Privacy Policy
Effective date: 25 September 2026 · Version: 1.0
Handholder is operated by Varloch Group Pty Ltd (ABN 49 646 184 803). This policy explains what personal information we handle, why, where it goes and the choices you have.
Privacy at a glance
- We handle account, security, billing, support and enquiry information to run Handholder.
- Organisations that use Handholder decide what personal information they put into their workspace. We handle that information on their behalf to provide the service.
- Our app servers, main database, sign-in system and main file storage are in Sydney. Some files, logs, emails, payments and AI processing are handled overseas, so processing is not limited to Australia.
- AI features inside Handholder use the organisation's own connected AI account. Separately, we use our own cloud AI assistant for engineering and support, and it can see personal information.
- Deleting a record or cancelling doesn't remove every copy straight away. Some records are kept on purpose, and this policy explains which ones and for how long.
- For access, correction, deletion or a complaint, email admin@handholder.com.au.
1. Who we are and what this policy covers
1.1 "We", "us" and "Varloch" mean Varloch Group Pty Ltd, ABN 49 646 184 803, the operator of Handholder, our board and company governance software. Handholder is a product of Varloch, not a separate company.
1.2 "Personal information" means information or an opinion about an identified person, or a person who can reasonably be identified.
1.3 We handle information in two ways:
- (a) Information we manage for our own business: account details, sign-in and security information, billing contacts, support emails and website enquiries. We decide how this is used to run Handholder and manage our customer relationships.
- (b) Customer information: information an organisation puts into, or creates in, its Handholder workspace. This includes information about directors, employees, shareholders, contacts and people who sign documents. The organisation decides why it's collected and how it's used. We handle it on that organisation's behalf to provide, operate and support Handholder.
1.4 For questions about customer information, contact the organisation that invited you, sent you a document or collected your details. You can also contact us, and we'll help you find the right organisation and help with your request.
1.5 Where Varloch uses Handholder for its own staff or governance records, Varloch is also the organisation responsible for those records.
1.6 Contact: admin@handholder.com.au, which handles privacy, support and enquiries. Post: U10C, 1 Campbell Parade, Manly Vale NSW 2093.
2. How we manage personal information
2.1 We handle personal information in line with the Australian Privacy Principles (APPs).
2.2 You can ask for a free copy of this policy, including in another accessible format, by emailing us. We review it at least once a year and whenever our practices materially change.
3. Staying anonymous
3.1 You can browse our public pages without an account, and you can make a general enquiry without giving your name. An email shows the address you send from, and ordinary technical logs may record your IP address and browser details.
3.2 We need to identify you to create and secure an account, manage billing, give you access to an organisation's workspace or deal with a request about you. Your organisation may also need to identify you for voting, registers, document signing or other governance tasks.
3.3 Board evaluations store answers without a name, email address or person ID, but we can't promise complete anonymity. Whether someone has completed the evaluation is tracked separately, so while an evaluation is open, someone with database access might work out who answered. Answers are shuffled when it closes. Free text and small groups can still identify people. Results are hidden when fewer than three people respond. Directors' questionnaires are signed and identified; they aren't anonymous.
3.4 Pulse surveys store answers without your name. The organisation only sees results once a minimum number of people have answered (five by default). The survey link records that you've responded, so you can't answer twice. Free-text comments can still identify you.
4. What we collect and how
4.1 Information we handle for our own business:
| Category | Examples |
|---|---|
| Account information | Name, work email, password (stored only as a one-way hash), sign-in method and two-step login settings |
| Security and technical | IP address, browser and device details, sign-in events, failed sign-ins, security-setting changes, request and error logs |
| Billing | Billing contact, business name, ABN, address, invoices and payment records (see 4.2) |
| Support and enquiries | Your email address, what you write to us and anything you send us |
| Engineering and support material | Information we come across while fixing problems, including database results, logs, files and AI support sessions (see sections 7 and 14) |
4.2 Payments. We issue invoices through Xero. We plan to take payment by debit card or direct debit from an Australian bank account through Stripe; that isn't connected yet. Card and bank details will be entered directly with Stripe. They never pass through or get stored in Handholder, and Varloch doesn't keep them. We will be able to see limited payment details: the payer's name and email; the card brand, last four digits and expiry, or the BSB and the last digits of the bank account; and payment history. Xero holds the billing contact's name and email, business name, ABN, address, and invoice and payment records.
