Privacy Policy
Entity: IntraWork Group Pty Ltd (ABN 35 661 220 748), trading as GroundWork by IntraWork ("GroundWork", "we", "us"). Effective: 1 October 2026.
1. About this policy
This policy explains how we handle personal information in connection with GroundWork (web and iOS). We handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
2. Whose information we handle
- Users: people who sign up for, or use, a GroundWork workspace.
- Visitors trying GroundWork before creating an account: we create a temporary workspace so you can upload documents and see results before signing up.
- People in our customers' records: our customers store information about their staff, subcontractors and referees (for example licences, qualifications, CVs and checks) and about their own clients (for example names, contact details and site addresses). We hold this on the customer's behalf.
- People who receive documents through GroundWork: clients who view, accept, sign or pay a quote, invoice, booking, proposal or agreement sent by one of our customers.
If you are in the last two groups, the customer that added you is your first point of contact; we will help them respond to you (§12).
3. What we collect
- Account: name, email, organisation, role, and sign-in details. If you sign in with Google, Microsoft or Apple we receive your name and email from them. Passwords are held, hashed, by our authentication provider; we never see them. Multi-factor enrolment status.
- Customer Content: documents, records, tender responses, quotes, invoices and other content our customers upload or create, including any personal information in it.
- Signature and acceptance records: the signer's name as entered, the email address the document was sent to, time, IP address, browser details and a document hash.
- Billing: a Stripe customer and subscription identifier and status. Card details go directly to Stripe and never reach our servers.
- Business lookups: public details from the Australian Business Register when you enter an ABN.
- Technical and security: IP address, device and browser information, logs, security events and, on iOS or web, a push notification token if you turn notifications on.
- Usage: We do not use third-party analytics.
4. How we use it
To provide and secure GroundWork; to process documents you ask us to read; to send documents you ask us to send; to bill; to send service and account emails; to provide support; to prevent abuse and enforce spend limits; and to meet legal obligations. We do not sell personal information. We do not use Customer Content to train AI models.
5. Sensitive information
Our customers may store sensitive information, such as criminal record checks, where a tender or client requires it. We handle it only to provide the Service, as the customer directs. Customers should upload it only where needed and limit access within their team.
6. AI processing of documents
When you ask GroundWork to read a document (for example a tender pack or a company document during onboarding), its content is sent to our AI provider in the United States (OpenAI, or Anthropic — see §9) for processing. It is processed transiently to return the result to us. Under each provider's commercial API terms it is not used to train models and is retained by the provider for no more than 30 days. The result is stored in Australia with the rest of your data.
7. AI assistants and services you connect
If you connect an AI assistant (for example Claude or ChatGPT) or another service (for example Xero), we send it the information you authorise. From then on, that provider's privacy policy applies. Assistants connected to GroundWork cannot send, sign or delete anything.
8. Where your information is stored
Our database, file storage and application servers are in Australia (Sydney). Some processing happens overseas, as set out in §6 and §9.
9. Who we share it with
We use these service providers. Each handles personal information only to provide its service to us.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage, authentication | Australia (Sydney) |
| Vercel | Application hosting | Australia (Sydney) |
| OpenAI | AI processing of documents you ask us to read | United States |
| Anthropic | AI processing of documents you ask us to read (secondary provider) | United States |
| Stripe | Subscription billing; payments to our customers via their connected accounts | United States and other locations |
| Resend | Sending emails | United States |
| Upstash | Rate limiting (IP address, request counts) | Australia (Sydney) |
| Google, Microsoft, Apple | Sign-in (if you choose it); push notifications | United States |
We also share information: with the other party to a document when you send it through GroundWork; with services you connect (§7); with professional advisers; and where the law requires.
Overseas disclosure. We may disclose personal information to recipients in the United States. We take reasonable steps, including contractual terms, so those recipients handle it consistently with the APPs.
10. Security
Each customer's data is isolated from every other customer's by database-level access controls that are tested automatically on every change. Files are private and reached only through short-lived links. We use encrypted connections, offer multi-factor authentication, apply rate limits and spend limits, and log security-sensitive actions. Access by our staff to customer data is restricted to support and security needs.
11. How long we keep it
- Active accounts: for as long as the workspace exists. A cancelled subscription moves to a free tier and the data remains.
- Trying GroundWork without an account: if you do not create an account, the temporary workspace and its documents are deleted after 7 days.
- Deleted accounts: disabled immediately and permanently deleted after 30 days.
- Attestations and executed agreements: kept after deletion as evidentiary records, including the signature evidence above, because the other party relies on them. They are held under restricted access.
- Backups: expire on a rolling schedule of up to 30 days.
- Security logs: up to 12 months.
12. Access, correction and requests
You can ask to access or correct personal information we hold about you at support@intrawork.com.au. We will respond within 30 days. If your information was added by one of our customers, we may refer your request to that customer and help them respond. You can export your workspace data and delete your account in the app.
13. Email, cookies and local storage
We send service emails (account, security, billing, invitations, documents you send). Any marketing email will only be sent with consent and will include an unsubscribe link. We use cookies and similar local storage only to keep you signed in, remember preferences and protect the Service.
14. Automated decisions
GroundWork uses automated processes to extract tender requirements and show readiness views about businesses. We do not use them to make decisions that significantly affect individuals' rights or interests.
15. Data breaches
We have an incident response process. If an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where a breach affects a customer's records, we will tell that customer promptly.
16. Changes
We will post changes here and, for material changes, tell account owners by email.
17. Contact and complaints
support@intrawork.com.au. We aim to resolve complaints within 30 days. If you are not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.