Legal

Privacy Policy

How Cloutly collects, holds, uses and discloses personal information — including the personal information of your customers, guests and staff that flows through the platform — and how you can exercise your privacy rights.

Effective 4 September 2026 · Last updated 4 September 2026.

This Privacy Policy explains how Cloutly Co Pty Ltd (ACN 637 155 045) (“Cloutly”, “we”, “us”, “our”) collects, holds, uses and discloses personal information, and how you can contact us about it.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”). Where we handle the personal information of individuals in other places — for example, businesses and their customers in the United States, New Zealand, the United Kingdom, Canada or the European Union — we aim to handle it consistently with applicable local privacy laws, including US state privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA) and the GDPR and UK GDPR, where they apply. Region-specific sections for EU/UK and US individuals appear at the end of this policy.

1. Who this policy covers

Cloutly provides a customer-experience and reputation platform for businesses — from single locations to multi-location groups and franchise networks. Our direct customer is the business or organisation that subscribes to the Service (the “Customer”). Because of how the platform works, we handle personal information about several groups of people:

Customer personnel — the account holders and authorised users who hold Cloutly accounts and use the platform, including through our mobile app.

Review recipients and reviewers — the Customer’s own customers, clients, guests and contacts: people whose details a Customer imports or syncs in order to send review invitations, who receive messages from or reply to the Customer through the Service, or who leave reviews and feedback — whether through the Service directly or on a public Review Platform that the Customer monitors.

Customer staff — employees and contractors of the Customer who are named or identifiable in reviews and feedback, or whose names appear in a staff roster or a connected booking, point-of-sale or CRM system, so that praise can be attributed to the right person.

Website visitors — people who visit cloutly.com or our other sites, people who visit a public business page (“microsite”) that we host for a Customer, and people who interact with a review, chat or lead-capture widget that a Customer has embedded on its own website.

Prospective customers and contacts — people who enquire about Cloutly, request a demo, respond to a proposal, or correspond with us.

An important note on how Cloutly works. Cloutly is engaged by a business to manage that business’s reviews, feedback and customer experience. When a Customer uploads or syncs its contacts, sends review invitations, monitors public reviews, connects its listings, or analyses feedback through the Service, Cloutly generally acts as a service provider / processor handling that information on the Customer’s behalf and under its instructions. The Customer decides which people to contact, which sources to connect, who in its organisation can see what, and what to do with the results, and is responsible for providing any privacy notices to — and obtaining any consents from — its own customers and staff. If you received a review invitation from a business, or believe a business is analysing feedback that mentions you, the business is the right first point of contact; this policy supplements, and does not replace, that business’s own privacy notice.

2. What we collect

Account and contact information. Name, business email address, phone number, role, organisation, venue or location assignments, and account preferences. If you sign in with Google or LinkedIn, we receive your name, email address and profile identifier from that provider. Billing details are collected and held by Paddle, our payment provider and merchant of record — not by us (see section 5).

Contact data uploaded or synced by Customers. The names, email addresses, phone numbers and related details of the Customer’s own customers and contacts — imported by the Customer, entered by hand, or synced from a system the Customer has connected (for example a booking, appointment, point-of-sale, reservation or CRM system). Where the Customer connects such a system, we may also receive the context needed to time and attribute an invitation, such as the date and time of a visit or appointment, the location, the service purchased, and the name of the staff member who served the customer. We do not receive payment card numbers from connected systems.

Review and feedback content. Reviews, ratings, testimonials, written feedback, survey responses, photos and videos submitted through the Service, collected from connected Review Platforms, or gathered from publicly available review pages the Customer monitors — together with the reviewer’s public display name and avatar where the platform provides them, and the Customer’s responses. This includes direct feedback the Customer collects through its own forms, surveys or reservation systems and chooses to bring into the Service.

Video and voice testimonials. Where a Customer invites a customer to record a video testimonial, we hold the recording, and generate a transcript and captions from it using a speech-to-text service.

Messaging data. The content and delivery metadata of emails, SMS and in-app messages sent through the Service, including delivery status, replies, and opt-out (unsubscribe / STOP) records.

Staff data. Where a Customer uses staff attribution or leaderboards: staff names, roles, locations and aliases from a roster the Customer maintains or from a connected system, and the association between a staff member and the reviews that mention them.

