PostMyDoc Business – Privacy Policy
How PostMyDoc handles personal information in connection with the PostMyDoc Business Portal.
1. Who we are
This Privacy Policy explains how PostMyDoc collects, holds, uses, discloses and protects personal information in connection with the PostMyDoc Business service.
In this Privacy Policy, we, us and our mean PostMyDoc Digital Mailing Service Pty Ltd (ACN 697 539 512), trading as PostMyDoc, of 82 Onkaparinga Valley Road, Woodside, South Australia 5244 (ABN 18 697 539 512). We are an APP entity for the purposes of the Privacy Act 1988 (Cth) (the Privacy Act).
PostMyDoc operates a digital-to-physical mail service. Through the Business service, an approved business customer submits one or more PDF files and delivery instructions through the Business Portal or another ordering channel accepted by PostMyDoc. We prepare and print the PDF files and, where the order proceeds to dispatch, post the resulting item to the nominated recipient through Australia Post.
PDF files held in live server storage are removed under the Burn After Reading Policy described in Section 9. The automated purge is based on the age of each PDF file in live server storage and is not conditional on dispatch. A PDF file may be removed before or after dispatch, or where the associated item is cancelled or never dispatched.
We handle document content under our Burn After Reading Policy, described in Section 9. The applicable deletion or destruction process depends on where the document is held. Stored server-side files, temporary local operational copies, customer-initiated email copies, hosting-platform back-ups and returned physical mail each have the lifecycle described in Sections 9 and 11.
We are committed to handling personal information in accordance with the Privacy Act and the Australian Privacy Principles (the APPs). This commitment applies regardless of any small-business exemption that might otherwise be available.
2. What this Privacy Policy covers
This Privacy Policy applies to the PostMyDoc Business service. It covers personal information handled in connection with an approved Business account and a Business Order, regardless of whether the Business Order is submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc.
A Business Order is an order that PostMyDoc treats as an order under an approved Business account. An order placed by a person or entity that does not hold an approved Business account is governed by the applicable consumer privacy policy unless PostMyDoc expressly agrees to treat it as a Business Order.
This Privacy Policy also applies where an entity formed outside Australia applies for a Business account through a manual application process accepted by PostMyDoc. In that process, we may collect official company, business or tax registration identifiers and other information reasonably required to verify the applicant’s legal identity, registration status, business activities, ownership, authority and suitability for the Business service.
Submitting an application does not guarantee approval. An overseas applicant must not provide document content, recipient information or other Customer Personal Data for a Business Order unless and until its Business account has been approved, it has accepted the applicable PostMyDoc Business documents, and any data-transfer requirements under the DPA have been satisfied.
This Privacy Policy covers personal information handled through:
- the Business account application and our approval of that application;
- the Business Portal and its features, including order creation, recipient entry, saved-recipient and address-book features, team and invitation management, account management, and billing, invoices and statements;
- Business Orders submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc;
- the Business-order pipeline, including receipt of documents and delivery instructions, preparation and printing, dispatch, tracking, returns, reposting, deletion and secure destruction;
- temporary local operational copies created where reasonably necessary to prepare, print, dispatch or complete fulfilment of a Business Order;
- customer-initiated email copies of documents submitted for Business Orders;
- returned physical mail held for possible reposting and then securely destroyed;
- document-deletion records and certificates;
- business-related emails, including order confirmation, dispatch, delivery, first-deletion, weekly digest, account and approval emails; and
- the business account information described in Section 4.
Not covered by this Privacy Policy
This Privacy Policy does not cover:
- an order placed by a person or entity that does not hold an approved Business account, unless PostMyDoc expressly agrees to treat it as a Business Order;
- the consumer PostMyDoc website, which is governed by our consumer Privacy Policy at postmydoc.au/privacy-policy;
- the PostMyDoc consumer mobile app, which is governed by its own privacy policy and the relevant app-store terms; or
- the Chatway chat widget, which operates only on consumer pages and is switched off across the Business Portal.
If you are a prospective customer browsing our marketing pages before your Business account is approved, that browsing is governed by the consumer Privacy Policy until your account is approved and the Business service begins.
3. Our two roles: information we handle for you, and information we handle for ourselves
Because this is a business service, it helps to be clear about who decides how personal information is handled. There are two situations.
3.1 Information you control: your Business Orders, documents and recipients
When your business uses the PostMyDoc Business service, your business decides what documents to send and to whom. This applies whether a Business Order is submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc.
