Who we are
ZIRUO is a registered business name of SAW SHARE PTY LTD (ABN 21 697 490 547), based in Sydney, Australia. In this policy, “we”, “us” and “our” refer to that company operating as ZIRUO. This policy covers our website, enquiries and business relationships, including our automation, connected business systems and Australia market-entry services.
Contact our privacy contact at support@ziruo.com.au about this policy or your information. We handle personal information in accordance with the Australian privacy laws that apply to us.
Information we collect
Depending on your dealings with us, we collect contact details, your name and business or role, enquiry content, service interests, correspondence, project requirements and information needed to prepare proposals, deliver services, provide support and administer payments. Our enquiry form collects your name, email, optional business name, chosen service, message and language, together with submission and notification records.
We usually collect information directly from you through forms, email, calls or meetings. We may also receive relevant business contact information from your organisation, an authorised representative, referrals or lawful public sources. If you give us someone else’s information, ensure you have authority to do so and provide any required notice.
Our website and infrastructure providers may process IP addresses, browser and device details, request times and diagnostic logs. The enquiry service uses a hashed network identifier to limit repeated submissions. Please do not send passwords, identity documents or sensitive personal information in an initial enquiry. Where sensitive information is necessary for an agreed service, we arrange appropriate handling and obtain consent where required.
You may make a general enquiry using a pseudonym where practicable. We need a contact method to reply, and sufficient identifying information to enter contracts or meet legal obligations. Without necessary information, we may be unable to respond or provide a service.
How we use information
We use relevant information to respond to and follow up enquiries; assess requirements; prepare quotes and agreements; build, operate and support agreed systems; manage customer and supplier relationships; administer billing and records; troubleshoot and improve our services; prevent abuse; and meet legal obligations or resolve disputes.
We may use aggregated or appropriately de-identified information for planning, service improvement and reporting. Other uses of identifiable information must be related and reasonably expected, authorised by you, or otherwise permitted or required by law.
Client systems and AI tools
When an engagement involves customer, employee or other personal information in a client’s systems, we handle that information for the agreed work and under the client’s authorised instructions, subject to applicable law. The client remains responsible for its own notices and lawful collection. Project-specific agreements describe relevant access, integrations and data-handling responsibilities.
Our current website enquiry flow stores submissions and sends notifications; it does not send enquiry content to a generative AI model. If an agreed service uses AI tools to process personal information, we assess the proposed data flow and provider settings, explain relevant handling and obtain any required authorisation or consent before that use. This policy is not blanket consent to train AI models on your information.
Who we share information with
We share information where reasonably needed with authorised personnel and contractors, technology and communications providers, and professional advisers supporting the purposes above. Access should be limited to what the recipient needs, with appropriate confidentiality and security arrangements.
Our enquiry database uses Supabase, notification emails use Resend, and our business inbox uses Namecheap Private Email. Hosting and other providers may change as the business develops. We may also disclose information with your authorisation, to meet legal requirements, protect lawful rights or manage a business sale or restructure with appropriate safeguards. We do not sell personal information as a business activity.
Storage and overseas processing
Our primary Supabase enquiry database is configured in Sydney, Australia. Email delivery through Resend is configured in Tokyo, Japan. Email, support, infrastructure and provider subprocessors can also involve overseas processing, including in the United States. The location of the primary database does not mean all copies, logs or support access remain in Australia.
Locations depend on the providers and services involved. Contact us for current details relevant to your information or project. Before introducing a material change, we review the privacy implications and update relevant notices. Where Australian law requires safeguards for overseas disclosure, we take reasonable steps to provide them; using this website does not waive those protections.
Website technologies and marketing
On our production website hosted on Vercel, we use Vercel Web Analytics to understand visits, popular pages, referring websites, approximate visitor locations and device types. It provides aggregated usage statistics without analytics cookies. We remove query parameters and URL fragments from the page URLs sent by our integration and do not send enquiry form contents to analytics. Analytics is disabled on local development and preview deployments. Vercel may process analytics information overseas. Hosting services may also keep operational and security logs.
We have not installed advertising pixels. If we introduce additional analytics, advertising technologies or optional cookies, we will describe their purposes and choices in an updated notice and obtain consent where required before using them. You can manage cookies through your browser, although blocking necessary technologies may affect functionality.
We may contact you about relevant services where the law permits. Commercial emails and SMS require express or otherwise legally valid consent, identify the sender and provide a straightforward unsubscribe method. Making an enquiry does not automatically subscribe you to a newsletter. You can opt out of marketing at any time; necessary project, billing or support messages may continue.
Security and retention
We take reasonable technical and organisational steps appropriate to the information and risk, including restricted database access and server-side credentials for the enquiry service. No system is completely secure. We assess suspected data breaches and notify affected people and authorities when required by law.
We retain information for as long as reasonably needed for the purposes described, taking account of ongoing enquiries or engagements, record-keeping obligations and disputes. When it is no longer needed and retention is not legally required, we take reasonable steps to delete or de-identify it. Backup copies may remain until their normal replacement or deletion cycle.
Your requests and complaints
Email support@ziruo.com.au to request access to, or correction or deletion of, your personal information, or to raise a privacy complaint. Tell us enough to locate the information and understand your request; we may reasonably verify your identity. We assess requests under applicable law, explain any lawful refusal or retention requirement, and provide available review options.
We aim to respond to requests and complaints within 30 days and will let you know if more time is needed. For a complaint, we review the relevant circumstances and tell you our findings and proposed resolution. If you remain dissatisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au, where it has jurisdiction, or another relevant regulator.
Changes to this policy
We may update this policy as our services, providers or legal obligations change. The current version and revision date appear here. For material changes, we provide additional notice or seek consent where required. An update does not itself authorise an otherwise unlawful use of information already collected.