Last Updated: 22 May 2026 | Effective Date: 22 May 2026 | Version 2.1
Updated from Version 2.0 (5 April 2026). Version 2.1 adds a new Section 12 (Meta Platform Integrations) covering Meta Lead Ads and Meta Page Messaging, and expands Sections 6.2 and 7 to include Meta as a service provider and overseas recipient. Previous versions (2.0 dated 5 April 2026; 1.0 dated 30 January 2026) are available upon request.
Meister Athlete Pty Ltd (ABN 49 162 434 513), trading as Valutten (“Valutten”, “we”, “us”, “our”), is committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our commission intelligence platform for Australian mortgage brokerages (“Service”, “Platform”).
This policy applies to:
By using our Service, you consent to the collection and use of information in accordance with this Privacy Policy. This policy should be read in conjunction with our Terms of Service.
We collect information you voluntarily provide when using our Service:
When you access our Service, we automatically collect:
We do not intentionally collect sensitive information (as defined in the Privacy Act) such as health information, racial or ethnic origin, political opinions, or religious beliefs. The commission data you upload may contain financial information related to loan transactions, which we treat with appropriate security measures.
We use your information to:
We may also use your information to:
We will never:
Under the Australian Privacy Principles, we collect and process your personal information on the following bases:
Primary data is stored in Google Cloud Platform's australia-southeast1 (Sydney) region. This includes your commission data (BigQuery), user accounts (Firestore), uploaded files (Cloud Storage), and audit logs.
Limited data is processed by overseas providers as disclosed in Section 7. This includes authentication tokens (Firebase Authentication, US), product analytics events (PostHog, EU), AI inference requests (Anthropic, US), transactional email delivery (Resend, US), payment processing (Stripe, US/Global), and Meta platform integrations for lead capture and Page messaging (Meta, US/Ireland) where you have explicitly connected a Meta Page (see Section 12).
We implement industry-standard security measures including:
In the event of a data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) within 72 hours and notify affected individuals as soon as practicable, in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
| Data Type | Retention Period | Reason |
|---|---|---|
| Commission Data | 7 years from upload | ASIC / Corporations Act 2001 record-keeping |
| RCTI Documents | 7+ years | Tax and compliance requirements |
| Audit Logs | 10 years | Regulatory compliance and security |
| Account Information | Active account + 90 days after deletion | Service operation |
| AI Query History | 90 days | Service improvement and context |
| Email Delivery Logs | 180 days | Deliverability monitoring |
| Product Analytics Events | 12 months | Product improvement (consent-gated) |
| Support Communications | 2 years after resolution | Service quality |
When you delete your account, we will remove your personal information within 90 days. However, commission data may be retained as required by law (7-year retention period for financial records under the Corporations Act 2001). Retained data will be anonymised where possible. Backups are retained for disaster recovery (maximum 30 days after deletion).
We disclose personal information to authorised users within your organisation based on their assigned roles and permissions. Company administrators can view all users and brokers within their company; office administrators can view users and data within their assigned offices; brokers can view their own commission data only.
We engage the following third-party service providers who process personal information on our behalf:
| Service | Provider | Location | Purpose |
|---|---|---|---|
| Core Infrastructure | Google Cloud Platform / Firebase | AU (australia-southeast1) | Cloud infrastructure, Firestore database, Cloud Storage, BigQuery data warehouse |
| Authentication | Firebase Authentication | US (not regionalized) | User authentication, session tokens, identity verification |
| Product Analytics | PostHog | EU (eu.posthog.com) | Page views, UI interactions, error reports (consent-gated) |
| AI Processing | Anthropic | US | Commission insights and natural-language queries (PII tokenized before transmission) |
| Email Delivery | Resend | US | Transactional email delivery (tracking pixels disabled) |
| Payment Processing | Stripe | US / Global | Subscription billing, PCI-DSS compliant (we do not store full card details) |
| Email Integration | Google OAuth / Gmail API | US | Optional commission email import (gmail.readonly scope) |
| Lead Capture (Meta Lead Ads) | Meta Platforms, Inc. | US / Ireland | Optional — receives lead form submissions from your authorised Facebook/Instagram ad campaigns into your Valutten lead inbox (see Section 12) |
| Page Messaging (Meta) | Meta Platforms, Inc. | US / Ireland | Optional — surfaces direct messages sent to your connected Facebook Page inside Valutten so you can respond from the platform (see Section 12). Available only after Meta App Review approval of the pages_messaging permission. |
All service providers are contractually obligated to protect your information, implement appropriate security measures, process data only as instructed by us, and delete data when no longer needed.