For the PDF files you submit and the recipient details and delivery instructions you provide, your business controls that information. We handle it on your business’s instructions to receive and verify the Business Order, prepare and print the PDF files, dispatch the resulting items where the order proceeds, complete fulfilment, administer returns and reposting, and carry out the applicable deletion or secure-destruction process.
PDF files held in live server storage are removed under the age-based Burn After Reading Policy independently of dispatch. Other active and back-up copies follow the separate lifecycles described in Sections 9 and 11.
Our handling of that information is governed by the PostMyDoc Business Data Processing Agreement (the DPA), under which your business is the controller and PostMyDoc acts as your processor. The DPA also sets out how requests from individuals about that information are handled, as explained in Section 12.
3.2 Information we control: running, securing and improving the service
Separately, we collect and use some personal information in our own right to operate, secure and improve the Business service, administer accounts and Business Orders, manage dispatch, returns and deletion records, bill and keep financial records, prevent fraud and abuse, and meet our own legal obligations. This Privacy Policy governs that information.
Under Australian privacy law, the APPs apply to all personal information we hold, in both situations. This Privacy Policy describes the whole picture, and points to the DPA where the DPA governs the detail.
4. The personal information we collect
The kinds of personal information we may collect and hold in connection with the Business Portal include the following.
| Category | What it includes |
| Account and identity information | Business name, Australian Business Number where applicable, official company, business or tax registration identifiers for an approved foreign applicant, jurisdiction of formation, industry or sector, and information reasonably required to verify the applicant’s legal identity, registration status, business activities, ownership and authority; the applicant’s name and email; the Primary Contact’s name, email and phone number; the names and emails of additional and invited business users; each user’s role; and internal notes we keep about the application and account. |
| Authentication and security information | Account passwords (stored only as salted hashes); login-attempt information used to protect against brute-force attacks, including IP address, time and the username entered; and the tokens behind invitation and password-reset links. |
| Order, recipient, dispatch, return and deletion information | Recipient names and delivery addresses, including address lines, suburb or city, state, postcode and country; partial address text entered while using address autocomplete; destination zone; postage service; tracking number and delivery status; dispatch date; order references such as a purchase-order number, cost centre or sender label; order intake channel; returned-mail receipt, hold, reposting and destruction information; and deletion and certificate information, including relevant submission, dispatch and deletion dates. |
| Document content | The content of PDF files submitted for a Business Order. You determine the content, which may include personal information and sensitive information of any kind. PDF files held in live server storage are removed by the automated hourly purge once they become more than 24 hours old. Removal is based on the age of the file in live server storage and is not conditional on dispatch. Other copies follow the separate retention and deletion periods described in Sections 9 and 11. |
| Operational custody information | Information about how document content is received, accessed, prepared, printed, deleted or securely destroyed, including authorised local access, customer-initiated email intake, deletion-event records, content hashes, filenames and document-deletion certificate records. These records do not ordinarily contain the document content itself. |
| Billing and transaction information | Order and pricing details, invoices and statements, payment status, and payment-transaction information. Card and payment-instrument details are collected and processed directly by our payment provider (Stripe); we do not store full card numbers. |
| Usage and analytics information | Page-view and usage information and related identifiers (including IP address), collected for site analytics. We collect this from visitors to the portal, including signed-in business users. |
Whose information it is
The individuals whose personal information we handle through the Business service fall into three groups:
- your authorised users, including your Primary Contact, shown in the Business Portal as the Account Admin, and other business users and invitees, typically your staff;
- recipients of mailed documents, including recipients of items that are returned to PostMyDoc as undeliverable; and
- individuals who appear within documents submitted for Business Orders.
You determine whose personal information appears in documents and the nature of that information. We do not control the document content.
How we collect personal information
We collect personal information:
- directly from you, when you apply for a Business account through the public online application or an accepted manual application process, provide identity, business-registration or authority information, set up or manage your account, submit a Business Order through the Business Portal or another accepted ordering channel, contact us, request reposting, or request a document-deletion certificate;
- automatically, through server logs, site analytics, cookies and similar technologies, as described in Section 14;
- from third parties, including when a colleague invites you to a Business account, our payment provider confirms a payment status, Australia Post provides tracking or return information, or returned physical mail is delivered to us; and
- from documents, delivery instructions and related communications submitted by or for your business in connection with a Business Order.
