Legal
Privacy Policy
Effective date: 1 March 2026 · Last updated: 1 March 2026
This Privacy Policy explains how talvex.com.au Pty Ltd ("talvex.com.au", "we", "us", "our") collects, uses, stores, and discloses personal information when you use our platform at portal1.onsys.com.au and related services.
We are bound by the Australian Privacy Act 1988 and the 13 Australian Privacy Principles (APPs). For users in the European Economic Area, UK, or Switzerland, this policy also covers our obligations under the General Data Protection Regulation (GDPR).
Contents
1. Who we are
talvex.com.au Pty Ltd is an Australian company that operates a platform connecting enterprise buyers with verified IT engineers and IT consulting companies. Our registered address and ABN will be published upon incorporation.
For privacy enquiries, contact our Privacy Officer at privacy@talvex.com.au.
2. Information we collect
Account information: Name, email address, password (hashed), account type, and profile details provided during registration.
Identity verification (KYC): For contractors and company administrators, we collect government-issued identity documents and conduct video identity sessions via LiveKit. Video recordings are stored in Azure Blob Storage and retained for 7 years for compliance purposes.
Professional credentials: Certifications, employment history, and specialisations provided during onboarding.
Insurance certificates: Public liability and professional indemnity insurance documents uploaded for contractor or company verification.
Payment information: We do not store full card numbers. Payment processing is handled by Stripe. We store Stripe customer IDs, payout account references, and transaction records.
Communications: Messages sent through the platform, dispute submissions, and support enquiries.
Usage data: IP addresses, browser user-agent strings, session activity, and audit log entries generated during platform use.
Credentials vault: For contractors who use our secure credential vault feature, encrypted credentials are stored in Azure Key Vault. We do not have access to stored credential values.
3. How we use your information
We use your personal information to:
- Create and manage your account and profile
- Verify your identity and professional credentials
- Facilitate engagements between buyers and service providers
- Process payments and manage escrow
- Generate purchase orders and invoices
- Operate our dispute resolution process
- Send transactional emails (verification, OTP codes, payment confirmations)
- Maintain audit logs for legal and compliance purposes
- Detect and prevent fraud and unauthorised access
- Improve the platform and develop new features
- Comply with our legal obligations under Australian and international law
We do not sell your personal information to third parties.
4. Legal basis for processing (GDPR)
For users in the EEA, UK, or Switzerland, we process personal data on the following legal bases:
- Contract performance: Processing necessary to provide you with platform services
- Legal obligation: KYC verification, AML checks, tax record retention
- Legitimate interests: Fraud prevention, platform security, audit logging
- Consent: Marketing communications (where applicable)
5. Disclosure to third parties
We share information with the following third-party service providers who are contractually required to protect your data:
- Stripe: Payment processing and escrow (United States)
- Microsoft Azure: Cloud infrastructure, Blob Storage, and Key Vault (Australia East and secondary regions)
- LiveKit: Video KYC session infrastructure
- Microsoft Graph / Exchange Online: Transactional email delivery
We may also disclose information where required by law, court order, or government request, or where necessary to protect the rights, property, or safety of talvex.com.au, our users, or others.
6. International transfers
Your data is primarily stored on Microsoft Azure servers in Australia East. Some service providers (including Stripe and LiveKit) process data in the United States. Where personal data is transferred internationally, we ensure adequate protections are in place, including standard contractual clauses where applicable under the GDPR.
7. Data retention
We retain personal data for as long as necessary to provide our services and comply with our legal obligations:
- Account data: Duration of account plus 7 years after closure
- KYC video recordings: 7 years from session date
- Financial records: 7 years (Australian tax law requirement)
- Audit logs: 7 years (append-only, cannot be deleted)
- Credential vault data: Deleted 48 hours after order completion or on account closure
8. Your rights
Under the Australian Privacy Act and the GDPR (where applicable), you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Erasure (GDPR): Request deletion of your data, subject to our legal retention obligations
- Portability (GDPR): Receive your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests
- Withdraw consent: Where processing is based on consent
To exercise your rights, email privacy@talvex.com.au. We will respond within 30 days.
Australian residents may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC). EEA residents may lodge a complaint with their local data protection authority.
10. Security
We implement industry-standard security measures including:
- All data encrypted in transit via TLS 1.2+
- Passwords stored as bcrypt hashes (cost factor 12)
- Tokens stored as SHA-256 hashes
- Refresh token rotation with reuse detection
- Multi-factor authentication available for all accounts
- Azure Key Vault for sensitive credential storage
- Role-based access control throughout
Despite these measures, no internet-based system is completely secure. If you believe your account has been compromised, contact security@talvex.com.au immediately.
11. Children
Our platform is not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, please contact us immediately.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 14 days before the changes take effect. Continued use of the platform after that date constitutes acceptance of the updated policy.
13. Contact us
For privacy enquiries, data access requests, or complaints:
Email: privacy@talvex.com.au
talvex.com.au Pty Ltd · Australia