Privacy Policy

Last updated: 21 July 2026

Suiviro Pty Ltd (ACN 699 266 987, ABN 30 699 266 987), trading as Smart Scheduler AI, is the data controller for personal information collected through the Service. Contact: privacy@smart-scheduler.com. This policy explains what we collect, why, how we protect it, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the GDPR and UK GDPR where applicable.

1. What we collect

  • Account data: name, email, organisation, role.
  • Usage and telemetry: pages visited, features used, error reports.
  • IP address and device metadata for security and authentication.
  • Support messages.
  • Job and customer data: jobs, addresses, staff schedules you enter.
  • Geolocation from addresses, geocoded via Google Maps Platform to compute travel time.
  • Calendar busy-time metadata when you connect Google or Microsoft calendars.
  • Where MCP Access is enabled, a log of the actions an AI assistant takes within your workspace and the scope of access you granted.

2. Why we use it

To provide the Service (contract); to secure it and prevent abuse (legitimate interest); to meet legal, tax and audit obligations (legal obligation); to send transactional and service notifications (contract); to send optional marketing where you have opted in (consent).

3. Subprocessors

  • Paddle.com, Merchant of Record for payments.
  • Lovable Cloud (Supabase), hosting, database, authentication and storage, Sydney region.
  • Google Maps Platform, geocoding and travel-time routing.
  • Google and Microsoft calendar APIs, busy-time sync where connected.
  • ClickSend, SMS delivery for reminders where enabled.
  • Microsoft Graph, email delivery via Outlook where enabled.

4. Retention

We keep account and operational data while your account is active. On deletion, personal data is purged within 30 days, subject to legal retention such as tax records for 7 years. Backups are rotated on a rolling 30-day cycle.

5. Security

Row-level security on every user-facing table, encrypted OAuth tokens for calendar and MCP integrations, TLS 1.2+ in transit, webhook signature verification, and quarterly restore drills. See our Security page.

6. International transfers

Personal data is stored in Sydney, Australia. Some subprocessors, including Google, Microsoft and Paddle, may process data in other jurisdictions under Standard Contractual Clauses or equivalent safeguards.

6A. EEA, UK and Swiss representative

We are established in Australia and do not currently offer goods or services to, or systematically monitor, individuals in the EEA or the UK at a scale that requires appointing a representative under Article 27 of the GDPR or UK GDPR. If our processing later meets those thresholds, we will appoint a representative and publish their contact details in this section within 30 days.

7. Your rights

Under the Australian Privacy Principles, and where applicable the GDPR/UK GDPR, you have rights to access, correct, erase, restrict, port, and object to processing of your personal data, and to withdraw consent. Email privacy@smart-scheduler.com; we respond within 30 days.

8. Complaints

Complain to us first at privacy@smart-scheduler.com. If unsatisfied, complain to the Office of the Australian Information Commissioner (oaic.gov.au), or, in the EU/UK, your local supervisory authority.

9. Notifiable Data Breaches

We maintain an incident response plan. If a notifiable data breach occurs, we notify affected individuals and the OAIC within the statutory timeframes.

10. AI-specific processing

Smart Scheduler AI uses constraint programming and, where enabled, generative AI. We do not sell your data and do not train third-party foundation models on your customer or staff data. Where you enable MCP Access, the connected AI assistant only receives the schedule, staff and job data within the permission scope you grant, and its actions are logged for your audit.

11. Cookies

See our Cookie Policy.