4.3 Customer information depends on the features an organisation uses:
| Feature | Examples of personal information |
|---|---|
| Governance and board portal | Names, contact details, dates of birth, home addresses, appointments, shareholdings, conflicts of interest, attendance, votes, minutes, board papers, notes, messages, questionnaire answers and share-trading requests |
| Board evaluations | Answers and separately kept completion records (see 3.3) |
| E-signature | Name, email, typed name, signature image, IP address, browser and device details, and location if you allow it |
| Optional HR features | Employee contact details, date of birth, address, salary, emergency contacts, reviews and self-assessments, pulse-survey answers, leave, and the last four digits of tax file numbers |
| Optional marketing features | Contact names and emails; email delivery, open and click events; and names, emails, phone numbers, messages and browser details from enquiry forms. Letterbox QR scans record browser details and a scrambled (one-way) form of the IP address before redirecting |
| Other optional features | Sales contacts, supplier contacts, tasks, wiki content, documents and AI conversations |
| Uploads and recordings | Documents, meeting audio, transcripts, comments and messages, which may include information about other people |
| Audit and activity records | Who did what, what changed and when. Some records still identify people after an erasure request (see 12.6) |
4.4 We collect information from you directly; from the organisation and its users; from sign-in providers and services the organisation connects; and automatically through sign-in, security, logging and feature activity. An organisation may give us information about someone who doesn't have a Handholder account.
4.5 If necessary information isn't provided, we or the organisation may not be able to provide the account, service or governance function concerned.
4.6 Notices. Our sign-up and login pages link to this policy. Public enquiry forms name the organisation collecting your details and link to its own privacy policy if it has set one. Employee self-assessment and pulse-survey pages say which organisation is collecting the information and why, and link to its privacy policy (or this one).
5. Sensitive information
5.1 Handholder has no dedicated fields for health, racial or ethnic origin, religion, union membership, criminal record, sexual orientation or biometric identification. This kind of information can still appear in notes, board papers, recordings, messages and uploads.
5.2 We ask customers not to enter sensitive information unless it's necessary and they're allowed to. Where consent is needed, it must be obtained. Using Handholder or reading this policy isn't consent to collecting sensitive information about you or anyone else.
5.3 Signature images are used only as evidence of signing. Audio and video recordings are used for transcription. Handholder doesn't do voiceprint, speaker-identification or biometric analysis.
6. Information we didn't ask for
6.1 If we receive personal information we didn't ask for, we'll decide whether we could lawfully have collected it. If not, we'll destroy or de-identify it where lawful and reasonable.
6.2 Where it's in customer content, we'll work with the organisation to deal with it.
7. How we use and share information
7.1 We use information to provide and run Handholder, sign people in, apply access permissions, protect the service, keep governance records, give support, fix faults, manage invoices and payments, respond to requests and meet our legal obligations.
7.2 We use operational logs and engineering tools to run, troubleshoot and secure the service. There are no product-analytics, advertising or tracking tools in the app. We don't sell personal information, and we don't use customer content for unrelated benchmarking or marketing.
7.3 Information may be shared with the organisation and its authorised users (according to their permissions), with the people a document is sent to, with services the organisation connects, and with these providers. We may also disclose information where the law requires or allows it.
| Provider | What they do for us |
|---|---|
| Vercel | App hosting, request handling and hosting logs |
| Supabase (on Amazon Web Services) | Database, sign-in, file storage and database backups |
| Cloudflare R2 | Uploaded files and file backups |
| Upstash | Sign-in rate limiting (short-lived counters of IP address and email) |
| Resend | Account, password-reset and security emails |
| Microsoft | Sign-in when "Sign in with Microsoft" or company single sign-on is used; and our privacy, support and enquiry mailbox (Microsoft 365) |
| Axiom | Copy of hosting and error logs, which can include IP address, browser, page address and error details |
| Anthropic | All AI tasks for Hermes, our engineering and support assistant |
| Discord | Messages in which Hermes reports to our team; these can include information from support or engineering work |
| Xero | Invoices, billing contacts, and invoice and payment records |
| Stripe (planned) | Debit-card and direct-debit payments; not connected yet |
7.4 An organisation can connect its own accounts with Microsoft 365, Xero, Google (Analytics, Business Profile, Search Console, YouTube), Meta (Facebook and Instagram), LinkedIn, X (Twitter) and Canva, as well as its own AI provider and email-sending accounts. These connections use the organisation's own account and agreement with that provider, and data is sent when the organisation uses them. Our own use of any provider is covered by this policy regardless.
