Privacy Policy
Effective date: 5 August 2026 · CONQRET is powered by SHWAY Agency · SHWAY AGENCY PTY LTD · ABN 35 682 867 232
Effective date: 5 August 2026
1. About this Policy
This Privacy Policy explains how CONQRET collects, holds, uses, discloses, protects and manages personal information. CONQRET is powered by SHWAY Agency and operated by SHWAY AGENCY PTY LTD (ABN 35 682 867 232, ACN 682 867 232), Rossmore NSW 2557, Australia.
We intend to manage personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable privacy laws to the extent they apply. We may also choose to apply these standards as good practice where a small-business exemption is available.
2. Scope
This Policy applies to the CONQRET website, builder accounts, employee and team access, tradie and subcontractor portals, client and property-owner portals, demonstrations, subscriptions, support, marketing, integrations, AI features and communications with us.
3. Our role
CONQRET handles personal information in two main roles:
- For account administration, subscriptions, billing, security, analytics, support and our own marketing, SHWAY AGENCY PTY LTD determines the purpose and means of handling the information.
- For project information entered by a Customer about clients, owners, workers, trades, suppliers and other participants, the Customer generally determines why the information is collected and how it is used, and CONQRET processes it to provide the Platform and follow lawful instructions.
Project-specific privacy requests should ordinarily be directed to the builder or other organisation responsible for the project. We will reasonably assist that Customer.
4. Personal information collected
Depending on use, we may collect:
- account details, including name, email, phone, role, employer, profile, credentials, account permissions, ABN, licence and insurance details;
- subscription and billing details, including billing address, plan, invoices, payment status, transaction identifiers and limited card metadata supplied by a payment provider;
- project details, including client and owner information, job-site addresses, stages, tasks, plans, contracts, budgets, costings, quotes, claims, invoices, variations, defects, approvals, handover and supplier or subcontractor records;
- communications and content, including messages, comments, photographs, videos, audio, uploaded files, support requests, electronic signatures and approval records;
- WHS and site records, including check-ins, acknowledgements, timestamps, approximate or precise location where enabled, IP address and device information;
- AI information, including prompts, uploaded documents, extracted information, generated drafts, recommendations, corrections and feedback;
- device, security and usage information, including IP address, browser, operating system, session identifiers, login times, pages and features used, diagnostics and audit logs; and
- sales and marketing information, including demonstration requests, interests, campaign source, preferences and engagement.
5. Sensitive information
CONQRET is not designed for routine collection of sensitive information. Sensitive information may nevertheless appear in project files, WHS or incident records. Customers must collect and upload it only where reasonably necessary, lawfully authorised, appropriately notified and protected by suitable permissions. We will intentionally collect sensitive information only with consent or where otherwise permitted by law.
6. How information is collected
We may collect personal information directly from you, from a Customer or administrator who invites you, from uploads and communications, from enabled integrations, from payment and authentication providers, from cookies and analytics tools, from public business sources and as otherwise authorised or required by law.
7. Purposes of handling
We may handle personal information to create and secure accounts, provide project and portal functions, process subscriptions, enable messages and notifications, process documents, provide AI functions, maintain audit records, support users, improve performance, prevent misuse, investigate incidents, enforce agreements, comply with law, resolve disputes and send permitted product marketing.
We will not use personal information for an unrelated purpose unless authorised by law or consented to where required.
8. AI and automated processing
CONQRET may use AI and automated systems to extract contract or project information, create draft project records, classify documents, summarise content, answer user questions, suggest tasks, assist with costings and flag possible missing or unusual information.
Relevant information may be securely transmitted to approved AI or technology providers. Users must review outputs. We do not use identifiable Customer Data to train public or general-purpose AI models without express agreement.
From 10 December 2026, if CONQRET arranges for a computer program to use personal information to make or substantially assist decisions that could reasonably be expected to significantly affect an individual's rights or interests, this Policy must identify the kinds of personal information used and the kinds of decisions involved. CONQRET is currently intended as an assistive platform requiring human review, not as a system making final high-impact decisions.
9. Disclosure
We may disclose personal information:
- to the relevant Customer and Authorised Users according to configured permissions;
- to providers of hosting, storage, backup, security, authentication, communications, analytics, AI, document processing, payments, accounting, customer support and related technology;
- to connected third-party services enabled by a Customer;
- to professional advisers, auditors and insurers;
- where required by law, lawful process, safety needs, fraud prevention or legal claims; and
- in a genuine investment, financing, restructure, merger or sale subject to appropriate confidentiality and privacy safeguards.
We do not sell personal information.
10. Overseas processing
Some service providers may store or process information outside Australia. Before publication, CONQRET must list the countries in which overseas recipients are likely to be located where practicable, based on the actual hosting, AI, analytics, communications and support providers in the Subprocessor Schedule.
Where Australian Privacy Principle 8 applies, we will take reasonable steps required by law in relation to overseas recipients. Privacy laws in another country may differ from Australian law.
11. Cookies and tracking
We may use essential cookies and similar technologies for login, security, preferences and session operation. Subject to consent requirements and the cookie controls made available, we may use analytics and marketing technologies to understand usage and measure campaigns.
