AgentHub 360 Logo

PRIVACY POLICY

Effective Date: 2026-07-17

Last Updated: 2026-07-17

Introduction

AGENTHUB AU PTY LTD ("we," "our" or "us") operates the AgentHub360 real-estate management platform. We are committed to safeguarding your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. What Personal Information We Collect

1. Contact Information

  • First and last name
  • Email address
  • Telephone number

2. Professional Information

  • Role
  • Company name and company ID

3. Account & Session Data

  • Session identifier
  • Login timestamps
  • IP address
  • Device and browser information

4. Usage & Technical Data

  • Pages viewed, features used, performance metrics
  • Referrer and exit pages

How we collect it:

  • Directly from you when you register or update your profile
  • Automatically via cookies and logs when you use AgentHub360
  • From third-party integrations (with your consent)
2. How We Use Your Information

We use your personal information to:

  • Provide and maintain the AgentHub360 platform
  • Authenticate and authorise your access (role-based permissions)
  • Communicate with you about account activity, support, and updates
  • Improve our features, performance, and security
  • Protect against fraud, abuse or unlawful activity
  • Fulfil legal & regulatory obligations
3. Disclosure of Your Information
  • We do not sell or rent your personal information.
  • We may share with trusted service providers (hosting, analytics, support) under strict confidentiality.
  • We may disclose when required by law, or to prevent fraud or security threats.
  • We will never share without your explicit consent, except as above.
4. Data Security

We implement robust measures, including:

  • AES-256 encryption for PII at rest and TLS 1.3 in transit
  • HttpOnly + Secure cookies for sessions
  • Role-based access controls
  • Regular audits, vulnerability scans and penetration tests
5. Data Retention

We keep your data only as long as needed:

  • Session data: 30 days
  • User profiles & company records: up to 7 years
  • Audit logs: 2 years

After which it is securely deleted or anonymised.

6. Your Rights

Under the APPs, you have the right to:

  • Access your personal data
  • Correct inaccuracies
  • Delete your account (subject to retention laws)
  • Export your data in a machine-readable format

To exercise these rights, contact our Privacy Officer (Section 9).

7. Cookies & Tracking

We use cookies to:

  • Manage secure sessions
  • Remember your preferences
  • Analyse anonymised usage

You may disable cookies in your browser, but this may affect functionality.

8. International Data Transfers

Your data is hosted on secure cloud infrastructure which may reside overseas. We ensure APP 8 compliance via:

  • Standard contractual clauses
  • Adequacy decisions
9. Contact & Complaints

Privacy Officer

AGENTHUB AU PTY LTD

Level 12, 412 St Kilda Rd, Melbourne VIC 3004

Email: privacy@agenthub360.com.au

We respond to all privacy requests within 30 days. If unresolved, you may contact the Office of the Australian Information Commissioner (OAIC).

10. Artificial Intelligence (AI) Transparency

We use artificial intelligence to enhance the services we provide through AgentHub360. We are committed to being transparent about how AI is used and how your data interacts with AI systems.

AI Providers

Our current AI provider is Google Gemini. We may add other vetted providers over time to improve our services. Any new provider will be subject to the same privacy and security standards described in this policy, and this section will be updated accordingly.

Your Data and AI

  • No model training: Your personal data is not used to train AI models.
  • Data minimisation: We only send the minimum data necessary for the AI feature to function.
  • No data retention by providers: We require our AI providers not to retain your data beyond what is needed to process the request.
  • Encryption: All data sent to AI providers is encrypted in transit using TLS 1.3.

Human Oversight

AI-generated outputs are used to assist — not replace — human decision-making. No automated decisions with legal or significant effects are made solely by AI.

11. Meta (Facebook / Instagram) Integrations

AgentHub360 offers buyer-agent agencies (our customers) optional integrations with Meta Platforms, Inc. (Facebook, Instagram and WhatsApp). These integrations are activated only when an agency administrator chooses to connect their Meta Business through the in-app Settings page. End consumers (e.g. property buyers) do not sign in to AgentHub360 with Facebook or Instagram.

