Privacy Policy

1. Introduction

Vennur Pty Ltd ("Vennur", "we", "our", or "us") respects your privacy and is committed to protecting the information we collect, use, store and disclose in connection with our website, applications, portals, integrations and related services.

This Privacy Policy explains how Vennur handles information when you use or interact with:
- the Vennur website;
- the Vennur Firm Portal;
- the Vennur Client Portal;
- connected accounting software integrations;
- financial briefing, script generation and audio briefing services;
- support, onboarding, demonstration and related communications; and
- any other Vennur products, features or services that refer to this Privacy Policy.

Vennur provides software that helps accounting firms generate and deliver financial briefings to their clients. In doing so, Vennur may process personal information, business information and accounting data obtained directly from users, accounting firms, client businesses and authorised accounting software platforms.

By accessing or using Vennur, you acknowledge that we will handle information in accordance with this Privacy Policy.

2. Who This Policy Applies to

This Privacy Policy applies to all users and visitors who interact with Vennur, including:

- accounting firms using Vennur to manage client entities;
- firm administrators and authorised firm users;
- client users who access financial briefings through the Client Portal;
- business owners, directors, managers or other representatives of client entities;
- website visitors;prospective customers who request a demo or contact us;
- individuals who communicate with us for support, onboarding or account administration; and
- any other person whose information is provided to or processed by Vennur.

Where an accounting firm provides access to Vennur for its own clients, the firm is responsible for ensuring that it has authority to provide relevant client and entity information to Vennur and to authorise Vennur to process that information for the purposes of providing the service.

3. Key Terms Used In This Policy

For clarity:

"Accounting Data" means financial, accounting, reporting and business information obtained from or connected to an accounting software platform or uploaded, entered or otherwise provided to Vennur.
"Client Entity" means a business, company, trust, sole trader, partnership or other entity whose financial information is connected to or processed through Vennur.
"Firm" means an accounting firm, advisory firm, bookkeeping firm or other professional services provider that uses Vennur to manage and deliver briefings to client entities.
"Personal Information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
"Platform" means the Vennur website, Firm Portal, Client Portal, integrations, software, systems, applications and related services.
"User" means any person who accesses or uses Vennur.

4. Information We Collect

The information we collect depends on how you use Vennur.

4.1 Account and User Information

When a user account is created or managed, we may collect:
- first name and surname;
- email address;
- business or firm name;
- user role;
- permissions;
- assigned client entities;
- login credentials;
- account status;
- authentication information;
- password reset information;
support preferences;
- contact details and
- other information reasonably required to operate the account.
Passwords are not stored in plain text. They are processed and stored using secure authentication systems.

4.2 Firm and Client Entity Information
Where a firm or authorised user sets up or manages client entities in Vennur, we may collect:

- firm name;
- client entity name;
- ABN, ACN or other entity identifiers where provided;
- entity contact information;
- billing or service status
- briefing cadence;
- assigned firm users;
- assigned client users;
- integration status;
- connected accounting platform details; and
- related administrative settings.

4.3 Accounting Data
Where authorised, Vennur may access, receive, process and store Accounting Data from connected accounting software platforms such as QuickBooks Online, Xero, MYOB, Sage or other supported systems.

This may include:
- Profit and Loss information;
- Balance Sheet information;
- cash and bank balances;
- revenue, expenses and margins;
- aged receivables and aged payables;
- tax obligations;
- Good & Services Tax, Activity Statements or similar reporting information;
- payroll-related summary information where available and authorised;
- account codes and account names;
- invoices, bills or transaction-level summaries where required for briefing generation;
- comparative period information;
- reporting cadence information;
- entity-level financial performance data; and
- other financial or operational information reasonably necessary to generate, review, and deliver Vennur briefings.

Vennur only seeks to access Accounting Data that is reasonably necessary to provide, maintain and improve the service.