Listing data. Business-level details the Customer maintains about each of its locations — name, address, phone, website, description, trading hours and special hours — and the corresponding details we read from connected and monitored platforms in order to detect discrepancies. Listing data is mostly about businesses rather than individuals, but can include a contact name or a direct phone number.

Generated intelligence. Categorisations, sentiment and topic classifications, severity grades, extracted “signals” and trends, summaries, executive briefs, staff attributions, answers to questions asked of the platform, and AI-drafted reply suggestions — all produced by the platform from the content above. Where review content describes a safety or health event (for example a suspected food-borne illness or allergic reaction), an injury, or discrimination or harassment, the platform may classify it as such so that the Customer can escalate it to the right person. See section 4.

Competitor and benchmarking data. Where a Customer uses our competitor-tracking features, we collect publicly available information about the other businesses it nominates — listing details, ratings, review counts and public review content, which can include the reviewer’s public display name. This information is already published by the platform concerned and is collected only to let the Customer benchmark itself. We do not collect private information about those businesses, do not contact the reviewers, and do not use the data for any purpose beyond providing the feature to the Customer that requested it.

AI-search measurement data. To measure how AI assistants describe the Customer’s venues, we periodically submit generic, scenario-style questions (for example, “where should I take eight people for dinner in Bondi?”) to AI assistants through a measurement provider, and record what they answer and which sources they cite. These queries do not include personal information; the recorded answers are about businesses, and can name a Customer’s competitors.

Integration data. Where a Customer connects a third-party account — for example Google Business Profile, Facebook, or a booking, point-of-sale, CRM, accounting or messaging tool — the access tokens for that connection and the data made available through it for the purposes the Customer has enabled.

Usage and technical data. Log data, IP address, browser and device information, mobile device identifiers and push-notification tokens, pages viewed, feature usage, in-app events, session recordings of the application interface (see the Cookie Policy), and diagnostic and error data.

Support and correspondence. Messages you send us through in-app chat, email, or our help desk, and records of those conversations.

Cookies and analytics. We use cookies and similar technologies on our websites and app for authentication, preferences, analytics and, on our marketing site, campaign measurement — see our Cookie Policy.

We collect personal information directly from you; from your organisation; from Customers (when they upload or sync contacts, connect accounts, or configure staff and listings); from reviews, messages and feedback sent through or collected by the Service; from publicly available Review Platforms; from sign-in and integration providers you authorise; and automatically through your use of the platform. We do not collect personal information covertly.

3. Why we collect, use and hold it

We collect, hold and use personal information to:

  • provide, operate, secure and support the platform, including our mobile app;
  • send review invitations and other communications on the Customer’s behalf, at the time and to the people the Customer has chosen, and manage replies and opt-outs;
  • collect, organise, categorise, summarise and analyse reviews and feedback — including extracting recurring themes, grading severity, tracking trends over time, comparing locations within the Customer’s own portfolio, and benchmarking against publicly available information about other businesses the Customer nominates;
  • answer questions the Customer asks of its own data, and generate reports, briefs and alerts for the people the Customer nominates;
  • generate suggested replies and, at the Customer’s direction, publish responses to Review Platforms;
  • attribute reviews to the staff members they praise, where the Customer enables this;
  • maintain the Customer’s listing records and, at the Customer’s direction, publish corrections to connected platforms;
  • measure how the Customer’s locations appear in AI assistants and search;
  • host public business pages and widgets the Customer chooses to publish;
  • administer accounts, billing, renewals and, where applicable, white-label partner arrangements;
  • communicate with you about the Service, including service notices, product updates and support;
  • improve and develop the platform, using aggregated or de-identified data wherever practicable;
  • comply with our legal obligations and enforce our terms; and
  • with consent or as otherwise permitted by law, send marketing about Cloutly (you can opt out at any time — we comply with applicable anti-spam laws, including the Spam Act 2003 (Cth) and, for recipients in the United States, the CAN-SPAM Act).

We do not sell personal information, and we do not “share” it for cross-context behavioural (targeted) advertising, as those terms are defined under applicable US state privacy laws.

