1. Who we are
FossickHQ (“we”, “us”, “our”) is an Australian software service providing a heritage collections management platform to Australian heritage organisations, museums, galleries, archives and history societies.
We are subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.
For privacy enquiries, contact us at: privacy@fossickhq.com
2. What personal information we collect
We collect the following categories of personal information:
- Account information: Name, email address, and password (stored as a bcrypt hash — we never store your actual password).
- Organisational information: The name and address of your heritage organisation.
- Usage data: Pages visited, actions taken within the application, and timestamps — used to improve the platform.
- Billing information: When you subscribe to a paid plan, payment details are handled directly by Stripe and are not stored on our servers. We receive only your Stripe customer ID and subscription status.
- Collection data: Catalogue records, images, audio notes, and videos that you upload — this is your data, not ours.
- Communications: Any emails or messages you send us.
We do not collect sensitive information (as defined by the Privacy Act) without your explicit consent.
3. How we collect personal information
We collect personal information:
- Directly from you when you register an account, subscribe to a plan, or contact us.
- Automatically through your use of the platform (log files, access records).
- From Stripe when you subscribe to a paid plan (subscription status and customer ID only).
4. Why we collect personal information (Purpose)
We use your personal information to:
- Provide, operate, and improve the FossickHQ platform.
- Create and manage your account.
- Process subscription payments and issue invoices.
- Send you service-related communications (e.g. password resets, subscription receipts).
- Respond to your support requests.
- Comply with our legal obligations.
We will not use your personal information for any purpose that is not directly related to providing our service without your explicit consent.
5. Disclosure of personal information
We do not sell, rent, or trade your personal information to any third party for marketing purposes.
We may disclose personal information to:
- Stripe Inc. — for payment processing. Stripe is PCI-DSS compliant. Their privacy policy is at stripe.com/au/privacy.
- Anthropic PBC — images and text may be sent to Claude AI for object identification and voice parsing. Anthropic's API data is processed under their commercial API terms and is not used to train their models. See anthropic.com/privacy.
- Microsoft Azure — our hosting infrastructure. All data is stored in Azure Australia Southeast (Melbourne, VIC). Azure is ISO 27001 certified and IRAP assessed.
- Law enforcement or regulators — only where required by Australian law.
6. Data storage and security
All FossickHQ data is stored in Microsoft Azure Australia Southeast (located in Melbourne, Victoria). Data does not leave Australia except as described in Section 5 (Anthropic API calls are processed in the United States — only the content of individual API requests is transmitted, never your full database).
We use the following security measures:
- TLS 1.3 encryption for all data in transit.
- Encryption at rest for all blob storage files (Azure SSE with Microsoft-managed keys).
- Passwords hashed using bcrypt (never stored in plaintext).
- HTTP-only, secure, SameSite session cookies for authentication.
- Role-based access control (ADMIN, MANAGER, CONTRIBUTOR, READ_ONLY).
- Security headers: Content Security Policy, X-Frame-Options DENY, X-Content-Type-Options nosniff.
While we take reasonable steps to protect your information, no internet transmission is completely secure. Please contact us immediately if you suspect any unauthorised access.
7. Your rights (Australian Privacy Principles)
Under the Privacy Act 1988, you have the right to:
- Access the personal information we hold about you (APP 12).
- Correct personal information that is inaccurate, incomplete, or out of date (APP 13).
- Make a complaint about how we handle your personal information.
To exercise any of these rights, email privacy@fossickhq.com. We will respond within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Cookies and tracking
FossickHQ uses a single authentication cookie (HTTP-only, Secure, SameSite=Lax) to maintain your login session. This cookie is essential for the platform to function and expires when you sign out or after 30 days of inactivity.
We do not use advertising cookies, cross-site tracking, or third-party analytics services.
9. Data retention
We retain your account data and collection records for as long as your account is active. If you close your account:
- Account credentials are deleted within 30 days.
- Collection data (catalogue records, images, audio, video) is deleted within 90 days, unless you have exported it first.
- Payment records are retained for 7 years as required by Australian tax law.
10. Children's privacy
FossickHQ is not directed at individuals under 18 years of age. We do not knowingly collect personal information from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email at least 14 days before they take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.
The current version of this policy is always available at fossickhq.com/privacy.
12. Contact us
For any privacy-related questions, access requests, or complaints:
Effective date: 26 May 2026 · This policy is written in plain English in compliance with APP 1.4(b).