Privacy Policy
This policy explains how Out Sauce ("we", "us", "our") handles personal information when you use The Kitchen, our online paraplanning portal, and the related onboarding and enquiry forms. As a matter of good practice we handle personal information to a standard consistent with the Australian Privacy Principles (APPs).
Who we are
Out Sauce provides contract paraplanning services to licensed financial advice firms in Australia. The portal is where advice firms submit paraplanning work, contractors (paraplanners) complete it, and we run the operation. We are based on the Gold Coast and our systems are hosted in Australia.
What we collect
We only collect information we need to provide the service. That includes:
- Firm details: entity name, ABN, business address, licensee name, AFSL number, and contact and invoicing names, emails and phone numbers.
- Portal user details: the names and email addresses of the people at a firm who log in to the portal.
- Contractor details: name, email, phone, business name, ABN, address, and bank account details (BSB, account number, account name) used to pay you.
- Work content: the jobs, documents, messages, quotes, invoices, remittances, survey responses and feedback created in the portal.
- Enquiry details: if you complete one of our enquiry forms, the details you provide and any CV or attachment you upload.
- Account and technical records: sign-in timestamps and IP addresses, and a change history of records kept for audit and security.
Why we collect it
- To set up and run your portal account and service agreement.
- To deliver, allocate and manage paraplanning jobs, including managing workload, turnaround and quality.
- To quote, invoice and pay for work, including accounting and tax records.
- To send service notifications and respond to support requests.
- To keep the service secure and meet our legal and record-keeping obligations.
- To improve the quality and consistency of our service. We learn de-identified, aggregated patterns from the work we complete, and we build up our own working knowledge of how each firm and its advisers prefer their work prepared. That knowledge can include the names and working preferences of a firm's portal users, but never a firm's clients' personal details or copies of a firm's documents. We do not sell your information or turn it into a separate product.
How we store and protect it
Your information is held in Australian data centres, with an encrypted disaster-recovery copy held in a second Australian region (Melbourne). Personal information is stored in Australia, apart from the limited overseas disclosures described under "When we share it" below.
- Bank account details are encrypted at rest.
- All traffic to and from the portal is encrypted in transit (HTTPS).
- Access is restricted by role, and each firm's data is separated from others.
- We keep an audit trail of changes and monitor the service for faults and security issues.
When we share it
We do not sell your personal information. We share it only with the service providers we use to run the portal and our own operations, and only to the extent needed:
- Resend to send transactional email (such as invitations and notifications). Along with your name and email address, this includes the content of the notification itself, which can name the job, your firm, the person who submitted the job, and the file that was uploaded, and can carry a short preview of the job description. It does not include your documents, your messages, or client working files.
- Annature to handle electronic signing of service agreements.
- Xero for invoicing and accounting.
- Cloudflare for domain and network services.
Resend and Xero both hold data in the United States, so using them means some personal information is disclosed overseas. Before any overseas disclosure we take steps that are reasonable in the circumstances to ensure the recipient handles your information consistently with the Australian Privacy Principles, including through the data-processing terms in our agreements with them. Your information is otherwise stored in Australia. We are moving our transactional email to an Australian region, and when that is live the email disclosure above ends and we will update this page.
We may also disclose information where required or authorised by law.
How long we keep it
We keep personal information only for as long as we need it. Financial records (such as invoices and remittances, including the invoice documents themselves where they are held in our accounting system) are retained for the period required by Australian tax and record-keeping law, even after an account is closed or erased. Removing an invoice from the portal does not remove it from our accounting records. If you are a contractor we pay, the bank account we pay you into is also held in our accounting system so that we can make and evidence those payments. It stays there as part of those payment records for the period the law requires, even after your portal account is erased. Erasing your account removes your bank details from the portal, but not from our accounting records. Enquiry leads that do not proceed are purged on a routine schedule. Our working knowledge of how each firm and its advisers prefer their work prepared is part of Out Sauce's own business records and may be kept after an engagement ends; as above, it never includes a firm's clients' personal details or copies of a firm's documents.
Your rights
You can ask us to give you a copy of the personal information we hold about you (an access request), to correct it if it is wrong, or to erase it where we are not required to keep it. We have a built-in process for both data export and erasure. To make a request, contact us at clinton@outsauce.au. We will verify your identity before acting on a request.
Note that some records we are legally required to retain (such as financial records) cannot be deleted on request. In those cases we de-identify the personal details we are able to remove and keep only the minimum the law requires.
Data breaches
We have a breach-response process. If an incident affects client information we handle for an advice firm, we notify that firm promptly and support its response; the firm is the responsible entity under privacy law and handles any notification to affected individuals and the Office of the Australian Information Commissioner (OAIC). For information we are responsible for in our own right, if a breach is likely to result in serious harm we will notify affected individuals and the OAIC consistently with the Notifiable Data Breaches scheme.
Cookies
The portal uses a small number of cookies that are necessary for you to log in and stay signed in. We do not use third-party advertising or tracking cookies.
Contact and complaints
If you have a question, a request, or a complaint about how we handle your personal information, contact us at clinton@outsauce.au. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes
We may update this policy from time to time. The effective date and version at the top of this page show when it last changed. If you have agreed to a specific version during onboarding, that record keeps the version you agreed to.