Privacy Policy

This Policy was last revised on 18 AUGUST 2026

Applies to: Flout Software websites, communications and the 1point platform

1. About this policy

Flout Software Pty Ltd (Flout Software, Flout, we, us or our) respects your privacy and is committed to handling personal information responsibly. This Privacy Policy explains how we collect, hold, use, disclose, protect, access, correct and dispose of personal information in connection with our business, websites, communications and the 1point software platform.

We manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), where they apply to us. This policy should be read with any collection notice or contractual privacy terms provided for a particular service or interaction.

Other privacy laws, including the European Union or United Kingdom General Data Protection Regulation, may apply to particular activities. Where they apply, we will meet those additional requirements; this policy does not claim that every interaction is governed by them.

This policy does not apply to information that is not personal information under applicable law, including information that has been effectively de-identified.

2. Who this policy covers

This policy covers personal information relating to:

  • users and administrators of 1point;

  • prospective and current customers, suppliers and business contacts;

  • people who contact us, use support or LiveChat, request a demonstration, make a booking, download material, subscribe to communications or use our website; and

  • individuals whose personal information is included in material supplied to us or entered into 1point by a customer.

3. Our role when customers use 1point

A customer may enter or upload information into 1point. The customer generally determines what information is entered, who may access it and the purposes for which it is used. To the extent that customer-controlled content contains personal information, Flout Software generally handles it on the customer's behalf to provide, secure, support, maintain and improve the contracted service.

Customers are responsible for ensuring they have authority to collect and use the personal information they place in 1point, for configuring access appropriately and for responding to requests relating to customer-controlled information. If we receive a request concerning information controlled by a customer, we may refer the requester to that customer and provide reasonable assistance.

Flout Software is responsible for personal information it collects for its own business purposes, such as user account administration, security, billing, website analytics, sales, marketing and support.

4. Personal information we collect

Depending on how you interact with us, we may collect:

  • Identity and contact information: name, organisation, job title or role, business or postal address, email address and telephone number.

  • Account and authentication information: username, account status, company membership, roles, permissions, multi-factor authentication status, account creation and last-login details. Passwords are stored using secure password hashing rather than in readable form.

  • Customer and project content: records, files, comments, messages and other information entered or uploaded by a customer. Depending on the customer's use, this may include contact details for landowners, holders, contractors or other project participants.

  • Commercial and billing information: enquiries, demonstration requests, proposals, contracts, billing contacts, company name and country, subscription, invoice and purchase-order details, and communications with us.

  • Support information: support requests, LiveChat, ticket or email correspondence, attachments, diagnostic information and records of how an issue was resolved.

  • Technical and usage information: IP address, approximate location derived from IP, browser and device information, page and feature interactions, authentication events, activity logs, error and diagnostic logs, security records and cookie or similar identifiers.

  • Marketing and website information: form submissions, downloads, appointment or demonstration bookings, communication preferences, campaign source and interactions with our website or communications.

  • AI-assisted query information: prompts, recent AI conversation history, relevant database schema metadata and AI-generated output when the optional AI Query feature is used.

  • Other information: any other personal information you choose to provide to us or that a customer lawfully provides through 1point.

We do not generally require sensitive information. Please do not provide sensitive information unless it is reasonably necessary and you are authorised to do so. If sensitive information is provided, we will handle it in accordance with applicable law.

5. How we collect personal information

We may collect personal information:

  • directly from you when you contact us, complete a form, create or use an account, request support, use LiveChat, attend a meeting or demonstration, make a booking, subscribe to communications or otherwise interact with us;

  • from an organisation that employs or engages you, an authorised representative or a 1point customer;

  • automatically when you use our website or 1point, through cookies, tags, application monitoring, authentication, security and operational logs;

  • from payment, website-form, support, analytics, communications and other service providers acting for us; and

  • from public sources, professional directories and business networking platforms where appropriate.

Where required, we will take reasonable steps at or before collection, or as soon as practicable afterwards, to notify you of the circumstances and purposes of collection and the other matters required by law. If you do not provide information that we reasonably require, we may be unable to create an account, provide a requested service, process a payment, respond to an enquiry or meet our contractual obligations.

6. Why we collect, use and disclose personal information

We may collect, hold, use and disclose personal information to:

  • provide, configure, administer and support 1point and our other services;

  • create and manage accounts, roles, permissions and authentication;

  • communicate with customers, users, prospects, suppliers and business contacts;

  • conduct demonstrations, onboarding, data migration, training, support and service communications;

  • process subscriptions, invoices, purchase orders and payments;

  • monitor performance, diagnose errors, maintain availability, analyse website use and improve our products, services and user experience;

  • detect, investigate and respond to security incidents, misuse, fraud or unlawful activity;

  • manage contracts, records, insurance, governance and internal administration;

  • send relevant product, service or business communications where permitted by law;

  • comply with legal obligations and lawful requests; and

  • establish, exercise or defend legal rights.

