← Conqret

Privacy Policy

Effective date: 5 August 2026 · CONQRET is powered by SHWAY Agency · SHWAY AGENCY PTY LTD · ABN 35 682 867 232

Effective date: 5 August 2026

1. About this Policy

This Privacy Policy explains how CONQRET collects, holds, uses, discloses, protects and manages personal information. CONQRET is powered by SHWAY Agency and operated by SHWAY AGENCY PTY LTD (ABN 35 682 867 232, ACN 682 867 232), Rossmore NSW 2557, Australia.

We intend to manage personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable privacy laws to the extent they apply. We may also choose to apply these standards as good practice where a small-business exemption is available.

2. Scope

This Policy applies to the CONQRET website, builder accounts, employee and team access, tradie and subcontractor portals, client and property-owner portals, demonstrations, subscriptions, support, marketing, integrations, AI features and communications with us.

3. Our role

CONQRET handles personal information in two main roles:

  • For account administration, subscriptions, billing, security, analytics, support and our own marketing, SHWAY AGENCY PTY LTD determines the purpose and means of handling the information.
  • For project information entered by a Customer about clients, owners, workers, trades, suppliers and other participants, the Customer generally determines why the information is collected and how it is used, and CONQRET processes it to provide the Platform and follow lawful instructions.

Project-specific privacy requests should ordinarily be directed to the builder or other organisation responsible for the project. We will reasonably assist that Customer.

4. Personal information collected

Depending on use, we may collect:

  • account details, including name, email, phone, role, employer, profile, credentials, account permissions, ABN, licence and insurance details;
  • subscription and billing details, including billing address, plan, invoices, payment status, transaction identifiers and limited card metadata supplied by a payment provider;
  • project details, including client and owner information, job-site addresses, stages, tasks, plans, contracts, budgets, costings, quotes, claims, invoices, variations, defects, approvals, handover and supplier or subcontractor records;
  • communications and content, including messages, comments, photographs, videos, audio, uploaded files, support requests, electronic signatures and approval records;
  • WHS and site records, including check-ins, acknowledgements, timestamps, approximate or precise location where enabled, IP address and device information;
  • AI information, including prompts, uploaded documents, extracted information, generated drafts, recommendations, corrections and feedback;
  • device, security and usage information, including IP address, browser, operating system, session identifiers, login times, pages and features used, diagnostics and audit logs; and
  • sales and marketing information, including demonstration requests, interests, campaign source, preferences and engagement.

5. Sensitive information

CONQRET is not designed for routine collection of sensitive information. Sensitive information may nevertheless appear in project files, WHS or incident records. Customers must collect and upload it only where reasonably necessary, lawfully authorised, appropriately notified and protected by suitable permissions. We will intentionally collect sensitive information only with consent or where otherwise permitted by law.

6. How information is collected

We may collect personal information directly from you, from a Customer or administrator who invites you, from uploads and communications, from enabled integrations, from payment and authentication providers, from cookies and analytics tools, from public business sources and as otherwise authorised or required by law.

7. Purposes of handling

We may handle personal information to create and secure accounts, provide project and portal functions, process subscriptions, enable messages and notifications, process documents, provide AI functions, maintain audit records, support users, improve performance, prevent misuse, investigate incidents, enforce agreements, comply with law, resolve disputes and send permitted product marketing.

We will not use personal information for an unrelated purpose unless authorised by law or consented to where required.

8. AI and automated processing

CONQRET may use AI and automated systems to extract contract or project information, create draft project records, classify documents, summarise content, answer user questions, suggest tasks, assist with costings and flag possible missing or unusual information.

Relevant information may be securely transmitted to approved AI or technology providers. Users must review outputs. We do not use identifiable Customer Data to train public or general-purpose AI models without express agreement.