5. Sensitive information
Sensitive information is a special category of personal information that receives a higher level of protection under the APPs. It includes information about a person’s health, racial or ethnic origin, political opinions or memberships, religious or philosophical beliefs, trade-union membership, sexual orientation or practices, criminal record, and genetic and biometric information.
Where a document contains sensitive information, you remain responsible for the document content and for having any consent or other authority required to send it. You instruct us to handle that information only as reasonably necessary to receive and verify the Business Order, prepare and print the document, dispatch it to the nominated recipient, complete fulfilment, administer any return or reposting, and carry out the applicable deletion or secure-destruction process.
The relevant security and lifecycle measures are described in Sections 9, 10 and 11. We do not use document content for analytics, advertising, product development or any other unrelated purpose.
6. How we use personal information
We collect, hold, use and disclose personal information for the following purposes:
- to set up and provide the Business service and the print-and-post service;
- to create accounts, verify and approve Business account applications, and manage your account and team;
- to receive and administer Business Orders submitted through the Business Portal or another accepted ordering channel;
- to receive and verify document content and delivery instructions;
- to create temporary local operational copies where reasonably necessary to prepare, print, dispatch or complete fulfilment;
- to print and post documents to the recipients you nominate;
- to track dispatch and delivery;
- to receive, hold and, on request, repost returned physical mail;
- to securely destroy returned physical mail that is not reposted within the applicable holding period;
- to create and retain deletion records and provide document-deletion certificates;
- to send order, dispatch, delivery, deletion and account communications, and the weekly digest;
- to process payments, issue invoices and statements, and keep financial records;
- to respond to enquiries and provide customer support;
- to operate, secure, maintain and improve the Business service, including site analytics;
- to detect, investigate and prevent fraud, abuse and security threats; and
- to comply with our legal obligations, including tax record-keeping, and to establish, exercise or defend legal claims.
We do not send unsolicited marketing. We send service-related and account communications connected to your use of the Business Portal. If we ever introduce optional product or marketing communications, they will be sent consistently with the Spam Act 2003 (Cth) and will include an easy way to opt out.
We do not sell, rent or trade personal information.
7. Who we disclose personal information to
We disclose personal information only where it is needed to provide the service, where you would expect it, or where we are required or authorised by law. We use a small number of trusted service providers to run the Business Portal. The main ones are:
| Provider | What they do for us | Where |
| Netregistry Pty Ltd trading as Webcentral | Website and database hosting, file storage, and the outgoing email (SMTP) infrastructure for our business emails. | Australia (Sydney) |
| Stripe Payments Europe, Limited (SPEL), together with other Stripe group entities and service providers | Processing payments for orders, invoices and statements, and providing checkout security and fraud-prevention services. Stripe may process payment information, checkout-session interaction data, cookies or similar technologies, IP address, device and browser information, and session identifiers. We do not store full card numbers. | Ireland, Australia, the United States and other locations where Stripe group entities and approved service providers operate |
| Australia Post | Physical dispatch, delivery and tracking; return of undeliverable mail to PostMyDoc; and reposting where requested. | Australia |
| Google Maps Platform (Google LLC) | Address autocomplete while you enter a recipient’s address. | United States and other locations |
| Google Analytics (GA4) (Google LLC) | Site analytics for the Business Portal, covering both logged-out visitors and signed-in business users. | United States and other locations |
| Google Fonts (Google LLC) | Delivery of web fonts used to render Business Portal pages; loading a font sends the visitor’s IP address and User-Agent to Google. | United States and other locations |
| Google Tag Manager (Google LLC) | Tag-management container that loads and manages measurement tags on the portal. | United States and other locations |
| Cloudflare, Inc. | Turnstile bot and abuse protection (a CAPTCHA) on the Business account application form. | United States (with Australian points of presence) |
| Limit Login Attempts Reloaded cloud (Atlantic Silicon Inc.) | Login-security firewall that checks login attempts against a shared IP-reputation list and contributes login-attempt information to it. | United States |
Our Business Portal administrative and transactional notifications do not include customer document files as email attachments. If your business chooses to submit document content to us by email, the email provider involved in transmitting and hosting that communication may process the email and attachment. Our handling of customer-initiated email copies is described in Sections 9, 10 and 11.
We may also disclose personal information to:
- our professional advisers (such as lawyers and accountants), under confidentiality;
- courts, tribunals, regulators and law-enforcement agencies, where required or authorised by law, or to establish, exercise or defend our legal rights; and
- a buyer or successor, if our business or assets are transferred, merged or sold — in which case we will take reasonable steps to ensure the information remains protected.
