SEQRA POLICY

Privacy Policy

Version 2026-09-28-pilot.2 · Effective 28 September 2026

Who handles information

SeQRa is operated by Legal entity to be confirmed before live activation. Privacy enquiries, access, correction and complaints: Privacy contact to be confirmed before live activation. SeQRa does not claim an exemption from applicable Australian privacy obligations.

Information collected

SeQRa processes Provider and Client identity and contact information, ABN and Business details, Projects, agreements, evidence, communications, audit history and payment transaction metadata. Collection is limited to operating, securing, supporting and improving the service and meeting legal obligations.

Stripe and other providers

Stripe independently collects card, bank, identity and verification information through Stripe-hosted surfaces. SeQRa does not request bank statements, bank-account evidence, consumer credit reports, tax file numbers, raw card details, bank login credentials or Stripe verification documents. Business identity/registration evidence, trade licences, insurance and professional credentials submitted for SeQRa review remain separate and private. Payment onboarding and payout eligibility are handled by Stripe; SeQRa does not financially or government-verify a business. Authentication, hosting, email, monitoring, storage, scanning and payment providers receive information only as needed to provide their services.

Use, disclosure and overseas processing

Information may be used and disclosed for authentication, Projects, communications, payments, support, security, compliance and audit. Hosting and service providers may process information overseas; exact provider locations must be confirmed in the production service register before live activation.

Retention, deletion and security

Records are retained for operational, contractual, security and legal needs. Some immutable agreement, payment and audit records cannot be erased on request where retention is required. SeQRa uses access controls, tenant boundaries, encryption in transit, secret management and audit records, but no system is risk-free.

Cookies, analytics, access and correction

SeQRa uses essential session and security cookies. Where enabled and disclosed, SeQRa uses PostHog for limited product and web analytics. The Platform configuration disables session replay, form and element autocapture, persistent browser tracking and PostHog person profiles; it sends privacy-filtered page navigation data without query strings, invitation tokens or record identifiers. PostHog may process that limited information in the configured overseas data region. Users can request access or correction and make a privacy complaint through the privacy contact.

APP mapping

This policy is intended to support transparent management and notices, purpose-limited collection, controlled use and disclosure, security, access and correction under the Australian Privacy Principles.