From 10 December 2026, if CONQRET arranges for a computer program to use personal information to make or substantially assist decisions that could reasonably be expected to significantly affect an individual's rights or interests, this Policy must identify the kinds of personal information used and the kinds of decisions involved. CONQRET is currently intended as an assistive platform requiring human review, not as a system making final high-impact decisions.

9. Disclosure

We may disclose personal information:

  • to the relevant Customer and Authorised Users according to configured permissions;
  • to providers of hosting, storage, backup, security, authentication, communications, analytics, AI, document processing, payments, accounting, customer support and related technology;
  • to connected third-party services enabled by a Customer;
  • to professional advisers, auditors and insurers;
  • where required by law, lawful process, safety needs, fraud prevention or legal claims; and
  • in a genuine investment, financing, restructure, merger or sale subject to appropriate confidentiality and privacy safeguards.

We do not sell personal information.

10. Overseas processing

Some service providers may store or process information outside Australia. Before publication, CONQRET must list the countries in which overseas recipients are likely to be located where practicable, based on the actual hosting, AI, analytics, communications and support providers in the Subprocessor Schedule.

Where Australian Privacy Principle 8 applies, we will take reasonable steps required by law in relation to overseas recipients. Privacy laws in another country may differ from Australian law.

11. Cookies and tracking

We may use essential cookies and similar technologies for login, security, preferences and session operation. Subject to consent requirements and the cookie controls made available, we may use analytics and marketing technologies to understand usage and measure campaigns.

We will seek to minimise unnecessary collection and avoid intentionally sending sensitive project information to advertising platforms. Users may reject non-essential cookies through the consent tool when available, but disabling essential technologies may prevent secure use of the Platform.

12. Direct marketing

We may send product information, offers or event invitations where consent or another lawful basis exists. Marketing communications will identify the sender and include a clear, functional and low-cost unsubscribe method. We will generally action unsubscribe requests within 5 business days.

Unsubscribing from marketing does not prevent necessary security, billing, account or active-project communications.

13. Security

We use reasonable technical and organisational safeguards appropriate to the information and risks involved. Measures may include access controls, authentication, encryption in transit, encryption at rest where supported, logging, backups, provider due diligence, staff restrictions, vulnerability management and incident-response procedures.

No online system is completely secure. Users must protect credentials, devices and account permissions. Suspected incidents should be reported to support@conqret.com.au.

14. Data breaches

We maintain procedures for assessing and responding to suspected data breaches. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm that cannot be prevented by remedial action, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

15. Retention

We retain information only for as long as reasonably required for the Platform, the purpose of collection, legal obligations, tax and accounting, security, fraud prevention, disputes, backup integrity and legitimate business needs.

Unless a different operational schedule is approved:

  • active Customer Data is retained during the Subscription;
  • a Customer has 30 days after termination to request export;
  • Customer Data may be deleted or de-identified from active systems within 90 days after the export period;
  • backups are deleted through the ordinary rotation cycle, targeted at no more than 90 additional days;
  • financial and tax records are retained as required by law; and
  • security, support and legal records are retained for reasonable periods based on risk and legal need.

16. Access and correction

You may request access to personal information we hold about you or correction of inaccurate, outdated, incomplete, irrelevant or misleading information by emailing support@conqret.com.au. We may verify identity. Where information is controlled by a Customer, we may refer the request to that Customer or work with it to respond.

17. Deletion and account controls

Customer administrators may be able to update user information, change permissions, remove users, archive projects, export records and request account closure. Deletion may be limited by legal retention, project disputes, another party's lawful rights, backups and security needs.

18. Anonymity and pseudonyms

You may contact us anonymously or using a pseudonym where practical. Identification is generally required for secure accounts, billing, project access, authority verification, personalised support and legal compliance.

19. Children

CONQRET is a business platform and is not directed to children. A person under 18 must not create an independent account. Customers should avoid uploading a child's information unless it is reasonably necessary, lawful and appropriately protected.