Sensitive information. Reviews and feedback are written by members of the public and occasionally describe health matters (such as an allergic reaction or illness), or allege discrimination or harassment. We do not seek this information and do not use it for any purpose other than to organise and surface the Customer’s own feedback — including flagging such content so the Customer’s nominated people can respond appropriately. We ask that Customers and their contacts not submit sensitive information through the platform unless it is necessary.

4. AI and automated processing

Cloutly uses artificial intelligence — including large language models operated by third-party providers, and classification and embedding models we run ourselves — throughout the platform. This section explains what that processing does, what it does not do, and where people remain in control.

What AI is used for.

  • Drafting. Proposing suggested replies to reviews and messages in the Customer’s voice, for a person to review before anything is published.
  • Classification and signals. Reading reviews and feedback to identify topics, sentiment and recurring issues; grading the severity of an issue; grouping similar issues across locations and over time; and identifying dishes, services or staff members mentioned.
  • Summarisation and reporting. Producing summaries, weekly and monthly briefs, and narrative explanations of trends.
  • Answering questions (“Ask”). When a Customer asks a question of its data, the platform computes the answer from its database and uses a language model to phrase the result. Counts and attributions come from the database, not from the model’s memory, and answers link to the underlying reviews so they can be checked.
  • Listing consistency. Comparing the Customer’s own listing record against what connected and monitored platforms display, and identifying discrepancies.
  • AI-search measurement. Submitting generic scenario questions to third-party AI assistants and recording what they say about businesses.
  • Transcription. Converting video testimonials to text and captions.
  • Conversational widgets. Powering chat and lead-capture widgets a Customer embeds on its own website, using content the Customer supplies or that is read from the Customer’s website.
  • Third-party AI assistants. Where we make the Cloutly platform available inside an AI assistant the Customer already uses (for example through the Model Context Protocol), the Customer’s authorised users can query their Cloutly data from that assistant, subject to the same access permissions as the dashboard. That assistant is operated by its own provider under its own terms.

Where people stay in control. AI outputs are decision support. The platform never publishes a reply, changes a listing, or contacts anyone autonomously: those actions happen when a person at the Customer approves them. Where a review is classified as describing a safety, health, legal or discrimination event, the platform routes it to the people the Customer has nominated rather than drafting an automatic response. Automated classifications are probabilistic and can be wrong; they are not a substitute for the Customer’s own incident-reporting, complaints-handling or legal processes.

What we do not do. We do not use your personal information, reviews, feedback or messages to train generalised AI models made available to other customers, and we do not permit our AI providers to do so — our model providers process content on a per-request basis under API terms that exclude use for model training, and our AI-observability tool retains prompts and outputs only for a limited period so we can check quality and debug errors. We do not build profiles of reviewers or contacts, and we do not use AI to make decisions that produce legal or similarly significant effects on individuals.

Transparency about automated decisions. Where our use of automated processing is subject to transparency requirements under the Privacy Act 1988 (Cth) (including the automated decision-making provisions introduced by the Privacy and Other Legislation Amendment Act 2024) or other applicable law, this section describes the kinds of decisions involved and the personal information used in them, and we will keep it up to date.

5. Who we disclose personal information to

The Customer. Reviews, feedback, messages and the intelligence derived from them are made available to the Customer that operates the account — this is the core function of the platform. Within a Customer’s account, access is scoped by role and location, and for some data sources by explicit authorisation, as the Customer configures.

Service providers (sub-processors). Providers of cloud hosting and storage, AI and language-model processing, vector search, speech-to-text, review and listing data collection, AI-search measurement, email and SMS delivery, push notifications, authentication, payment processing, product analytics and session replay, error monitoring, and customer-support tooling — in each case only to the extent needed to provide the Service and under obligations of confidentiality and data protection. Our core sub-processors, and the categories of other providers we use, are listed in our Sub-processors page. Customers on an enterprise agreement receive a complete, named sub-processor schedule in their contract, with advance notice of changes.

Review Platforms and listing platforms. Where a Customer connects a platform such as Google Business Profile or Facebook, we exchange data with that platform to fetch reviews and, at the Customer’s direction, publish responses and listing updates. Platforms the Customer monitors without a direct connection are read through our data-collection providers.