We require our service providers to handle personal information only for the purposes for which we engage them, and to protect it to a standard consistent with this Privacy Policy and the APPs.
8. Overseas disclosure of personal information
We store personal information primarily in Australia (Sydney). Some service providers process limited information outside Australia, or both inside and outside Australia, as described below. Customer-initiated email communications may also be processed or backed up in locations used by the relevant email-service or hosting provider.
| Provider | Country | Purpose |
| Stripe | Ireland, Australia, United States and other locations where Stripe group entities and approved service providers operate | Payment processing, checkout security and fraud prevention |
| Google LLC (Maps Platform, Analytics, Fonts and Tag Manager) | United States and other locations | Address autocomplete; site analytics |
| Cloudflare, Inc. | United States (Australian points of presence) | Bot/abuse protection on the application form |
| Atlantic Silicon Inc. (Limit Login Attempts Reloaded cloud) | United States | Login security and IP reputation |
Where your business submits document content by email, the email and attachment may pass through or be backed up by the email infrastructure used by the sender, PostMyDoc or their respective service providers. You should use the Business Portal rather than email where you do not want document content to pass through email systems.
Where we disclose personal information to an overseas recipient, we take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs in relation to that information, consistent with APP 8.1. We also recognise that, under section 16C of the Privacy Act, we may be accountable for the handling of personal information by some overseas recipients.
The Business Portal is available to Australian businesses that satisfy our standard application requirements and to entities formed outside Australia that we expressly approve through our manual application process. Overseas entities are considered individually and are not automatically eligible for a Business account. If we accept a customer to whom the GDPR or UK GDPR applies, and that law requires a transfer mechanism for personal information sent to us in Australia, we will enter into the required mechanism with that customer before the restricted transfer begins, as provided in clause 16.3 of the DPA.
9. The Burn After Reading Policy: how we handle your documents
The Burn After Reading Policy applies to document content submitted for a Business Order. A Business Order may be submitted through the Business Portal or through another ordering channel accepted by PostMyDoc, including email or telephone.
Different custody channels have different deletion, retention or destruction processes. The automated server-side purge applies to document files held in live server storage. Temporary local operational copies, customer-initiated email copies, hosting-platform back-ups and returned physical mail are handled under the separate lifecycles described in this Section 9 and Section 11. Deletion, removal or destruction in one custody channel does not itself delete, remove or destroy a copy held in another custody channel.
9.1 Encryption in transit and at rest. Documents are encrypted in transit and at rest. All connections to the Business Portal and to our service are served over HTTPS/TLS.
9.2 Restricted storage. Uploaded documents are stored in a restricted server location that is not publicly accessible. They cannot be reached by a direct link and require authenticated, server-side access.
9.3 Purpose limitation
We handle PDF file content only as reasonably necessary to receive and verify a Business Order, prepare and print the documents, dispatch them where the order proceeds, complete fulfilment, administer any return or reposting, and carry out the applicable deletion or secure-destruction process.
Our personnel may access PDF file content only to the extent reasonably necessary for those purposes. We do not use PDF file content for analytics, advertising, product development or any unrelated purpose.
9.4 Automatic deletion
An automated server-side purge runs hourly and removes each uploaded PDF file from live server storage once it becomes more than 24 hours old. If the purge process is interrupted, deletion completes when it next runs successfully.
The deletion timetable is measured from the age of the PDF file in live server storage and is not conditional on dispatch. A PDF file may therefore be removed before or after dispatch, while an order is awaiting payment settlement or another pre-dispatch step, after an order or Envelope is cancelled, or where dispatch never occurs.
Removal deletes the PDF file from the live server file system. It is not cryptographic erasure and does not itself delete a temporary local operational copy or customer-initiated email copy, rotate out a protected back-up copy, or destroy returned physical mail.
When the automated purge removes a PDF file from live server storage, our system records the deletion event for that PDF file and its associated Envelope. The deletion record is created when the purge occurs, whether or not the Envelope has been dispatched. Dispatch information, if any, is recorded separately.
9.5 Temporary local operational copies
Where reasonably necessary to prepare, print, dispatch or complete fulfilment of a Business Order, authorised personnel may download or create a temporary local operational copy on an access-controlled local device.
Access is limited to authorised personnel who require the copy for fulfilment. The copy must not be used for another purpose. It is deleted promptly after dispatch is confirmed or, if fulfilment does not proceed, promptly after cancellation or closure of the Business Order.
