Privacy & Data Transparency Policy

Abora.com.au  ·  Last Updated: 26 April 2026  ·  Compliant with the Privacy Act 1988 (Cth) and Australian Privacy Principles (APP)

🔒

AES-256 Encryption

Data at rest & in transit

🇦🇺

Australian Hosted

Data sovereignty compliant

📋

No Data Sales

Your data is never sold

Our Commitment to Your Privacy

Abora Pty Ltd is bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Privacy and Other Legislation Amendment Act 2024 (Cth). This Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights to access, correct, and delete it.

1. Data Ingestion & Transparency

We collect personal information only where it is reasonably necessary for our functions. We collect the following categories:

Account Data

What: Name, email address, password (hashed), profile preferences.

Why: To create and manage your account.

Subscription & Billing Data

What: Subscription plan, billing history. Payment method details are held by Stripe, not Abora.

Why: To process payments and manage subscriptions.

Usage Data

What: Pages visited, search queries, suburb comparisons, feature interactions, session duration.

Why: To improve Platform features and personalise your experience.

Device & Technical Data

What: IP address, browser type, device type, operating system, referral URLs.

Why: For security, analytics, and compatibility.

User-Generated Content

What: Suburb reviews, property notes, feedback submissions.

Why: To provide Platform features and improve AI models (opt-out available).

We do not collect sensitive information (as defined by the Privacy Act) unless you voluntarily provide it and we have obtained your consent.

2. AI Processing & Personal Information

The Platform uses AI and machine learning to generate property insights, suburb scores, and recommendations. In doing so:

  • Your search queries and property preferences may be processed by AI models to personalise results.
  • We use aggregated and de-identified usage data to train and improve AI models. We do not train models on identifiable personal information without your explicit consent.
  • In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth), we will publish information about substantially automated decision-making processes that significantly affect you as those obligations take effect.

AI-generated outputs are based on statistical models and public data — they are not decisions made about you as an individual. See our Disclaimer for full detail on AI limitations.

3. Data Security & Storage

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure:

TLS/HTTPS encryption for all data in transit
Passwords stored as salted hashes (never in plaintext)
Data hosted on Australian servers where possible (Google Cloud)
Role-based access controls for Abora staff
Regular security reviews and vulnerability assessments
Incident response plan aligned with the NDB Scheme

No method of data transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

4. Third-Party Sharing

We do not sell your personal information. We may share it with trusted third parties only in the following circumstances:

Service Providers

Stripe (payments), Firebase/Google (infrastructure), analytics providers — each bound by confidentiality and data processing agreements.

Legal & Regulatory

Where required by Australian law, court order, or regulatory authority (e.g., OAIC, ACCC, police).

Business Transfers

In the event of a merger, acquisition, or asset sale, your information may be transferred to the successor entity. We will notify you before any transfer occurs.

With Your Consent

For any other purpose with your explicit prior consent.

5. Notifiable Data Breaches (NDB Scheme)

Abora is subject to the Notifiable Data Breaches (NDB) Scheme under Part IIIC of the Privacy Act 1988 (Cth). This section explains what happens if a data breach occurs that is likely to result in serious harm to you.

5.1 What Triggers a Notifiable Breach?

A breach is "notifiable" where it is likely to result in serious harm to one or more affected individuals. Serious harm includes financial loss, physical harm, psychological harm, harm to reputation, or identity theft.

5.2 Our Obligations

  • We will notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable — and no later than 30 days after becoming aware of an eligible data breach.
  • We will notify affected individuals directly (by email where possible) at the same time or as soon as practicable, including: a description of the breach, the kinds of information involved, the steps we are taking, and recommended steps you can take to protect yourself.

5.3 Containment Steps

Upon becoming aware of a suspected breach, Abora will: (a) immediately contain the breach; (b) assess whether it is eligible under the NDB scheme; (c) notify the OAIC and affected individuals if required; and (d) review and improve security measures to prevent recurrence.

5.4 Contact the OAIC

If you believe your privacy has been breached and are unsatisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au .

6. Cookies & Tracking Technologies

We use cookies, pixel tags, and similar technologies. Key points:

  • Essential cookies are required for the Platform to function (authentication, session management).
  • Analytics cookies (usage metrics, error tracking) are used only with your consent.
  • Marketing cookies require consent before being set.
  • You can manage preferences via the cookie banner on your first visit, or by clearing browser cookies.

We do not use cookies to build behavioural profiles for sale to third-party advertisers. Full cookie details are in Section 11 of our Terms & Conditions.

7. Your Rights & Contact

Under the Privacy Act and APPs, you have the right to:

Access

Request a copy of the personal information we hold about you.

Correction

Ask us to correct inaccurate or outdated personal information.

Deletion

Request deletion of your account and associated personal data (subject to legal retention obligations — see Section 9).

Opt-Out of Marketing

Opt out of direct marketing communications at any time.

AI Training Opt-Out

Opt out of your data being used for AI model training by emailing privacy@abora.com.au.

Complaint

Lodge a privacy complaint with Abora or escalate to the OAIC.

To exercise any of these rights, contact our Privacy Officer at privacy@abora.com.au. We will respond within 30 days. We may ask for identity verification before processing your request. We will not charge for standard access requests.

8. Direct Marketing & Opt-Out

Abora complies with the Spam Act 2003 (Cth). We will only send you commercial electronic messages where you have provided express or inferred consent, and every marketing message will include a clear, functional unsubscribe mechanism.

8.1 Types of Emails We Send

Transactional Emails

Account confirmation, password reset, billing receipts, renewal reminders, security alerts, and material changes to these policies. Sent regardless of marketing preferences as they are essential to the service. Cannot be opted out of while your account is active.

Marketing Emails

Property market insights, feature announcements, promotional offers, and Abora news. Sent only with your consent. You may opt out at any time.

8.2 One-Click Opt-Out

Every marketing email includes a one-click unsubscribe link in the footer — no login required. You may also update your notification preferences via your Profile settings. We will process opt-out requests within 5 business days.

9. Data Retention

We retain your personal information only for as long as necessary for the purposes described in this Policy and to comply with legal obligations.

Account Closure / Deletion Request

To allow for account recovery and to finalise outstanding matters, then permanently deleted.

30 days

Financial & Billing Records

Required under the Income Tax Assessment Act 1997 (Cth) and ATO record-keeping obligations.

7 years

Legal Hold / Dispute

Retained for the duration of any legal claim plus the applicable limitation period.

Until resolved

Aggregated Analytics (de-identified)

De-identified aggregate data is no longer personal information and may be retained for platform improvement. Personal data used for AI training is deleted per account closure policy (unless opted out).

Indefinite

Inactive Accounts

We send a re-engagement notice 90 days before deletion. After 3 years of no login, accounts and associated personal data are permanently deleted.

3 years inactivity

10. International Data Transfers

Abora's primary data hosting is within Australia. However, some personal information may be routed through or processed in the United States due to:

Stripe (US)

Payment processing

Google LLC (US)

Firebase authentication, Analytics, Maps Platform

AI model providers (various)

Where LLM API calls are processed

APP 8 Compliance: Before disclosing personal information overseas, Abora takes reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information. This includes Data Processing Agreements (DPAs) and standard contractual clauses (SCCs) with overseas providers. By using the Platform, you consent to these transfers on the basis that Abora has implemented APP 8 compliance steps.

You may withdraw consent to international transfers by deleting your account. This will prevent you from using the Platform. Contact privacy@abora.com.au for more information.

For all privacy enquiries: privacy@abora.com.au ·  OAIC: oaic.gov.au · Terms · Disclaimer ·  © 2026 Abora. All rights reserved.