PostMyDoc Business – Privacy Policy
How PostMyDoc handles personal information in connection with the PostMyDoc Business Portal.
1. Who we are
This Privacy Policy explains how PostMyDoc collects, holds, uses, discloses and protects personal information in connection with the PostMyDoc Business Portal.
In this Privacy Policy, we, us and our mean PostMyDoc Digital Mailing Service Pty Ltd (ACN 697 539 512), trading as PostMyDoc, of 82 Onkaparinga Valley Road, Woodside, South Australia 5244 (ABN 18 697 539 512). We are an APP entity for the purposes of the Privacy Act 1988 (Cth) (the Privacy Act).
PostMyDoc operates a digital-to-physical mail service. Through the Business Portal, an approved business customer uploads a document, we print it and post it to the nominated recipient through Australia Post, and the uploaded document is then permanently deleted in accordance with our Burn After Reading Policy (described in Section 9).
We are committed to handling personal information in accordance with the Privacy Act and the Australian Privacy Principles (the APPs). This commitment applies regardless of any small-business exemption that might otherwise be available.
2. What this Privacy Policy covers
This Privacy Policy applies to the PostMyDoc Business Portal only (the business-to-business, or B2B, service). It covers personal information handled through:
the Business account application and our approval of that application;
the business dashboard and its features (at postmydoc.au/business-dashboard/ and its sub-pages) — including order creation, recipient entry, saved-recipient and address-book features, team and invitation management, account management, and billing (invoices and statements);
the business order pipeline — documents uploaded for printing and dispatch, and their associated recipient and dispatch information — and the deletion of those documents under the Burn After Reading Policy;
the business-related emails we send (order confirmation, dispatch, delivery, first-deletion, weekly digest, and account and approval emails); and
the business account information described in Section 4.
Not covered by this Privacy Policy
This Privacy Policy does not cover:
the consumer (B2C) PostMyDoc website, which is governed by our consumer Privacy Policy at postmydoc.au/privacy-policy;
the PostMyDoc consumer mobile app, which is governed by its own privacy policy and the relevant app-store terms; or
the Chatway chat widget, which operates only on consumer pages and is switched off across the business dashboard.
If you are a prospective customer browsing our marketing pages before your Business account is approved, that browsing is governed by the consumer Privacy Policy until your account is approved and the service begins.
3. Our two roles: information we handle for you, and information we handle for ourselves
Because this is a business service, it helps to be clear about who decides how personal information is handled. There are two situations.
3.1 Information you control — your documents and recipients
When your business uses the Business Portal, your business decides what documents to send and to whom. For the documents you upload and the recipient details you enter, your business is the entity that controls that information. We handle it on your business's instructions — to print and post it — and we hold it only briefly before documents are deleted under the Burn After Reading Policy.
Our handling of that information is governed by the PostMyDoc Business Data Processing Agreement (the DPA), under which your business is the controller and PostMyDoc acts as your processor. The DPA also sets out how requests from individuals about that information are handled (see Section 12).
3.2 Information we control — running, securing and improving the service
Separately, we collect and use some personal information in our own right — to operate, secure and improve the Business Portal, to administer accounts, to bill and keep financial records, to prevent fraud and abuse, and to meet our own legal obligations. This Privacy Policy governs that information.
Under Australian privacy law, the APPs apply to all personal information we hold, in both situations. This Privacy Policy describes the whole picture, and points to the DPA where the DPA governs the detail.
4. The personal information we collect
The kinds of personal information we may collect and hold in connection with the Business Portal include the following.
| Category | What it includes |
| Account and identity information | Business name, ABN and industry or sector; the applicant's name and email; the Primary Contact's name, email and phone number; the names and emails of additional and invited business users; each user's role (Primary Contact or business user); and internal notes we keep about the account. |
| Authentication and security information | Account passwords (stored only as salted hashes); login-attempt information used to protect against brute-force attacks, including IP address, time and the username entered; and the tokens behind invitation and password-reset links. |
| Order, recipient and dispatch information | Recipient names and delivery addresses (address lines, suburb or city, state, postcode and country); partial address text entered while using address autocomplete; the destination zone; the postage service chosen; tracking numbers and delivery status; the dispatch date; and order references such as a purchase-order number, cost centre or sender label. |
| Document content | The content of the documents (PDFs) you upload. This is determined by you and may contain personal information — and sometimes sensitive information — of any kind (see Section 5). Documents are permanently deleted within 24 hours of dispatch (see Section 9). |
| Billing and transaction information | Order and pricing details, invoices and statements, payment status, and payment-transaction information. Card and payment-instrument details are collected and processed directly by our payment provider (Stripe); we do not store full card numbers. |
| Usage and analytics information | Page-view and usage information and related identifiers (including IP address), collected for site analytics. We collect this only from logged-out visitors to the portal; signed-in business users are excluded from analytics. |
Whose information it is
The individuals whose personal information we handle through the Business Portal fall into three groups:
your authorised users — your Primary Contact (shown in the Portal as the Account Admin) and other business users and invitees, typically your staff;
recipients of mailed documents — the people to whom your documents are addressed; and
individuals who appear within documents — anyone whose personal information is contained in the content of an uploaded document. You determine this, and we do not inspect or control it.