Authentication: Facebook Login for Business

When an agency administrator clicks “Connect Meta Business” in AgentHub360 Settings, we use Facebook Login for Business solely to obtain a permissions token scoped to the Meta assets they explicitly grant (Ad Account, Page, Pixel and Business). We do not read profile information, friend lists, photos or any other personal Facebook data about the administrator.

Meta Pixel

Agency-published landing pages (hosted at buyr.at) may include the Meta Pixel when the agency selects one in their funnel settings. The Pixel records anonymised events (e.g. PageView, Lead) tied to a Meta-issued browser cookie (_fbp). Those identifiers are held by Meta on the buyer's behalf, not by AgentHub360.

Conversions API

When a buyer submits a form on a funnel page, AgentHub360 may send a server-side Lead event to Meta's Conversions API. We hash the buyer's email, phone, first name and last name using SHA-256 before transmission. We also forward the buyer's IP address, browser user-agent, and Meta-issued cookies (_fbp, _fbc) so Meta can deduplicate the event against the browser-side Pixel event.

Custom Audiences

When an agency connects Meta, AgentHub360 may automatically build and refresh a Meta Custom Audience from that agency's buyer list. We upload only SHA-256 hashed identifiers (email, phone, first name, last name), never raw values. The audience is created on the agency's own Ad Account; Meta's Customer Audience Terms apply.

Lead Ads (leads_retrieval)

When a buyer fills out a Facebook Lead Ad form run by an agency that has connected Meta to AgentHub360, Meta sends the lead submission to AgentHub360 via a secure webhook. We route it to the agency's CRM record so the agency can follow up. The legal basis for processing this lead is the consent the buyer gave when submitting the Lead Ad form on Facebook or Instagram.

Ad Management (Marketing API)

Agency administrators can create paused Meta ad campaigns from inside AgentHub360. Only ad metadata (campaign name, creative copy, image URL, destination URL, budget) is sent to Meta. No buyer data leaves AgentHub360 as part of this flow.

Meta as a data processor

For Custom Audiences and Conversions API, Meta acts as our data processor under its Business Tools Data Processing Terms and Custom Audiences Terms. For Pixel and Facebook Login for Business, Meta is the data controller and its Privacy Policy applies.

Your choices

To opt out of Meta-related processing of your data by AgentHub360, follow the steps on our Data Deletion Instructions page. To control how Meta itself processes your activity, use the privacy controls in your Facebook account or Instagram Accounts Center.

12. Changes to This Policy

We may update this policy from time to time. We will:

  • Post the new policy here with updated "Last Updated" date
  • Notify you by email or in-app message for material changes
  • Your continued use constitutes acceptance of those changes
13. Identity Service Provider (IDSP) role under the AML/CTF Act

13.1 Two roles, two sets of data. AgentHub processes personal information in two distinct capacities. This Section 13 applies only to information AgentHub collects in its capacity as an Identity Service Provider (IDSP) for Australian buyer's agency customers ("AML Data"). All other information continues to be governed by the other sections of this policy ("SaaS Data"). Where there is any conflict between this Section 13 and the other sections, this Section 13 prevails for AML Data.

13.2 IDSP registration. AGENTHUB AU PTY LTD (ABN 89 692 709 390) is registered as an Identity Service Provider with the Australian Government Attorney-General's Department under the Document Verification Service Access Policy, governed by the Identity Verification Services Act 2023 (Cth) and AgentHub's DVS Participation Agreement.

13.3 Gateway Service Provider. AgentHub uses GBG (greenID) as its approved Gateway Service Provider for routing requests to the DVS Hub.