Systems the Customer connects. Where a Customer connects a booking, point-of-sale, reservation, CRM, accounting, messaging or automation tool, we exchange the data the Customer has enabled with that system. Those systems are operated under their own terms and are chosen and authorised by the Customer.

Third-party AI assistants. Where a Customer’s authorised user accesses Cloutly from within an AI assistant they use, the data returned to that assistant is handled by the assistant’s provider under the user’s or Customer’s own agreement with that provider.

White-label partners. Where a Customer accesses the Service through an authorised white-label partner, we share account and operational information with that partner as needed to provide and support the Service.

Professional advisers and authorities. Our lawyers, accountants, insurers and auditors where reasonably required; and courts, regulators or law enforcement where required or authorised by law.

Business transfers. A purchaser or investor (and their advisers) in connection with an actual or proposed sale, merger, financing or reorganisation of our business, under confidentiality obligations.

Payments (merchant of record). We sell subscriptions through Paddle, which acts as our merchant of record. When you purchase, Paddle collects and processes your payment and billing information as an independent controller / business for that purpose, under its own terms and privacy policy, and handles billing, tax, invoicing and payment-dispute resolution. We receive transaction and subscription-status information from Paddle but do not receive or store full payment card numbers. Some long-standing accounts are billed through Stripe on the same basis; enterprise customers may be invoiced directly.

6. Overseas disclosure and hosting

Cloutly is based in Australia. Our production platform and database are hosted on Google Cloud Platform in the European Union (Belgium, europe-west1), encrypted in transit and at rest. Some of our service providers — including AI, data-collection, email, SMS, analytics, payment and content-delivery providers — store or process data in the United States, the United Kingdom, the European Union and other countries where those providers operate; see our Sub-processors page for locations by provider and category.

Before disclosing personal information overseas, we take steps reasonable in the circumstances to ensure the recipient handles it consistently with the APPs, including through contractual protections such as standard contractual clauses where appropriate. Enterprise customers may request our security and privacy annexure, which sets out sub-processors, retention and incident-response commitments in more detail.

7. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit and at rest; role-based permissions with per-location scoping, and source-level scoping where enabled; logical separation between customer accounts; single sign-on options; rate limiting on public endpoints; logging of internal Cloutly staff access to customer accounts; staff confidentiality obligations; and vendor due diligence.

No system is completely secure. If a data breach occurs that triggers a notification obligation, we will notify affected individuals and the relevant regulator(s) as required by applicable data-breach notification laws — including the Australian Notifiable Data Breaches scheme (notifiable to the Office of the Australian Information Commissioner, OAIC), the GDPR, and applicable US state breach-notification laws — and will notify affected Customers so they can meet their own obligations.

8. Retention, export and deletion

We keep personal information only as long as needed for the purposes described in this policy, to provide the Service to the Customer, and to meet legal, accounting and dispute-resolution requirements.

Contact data, review data, staff data and generated intelligence are retained while the Customer’s account is active and are handled on the Customer’s instructions. A Customer can delete contacts, staff records and content within the platform, and can export its data at any time in CSV form (and, where enabled, through the API).

When a Customer’s subscription ends, the Customer may export its data for 30 days, after which we delete or de-identify it within a reasonable period unless we are required to retain it for longer by law. A Customer may also request deletion earlier, and we will confirm when it is complete. Free or trial accounts that remain inactive for an extended period may be closed on notice and their data deleted on the same basis. Backup copies are deleted on a rolling schedule. Opt-out and suppression records are retained as needed to honour opt-out requests. Aggregated, de-identified statistics that cannot reasonably identify any person may be retained.

9. Access, correction and your choices

You may request access to, or correction of, the personal information we hold about you by contacting privacy@cloutly.com. We will respond within a reasonable period (usually 30 days). We may need to verify your identity, and in some cases the law allows us to refuse access (we will tell you why and how to complain).

If you are a review recipient, reviewer, guest, or a member of a Customer’s staff, requests about how your information is used in connection with a particular business are often best directed to that business, since it controls that use; we will assist and will refer requests to the Customer where appropriate.

You can opt out of marketing at any time using the unsubscribe link or by contacting us, and you can opt out of SMS by replying STOP. You can disable push notifications in your device settings. Providing personal information is your choice, but some features may not work without basic contact details.