How we collect personal information
Directly from you — when you apply for a Business account, set up and manage your account, create orders, or contact us.
Automatically — through server logs, through analytics for logged-out portal visitors, and through cookies and similar technologies (see Section 14).
From third parties — for example, when a colleague invites you to a Business account, or when our payment provider confirms the status of a payment.
5. Sensitive information
Sensitive information is a special category of personal information that receives a higher level of protection under the APPs. It includes information about a person's health, racial or ethnic origin, political opinions or memberships, religious or philosophical beliefs, trade-union membership, sexual orientation or practices, criminal record, and genetic and biometric information.
We do not ask for sensitive information in our account or order fields. However, because you choose the documents you send, the content of an uploaded document may contain sensitive information — for example, health information (relevant to medical and allied-health customers), or information about a person's legal or financial affairs.
Where a document contains sensitive information, you remain responsible for the content of your documents and for having any consent required to send it. You instruct us to handle that information for the single purpose of printing and dispatching the document, and we apply the security and deletion measures described in Sections 9 and 10. We do not use the content of your documents for any other purpose.
6. How we use personal information
We collect, hold, use and disclose personal information for the following purposes:
to set up and provide the Business Portal and the print-and-post service;
to create accounts, verify and approve Business account applications, and manage your account and team;
to print and post your documents to the recipients you nominate;
to send you order, dispatch, delivery and account communications, and the weekly digest;
to process payments, issue invoices and statements, and keep financial records;
to respond to your enquiries and provide customer support;
to operate, secure, maintain and improve the Business Portal, including site analytics for logged-out visitors;
to detect, investigate and prevent fraud, abuse and security threats; and
to comply with our legal obligations (including tax record-keeping) and to establish, exercise or defend legal claims.
We do not send unsolicited marketing. We send service-related and account communications connected to your use of the Business Portal. If we ever introduce optional product or marketing communications, they will be sent consistently with the Spam Act 2003 (Cth) and will include an easy way to opt out.
We do not sell, rent or trade personal information.
7. Who we disclose personal information to
We disclose personal information only where it is needed to provide the service, where you would expect it, or where we are required or authorised by law. We use a small number of trusted service providers to run the Business Portal. The main ones are:
| Provider | What they do for us | Where |
| Netregistry Pty Ltd t/a Webcentral | Website and database hosting, file storage, and the outgoing email (SMTP) infrastructure for our business emails. | Australia (Sydney) |
| Stripe (Stripe Payments Australia Pty Ltd, with Stripe, Inc. as the United States processing entity) | Processing payments for orders, invoices and statements. We do not store full card numbers. | Australia and United States |
| Australia Post | Printing-to-post dispatch and parcel tracking. | Australia |
| Google Maps Platform (Google LLC) | Address autocomplete while you enter a recipient's address. | United States and other locations |
| Google Analytics (GA4) (Google LLC) | Site analytics for logged-out portal visitors only; signed-in business users are excluded. | United States and other locations |
| Google Fonts (Google LLC) | Delivery of web fonts used to render Business Portal pages; loading a font sends the visitor’s IP address and User-Agent to Google. | United States and other locations |
| Google Tag Manager (Google LLC) | Tag-management container that loads and manages measurement tags on the portal. | United States and other locations |
| Cloudflare, Inc. | Turnstile bot and abuse protection (a CAPTCHA) on the Business account application form. | United States (with Australian points of presence) |
| Limit Login Attempts Reloaded cloud (Atlantic Silicon Inc.) | Login-security firewall that checks login attempts against a shared IP-reputation list and contributes login-attempt information to it. | United States |
We may also disclose personal information to:
our professional advisers (such as lawyers and accountants), under confidentiality;
courts, tribunals, regulators and law-enforcement agencies, where required or authorised by law, or to establish, exercise or defend our legal rights; and
a buyer or successor, if our business or assets are transferred, merged or sold — in which case we will take reasonable steps to ensure the information remains protected.
We require our service providers to handle personal information only for the purposes for which we engage them, and to protect it to a standard consistent with this Privacy Policy and the APPs.
