Privacy

Privacy Policy

Effective
12 March 2026
Last updated
3 October 2026

01Overview

Rand Advisory Pty Ltd (ABN 75 696 205 660) (“Rand”, “we”, “us”) operates an AI-powered R&D Tax Incentive compliance platform for Australian technology companies. This privacy policy explains how we collect, use, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy applies to all users of the Rand platform, including organisation members, administrators, and expert reviewers.

02Collection principles

We only collect personal information that is reasonably necessary to provide the Rand platform and fulfil our obligations (APP 3). We do not collect information we do not need.

Due to the nature of the service, preparing R&D Tax Incentive claims tied to specific individuals, organisations, and financial records, it is not practicable to provide the service on an anonymous or pseudonymous basis (APP 2).

03Information we collect

We collect the following categories of information:

  • Account information: your name, email address, and role within your organisation.
  • Organisation data: company name, ABN, industry, and company description provided during onboarding.
  • Employee data: names, roles, employment type, salary information, and optional GitHub/Jira usernames for staff involved in R&D activities. This data is used to calculate R&D expenditure allocations.
  • R&D activity data: core and supporting activity descriptions, hypotheses, experimental methodologies, outcomes, evidence records, and confidence assessments.
  • Integration data: when you connect GitHub, Jira, Linear, Notion, Slack, or Xero, we sync relevant signals such as pull request titles, descriptions, issue summaries, page content, channel messages, and (for Xero) employee and payroll records, bills, spend transactions, the chart of accounts, the profit and loss report and fixed assets used to calculate R&D expenditure. We access this data via OAuth (or, for GitHub, a GitHub App) with the minimum permissions required.
  • Financial data: R&D expenditure figures, allocation percentages, and claim amounts compiled for your R&D Tax Incentive submission.
  • Usage data: page views, feature usage, and performance metrics collected via PostHog (product analytics) and Sentry (error and performance monitoring) to improve the service. PostHog session replays are sampled and have all input values and visible text masked before capture; Sentry replays mask all text and block media.
  • Billing information: the signed consultant agreement, the organisation and signatory details on that agreement, and the Service Fee amounts invoiced against a lodged claim.

Third-party personal information: If you enter personal information about your employees or contractors (such as names, salaries, roles, and developer usernames), you are responsible for ensuring you have the authority to provide this information and that those individuals have been notified their data will be processed through Rand.

Sensitive information: We do not intentionally collect sensitive information as defined in section 6 of the Privacy Act 1988 (such as health information, racial or ethnic origin, political opinions, or biometric data). Salary and financial data collected through the platform is business information used for R&D expenditure calculations and is not classified as sensitive information under the Act.

04How we use your information

We use your information to:

  • Provide the Rand platform, including AI-powered analysis of R&D signals, drafting of activity descriptions, and compilation of R&D Tax Incentive claims.
  • Facilitate expert review of your R&D activities by assigned reviewers.
  • Calculate R&D expenditure allocations based on employee data and time records.
  • Send notifications about your claim progress, reviewer tasks, and AI-generated suggestions.
  • Invoice Service Fees against lodged claims under the signed consultant agreement.
  • Improve and maintain the platform.
  • Comply with legal obligations, including ATO record-keeping requirements.

05AI and automated processing

Rand uses artificial intelligence to analyse R&D signals (such as pull requests and technical tickets) and draft activity descriptions aligned to AusIndustry R&D Activity Registration requirements. Our AI processing runs on commercial AI model APIs from established providers.

Key points about our AI processing:

  • All AI-generated content is clearly marked as a draft and requires human review before it becomes part of your claim. AI outputs are probabilistic assessments, not factual determinations.
  • AI is used to assess relevance, map signals to activities, and suggest R&D allocations, but no claim content is finalised without human approval.
  • AI confidence scores and risk assessments are visible so you can make informed decisions.
  • We only send the minimum data necessary to our AI providers for each specific task.
  • Data sent to our AI providers is processed under their commercial API terms. It is not used to train their models and is not accessible to their other customers.
  • Rand does not use AI to make automated decisions that have legal or similarly significant effects on individuals without human oversight.