10. Anonymity and pseudonymity

Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym — for example, general enquiries to our website. However, the platform’s function is to connect communications, reviews and feedback to identifiable contacts and accounts, so review invitations and account activity generally cannot be handled anonymously.

11. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal information from children. Customers must not use the Service to collect personal information from individuals below the age at which consent is required under applicable law without an appropriate lawful basis. If you believe a child’s personal information has been provided to us, contact privacy@cloutly.com and we will take appropriate steps.

12. Complaints

If you have a concern about how we have handled your personal information, contact us at privacy@cloutly.com with the details. We will acknowledge your complaint promptly, investigate, and respond within 30 days. If you are not satisfied with our response, you can complain to the OAIC at www.oaic.gov.au or 1300 363 992. Individuals in other jurisdictions may also have the right to complain to their local privacy or data-protection regulator (see sections 13 and 14).

13. Individuals in the EU/UK (GDPR)

Where the GDPR or UK GDPR applies to our handling of your personal data: for reviews, feedback, messages, contact data, staff data and integration data processed on a Customer’s behalf we generally act as a processor for that Customer (the controller); and for account, billing, website and marketing data we act as a controller. Our legal bases include performance of a contract, legitimate interests (operating, securing and improving the Service), consent (for example, certain marketing and non-essential cookies), and legal obligation.

Subject to the conditions in the law, you may have rights to access, rectify, erase, restrict or port your personal data, to object to processing, and to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact privacy@cloutly.com; where your request concerns data we process for a Customer, we will refer it to that Customer and assist. International transfers of EU/UK personal data are protected by appropriate safeguards such as the European Commission’s standard contractual clauses (and the UK addendum) where required.

14. US state privacy rights (California and other states)

This section applies to residents of US states with comprehensive privacy laws (including California under the CCPA, as amended by the CPRA, and states such as Virginia, Colorado, Connecticut, Texas and others with analogous laws). It applies in addition to the rest of this policy.

Our role. For reviews, feedback, messages, contact data, staff data and integration data processed on a Customer’s behalf, we act as a service provider / processor that handles personal information only on the documented instructions of the Customer (the business / controller) and not for our own independent purposes. For account, billing, website and marketing data, we act as a business / controller. Paddle, our merchant of record, is an independent business / controller for the payment data it collects.

No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioural (targeted) advertising. We have not done so in the preceding 12 months.

Categories and notice at collection. The categories of personal information we collect, our sources, the purposes of use, and the categories of recipients are described in sections 2, 3 and 5 above. This policy serves as our notice at collection.

Sensitive information. We ask that sensitive personal information not be submitted through the platform unless necessary. Where review content happens to contain sensitive information, we use it only to organise and surface the Customer’s own feedback, and we do not use it to infer characteristics or for any purpose that would give rise to a right to limit its use.

Your rights. Subject to identity verification and the exceptions in applicable law, you may have the right to know and access the personal information we hold about you; delete it; correct it; opt out of any sale or sharing and of certain profiling (we do not sell or share); and not receive discriminatory or retaliatory treatment for exercising these rights.

How to exercise. Contact privacy@cloutly.com. We will verify your request and respond within the timeframe required by law (generally 45 days, extendable once). You may use an authorised agent with proof of authority. If you are a review recipient, reviewer, guest or a Customer’s staff member, the Customer (business) directs how that data is used, and we will refer your request to it and assist. If we deny your request and your state provides a right of appeal, you may appeal by replying to our decision; if you remain unsatisfied, you may contact your state attorney general.

15. Cookies

We use cookies and similar technologies on our websites, application, mobile app and hosted pages. For details of the cookies and analytics tools we use, their purposes, and how to control them, see our Cookie Policy.

16. Changes to this policy

We may update this policy from time to time. The current version will always be available at cloutly.com, with the “last updated” date shown above. For material changes, we will take reasonable steps to notify you, such as by email or in-app notice.


Privacy Officer · Cloutly Co Pty Ltd (ACN 637 155 045)
WOTSO Workspace, Level 2, 194 Varsity Parade, Varsity Lakes QLD 4227, Australia
Email: privacy@cloutly.com · Phone: +61 1800 571 975 · Web: cloutly.com