Privacy Policy
Last Updated: 4 November 2025
1. Introduction
evalu8 ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using evalu8, you consent to the collection and use of your information as described in this Privacy Policy.
2. Information We Collect
2.1 Personal Information
We collect the following personal information:
- Account Information: Name, email address, password (encrypted)
- Business Information: Company name, ABN, business address
- Contact Information: Email addresses for invitations and notifications
- Usage Data: IP address, browser type, device information, access times
- Communications: Messages sent through the platform, support emails
2.2 Business Content
We collect and store business content you upload or create on the platform:
- Tender documents and Scope of Works (SoW) files
- Schedules of Costs and line item data
- Quote documents and pricing information
- Project information and metadata
- Communications between head contractors and subcontractors
2.3 Automatically Collected Information
- Cookies and similar tracking technologies
- Log files (IP address, browser type, pages visited, time stamps)
- Platform usage analytics
- Error logs and diagnostic information
3. How We Use Your Information
We use your personal information for the following purposes:
3.1 Service Provision
- Create and manage your account
- Process and display tender documents, schedules, and quotes
- Extract information from documents using AI/ML processing
- Generate comparisons and analytics
- Facilitate communication between users
- Send invitations to subcontractors on your behalf
3.2 Platform Improvement
- Monitor and improve platform performance
- Debug and fix technical issues
- Analyze usage patterns (aggregated and anonymized)
- Develop new features and functionality
3.3 Communication
- Send transactional emails (account verification, password resets, invitations)
- Provide customer support and respond to inquiries
- Send important platform updates and security notices
- Notify you of beta testing opportunities (with consent)
3.4 Legal Compliance
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service
- Protect against fraud, abuse, and security threats
- Respond to lawful requests from authorities
4. AI Processing & Third-Party Services
4.1 OpenAI Processing
We use OpenAI's API to process your documents (Scope of Works, quotes) to extract information, generate summaries, and provide intelligent features. When you upload documents:
- Document content is sent to OpenAI's servers for processing
- OpenAI processes data according to their API terms and does not use API data to train their models
- Processed data is returned to our platform and stored in our systems
4.2 Firebase & Google Cloud
We use Firebase (Google Cloud) for authentication, database, and file storage:
- Authentication data is managed by Firebase Authentication
- Application data is stored in Firestore (NoSQL database)
- Files are stored in Firebase Cloud Storage
- Data is stored in Google's Asia-Pacific region (Australia/Sydney when possible)
4.3 Other Third-Party Services
We may use additional services for analytics, error tracking, and platform operations. We ensure all third-party processors comply with privacy standards comparable to Australian requirements.
5. How We Disclose Your Information
5.1 Within the Platform
- Your company name and contact details are visible to users you're invited to collaborate with (e.g., subcontractors see the contractor's company name)
- Tender submissions are visible to the head contractor who invited you
- Project data is only visible to authorized users within that project
5.2 Third-Party Service Providers
We share information with trusted service providers who process data on our behalf:
- Firebase/Google Cloud (hosting, storage, authentication)
- OpenAI (AI-powered document processing)
- Email service providers (transactional emails)
All service providers are contractually bound to protect your information and use it only for specified purposes.
5.3 Legal Requirements
We may disclose your information if required by law, court order, or to:
- Comply with legal processes or government requests
- Enforce our Terms of Service
- Protect our rights, property, or safety
- Investigate fraud or security issues
5.4 Business Transfers
If evalu8 is acquired or merged, your information may be transferred to the new owner, who will be required to honor this Privacy Policy.
5.5 With Your Consent
We will not share your information with other parties except as described in this policy, unless we obtain your explicit consent.
6. Data Security
We implement appropriate technical and organizational measures to protect your information:
- Encryption in transit (HTTPS/TLS) and at rest
- Firebase security rules to control data access
- Regular security assessments and updates
- Password hashing and secure authentication
- Access controls and monitoring
However, no method of transmission over the internet is 100% secure. During the beta period, additional security risks may exist. We cannot guarantee absolute security of your data.
7. Data Retention
7.1 Active Accounts: We retain your information for as long as your account is active or as needed to provide services.
7.2 Closed Accounts: After account closure, we may retain certain information for:
- Legal compliance (e.g., tax records, dispute resolution)
- Fraud prevention and security
- Enforcing our Terms of Service
7.3 Beta Period: During closed beta, we may retain data longer for debugging and platform improvement purposes.
7.4 Anonymized Data: We may retain anonymized, aggregated data indefinitely for analytics and research.
8. Your Rights Under Australian Privacy Law
Under the Australian Privacy Principles (APPs), you have the following rights:
8.1 Access
You have the right to access your personal information. You can view most of your information through your account settings.
8.2 Correction
You can update your personal information through your profile page. For other corrections, contact noah@nunu.pro.
8.3 Deletion
You can request deletion of your account and personal information. Note that we may retain certain information as required by law or for legitimate business purposes.
8.4 Complaints
If you have privacy concerns, contact us at noah@nunu.pro. We will investigate and respond within 30 days. You also have the right to complain to the Office of the Australian Information Commissioner (OAIC).
8.5 Exercising Your Rights
To exercise any of these rights, contact noah@nunu.pro with your request. We may need to verify your identity before processing your request.
9. Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Maintain your login session
- Remember your preferences
- Analyze platform usage
- Improve user experience
You can control cookies through your browser settings, but disabling cookies may affect platform functionality.
10. International Data Transfers
While we primarily store data in Australia/Asia-Pacific regions through Firebase, some data processing may occur in other countries (e.g., United States for OpenAI processing). These countries may have different data protection laws than Australia. We ensure appropriate safeguards are in place for international transfers.
11. Children's Privacy
evalu8 is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we discover we have collected information from a child, we will delete it promptly.
12. Data Breach Notification
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or platform notification. The "Last Updated" date at the top indicates when the policy was last revised. Continued use of the platform after changes constitutes acceptance of the updated policy.
14. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your personal information, contact:
evalu8 Privacy
Email: noah@nunu.pro
Office of the Australian Information Commissioner (OAIC):
If you wish to make a privacy complaint, you can contact the OAIC at www.oaic.gov.au