We will seek to minimise unnecessary collection and avoid intentionally sending sensitive project information to advertising platforms. Users may reject non-essential cookies through the consent tool when available, but disabling essential technologies may prevent secure use of the Platform.
12. Direct marketing
We may send product information, offers or event invitations where consent or another lawful basis exists. Marketing communications will identify the sender and include a clear, functional and low-cost unsubscribe method. We will generally action unsubscribe requests within 5 business days.
Unsubscribing from marketing does not prevent necessary security, billing, account or active-project communications.
13. Security
We use reasonable technical and organisational safeguards appropriate to the information and risks involved. Measures may include access controls, authentication, encryption in transit, encryption at rest where supported, logging, backups, provider due diligence, staff restrictions, vulnerability management and incident-response procedures.
No online system is completely secure. Users must protect credentials, devices and account permissions. Suspected incidents should be reported to support@conqret.com.au.
14. Data breaches
We maintain procedures for assessing and responding to suspected data breaches. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm that cannot be prevented by remedial action, we will notify affected individuals and the Office of the Australian Information Commissioner as required.
15. Retention
We retain information only for as long as reasonably required for the Platform, the purpose of collection, legal obligations, tax and accounting, security, fraud prevention, disputes, backup integrity and legitimate business needs.
Unless a different operational schedule is approved:
- active Customer Data is retained during the Subscription;
- a Customer has 30 days after termination to request export;
- Customer Data may be deleted or de-identified from active systems within 90 days after the export period;
- backups are deleted through the ordinary rotation cycle, targeted at no more than 90 additional days;
- financial and tax records are retained as required by law; and
- security, support and legal records are retained for reasonable periods based on risk and legal need.
16. Access and correction
You may request access to personal information we hold about you or correction of inaccurate, outdated, incomplete, irrelevant or misleading information by emailing support@conqret.com.au. We may verify identity. Where information is controlled by a Customer, we may refer the request to that Customer or work with it to respond.
17. Deletion and account controls
Customer administrators may be able to update user information, change permissions, remove users, archive projects, export records and request account closure. Deletion may be limited by legal retention, project disputes, another party's lawful rights, backups and security needs.
18. Anonymity and pseudonyms
You may contact us anonymously or using a pseudonym where practical. Identification is generally required for secure accounts, billing, project access, authority verification, personalised support and legal compliance.
19. Children
CONQRET is a business platform and is not directed to children. A person under 18 must not create an independent account. Customers should avoid uploading a child's information unless it is reasonably necessary, lawful and appropriately protected.
20. Complaints
Privacy complaints may be sent to the Privacy Officer at support@conqret.com.au, with a copy to info@shway.agency, or addressed to CONQRET / SHWAY AGENCY PTY LTD, Rossmore NSW 2557, Australia. Please describe the issue, relevant dates, account or project and requested outcome.
We will acknowledge the complaint and aim to provide a substantive response within 30 days. If you are dissatisfied, you may be entitled to contact the Office of the Australian Information Commissioner or another relevant regulator.
21. Changes and contact
We may update this Policy for legal, technical, security or product changes. Material changes will be notified where reasonable, and consent will be sought where required.
CONQRET - powered by SHWAY Agency
SHWAY AGENCY PTY LTD
ABN 35 682 867 232 | ACN 682 867 232
Rossmore NSW 2557, Australia
Website: www.conqret.com.au
Privacy, security and support: support@conqret.com.au
Secondary contact: info@shway.agency
Service Providers & Data Locations
The technology providers that process information to deliver CONQRET, current as at 5 August 2026.
Amazon Web Services (AWS Amplify)
Application hosting and delivery of the Platform
Processing location: Australia (Sydney, ap-southeast-2)
No use of Customer Data for provider training
Supabase
Database, user authentication, document and photo storage, backups
Processing location: Australia (Sydney), with provider backup handling per Supabase policy
No use of Customer Data for provider training
Stripe
Subscription billing, card processing, invoices and receipts
Processing location: United States and global Stripe infrastructure
Payment data held by Stripe under its own terms; CONQRET stores limited billing metadata only
Resend
Transactional and lifecycle email delivery
Processing location: Sending infrastructure in Japan (Tokyo); provider operated from the United States
Message content processed transiently for delivery
Anthropic (Claude API)
Contract extraction, drafting assistance, Ask CONQRET answers
Processing location: United States
API inputs and outputs are not used by Anthropic to train its models by default
None (device-native SMS links open in the user's own messaging app)
None currently deployed (essential cookies only)
Built into the Platform (no third-party e-signature provider)
Typed-name approvals with timestamp, device and IP records
Processing location: Australia (Sydney)
Stored as Customer Data
Outbound links to Google Maps only (no embedded maps API)
Viewing a recorded check-in location
Processing location: Google's own terms apply when a link is opened
None currently
CONQRET — powered by SHWAY Agency · SHWAY AGENCY PTY LTD · ABN 35 682 867 232 · Rossmore NSW 2557, Australia · Privacy: support@conqret.com.au