We may disclose your information if required to:
If Valutten is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
While our primary data infrastructure is in Australia (GCP australia-southeast1), certain service providers process limited categories of data outside Australia. Under APP 8, we disclose the following:
| Service | Country | Data Categories | Safeguards |
|---|---|---|---|
| Firebase Authentication | United States | Email, hashed password, session tokens, MFA config | Google Cloud Data Processing Terms, SOC 2/3, ISO 27001 |
| PostHog | European Union | Anonymised usage events, page views, UI interactions, error reports | EU-hosted instance (eu.posthog.com), Data Processing Agreement, SOC 2 |
| Anthropic (Claude AI) | United States | Tokenized commission queries (broker/lender names replaced with opaque tokens), dollar amounts, date ranges | Data Processing Agreement, PII tokenization before transmission, 30-day prompt retention for safety monitoring only, not used for model training |
| Resend | United States | Recipient email addresses, email subject lines, delivery metadata | Data Processing Agreement, tracking pixels disabled on transactional emails |
| Stripe | United States / Global | Billing name, email, payment card tokens, subscription status | PCI-DSS Level 1, Standard Contractual Clauses, SOC 2 |
| Google OAuth / Gmail API | United States | OAuth tokens, email message content (gmail.readonly scope, optional) | Google API Services User Data Policy, OAuth consent screen, revocable at any time |
| Meta (Lead Ads) | United States / Ireland | Lead form field responses (name, email, phone, custom questions you configured), form/campaign/page identifiers, submission timestamp | Meta Platform Terms, Meta Data Processing Terms, OAuth-issued Page Access Token stored in Google Secret Manager (australia-southeast1), HMAC-SHA256 webhook signature verification, revocable at any time (see Section 12) |
| Meta (Page Messaging) | United States / Ireland | Direct message content sent to your connected Facebook Page, Page-Scoped User ID (PSID), sender display name, message timestamp. Available only when the optional Page Messaging integration is enabled. | Meta Platform Terms, Meta Data Processing Terms, granted via Meta App Review (pages_messaging permission), Page Access Token stored in Google Secret Manager (australia-southeast1), revocable at any time (see Section 12) |
Before disclosing personal information overseas, we take reasonable steps to ensure the recipient is subject to a law or binding scheme substantially similar to the Australian Privacy Principles, or has contractually agreed to handle the information in accordance with the APPs.
By using Valutten, you consent to the international transfers described above. If you do not consent, please contact us to discuss alternatives, noting this may limit available functionality.
We use PostHog (EU-hosted at eu.posthog.com) for product analytics, routed through our own servers to ensure reliability. Analytics data collection requires your opt-in consent.
Valutten uses Anthropic's Claude AI to provide commission intelligence features. This section explains what data is sent, how it is protected, and your opt-out rights.
Before any data is sent to Anthropic:
[VT_BROKER_0])[VT_LENDER_0])Anthropic may retain prompts for up to 30 days for safety and abuse monitoring purposes. Prompts are not used to train AI models. After 30 days, prompts are deleted from Anthropic's systems.
AI features are available to Enterprise and Pro tier subscribers. If you do not wish to use AI features, you can avoid them entirely — they are not invoked unless you navigate to the AI Assistant or trigger the first-login briefing. You may also contact us to disable AI features for your account.
Valutten offers an optional Gmail integration to help automate commission file imports. This feature requires explicit authorization and can be revoked at any time.
gmail.readonly — read-only access to email messagesExtracted commission files are stored in our Australian infrastructure (Cloud Storage, australia-southeast1) and processed identically to manually uploaded files. We do not store the full email body — only the extracted attachments and metadata needed for processing (sender, subject, date).
You can revoke Gmail access at any time by:
Revoking access stops future email imports but does not delete commission data already processed (retained per Section 5).