A temporary local operational copy may remain after the corresponding PDF file has been removed from live server storage where this is reasonably necessary to complete delayed fulfilment, including an order awaiting payment settlement.
9.6 Email handling
Business Portal administrative and transactional notifications do not include customer document files as email attachments.
If your business chooses to submit document content to us by email, authorised personnel may access the email and attachment only as reasonably necessary to receive, verify, prepare, fulfil and administer the Business Order. After those activities are complete, the attachment and any operational email copy containing it are deleted from our active email systems.
A protected copy may remain in an email-service or hosting-provider back-up until the applicable back-up rotates out. Back-up copies are not used for ordinary access or order fulfilment.
9.7 Returned physical mail
If an item is returned to PostMyDoc as undeliverable, we hold the returned physical mail securely for five business days after we receive it. Access during this period is limited to authorised personnel.
During the five-business-day period, we may repost the item if your business asks us to do so. If it is not reposted during that period, we securely destroy the returned physical mail after the period ends.
We retain returned physical mail for longer only where required by law or a valid and binding legal preservation requirement.
9.8 Back-ups
Our hosting provider creates full-volume, rolling disaster-recovery back-ups of the hosting account. These back-ups may include files, databases, email accounts, account configurations and encryption-related material present in the hosted environment at the time of capture.
The provider's back-up system cannot be configured to exclude a particular folder or directory. If a PDF file is captured before the automated purge removes it from live server storage, a back-up copy may remain until the relevant back-up is overwritten or rotated out. The provider's current configured retention period is up to approximately 30 days.
Only the most recent seven days of restore points are routinely available to us. We cannot selectively retrieve or delete an individual PDF file from a back-up, and we cannot accelerate the provider's rotation of a particular back-up copy.
The provider states that back-ups may be used to restore data or an account where data or the account is accidentally or maliciously deleted, corrupted or otherwise damaged. PostMyDoc does not use back-ups for ordinary document access, retrieval or resending.
Our application-level encryption protects PDF file content in the live environment. Because a full-volume back-up may also capture encryption-related material from the hosted account, we do not represent that application-level encryption provides complete separation between encrypted PDF files and the material needed to access them within a back-up. Back-up risk is instead reduced through limited retention, restricted use and automatic rotation.
We rely on the hosting provider's published privacy and security practices for its handling of back-up infrastructure. Those published practices are not equivalent to a separate data processing agreement, security schedule, audit right or contractual security standard between PostMyDoc and the provider.
9.9 Deletion records and certificates
When the automated purge removes a PDF file from live server storage, our system creates a deletion record for that PDF file and the associated envelope. The deletion record is generated by the purge event and does not depend on dispatch.
A document-deletion certificate records the automated purge of the stored server-side PDF file or files associated with an envelope. Eligibility for a certificate is based on the purge and the creation of the required system records, not on dispatch.
Where both deletion and dispatch have been recorded, an eligible certificate may be available through the Business Portal or the applicable deletion-notification link. If self-service access is unavailable, including because dispatch has not occurred or has not been recorded, the business customer may request the certificate from PostMyDoc by email.
An eligible certificate may be issued where the associated item was cancelled, refunded or never dispatched. It may record no dispatch date or show that deletion occurred before dispatch.
A certificate records only deletion from live server storage by the automated purge. It does not certify deletion of temporary local operational copies, customer-initiated email copies or other manually held copies, rotation of back-up copies, or destruction of returned physical mail.
We retain the limited account, order, dispatch, return, deletion and certificate information needed to operate the service and meet our legal obligations, for the periods described in Section 11 and the DPA.
PostMyDoc may retain the limited system records reasonably required to create, provide and verify deletion records and document-deletion certificates, including the Envelope identifier, filename, content hash and relevant event dates, until those records are deleted in accordance with Section 11.
9.10 No recovery
After a PDF file has been removed from live server storage, it cannot be recovered or resent from the live server.
A temporary local operational copy may remain only where reasonably necessary to complete fulfilment and is deleted under Section 9.5. Once all active operational copies have been deleted, we cannot ordinarily resend or recover the PDF file. If it is needed again, you must provide it again.
9.11 Local print handling
Our printing process does not send PDF file content submitted for a Business Order to a third-party cloud print service. PDF file content is prepared for printing within our controlled operating environment and is not intentionally stored by a cloud print provider.
This section applies only to submitted PDF file content. It does not prevent a printer, device or supporting service from processing ordinary operational or technical information that does not contain submitted PDF file content.