8. Overseas disclosure of personal information
We store the personal information we hold primarily in Australia (Sydney). Some of our service providers process limited information outside Australia, as follows.
| Provider | Country | Purpose |
| Stripe | United States | Payment processing |
| Google LLC (Maps Platform, Analytics, Fonts and Tag Manager) | United States and other locations | Address autocomplete; site analytics (logged-out visitors) |
| Cloudflare, Inc. | United States (Australian points of presence) | Bot/abuse protection on the application form |
| Atlantic Silicon Inc. (Limit Login Attempts Reloaded cloud) | United States | Login security and IP reputation |
Where we disclose personal information to an overseas recipient, we take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs in relation to that information, consistent with APP 8.1. We also recognise that, under section 16C of the Privacy Act, we may be accountable for the handling of personal information by some overseas recipients.
Where a customer is established in the European Economic Area or the United Kingdom, and the GDPR or UK GDPR requires a transfer mechanism for personal information sent to us in Australia, the cross-border transfer terms in the DPA apply (including, where relevant, the EU Standard Contractual Clauses and the UK Addendum).
9. The Burn After Reading Policy — how we handle your documents
How we handle uploaded documents is governed by our Burn After Reading Policy, which is a core commitment of the PostMyDoc service.
9.1 Encryption in transit. Documents are encrypted in transit. All connections to the Business Portal and to our service are served over HTTPS/TLS.
9.2 Restricted storage. Uploaded documents are stored in a restricted server location that is not publicly accessible. They cannot be reached by a direct link and require authenticated, server-side access.
9.3 Purpose limitation. We use your uploaded document only to print and post your order. Our personnel access a document only to the extent needed to print and prepare it for dispatch.
9.4 Automatic deletion. Each uploaded document is permanently deleted within 24 hours of dispatch. An automated task runs on the server every hour and removes any uploaded document more than 24 hours old. Because dispatch occurs within 24 hours of upload, document content is deleted within 24 hours of dispatch and never later. The task runs on the server's own schedule, independently of website traffic, and a deletion record is generated for each dispatched document.
9.5 No recovery. Once a document is deleted we cannot re-send or recover it, and we cannot provide it to anyone. If you need it again, you must upload it again.
9.6 Back-ups. Our hosting platform takes full-volume back-ups of the entire account and cannot be set to exclude the document folder. Where a document is captured in a back-up before its primary copy is deleted, that back-up copy is kept only until it rotates out of the platform's rolling window of recent restore points — up to approximately 30 days. Back-up copies remain subject to the same security and confidentiality measures until they rotate out. This is the only situation in which a copy persists beyond the 24-hour window.
9.7 What we keep. The Burn After Reading Policy applies to uploaded document content. We keep the account, order and dispatch information needed to run the service and meet our legal obligations — including recipient details and the document's filename and content hash recorded in the dispatch and deletion records (see Section 11).
10. How we keep personal information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification and disclosure, as required by APP 11. Our measures include:
Encryption in transit — all connections are served over HTTPS/TLS.
Encryption at rest — business document content is encrypted at rest on our systems using authenticated encryption (the libsodium library), so the stored files are ciphertext and our database holds no document content. This sits on top of data minimisation: under the Burn After Reading Policy, document content is also deleted within 24 hours of dispatch. Access to stored information is role-restricted.
Role-based access — a dedicated business-user role; row-level visibility so the Primary Contact sees the account's orders while other users see only their own; a fail-secure default (own-records-only) until a Primary Contact is set; and an opaque “not found” response when someone tries to reach a record they are not permitted to see.
Authentication — passwords stored only as salted hashes, a minimum password length, a branded login, and a tokenised password-reset flow.
Multi-factor authentication — enforced on administrative and operator access, and on the third-party consoles used to run the service (hosting, payments and connected services).
Gated downloads — documents and billing files are served only through authenticated, permission-checked download paths; direct unauthenticated file access is not allowed.
Brute-force and abuse protection — login-attempt rate limiting with lockout, and cloud-assisted IP-reputation checks.
Input validation — uploads are checked by file type and capped in size, key values are validated against strict allow-lists, and errors are returned without exposing internal detail.
Privacy-by-design in notifications — email subject lines deliberately omit recipient location detail, and an anonymous-sender option lets the sender's identity be withheld on dispatch.
Secure hosting — hosting in Australia (Sydney) on a managed platform in an ISO/IEC 27001-certified data centre, with a web application firewall, malware scanning, security patching, twice-daily back-ups with tested recovery, and monitoring for suspected incidents. Scheduled tasks (including document deletion) run on a server-level scheduler.
Logging and incident response — we log document-deletion events, payment and webhook processing, and authentication failures and lockouts, and we follow a process to detect, contain, assess and notify data breaches (see Section 11 for log retention).