We send transactional emails via Resend for:
Tracking pixels are disabled on all transactional emails. We do not track whether you open transactional emails or click links within them.
Marketing emails require your explicit opt-in consent, collected during the subscription checkout process via Stripe. You may unsubscribe at any time via the unsubscribe link in any marketing email, or by contacting us. We comply with the Spam Act 2003 (Cth) for all commercial electronic messages.
All emails from Valutten are sent from noreply@valutten.com or support@valutten.com. We authenticate all outgoing email with SPF, DKIM, and DMARC to protect against spoofing.
Valutten offers optional integrations with Meta platforms (Facebook and Instagram) to help your team capture leads and respond to customer enquiries from a single inbox. These integrations are off by default and are only enabled when an authorised user of your organisation connects a Facebook Page through Settings > Integrations > Meta.
pages_messaging permission): Valutten surfaces direct messages sent by Facebook users to your connected Page inside the Valutten lead inbox so your team can respond from within the platform. This feature is available only after Meta grants the permission and you enable it on your Page.| Integration | Categories of Personal Information |
|---|---|
| Lead Ads | Lead form field responses you configured in Meta Ads Manager — typically name, email address, phone number, and any custom qualifying questions; lead provenance metadata (form ID, ad/campaign ID, Page ID, submission timestamp) |
| Page Messaging | Message content sent by Facebook users to your Page; the sender's Page-Scoped User ID (PSID); sender display name as exposed by Meta; message timestamps; conversation history retrieved through the Meta Graph API for the active conversation |
We do not receive a Facebook user's broader profile, friends list, ad preferences, location, or content posted outside the conversation with your Page.
leads_retrieval, pages_show_list, pages_manage_metadata, and, where granted, pages_messaging)When you run Meta Lead Ads, you are the controller of the data subject's lead submission and you are responsible for the privacy notice presented to the lead inside the Meta lead form, as required by Meta's Terms for Lead Ads. Valutten acts as your processor for the purpose of receiving, storing, routing, and surfacing those submissions inside your tenant.
For Page Messaging, Meta presents its own messaging notices to the Facebook user; by sending your Page a message the user has initiated a 1:1 conversation that we surface to your team in line with Meta's Platform Terms.
You can disconnect a Meta integration at any time. Either:
Either action immediately revokes our tokens and stops further lead or message ingestion from that Page. Records already received remain inside your tenant per Section 12.5 unless you separately request deletion under Section 14.
We use essential cookies that are necessary for the operation of our Service, including authentication tokens and session management. These cookies cannot be disabled as they are required for the Service to function.
PostHog may set first-party cookies to track anonymous session identifiers if you consent to analytics. No third-party advertising or tracking cookies are used. We do not use Google Analytics.
You can manage cookie preferences through your browser settings or via our consent banner. Please note that disabling essential cookies may prevent you from using some features of our Service.
For detailed information about specific cookies, their purposes, and durations, see our Cookie Notice.
Under the Privacy Act 1988 and Australian Privacy Principles, you have the following rights:
You have the right to request access to the personal information we hold about you. We will provide this information within 30 days of your request, subject to verification of your identity. We may charge a reasonable fee for access requests that require significant effort to fulfil.
You have the right to request correction of any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. You can update most account information directly through your account settings.
You can request deletion of your account and personal information by contacting us. Please note that some information may be retained as required by law (see Section 5).
Where practical, you may choose not to identify yourself when dealing with us. However, this is not possible for account registration, commission data processing, or support requests where identity verification is required.
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint with us using the contact details below. We will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by phone at 1300 363 992.
Our Service is intended for business use by mortgage broking professionals and is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
Your continued use of Valutten after changes take effect constitutes acceptance of the updated policy.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Valutten Privacy Officer
Meister Athlete Pty Ltd (ABN 49 162 434 513), trading as Valutten
Support
Phone
0409 774 479
Address
Sunrise Beach, QLD 4567, Australia
We will respond to your inquiry within 30 days. For access or correction requests, we may need to verify your identity before processing your request.
This Privacy Policy is governed by the laws of Queensland, Australia. For more information about privacy in Australia, visit the OAIC at www.oaic.gov.au.
Version 2.1 | Effective 22 May 2026 | Approved by Dieter Roylance, Director