Privacy Policy — Launchr

Effective: 27 May 2026 · Last updated: 4 July 2026 · ABN 46 696 518 206 · Launchr Pty Ltd

1. INTRODUCTION

Launchr Pty Ltd ("we", "us", "our") operates Launchr platform ("Platform"). We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 (Privacy Act) and the Australian Privacy Principles (APPs).

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform.

1A. AN AGENT-DRIVEN COMPANY

Launchr is an Agent-driven company. Our Agents — artificial intelligence (AI) systems — perform much of the work of operating the Platform and may process personal information as part of delivering our services. AI systems can make mistakes, so we layer human verification over Agent output and take all reasonable steps to catch errors before they affect you. Our liability in connection with the Platform, including Agent-performed processing, is governed by sections 10 and 11 of our Terms of Service. Nothing in this policy or those Terms excludes rights that cannot lawfully be excluded, including your rights under the Privacy Act 1988 (Cth) and the Australian Consumer Law.

2. DEFINITIONS

3. TYPES OF INFORMATION WE COLLECT

3.1 Information You Provide

3.2 Information Collected Automatically

3.3 Information from Third Parties

4. HOW WE USE YOUR INFORMATION

4.1 To Provide Services

4.2 To Improve Services

4.3 Legal and Compliance

4.4 Marketing (with consent)

We obtain your express consent for marketing communications at the time of account registration via a clearly labelled opt-in checkbox. You may withdraw consent at any time by clicking 'Unsubscribe' in any marketing email or by contacting us at privacy@launchr.bot. Withdrawal of marketing consent does not affect service-related communications.

5. DISCLOSURE OF INFORMATION

5.1 Service Providers

We may share information with:

Several of these providers (including Anthropic, Cloudflare, Stripe, Twilio, ElevenLabs, and Resend) are based in, or process data in, the United States and other overseas locations — see section 9 (International Data Transfers) and Schedule A.

5.2 Legal Requirements

We may disclose information if required by:

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.

5.4 With Your Consent

We will share information with third parties when you give us explicit consent to do so.

6. DATA SECURITY

6.1 Security Measures

We implement appropriate technical and organisational measures including:

6.2 Data Isolation

Each business's data is isolated by business_id to prevent unauthorised access between accounts.

6.3 Employee Access

Our employees access personal information only on a need-to-know basis and are bound by confidentiality obligations.

7. DATA RETENTION

7.1 Retention Periods

We retain personal information for as long as:

7.2 Deletion

You may request deletion of your account and associated data. We will delete or anonymise your information within 30 days of account closure, except where retention is required by law.

8. YOUR RIGHTS

8.1 Access and Correction

You have the right to:

8.2 Opting Out

You may:

8.3 Making a Request

To exercise your rights, contact us at privacy@launchr.bot. We will respond within 30 days.

9. INTERNATIONAL DATA TRANSFERS

9.1 Data Location

Our services are hosted on global cloud infrastructure, including Cloudflare's network (which has Australian points of presence but is US-based and operates globally). Several of our service providers — including Anthropic (Agent processing), Stripe, Twilio, ElevenLabs, and Resend — are based in, or process data in, the United States and other countries. Schedule A lists each provider and its location.

9.2 Adequate Protection

When transferring data outside Australia, we ensure adequate protection through:

10. GDPR COMPLIANCE

10.1 For EU Users

If you are subject to the EU General Data Protection Regulation (GDPR), you have additional rights including:

10.2 Data Processing Agreement

Business customers requiring GDPR compliance may request a Data Processing Agreement.

10.3 Data Protection Officer

Our Data Protection Officer can be contacted at dpo@launchr.bot.

11. COOKIES AND TRACKING

11.1 Types of Cookies

We use:

11.2 Cookie Management

You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect platform functionality.

12. CHILDREN'S PRIVACY

Our Platform is not intended for children under 16. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it promptly.

13. DATA BREACH NOTIFICATION

13.1 Our Obligations

If a data breach occurs that is likely to result in serious harm, we will:

13.2 Notification Timeline

Upon becoming aware of a suspected data breach, we will conduct an assessment within 30 days to determine whether the breach is likely to result in serious harm. If serious harm is likely, we will notify the OAIC and affected individuals as soon as practicable following that assessment, and in any event within the timeframe required under Part IIIC of the Privacy Act 1988 (Cth).

14. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Platform. The effective date at the top indicates when changes take effect.

15. COMPLAINTS

15.1 Making a Complaint

If you have a privacy complaint, contact us at privacy@launchr.bot. We will investigate and respond within 30 days.

15.2 External Complaint

If you are not satisfied with our response, you may complain to:

16. CONTACT INFORMATION

Launchr Pty Ltd
81-83 Campbell St, Surry Hills NSW 2010
ABN: 46 696 518 206
Privacy Officer: privacy@launchr.bot
Data Protection Officer (GDPR): dpo@launchr.bot
Phone: +61 7 4800 4040


Schedule A: Third-Party Services

| Service Provider | Purpose | Data Shared | Location | |-----------------|---------|-------------|----------| | Stripe | Payment processing | Billing information, transaction data | Global (US-based) | | Anthropic | Agent (AI) processing — see section 1A | Content and communications submitted for processing, which may contain personal information | United States | | Cloudflare | Hosting and infrastructure | All platform data | Global (US-based, Australian points of presence) | | Resend | Email communications | Email addresses, message content | Global (US-based) | | Twilio | Telephony and SMS | Phone numbers, call and message content | United States | | ElevenLabs | Voice synthesis for phone and reception services | Call audio and transcripts | United States | | Google / Microsoft | Calendar integration (where you connect it) | Calendar and booking data | Global |

Cross-border note (APP 8): where a provider above is located outside Australia, we disclose personal information to it only for the purposes described in this policy and take reasonable steps (including contractual safeguards) to ensure it handles that information consistently with the Australian Privacy Principles.

Schedule B: Data Retention Schedule

| Data Type | Retention Period | Reason | |-----------|-----------------|--------| | Account Information | 7 years after account closure | Tax and legal requirements | | Transaction Records | 7 years | Financial reporting | | Communication Logs | 3 years | Service improvement | | Usage Analytics | 2 years | Analytics and reporting | | Backup Data | 30 days after deletion | Disaster recovery |