06Who we share data with

We do not sell your personal information. We share data with the following third parties solely to operate the platform:

  • Supabase: database hosting and authentication.
  • AI model providers: AI processing of R&D signals and activity drafting, through commercial APIs that do not train models on your inputs.
  • Vercel: application hosting.
  • PostHog: product analytics and sampled, masked session replays (EU region).
  • Sentry: application error tracking and performance monitoring, including sampled session replays with all text masked and media blocked.
  • Resend: transactional email delivery (notifications and monthly summaries).
  • Cal.com: scheduling and booking embeds used for demo calls and expert reviewer meetings.
  • Connected tool providers: GitHub, Atlassian (Jira), Linear, Notion, Slack, and Xero, only where you connect them, and only to the extent needed to sync the signals or records you authorise.
  • Expert Reviewers: R&D professionals assigned to your organisation under the Consultant Agreement can access your R&D Activity data to provide expert review and approval.

We may also disclose information where required by law, regulation, or legal process.

07Data security

We take reasonable steps to protect your information from misuse, interference, loss, and unauthorised access. Our security measures include:

  • Encryption in transit (TLS) and at rest.
  • Row-level security (RLS) ensuring each organisation’s data is isolated at the database level.
  • Role-based access controls with separate permissions for members, administrators, and reviewers.
  • Immutable audit logging of all significant actions within the platform.
  • Secure authentication with session management.

08Data retention

We retain your information for as long as your account is active and as needed to provide the service. Specific retention periods:

  • Financial and tax records: we aim to keep these for at least 5 years, in line with ATO record-keeping requirements.
  • Audit logs: retained for the life of the associated claim year plus 5 years.
  • Account data: retained while your account is active. On account closure, we delete personal data within 30 days, subject to legal retention obligations.

You may request deletion of your data at any time. Where we are required by law to retain certain records (e.g. tax-related data), we will inform you of the applicable retention period.

09Your rights

Under the Australian Privacy Principles, you have the right to:

  • Access your personal information held by us (APP 12).
  • Request correction of inaccurate or incomplete information (APP 13).
  • Opt out of receiving any direct marketing communications from us at any time (APP 7). Currently, Rand only sends transactional notifications related to your account and claim activity.
  • Complain if you believe we have breached the APPs.

To exercise these rights, contact us at the details below. We will respond to access and correction requests within a reasonable period, generally within 30 days. For complex requests, we will notify you if additional time is needed and provide reasons for the delay.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10Cookies

Rand uses a minimal set of cookies, all essential to the operation of the platform:

  • Authentication cookies: managed by Supabase to maintain your logged-in session.
  • Claim year cookie (rand-claim-year-id): a 90-day cookie to remember your selected financial year within the application.
  • OAuth state cookies: short-lived cookies (up to 10 minutes) used during GitHub and Jira integration setup for security verification (CSRF protection). These are automatically deleted after use.

We use PostHog for product analytics and Sentry for error and performance monitoring. Both are configured to minimise the personal information sent: input values and on-screen text are masked before any session replay is captured, and replays are sampled (not recorded for every session). We do not use advertising, marketing, or cross-site tracking cookies.

11Data breach notification

In the event of a data breach that is likely to result in serious harm, we will notify the OAIC and affected individuals as soon as practicable, in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.

We maintain a data breach response plan and will assess any suspected breach as expeditiously as possible, and in any event within 30 days of becoming aware of it, as required under the Act.

12International data transfers

Some of our third-party service providers are based outside Australia. Your data may be transferred to the following countries as part of providing the service:

  • United States: our AI model providers (AI processing), Vercel (hosting), Sentry (error and performance monitoring), Resend (email delivery), Cal.com (scheduling embeds), and, where you connect them, GitHub, Atlassian (Jira), Linear, Notion, and Slack for integration data syncing.
  • European Union: PostHog (product analytics and sampled, masked session replays, EU region).
  • New Zealand: Xero (payroll and accounting data syncing, where you connect Xero).
  • Australia: Supabase (database hosting and authentication, Sydney region).

In accordance with APP 8, we take reasonable steps to ensure each overseas recipient handles your personal information consistently with the APPs. This includes entering into contractual arrangements that require the recipient to protect personal information, and selecting providers with established privacy and security practices that meet or exceed Australian standards.

13Changes to this policy

We may update this policy from time to time. For material changes, we will notify you via email or through the Rand platform before the changes take effect. We encourage you to review this page periodically.

14Contact

For privacy enquiries, access requests, or complaints, contact us at:

Rand Advisory Pty Ltd (ABN 75 696 205 660)

Email: support@randadvisory.com.au

Melbourne, Victoria, Australia

You may also contact the Office of the Australian Information Commissioner (OAIC) directly if you have concerns about how we handle your personal information.