This section does not limit our use of the service providers identified in Sections 7 and 8 or in the DPA for hosting, security, payments, address services or other supporting functions that do not involve third-party cloud printing of submitted PDF file content.
This section describes security and print-handling controls that apply during relevant processing stages. It does not create a separate custody channel or alter the deletion, retention or destruction lifecycle applying to any copy under Sections 9 and 11.
10. How we keep personal information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure, as required by APP 11. Our measures include:
Encryption in transit — all connections are served over HTTPS/TLS.
Encryption at rest — business document content is encrypted at rest on our systems using authenticated encryption (the libsodium library), so the stored files are ciphertext and our database holds no document content. This protection is combined with data minimisation. PDF files held in live server storage are removed by the automated hourly purge when they become more than 24 hours old, whether or not the associated item has been dispatched. Temporary local operational copies and customer-initiated email copies follow their separate security and deletion controls under Sections 9 and 11. Access to stored information is role-restricted.
Role-based and least-privilege access: A dedicated business-user role applies. Row-level visibility allows the Primary Contact to see the account’s orders, while other users see only their own. Access defaults securely to a user’s own records until a Primary Contact is set. An opaque “not found” response is returned when someone attempts to access a record they are not permitted to see. Database permissions, application permissions and hosting file permissions are configured on a least-privilege basis.
Temporary local-copy controls: Temporary local operational copies are created only where reasonably necessary for print preparation, dispatch or fulfilment. They are held on access-controlled devices, are available only to authorised personnel who require them for fulfilment, and are deleted promptly after dispatch confirmation or cancellation.
Authentication — passwords stored only as salted hashes, a minimum password length, a branded login, and a tokenised password-reset flow.
Multi-factor authentication — enforced on administrative and operator access, and on the third-party consoles used to run the service (hosting, payments and connected services).
Gated downloads — documents and billing files are served only through authenticated, permission-checked download paths; direct unauthenticated file access is not allowed.
Brute-force, reset and abuse protection: Login attempts are rate-limited and may be locked out following repeated failures. Password-reset requests are subject to separate throttling by email address and source address. Cloud-assisted IP-reputation checks are also used to identify suspected automated attacks, abusive activity and known malicious sources.
Input validation — uploads are checked by file type and capped in size, key values are validated against strict allow-lists, and errors are returned without exposing internal detail.
Privacy-by-design in notifications — email subject lines deliberately omit recipient location detail, and an anonymous-sender option lets the sender’s identity be withheld on dispatch.
Secure hosting — Our hosting is provided in Australia (Sydney) by Netregistry Pty Ltd trading as Webcentral on a managed platform. Based on the provider information available to us, the platform includes a web application firewall, malware scanning, platform security patching, twice-daily full-volume back-ups, recovery functions and monitoring for suspected security incidents. Scheduled tasks, including document deletion, run on a server-level scheduler.
We have reviewed an ISO/IEC 27001:2022 certificate naming Netregistry Pty Ltd and Terrific.com.au Pty Ltd. Its stated scope is information security for internet domain name registration services. It does not state that our managed hosting service or the relevant data centre is within the certification scope. We therefore do not claim that the hosting service, hosting environment, relevant data centre or PostMyDoc is ISO/IEC 27001 certified.
Logging and incident response — we log document-deletion events, payment and webhook processing, and authentication failures and lockouts, and we follow a process to detect, contain, assess and notify data breaches (see Section 11 for log retention).
We consider supplier certifications and compliance information where they are relevant to the particular service we use and their stated scope. A certification held by a supplier does not necessarily cover every service, system or facility the supplier operates. PostMyDoc does not claim a supplier certification as its own and does not describe a service or data centre as certified unless the available certification expressly covers it.
Where a payment provider maintains an industry certification or compliance status, such as PCI DSS, that status applies only to the provider, services and scope identified by the provider. It does not constitute a certification of PostMyDoc.