7. Website analytics, cookies and similar technologies

Our websites and 1point use cookies and similar technologies. These may be set by us or by service providers. The technologies currently used fall into the following categories:

  • Strictly necessary and security: support authentication, sessions, security, fraud prevention, load balancing and storage of preferences such as whether a cookie notice has been acknowledged.

  • Functional and support: enable features such as LiveChat and help retain support-chat or interface settings.

  • Analytics: Google Analytics helps us understand numbers of visitors, sessions, approximate location, browsers, devices, referral sources and how pages are used. Google Analytics uses a first-party client identifier such as the _ga cookie.

  • Advertising and campaign measurement: the LinkedIn Insight Tag measures visits, conversions and campaign performance and may support retargeting. It may collect URL, referrer, IP address, device and browser characteristics, timestamp and limited page or button actions.

  • Anti-spam and embedded services: Google reCAPTCHA and embedded form, booking, font or media services may receive technical and interaction information needed to provide their functions.

You can control or delete cookies through your browser and, where available, provider or website controls. Blocking some cookies may affect website or support functionality. Our use of analytics or advertising technologies is subject to applicable law, and we will seek consent where the law requires it.

8. LiveChat, support and communications

When you contact us by LiveChat, email, telephone, an in-app support channel or another communication method, we may collect your contact details, organisation, the content of the communication, attachments, technical or diagnostic information and records of our response. LiveChat may also use cookies and collect IP address, browser, device and interaction information. Pre-chat details, chat content and support tickets are processed through the LiveChat service operated by Text, Inc. and its affiliates.

We use this information to respond to enquiries, provide support, investigate and resolve issues, maintain service and security records, train support personnel and improve our services. Please avoid placing sensitive or unrelated personal information in support communications unless it is necessary and authorised.

9. Email, marketing and website forms

We use email and website-form or customer-relationship services to receive enquiries, provide demonstrations and bookings, deliver requested material, send service and security notices, and manage permitted sales and marketing communications. Website forms and booking functions may be provided through HighLevel/LeadConnector. Our configured email providers process email addresses, message content, delivery data and attachments as needed to send and receive communications.

We may use business contact information to send information about Flout Software and 1point where permitted by the Privacy Act and Spam Act 2003 (Cth). You may opt out of marketing at any time using the unsubscribe facility in the communication or by contacting us. We may still send service, security, account and transactional communications that are not marketing.

10. Payments and subscriptions

We use Stripe to help manage customer billing, subscriptions, invoices and payments. Information provided to Stripe may include company name, billing contact name and email, country, subscription or invoice details, purchase-order references and payment information. Where card or bank details are entered into Stripe's payment services, Stripe processes those details and Flout Software does not intentionally store the full payment credential in 1point.

Stripe handles information under its own privacy notice and contractual data-protection arrangements. We may retain invoice, transaction and accounting records as required for service administration, dispute resolution and legal, tax or accounting obligations.

11. AI-assisted query feature

1point includes an optional AI-assisted query feature (AI Query). It is not required for 1point's core functionality and may be disabled or made unavailable for a customer configuration.

When AI Query is used, 1point sends the user's natural-language request, relevant recent AI conversation history and the database structure needed to draft a query, such as table and column names, descriptions and data types, to OpenAI's API. Under the current design, the workflow does not send the underlying database rows to OpenAI. Users should not include personal, sensitive, confidential or regulated information in a prompt unless they are authorised and it is necessary.

Flout Software does not use customer content to train AI models and does not authorise customer API data to be used for general model training. Under OpenAI's current API data controls, API inputs and outputs are not used to train models by default unless the API customer opts in. OpenAI may retain limited API data for abuse-monitoring purposes for up to 30 days, unless different approved controls apply.

AI Query produces an assisted query or response for user review. Outputs may be incomplete or incorrect and should be checked before use. Flout Software does not use AI Query to make decisions that have legal or similarly significant effects on individuals.

12. Who we disclose personal information to

We may disclose personal information where reasonably necessary to:

  • our personnel who need the information to perform their duties;

  • the customer or organisation responsible for the relevant 1point account, including authorised administrators;

  • technology, hosting, security, support, analytics, communications, payment, AI and professional service providers acting for us;

  • professional advisers, insurers, auditors and financiers;

  • a purchaser or successor in connection with a proposed or completed business transaction, subject to appropriate confidentiality protections; and

  • government agencies, courts, regulators or other parties where required or authorised by law.

We do not sell personal information. We may provide website interaction and technical information to analytics and advertising providers, including Google and LinkedIn, as described in this policy.

13. Key service providers

The following table summarises the main external services identified in our current website and 1point implementation. Providers may use approved affiliates and subprocessors, and their locations or services may change. We review this information when our services change.