20. Complaints

Privacy complaints may be sent to the Privacy Officer at support@conqret.com.au, with a copy to info@shway.agency, or addressed to CONQRET / SHWAY AGENCY PTY LTD, Rossmore NSW 2557, Australia. Please describe the issue, relevant dates, account or project and requested outcome.

We will acknowledge the complaint and aim to provide a substantive response within 30 days. If you are dissatisfied, you may be entitled to contact the Office of the Australian Information Commissioner or another relevant regulator.

21. Changes and contact

We may update this Policy for legal, technical, security or product changes. Material changes will be notified where reasonable, and consent will be sought where required.

CONQRET - powered by SHWAY Agency

SHWAY AGENCY PTY LTD

ABN 35 682 867 232 | ACN 682 867 232

Rossmore NSW 2557, Australia

Website: www.conqret.com.au

Privacy, security and support: support@conqret.com.au

Secondary contact: info@shway.agency

Cookie Notice

CONQRET currently uses essential technologies only — secure login, session continuity and fraud prevention. No analytics or advertising cookies are deployed. If that changes, this notice and a consent tool will be updated first.

CONQRET uses cookies and similar technologies to operate, secure and improve its website and Platform.

Essential technologies

These support secure login, session continuity, fraud prevention, load balancing, preferences and core functionality. They cannot ordinarily be disabled through the consent tool because the service may not function without them.

Analytics technologies

With consent where required, analytics tools may measure page use, feature adoption, errors and performance. The actual analytics providers and cookie durations must be inserted in the Subprocessor Schedule and cookie manager.

Marketing technologies

With consent where required, marketing tools may measure campaign performance and display relevant advertising. CONQRET should not intentionally send client project content, uploaded documents or sensitive information to advertising platforms.

Your choices

Users should be offered Accept all, Reject non-essential and Manage preferences controls. Consent records should be retained, and users should be able to change preferences later. Browser controls may also block cookies, although essential functions may be affected.

Recommended banner wording

Cookie banner

We use essential technologies to operate and secure CONQRET. With your permission, we also use analytics and marketing technologies to understand usage and improve our services. [Accept all] [Reject non-essential] [Manage preferences]

Service Providers & Data Locations

The technology providers that process information to deliver CONQRET, current as at 5 August 2026.

Cloud application hosting

Amazon Web Services (AWS Amplify)

Application hosting and delivery of the Platform

Processing location: Australia (Sydney, ap-southeast-2)

No use of Customer Data for provider training

Database, authentication, file storage & backups

Supabase

Database, user authentication, document and photo storage, backups

Processing location: Australia (Sydney), with provider backup handling per Supabase policy

No use of Customer Data for provider training

Payment processing

Stripe

Subscription billing, card processing, invoices and receipts

Processing location: United States and global Stripe infrastructure

Payment data held by Stripe under its own terms; CONQRET stores limited billing metadata only

Email delivery

Resend

Transactional and lifecycle email delivery

Processing location: Sending infrastructure in Japan (Tokyo); provider operated from the United States

Message content processed transiently for delivery

AI model / document processing

Anthropic (Claude API)

Contract extraction, drafting assistance, Ask CONQRET answers

Processing location: United States

API inputs and outputs are not used by Anthropic to train its models by default

SMS / notifications

None (device-native SMS links open in the user's own messaging app)

Analytics and advertising

None currently deployed (essential cookies only)

Electronic signatures

Built into the Platform (no third-party e-signature provider)

Typed-name approvals with timestamp, device and IP records

Processing location: Australia (Sydney)

Stored as Customer Data

Maps / location

Outbound links to Google Maps only (no embedded maps API)

Viewing a recorded check-in location

Processing location: Google's own terms apply when a link is opened

Accounting integration

None currently

CONQRET — powered by SHWAY Agency · SHWAY AGENCY PTY LTD · ABN 35 682 867 232 · Rossmore NSW 2557, Australia · Privacy: support@conqret.com.au