4.4 Connected Accounting Software Information
When you connect Vennur to an accounting platform, we may collect or process:
- authorisation status;
- OAuth tokens or similar secure access credentials;
- tenant, company, organisation or realm identifiers;
- connection metadata;
- integration refresh status;
- connection error logs;
- data sync timestamps; and
- permission scopes authorised through the connected platform.

OAuth tokens and similar credentials are used to maintain authorised integrations and are not intended to be visible to ordinary users.

4.5 Generated Briefings, Scripts and Audio Content
Vennur may generate and store content created through the Platform, including:
- draft financial briefing scripts;
- published briefing scripts;
- audio briefings;
- key takeaways;
- financial explanations;
- reviewer notes;
- status changes;
- briefing history;
- regeneration history; andrelated metadata.

This content may be based on Accounting Data, user instructions, firm settings, cadence preferences and platform logic.

4.6 Usage, Device and Technical Information
When you use Vennur, we may collect technical and usage information such as:
- IP address;
- device type;
- browser type;
- operating system;
- referring pages;
- pages viewed;
- buttons clicked;
- session activity;
- login attempts;
-date and time of access;
- audit logs;
- error logs;
- performance data;
- security event data; and
- approximate location inferred from technical information.
This information helps us operate, secure, troubleshoot and improve the Platform.

4.7 Communications and Support Information
If you contact Vennur, request a demo, submit a form or communicate with us, we may collect:
- name;
- email address;
- organisation name;
- role or job title;
- message content;
- support requests;
- onboarding information;
- meeting notes;
- feedback;
- correspondence history; and
any other information you choose to provide.

4.8 Marketing and Website Information
When you visit our website or engage with marketing materials, we may collect:
- website analytics;
- form submissions;
- demo requests;
- email engagement information;
- marketing preferences; and
information collected through cookies or similar technologies.
You may opt out of marketing communications where required by applicable law.

5. How We Collect Information

We collect information in several ways, including:

- directly from users when they create accounts, complete forms or communicate with us;
- from accounting firms that use Vennur to manage client entities;
- from client users invited to access the Client Portal;
- from connected accounting software platforms authorised by users or firms;
- automatically through the Platform, including logs and analytics;
- from service providers who help us operate Vennur;
- from publicly available sources where relevant to business contact or onboarding processes; and
- from third parties where permitted by law and reasonably necessary to provide the service.

Where a firm provides information about a client entity or client user, the firm is responsible for ensuring that it has the necessary authority, consent or lawful basis to provide that information to Vennur.

6. Why We Collect and Use Information

Vennur collects and uses information for the purposes of operating, securing and improving the Platform.

These purposes include:
- creating and managing user accounts;
- authenticating users;
- managing firm and client entity access;
- connecting to authorised accounting software platforms;
- syncing relevant Accounting Data;
- generating financial briefing scripts;
- generating audio financial briefings;
- displaying briefing history;
- enabling draft, review and publish workflows;
- supporting role-based permissions;
- maintaining audit logs;
- troubleshooting integration issues;
- providing customer support;
- responding to enquiries;
- onboarding accounting firms and users;
- improving Platform reliability and performance;
- detecting, preventing and responding to security incidents;
- complying with legal obligations;
- enforcing our agreements;
- developing new features and services;
- creating aggregated or de-identified analytics;
- communicating service updates; and sending marketing communications where permitted.

We do not sell personal information.

7. Accounting Software Integrations

Vennur may connect to third-party accounting software platforms where authorised by a firm, client entity or authorised user.
When an integration is connected, Vennur accesses Accounting Data through the relevant platform’s authorised connection process, such as OAuth.

The information available to Vennur depends on:
- the accounting platform used;
- the permissions granted;
- the data available within that platform;
- the user’s role within that platform;
- the entity connected; and
- the features enabled in Vennur.

You may disconnect an integration through Vennur or through the connected accounting platform where supported. Disconnecting an integration may prevent Vennur from generating new briefings or refreshing financial information, but historical briefing records may remain available unless deleted in accordance with applicable retention rules and customer instructions.