8. Direct marketing
8.1 We don't use contacts in customer workspaces for our own marketing. Account, billing, security and support messages are sent only for those purposes.
8.2 If we send promotional messages, we'll have the consent the law requires, identify ourselves and give you an easy way to unsubscribe. You can also email us to stop. Opting out doesn't stop necessary account or security messages.
8.3 Organisations that use Handholder's campaign and enquiry-form features are responsible for their own marketing permissions and notices. To stop a campaign an organisation sends, use its unsubscribe link or contact it; we can help you identify it.
9. Overseas processing
9.1 The app, main database, sign-in system and main file storage (Supabase) are in Sydney. Other uploaded files and file backups are in Cloudflare R2 with an Oceania location setting. That setting is best effort and doesn't guarantee the files stay in Australia.
9.2 These are handled overseas:
| Activity | Location |
|---|---|
| Sign-in rate-limit counters (Upstash) | United States |
| Account emails (Resend) | United States |
| Hosting and error log copy (Axiom) | United States |
| Hermes AI tasks (Anthropic) | United States |
| Hermes reports (Discord) | United States, and other countries where Discord operates |
| Invoicing (Xero) | Australia, New Zealand and the United States |
| Payments (Stripe, planned) | United States and other countries where Stripe operates |
| Microsoft sign-in | Microsoft's global systems |
| Vercel edge services, support and internal logs | May include the United States and other countries |
9.3 Our Microsoft 365 mailbox content is stored in Australia under Microsoft's data residency terms, though some Microsoft service and support functions may operate elsewhere. Services an organisation connects may process information overseas under that organisation's own account and settings.
9.4 We take the reasonable steps Australian privacy law requires when information goes to overseas recipients. Using Handholder doesn't mean you give up those protections.
10. Government identifiers and tax file numbers
10.1 Company tax file number fields keep only the last four digits; full numbers were removed on 25 September 2026. Employee tax file number fields in the HR add-on also keep only the last four digits.
10.2 People can still type full numbers into free text or uploads, and database backups taken before 25 September 2026 may contain the removed numbers until those backups expire (within 7 days). Handholder doesn't scan content for tax file numbers. Please don't put full tax file numbers in notes, messages or uploads.
10.3 We don't use government identifiers as our own identifier for you, and we only use or disclose them where the law allows.
11. Keeping information accurate
11.1 We try to keep the information we use accurate, up to date, complete and relevant. Tell us if your account, billing or support details need correcting.
11.2 Organisations are responsible for the accuracy of what's in their workspace. Contact the organisation about its records, or contact us for help. A historical record may be corrected with a note rather than the original being removed.
12. Security and how long we keep information
12.1 Our security includes encrypted connections, encryption of stored data by our providers, extra encryption of dates of birth, home addresses, salaries and connected-service credentials, and separation between customer workspaces that's enforced in both the app and the database.
12.2 Two-step login is required for owners, full-access administrators and board members, and an organisation can require it for everyone. Passwords must be at least eight characters and are checked against known breached passwords. Company single sign-on and configurable sign-in time limits are available. Sign-in attempts are rate-limited, and account security changes trigger an email to the user.
12.3 Not every copy has field-level encryption. Older audit entries, and information copied into support or engineering tools, can contain readable personal information. The audit log can't be altered through the app. It records changes, not every time someone views data.
12.4 We've tested restoring both the database and files. We don't have point-in-time database recovery, an independent penetration test or a security certification, and we don't offer customer-managed encryption keys. No service can promise absolute security.