Provider Purpose Information involved Likely processing
Microsoft Azure hosting, SQL and file storage, backups, application monitoring and diagnostics User accounts, customer content, logs, diagnostics and technical data Core production resources: Australia Southeast. Some support or subprocessors may operate internationally.
Google Google Analytics, reCAPTCHA and related website or communications services Cookie/client identifier, page activity, approximate location, browser/device data, anti-spam interaction and communication data where used International, including the United States; regional collection may apply.
LinkedIn Insight Tag, campaign measurement, audience insights and retargeting URL, referrer, IP address, device/browser characteristics, timestamp and limited page or button actions International, including the United States.
LiveChat / Text Website and in-app chat, support messages and tickets Pre-chat/contact details, chat and ticket content, cookies, IP address, browser/device and interaction information Mainly the United States; support, affiliates or subprocessors may include Poland/EEA and other countries.
HighLevel / LeadConnector Website forms, downloads, bookings, enquiries and marketing communications Contact and company details, form or booking responses, campaign and communication information United States and other approved subprocessor locations.
Stripe Subscriptions, billing, invoices and payments Company and billing contact details, country, subscription/invoice/purchase-order data and payment information International, including the United States.
OpenAI Optional AI Query processing Prompt, recent AI conversation history, relevant schema metadata and generated output; not underlying database rows in the current workflow International, including the United States, unless different regional controls are configured.
Email providers Transactional, service, support and permitted marketing email Email addresses, message content, delivery data and attachments Australia, the United States or other locations depending on the configured provider and its subprocessors.

14. Data hosting and overseas disclosure

In the current production configuration, the core 1point application, Azure SQL databases, Cosmos DB and Blob Storage resources are hosted in Microsoft Azure's Australia Southeast region. Core database backups are also configured for storage in that region using locally redundant backup storage. Access is restricted through role-based permissions and other security controls.

Not all information handled through our website or third-party features remains in Australia. Depending on the service used, personal information may be disclosed to or accessed by providers and their subprocessors in the United States, Poland, other European Economic Area countries and other countries in which those providers operate. This may include support communications, website analytics, form and booking data, billing data and optional AI Query data.

Before disclosing personal information overseas, we take reasonable steps appropriate to the circumstances to assess the provider, use contractual and security protections and require handling consistent with applicable privacy obligations. Overseas recipients may be subject to privacy laws that differ from Australian law.

15. Data security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures used for 1point include access controls, role-based permissions, multi-factor authentication capability, encryption in transit using HTTPS/TLS, Azure-managed encryption at rest, operational logging, application monitoring, backup and recovery arrangements, and processes for reviewing and remediating security issues.

We limit access to people and providers who need information for authorised purposes and expect them to protect it. No method of electronic transmission or storage is completely secure. Users must protect their credentials, use appropriate access settings and notify us promptly if they suspect unauthorised access or misuse.

16. Data retention and deletion

We retain personal information for as long as reasonably necessary for the purposes described in this policy, to provide contracted services, maintain business and security records, resolve disputes, enforce agreements and comply with legal, accounting, insurance and regulatory obligations. Retention periods vary according to the type of information and the reason it is held.

When personal information is no longer required, we take reasonable steps to destroy it or de-identify it, unless we are required or authorised by law to retain it. Residual copies may remain temporarily in secure backups until the relevant backup expires under our retention schedule. Some third-party providers retain information according to their own documented schedules and our settings or contractual arrangements.

Customers can export project information through 1point. A structured extraction and deletion process may also be agreed as part of offboarding, subject to contractual, legal and legitimate retention requirements.

17. Accessing and correcting personal information

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact our Privacy Officer using the details in section 21. We may need to verify your identity or authority before responding.

We will respond within a reasonable period. We do not charge for making a request, although we may charge reasonable costs for providing access where permitted by law. If we refuse a request, we will provide written reasons and information about available complaint mechanisms, unless the law permits otherwise.

For personal information controlled by a 1point customer, you should generally direct your request to that customer. We will provide reasonable assistance where required under our agreement with the customer or applicable law.

18. Data breaches

We maintain processes for assessing and responding to suspected data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law. We may coordinate assessment and notifications with a customer where the customer has the more direct relationship with affected individuals.

19. Privacy complaints

If you believe we have mishandled your personal information:

  1. contact our Privacy Officer and describe the issue, including relevant dates and documents;

  2. we will acknowledge and investigate the complaint and may request additional information; and

  3. we will aim to provide a response within 30 days, although complex matters may require additional time.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.

20. Children

Our business services and 1point are not directed to children. We do not knowingly seek to collect personal information directly from children. If you believe a child has provided personal information to us without appropriate authorisation, please contact our Privacy Officer so we can assess and take appropriate action.

21. Contact us

Privacy Officer
Flout Software Pty Ltd
Level 21, 167 Eagle Street
Brisbane QLD 4000
Australia

Email: hello@floutsoftware.com
1point support:
support@floutsoftware.com
Phone:
+61 481 615 634

22. Changes to this policy

We may update this policy as our practices, services, technology or legal obligations change. The current version and effective date will be published on our website, and we will give additional notice where appropriate.