practices:
Advisa
[Entity name placeholder]
ABN: [Placeholder]
Email: privacy@advisa.app