12.5 How long we keep information:
| Information | What happens |
|---|---|
| Customer records, files, recordings, transcripts and AI conversations | Kept until deleted through the feature. Some records are hidden or marked deleted rather than removed, and the exceptions below apply |
| Account after erasure | The person's access to that organisation is removed. Their sign-in account is also deleted unless they belong to another organisation (the reason is shown) |
| Cancelled organisations | No automatic deletion yet. We delete an organisation's workspace on request |
| Signing evidence, security events and audit records | Kept indefinitely, with no scheduled deletion |
| Governance and evidence records during erasure | Votes, resolutions, minutes, attendance, signed documents and signing evidence, questionnaires, share-trading records, policy sign-offs, board meeting recordings and transcripts, board papers, shared board notes and messages, and HR documents are kept, with the reason shown |
| HR record after erasure | Preferred name, phone, date of birth, address, salary and emergency contacts are blanked. Name, email, role, employment dates and pay rate are kept, because employers must keep employment records for seven years under Fair Work rules |
| Records under a legal hold | Can't be deleted while the hold applies |
| Database backups | Daily, kept for seven days, then deleted automatically |
| File backups | Locked against deletion for 90 days. A backup copy of a deleted or replaced file is deleted automatically 90 days after the file stopped existing. Copies of files that still exist are kept while the file exists |
| Sign-in rate-limit counters | Expire after 15 minutes |
| Hosting logs (Vercel) | One day |
| Database and sign-in logs (Supabase) | Seven days |
| Hosting and error log copy (Axiom) | 30 days |
| Hermes session transcripts on our computer | 90 days, then deleted automatically |
| Anthropic (Hermes AI) | Under Anthropic's commercial terms, our data isn't used to train models. Anthropic keeps it for up to 30 days, depending on the model |
| Discord (Hermes reports) | Kept by Discord until deleted, under Discord's policies |
| Invoices and payment records | Kept for at least five years, as Australian tax law requires |
| Support and enquiry emails | Kept in our mailbox while needed to deal with the matter and for our business records |
12.6 Erasing a person. When an organisation's owner erases someone, Handholder deletes:
- their access to the organisation and their provisioning profile;
- notifications and board-portal markers;
- their marketing, sales and talent contact records, form submissions and email campaign records;
- their SOP view history and private board notes (unless under a legal hold);
- their AI conversations, messages, attachments, documents and search index, including the stored files;
- training videos they recorded, including transcripts, captions, summaries, screenshots and the video files.
Kept items and the reasons are shown to the owner, including anything whose deletion couldn't be confirmed. The owner also gets a list of remaining copies that expire on their own or need action by hand: backups, logs, emails already sent, the organisation's own AI and sign-in providers, copies outside Handholder and files with no recorded uploader. The audit log records that someone was erased (by whom and when), not the erased content. Audit entries from before 25 September 2026 may still contain some personal details. Erasure inside Handholder doesn't reach copies in our own engineering tools (Hermes transcripts, Anthropic and Discord); those expire as shown in 12.5.
12.7 Restoring backups. Every erasure is also recorded in a separate, locked store outside the database. If we ever restore the database or files from a backup, we re-apply every erasure made since that backup before the service goes back to normal use.
13. Access, correction and deletion requests
13.1 Email admin@handholder.com.au, tell us what you're after, and name the organisation or account if you know it. Don't send passwords, full tax file numbers or identity documents we haven't asked for. We may ask for reasonable information to confirm who you are.
13.2 We handle requests within a reasonable time and free of charge. For customer information, we help the organisation respond and deal with anything we hold ourselves. Owners can export and erase a person's information in Handholder. An export includes the person's AI chat conversations and a list of their files (names and sizes).
13.3 Access or correction may be limited where the law allows, for example to protect someone else's privacy. If we refuse, we'll explain why (where lawful) and how to complain. Where appropriate, we'll consider giving access another way, or record that you disagree with the information.
13.4 You can ask us to delete information. We can't promise to delete every record, but we'll consider the request against our legal obligations and the limits described above, and tell you the outcome.