While we take every reasonable precaution, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. How long we keep personal information
We keep personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as the law requires. In general:
| Information | How long we keep it |
| PDF file content held in live server storage | Removed by an automated purge that runs hourly once the PDF file becomes more than 24 hours old. The timing is measured from the age of the PDF file in live server storage and is not conditional on dispatch. Removal may occur before or after dispatch, or where the associated item is cancelled or never dispatched. A copy captured in a hosting-platform back-up may remain until that back-up rotates out, for up to approximately 30 days. Temporary local operational copies and customer-initiated email copies follow their separate retention periods in this Privacy Policy. |
| Recipient information and order/dispatch history | Deleted within 90 days after closure of the relevant Business account, unless retention of specific information is required by law or reasonably necessary for a legal claim, regulatory matter, fraud or security investigation. This does not affect the limited financial and tax records described below. |
| Business account, user and identity records | Deleted within 90 days after closure of the relevant Business account, subject to any limited retention required for a legal claim, regulatory matter, fraud or security investigation. |
| Internal account notes | Deleted within 90 days after closure of the relevant Business account, unless a particular note must be retained for a legal claim, regulatory matter, fraud or security investigation. Ordinary operational and support notes are not retained merely because financial records are kept. |
| Financial, tax, invoice, payment and reconciliation records | Up to 7 years, to meet Australian tax, accounting and record-keeping obligations and to establish, exercise or defend legal claims. We retain only the minimum personal information needed for those purposes and, where practicable, use an anonymised account reference or other limited identifier. |
| Authentication and security logs | Authentication and security logs are retained for approximately 30 days, unless a longer period is reasonably necessary for a documented investigation or response relating to a security incident, fraud, misuse or unlawful activity. Age-based deletion runs automatically through a server-level scheduled process and does not depend on user traffic. A record may be retained beyond the ordinary period only under a deliberate, documented hold with a specified expiry date and time. Records retained for longer are access-restricted, reviewed periodically and deleted through the automated process when the documented retention purpose ends. |
| Customer communications | About 3 years from the date of the communication. |
| Site analytics | In line with our configured Google Analytics retention, up to 14 months. |
When a Business account ends, we will, at your election, return or delete the personal information we hold for you and delete existing copies within 90 days, except where we are required or permitted by law to keep certain records.
This means we will delete the recipient graph and associated recipient information, including recipient names, delivery addresses, order and dispatch history, account and user identity records, and ordinary internal account notes, within that 90-day period. We will also disable account access and delete authentication records in accordance with our applicable retention periods.
We may retain the minimum personal information necessary to comply with legal obligations, including Australian tax, accounting and record-keeping requirements, to maintain invoices, payment, reconciliation and transaction records, or to establish, exercise or defend legal claims. We may also retain limited information where reasonably necessary to investigate or prevent fraud, security incidents, misuse or unlawful activity, or to comply with a request from a regulator, court, tribunal or law-enforcement agency.
Where financial or tax records must be retained, we will limit the information retained to what is reasonably necessary for that purpose. Where practicable, we will use an anonymised account reference or other limited identifier to preserve the integrity of those records. We will not retain recipient names, delivery addresses, recipient history, active account access, account credentials or uploaded document content merely because a financial or tax record is retained.
Any personal information retained after account closure will be access-restricted, will not be used for ordinary service administration, marketing, profiling or analytics, and will be securely deleted or irreversibly anonymised when the relevant retention purpose ends. The detailed return-and-deletion terms are in the DPA.
12. Your rights and choices
12.1 Access
You may ask for access to personal information we hold about you under APP 12.
Because PDF files are removed from live server storage by the age-based automated purge, we will generally be unable to provide their content after the purge has occurred. This may happen before or after dispatch, or where dispatch never occurs.
We may still be able to provide related account, order, dispatch, return, deletion-event and certificate information that we retain.
12.2 Correction. If you think any personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it (APP 13). We will take reasonable steps to do so.
12.3 Anonymity and pseudonymity. Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym (APP 2). In practice, running a Business account and printing and posting documents requires accurate identity, contact and recipient details, so this is limited.
12.4 Requests about recipients or people named in documents. If we receive a request from an individual whose personal information we hold only because your business sent it to us (for example, a recipient of a mailed document), we will, in line with the DPA, refer that request to your business as the controller of that information rather than responding to it ourselves, except where the law requires otherwise.
12.5 How to make a request. To exercise any of these rights, contact our privacy contact at privacy@postmydoc.au. We will respond within a reasonable time, and in any event within 30 days. We may need to verify your identity first, and an administrative fee may apply to an access request in limited circumstances permitted by the Privacy Act.
13. Automated decision-making
We do not use computer programs to make decisions about you that could reasonably be expected to significantly affect your rights or interests. Decisions such as approving a Business account are made by a person, and our automated security measures (such as login rate-limiting) protect the service rather than make significant decisions about individuals.