8. Accounting Software Data

Where Vennur is connected to platforms such as for reference purposes, Xero, Intuit, Myob, Sage Vennur will access data only as authorised through the Intuit connection and only for purposes related to providing the Vennur service.

This may include retrieving relevant financial, accounting and company information to generate financial briefings, provide reporting context, maintain integration functionality and support users.

Vennur does not control third party accounting software platforms and complies with their data transmition requirements and is reviewed regularly per public stipulated requirements.

Your use of said or similar accouting platforms remains subject to Intuit’s own terms, privacy policy and platform rules.

If you disconnect QuickBooks from Vennur, Vennur will no longer be able to refresh data from that QuickBooks company file unless the connection is re-authorised.

9. AI Processing

Vennur uses automated technologies, including artificial intelligence systems, to assist in generating financial summaries, briefing scripts, key takeaways and related content from authorised Accounting Data.

AI processing may be used to:
- identify relevant changes in financial performance;
- summarise financial information in plain language;
- compare current and prior periods;
- generate draft briefing scripts;
- create concise explanations of financial movements;
- assist with review and regeneration workflows; and
- support internal quality, consistency and product improvement processes.

AI-generated content may contain errors, omissions or interpretations that require human review. Vennur is designed to assist firms and users, not to replace professional judgment.

Unless we expressly state otherwise in a separate agreement, Vennur does not permit third-party AI service providers to use customer Accounting Data to train general-purpose AI models.

10. Audio Generation

Vennur may use audio generation technologies to convert approved or generated briefing scripts into audio format.

To provide this functionality, briefing text and related metadata may be processed by trusted service providers that support audio generation.

Audio files generated through Vennur may be stored and made available through the Client Portal or other authorised delivery channels.

11. De-identified and Aggregated Information

Vennur may use de-identified or aggregated information for purposes such as:
- service improvement;
- product development;
- benchmarking;
- system performance analysis;
- usage reporting;
- internal business analytics;
- security monitoring; and
development of new features.

De-identified or aggregated information is not intended to identify an individual or a specific client entity.
We will not intentionally publish identifiable client financial information without authorisation.

12. Disclosure of Information

We may disclose information where reasonably necessary for the purposes described in this Privacy Policy.
This may include disclosure to:

- cloud hosting providers;
- authentication providers;
- database and infrastructure providers;
- AI processing providers;
- audio generation providers;
- analytics and monitoring providers;
- customer support tools;
- email and communication service providers;
- accounting software platforms where required to maintain integrations;
- professional advisers, including lawyers, accountants and auditors;
- regulators, courts, law enforcement or government bodies where required or permitted by law;
- prospective investors, acquirers or advisers in connection with a corporate transaction, subject to confidentiality protections where appropriate; and
- other parties with your consent or at your direction.

We require service providers to handle information only for authorised purposes and to apply appropriate confidentiality and security measures.

13. International Data Processing

Vennur is based in Australia. Some of our service providers may process or store information in jurisdictions outside Australia.

These jurisdictions may include countries where our hosting, AI, audio, analytics, communication or infrastructure providers operate.

Where personal information is disclosed or processed overseas, we take reasonable steps to ensure that appropriate safeguards are in place, having regard to the nature of the information and the services being provided.

By using Vennur, you acknowledge that information may be processed outside Australia where necessary to provide the Platform.

14. Data Security

Vennur takes reasonable technical, organisational and administrative steps to protect information against misuse, interference, loss, unauthorised access, modification and disclosure.

Security measures may include:
- encrypted connections;
- secure authentication;
- role-based access controls;
- database access controls;
- audit logs;
- access monitoring;
- secure infrastructure providers;
- separation of user roles and permissions;
- least-privilege access principles;
- secure OAuth-based integration flows;
- system monitoring;
- backup and recovery processes; and
- internal access restrictions.

No online service can guarantee absolute security. Users are responsible for maintaining the security of their own login credentials and ensuring that access is granted only to appropriate authorised users.