We rely on recognised certifications (such as ISO/IEC 27001 and PCI DSS) at the level of our service providers, where applicable. We do not claim those certifications for PostMyDoc itself.
While we take every reasonable precaution, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. How long we keep personal information
We keep personal information only for as long as we need it for the purposes described in this Privacy Policy, or for as long as the law requires. In general:
| Information | How long we keep it |
| Uploaded document content | Deleted within 24 hours of dispatch (Burn After Reading Policy). Document content is encrypted at rest while held. Back-up copies persist only until they rotate out — up to approximately 30 days (see Section 9.6). |
| Account, order and dispatch information, and financial and transaction records | Up to 7 years, to meet Australian tax and record-keeping obligations. |
| Customer communications | About 3 years from the date of the communication. |
| Authentication and security logs | About 30 days. |
| Site analytics (logged-out visitors) | In line with our configured Google Analytics retention (up to 14 months). |
When a Business account ends, we will, at your election, return or delete the personal information we hold for you and delete existing copies within 90 days, except where we are required by law to keep certain records (for example, financial records). The detailed return-and-deletion terms are in the DPA.
12. Your rights and choices
12.1 Access. You may ask for access to the personal information we hold about you (APP 12). Because of the Burn After Reading Policy, we will generally not be able to provide the content of a document after it has been deleted; we can provide the related account, order and dispatch information we still hold.
12.2 Correction. If you think any personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it (APP 13). We will take reasonable steps to do so.
12.3 Anonymity and pseudonymity. Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym (APP 2). In practice, running a Business account and printing and posting documents requires accurate identity, contact and recipient details, so this is limited.
12.4 Requests about recipients or people named in documents. If we receive a request from an individual whose personal information we hold only because your business sent it to us (for example, a recipient of a mailed document), we will, in line with the DPA, refer that request to your business as the controller of that information rather than responding to it ourselves, except where the law requires otherwise.
12.5 How to make a request. To exercise any of these rights, contact our privacy contact at privacy@postmydoc.au. We will respond within a reasonable time, and in any event within 30 days. We may need to verify your identity first, and an administrative fee may apply to an access request in limited circumstances permitted by the Privacy Act.
13. Automated decision-making
We do not use computer programs to make decisions about you that could reasonably be expected to significantly affect your rights or interests. Decisions such as approving a Business account are made by a person, and our automated security measures (such as login rate-limiting) protect the service rather than make significant decisions about individuals.
From 10 December 2026, new transparency obligations under the Privacy Act (APP 1.7 to 1.9) will require organisations that use personal information in automated decisions with significant effects to disclose this in their privacy policy. If we introduce any such automated decision-making, we will update this Privacy Policy accordingly before then.
14. Cookies and similar technologies
The Business Portal uses cookies and similar technologies for the following purposes:
Essential and functional — to keep you signed in, to remember your selections on the order form, and to make the ordering and checkout process work.
Analytics — to understand how logged-out visitors use the portal, through Google Analytics. Signed-in business users are excluded from analytics.
Security — Cloudflare Turnstile is used on the Business account application form to tell humans from automated bots.
You can control cookies through your browser settings. Disabling some cookies may affect how the portal works. Where consent is required for non-essential cookies, we will obtain it through the consent options presented on the site.
The Business Portal does not use the consumer app's analytics or push-notification tools, and the consumer checkout pay-later options are not part of the Business Portal.
15. Links to other websites
The Business Portal may contain links to other websites and to our service providers' websites. We are not responsible for the privacy practices of those websites, which are governed by their own privacy policies. We encourage you to read them.
16. Children's privacy
The Business Portal is a service for businesses and is not directed at children under 18. We do not knowingly collect personal information from children through the Business Portal. If you believe we have inadvertently collected a child's personal information, please contact us and we will take reasonable steps to delete it.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, the Business Portal or the law. The current version is the one published at postmydoc.au/business-privacy-policy/ with the “Last updated” date shown at the top.
Where a change is material, we will give you reasonable notice and, where required, ask you to accept the updated Privacy Policy again. We keep a per-account record of the version of each PostMyDoc Business legal document you have accepted, and when.
18. Complaints and how to contact us
If you have a question about this Privacy Policy, or a complaint about how we have handled personal information, please contact us:
PostMyDoc — Privacy
PostMyDoc Digital Mailing Service Pty Ltd
82 Onkaparinga Valley Road, Woodside, South Australia 5244
Email: privacy@postmydoc.au
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. We will respond to you in writing, setting out the outcome of our investigation and any steps we will take.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, phone 1300 363 992.
End of Privacy Policy — PostMyDoc Business