13.4 Identity Opinion model and assurance levels. AgentHub forms an "Identity Opinion" based on multi-source verification. Two AgentHub-branded assurance levels are used:

  • AgentHub Standard - at least two DVS document matches from independent issuers, no sanctions hit, and no high-severity adverse media hit.
  • AgentHub Enhanced - AgentHub Standard plus a passed biometric face-match and liveness check.

AgentHub does not claim accreditation under the Trusted Digital Identity Framework (TDIF) and does not use TDIF identity-proofing (IP) labels.

13.5 Categories of AML Data we collect. Full legal name; previous names; date of birth; residential address; gender; document data and images for two of (driver's licence, passport, Medicare, ImmiCard, citizenship certificate, change-of-name certificate, birth certificate, or Visa/VEVO record); optional biometric face image and derived template (sensitive information under s. 6 of the Privacy Act 1988); device, IP, and session metadata captured during verification; and sanctions, PEP, and adverse-media screening results. For business customers, we also collect entity details and the identity information of Beneficial Owners.

13.6 Why we collect AML Data. Collection is required or authorised by Australian law - the applicable customer identification procedures under the AML/CTF Act 2006 and AML/CTF Rules, as relied upon by the Reporting Entity (the buyer's agency) under s. 37A of the AML/CTF Act. This satisfies APP 3.4(a) (collection required or authorised by or under an Australian law).

13.7 Third-party recipients of AML Data.

  • GBG (greenID) - routing to the DVS, biometric processing, and screening orchestration.
  • DVS source agencies via the AGD-administered DVS Hub (state and territory road authorities, DFAT, Services Australia, the Department of Home Affairs, Births Deaths and Marriages registries, and the AEC).
  • Sanctions, PEP, and adverse-media data providers contracted by GBG.
  • The Reporting Entity buyer's agency, which receives only the outcome, assurance level, and opinion reference ID.
  • AUSTRAC, AGD, the OAIC, courts, and law enforcement on lawful request.

13.8 Cross-border disclosure. Identity evidence and biometric templates are stored exclusively in AWS Sydney (ap-southeast-2). However, sanctions, PEP, and adverse-media screening may involve disclosure of name and date of birth to overseas recipients (typically in the UK, US, or EU). AgentHub takes reasonable steps under APP 8.1 to ensure overseas recipients handle the information consistently with the APPs, including contractual safeguards. AgentHub remains accountable under s. 16C of the Privacy Act for the acts of overseas recipients.

13.9 Retention. AML Data is retained for 7 years from the date the relevant Reporting Entity ceases to provide the designated service to the customer, in accordance with s. 107 of the AML/CTF Act and the AML/CTF Rules. After 7 years, AML Data is securely destroyed. This 7-year period overrides the standard retention period elsewhere in this policy for AML Data only.

13.10 Biometric information. Biometric templates are "sensitive information" under s. 6 of the Privacy Act 1988. AgentHub only collects biometric information where (a) the individual has given separate express consent on the consent screen, and (b) the Reporting Entity has enabled the biometric tier. Biometric templates are encrypted, never disclosed to the Reporting Entity, and never used for any purpose other than face-match and liveness for the original verification, plus a short rematch window in case of re-verification.

13.11 Subject access and correction for AML Data. Individuals may request access under APP 12 by emailing privacy@agenthub360.com.au. Access may be limited or refused where disclosure could prejudice an investigation under the AML/CTF Act (the "tipping off" provisions). Where access is refused on tipping-off grounds, AgentHub's notice will not state the reason for refusal, in accordance with the AML/CTF Act and OAIC guidance.

13.12 Complaints. Complaints regarding AML Data may be made to AgentHub at privacy@agenthub360.com.au; if unresolved within 30 days, to the Office of the Australian Information Commissioner at oaic.gov.au.

Thank you for trusting AGENTHUB AU PTY LTD with your data. Your privacy is our highest priority.

Save 8–10 hours per week on property research

Start your 14-day free trial. No credit card required. Set up in minutes, not days.

Enterprise-grade Security
24/7 Support
14-Day Free Trial