15. Users, Administrators and Client Access

Vennur may allow firm administrators or authorised firm users to create, manage or invite other users.Firm administrators may be able to:
- assign users to client entities;
- grant or remove access;
- determine whether a user can generate, review or publish briefings;
- manage client entity settings;
- connect or disconnect integrations;
- view audit activity; and
- control other firm-level settings.

Client users may have access to briefing content and entity information made available to them by the relevant firm or authorised administrator.

Vennur is not responsible for access decisions made by a firm administrator or authorised user, except to the extent required by law.

16. Data Retention

We retain information for as long as reasonably necessary to provide Vennur, comply with legal obligations, resolve disputes, enforce agreements, maintain security and preserve legitimate business records.

Retention periods may vary depending on the type of information, the purpose for which it is used and applicable legal or contractual requirements.

For example:
- account information may be retained while an account remains active;
- audit logs may be retained for security and accountability purposes;
- generated briefings may be retained to preserve briefing history;
- support communications may be retained for customer service and record-keeping;
- integration tokens may be retained while an integration remains connected;
- financial briefing data may be retained while required to provide the service or comply with customer instructions.

When information is no longer required, we will take reasonable steps to delete, de-identify or securely archive it.

17. Access, Correction and Deletion Requests

Subject to applicable law, you may request access to personal information we hold about you.

You may also request that we correct personal information that is inaccurate, incomplete or out of date.In some circumstances, you may request deletion of personal information.

We may not be able to delete information where retention is required for legal, security, contractual, accounting, audit or legitimate business purposes.

Where your access to Vennur is provided through an accounting firm, some requests may need to be directed to that firm, particularly where the firm controls the client relationship or determines user access.

To make a request, contact us using the details at the end of this Privacy Policy.

18. Marketing Communications

We may send marketing communications to business contacts, prospective customers or users where permitted by law.

You may opt out of marketing emails by using the unsubscribe link in the email or contacting us directly.

Even if you opt out of marketing communications, we may still send service-related messages, including security notices, account notifications, integration updates and important platform communications.

19. Cookies and Analytics

Vennur may use cookies, pixels, local storage and similar technologies to operate our website and Platform.

These technologies may be used to:
- remember user preferences;
- support login sessions;
- improve website performance;
- analyse website traffic;
- understand feature usage;
- detect errors;
- improve security; and
- support marketing or demo request workflows.

You may be able to control cookies through your browser settings. Disabling some cookies may affect website or Platform functionality.

20. Children's Privacy

Vennur is intended for business and professional use.

It is not directed to children under 18 years of age. We do not knowingly collect personal information from children.

If we become aware that a child has provided personal information to us without appropriate authority, we will take reasonable steps to delete that information.

21. Data Breaches

If Vennur becomes aware of a data breach affecting personal information, we will assess the incident and take steps to contain, investigate and remediate it.

Where required by law, we will notify affected individuals and relevant regulators.

Users and firms must promptly notify Vennur if they become aware of unauthorised access, compromised credentials or suspected misuse of the Platform.

22. Third-Party Websites and Services

Vennur may contain links to third-party websites, platforms or services.

This Privacy Policy does not apply to third-party websites or services that Vennur does not control.

You should review the privacy policies and terms of those third parties before using them.

23. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, legal requirements, technology, integrations or business operations.

The updated version will be published on our website with a revised effective date.Where changes are material, we may take additional steps to notify users where appropriate.

Your continued use of Vennur after an updated Privacy Policy is published indicates your acknowledgement of the updated policy.

24. Complaints

If you have concerns about how Vennur handles personal information, please contact us first so that we can review and respond to your concern.

We may ask for additional information to verify your identity and understand the nature of the complaint.

We will aim to respond within a reasonable period.

25. Contact Us

If you have questions about this Privacy Policy, wish to make a privacy request or wish to raise a complaint, please contact:

Vennur Pty Ltd
Email: info@vennur.com