From 10 December 2026, new transparency obligations under the Privacy Act (APP 1.7 to 1.9) will require organisations that use personal information in automated decisions with significant effects to disclose this in their privacy policy. If we introduce any such automated decision-making, we will update this Privacy Policy accordingly before then.
14. Cookies and similar technologies
The Business Portal uses cookies and similar technologies for the following purposes:
Essential and functional — to keep you signed in, to remember your selections on the order form, and to make the ordering and checkout process work.
Analytics — to understand how the portal is used, through Google Analytics. This covers both logged-out visitors and signed-in business users.
Security — The breached-password check forms part of the password controls described in Section 10. It is used only to determine whether a proposed password appears in the public breach corpus. We send only a short, partial fingerprint of the proposed password from our server. We never send the password itself, your name, your email address or your IP address.
Order drafts — the Business Portal saves your in-progress order as a draft in your own browser’s storage, so a part-completed order is not lost if you close the tab. The draft can include recipient names and addresses you have entered. It stays on your device: we do not transmit it, and uploaded documents are never stored in your browser. It is replaced or cleared as you complete or discard the order.
Payment technologies — When you use the payment fields in the Business Portal, our payment provider, Stripe, may collect and process payment-related information and technical information about your checkout session. This may include information about your interactions with Stripe’s payment fields, cookies or similar technologies, IP address, device and browser information, and session identifiers.
Stripe uses this information to process payments, help prevent fraud, maintain the security and functionality of its payment services, and improve its services. PostMyDoc does not store your full payment card number.
Stripe may process this information in Ireland, Australia, the United States and other countries in which Stripe group entities or their approved service providers operate. Our overseas-disclosure practices are described in Section 8. Stripe handles personal information in accordance with its own privacy policy, which is available at stripe.com/au/privacy. Stripe acts on our behalf when it processes a payment for us. For fraud prevention, security and its own legal and compliance obligations, Stripe also uses some of this information for its own purposes and as its own controller, under its own privacy policy.
Security — Cloudflare Turnstile is used on the Business account application form to tell humans from automated bots.
You can control cookies through your browser settings. Disabling some cookies may affect how the portal works. Where consent is required for non-essential cookies, we will obtain it through the consent options presented on the site.
The Business Portal does not use the consumer app’s analytics or push-notification tools, and the consumer checkout pay-later options are not part of the Business Portal.
Advertising conversion measurement
The Business account application and completed-order processes include tag configuration capable of supporting Google Ads conversion measurement. Enhanced conversions are currently disabled for both Business conversion actions. Accordingly, identifiers made available through that configuration are not currently used for enhanced-conversion matching.
The tag configuration remains present, but PostMyDoc does not represent that the associated identifier has been observed as transmitted while enhanced conversions are disabled. PostMyDoc will not enable enhanced-conversion matching unless the applicable Privacy Policy disclosure and point-of-action notice are operational and have been checked.
If enhanced-conversion matching is enabled in future, PostMyDoc will update this Privacy Policy as required to describe the personal information involved, its use, relevant disclosures and overseas processing, together with any applicable consent or choice mechanism.
15. Links to other websites
The Business Portal may contain links to other websites and to our service providers’ websites. We are not responsible for the privacy practices of those websites, which are governed by their own privacy policies. We encourage you to read them.
16. Children’s privacy
The Business Portal is a service for businesses and is not directed at children under 18. We do not knowingly collect personal information from children through the Business Portal. If you believe we have inadvertently collected a child’s personal information, please contact us and we will take reasonable steps to delete it.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our information-handling practices, the Business Portal, our service providers or applicable law. The current version is the version published at postmydoc.au/business-privacy-policy/, with the “Last updated” date shown at the top.
An update takes effect on the date stated in the updated Privacy Policy. Where an update materially affects how we collect, hold, use or disclose personal information, we will take reasonable steps to notify affected Business customers. Where appropriate or required by law, we may also request renewed acceptance or consent before the relevant practice begins.
We keep a per-account record of the version of each PostMyDoc Business legal document accepted through the Business Portal and the date and time of acceptance.
18. Complaints and how to contact us
If you have a question about this Privacy Policy, or a complaint about how we have handled personal information, please contact us:
PostMyDoc — Privacy
PostMyDoc Digital Mailing Service Pty Ltd
82 Onkaparinga Valley Road, Woodside, South Australia 5244
Email: privacy@postmydoc.au
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. We will respond to you in writing, setting out the outcome of our investigation and any steps we will take.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, phone 1300 363 992.
End of Privacy Policy — PostMyDoc Business