14. AI and automated decisions
14.1 AI inside Handholder. An organisation must connect its own AI account to use Handholder's AI features. Depending on the feature, prompts, documents, audio and transcripts are sent to that provider to produce minutes, chat replies, document drafts or marketing content. People review and approve meeting minutes. We don't supply our own AI account for these features.
14.2 We don't train AI models on customer information. The connected provider's handling is governed by the organisation's own agreement and settings with it.
14.3 AI we use to run Handholder. We use Hermes, an AI assistant, for engineering and support. It runs on our own computer but sends what it reads to Anthropic's cloud models. That can include names, emails, dates of birth, addresses, salaries, IP addresses, files, database results and logs. Hermes uses our own Anthropic account, not the organisation's. Since 25 September 2026, all Hermes AI tasks use Anthropic only. Hermes reports to our team through Discord. We keep what Hermes reads to what the task needs, but it doesn't automatically redact personal information.
14.4 No AI makes decisions about individuals in Handholder. Some ordinary software rules do affect people:
- role and conflict-of-interest information decides who can vote;
- sign-in rules can require you to sign in again;
- the number of responses decides whether survey results are shown;
- dates trigger share-trading blackout warnings, which a person then reviews;
- optional sales features calculate a lead score;
- marketing emails follow schedules the organisation sets.
15. E-signatures
15.1 When an organisation sends you a document to sign, Handholder records your name, email, typed name, signature image, IP address, browser and device details and signing events. A certificate records the evidence of signing.
15.2 Your browser's location is recorded only if you allow it. You can say no and still sign. The sending organisation controls the signing record, so contact it about the document or how it uses your information.
16. Board portal and offline copies
16.1 Board papers are watermarked with the reader's name. The organisation controls who can access papers and whether they can be downloaded. Directors can save permitted papers for offline reading in their browser.
16.2 Offline papers expire when the paper's access ends or when the organisation's offline limit is reached (30 days by default), whichever comes first. The device checks expiry without needing a connection. Signing out, or a session ending, removes saved papers.
16.3 If access is withdrawn, it takes effect the next time the device connects: when the portal opens, and every 15 minutes while it's open. A device that stays offline may keep a paper until it expires.
16.4 Downloaded, printed or screenshotted copies can't be withdrawn by Handholder.
17. Cookies and similar technologies
17.1 Handholder uses only the cookies it needs for sign-in and security. There are no advertising tags, tracking pixels or third-party analytics in the app or on our public pages, and we don't use Handholder to track you across other websites.
| Technology | Purpose and how long |
|---|---|
| Sign-in cookies (Supabase) | Keep you signed in. The cookie can last up to 400 days, but the access token inside it expires after an hour and is renewed; the organisation's sign-in rules still apply |
| hh_seen | Records activity so idle sessions can be signed out; 30 days |
| Connection security cookies | Protect the step where you connect a third-party account; expire after ten minutes and are removed after use |
| Browser local storage | Unsent review and self-assessment drafts, kept on your device until you submit |
| Offline browser storage | Saved board papers and pages (see section 16) |
17.2 You can block cookies or clear stored data in your browser, but you may then be unable to sign in, and drafts or offline papers may be lost. Marketing emails an organisation sends may track opens and clicks. Letterbox QR scans record browser details and a scrambled form of the IP address, then redirect straight away without showing a page. Scrambling alone doesn't guarantee anonymity.
18. Data breaches
18.1 We act on any suspected misuse, loss, or unauthorised access to or disclosure of personal information, and we work with the organisations affected. Where the Notifiable Data Breaches scheme requires it, we notify the Office of the Australian Information Commissioner (OAIC) and the people affected.
19. Complaints
19.1 Email admin@handholder.com.au with your concern, the relevant dates and the outcome you want. We'll look into it, ask for more information if needed and respond within a reasonable time. Complaints are free.
19.2 If you're not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC) on 1300 363 992 or at oaic.gov.au.
20. Children
20.1 Handholder is for business users aged 18 or over. Customer records may still include information about young people, such as young employees, apprentices or shareholders. The organisation is responsible for having the right authority and giving the right notices for that information.
20.2 If you think information about a child is being handled inappropriately, contact the organisation or us.
21. Changes to this policy
21.1 We publish changes on this page with a new effective date, and we tell account holders about material changes.