Service Assistant Private communication
Private access only. No guest users and no public chat rooms.
Security Centre Australian support
Privacy and personal information

Privacy Notice

This Privacy Notice explains how Service Assistant collects, uses, stores and protects information connected with memberships, accounts, payments and use of the Service Assistant platform.

Applies to visitors, members and organisations Last updated: 18 July 2026
01

About this Privacy Notice

Service Assistant provides subscription-based access to private communication tools, member account features and related services.

This Privacy Notice explains:

  • what personal information may be collected;
  • why that information is collected;
  • how it may be used or disclosed;
  • how account and membership records are protected;
  • how private chat information is handled;
  • how long information may be retained; and
  • how a person may request access, correction or further information.

This notice should be read together with the Service Assistant Terms and Conditions and Refund Policy.

02

Who this notice applies to

This notice applies to information relating to:

  • website visitors;
  • prospective members;
  • monthly and yearly members;
  • organisation and complimentary members;
  • people invited to use a private room;
  • people who contact Service Assistant support;
  • payment contacts; and
  • authorised representatives of organisations purchasing or managing memberships.
03

Names and identity information

Service Assistant recognises that some users may be experiencing domestic violence, coercive control, stalking, harassment or another situation in which revealing their legal identity could place them at risk.

A user may therefore provide an alias, chosen name or false name for their Service Assistant account where this is reasonably necessary to protect their identity or personal safety.

Service Assistant does not require a member to publicly display their legal name to other users.

Using an alias for safety

A supplied account name does not have to be the user’s legal name where an alias or false name is reasonably required to protect that person from harm.

An alias or chosen name must not be used to impersonate another real person, commit fraud, avoid a lawful obligation or engage in unlawful conduct.

A payment provider may separately require accurate billing or identity information to process a payment. Information supplied directly to a payment provider is handled under that provider’s own privacy practices and may not be visible to Service Assistant.

Where an organisation creates or pays for a membership, the member may still use an alias or chosen account name where this is required for safety, provided the membership can be administered without publicly exposing the member’s legal identity.

04

Information we may collect

Depending on how a person uses Service Assistant, we may collect:

  • an alias, chosen name or supplied account name;
  • username;
  • email address;
  • organisation name;
  • account status;
  • membership plan and membership type;
  • membership start and expiry dates;
  • renewal and cancellation information;
  • payment amount, currency and transaction reference;
  • payment status;
  • support enquiries and correspondence;
  • technical and security-event information;
  • browser, device and connection information;
  • login dates and account activity records;
  • consent, acknowledgement and settings selections; and
  • information required to investigate a payment, account or security issue.
Payment card information

Where payments are processed by an external payment provider, Service Assistant may receive transaction confirmations, payment references and payment status information without receiving or retaining the customer’s complete card details.

05

How information is collected

Information may be collected:

  • when a person selects a membership plan;
  • during checkout and payment;
  • when an account is created after successful payment;
  • when an administrator creates a manual membership;
  • when an organisation supplies authorised member details;
  • when a member logs in or manages an account;
  • when a person creates or joins a private room;
  • when a person changes account or security settings;
  • through support and contact forms;
  • from payment providers;
  • from website and server security records; and
  • where required or authorised by law.

Where practical, information will be collected directly from the person concerned.

06

Private chats and conversation content

Service Assistant is designed so that private chat content cannot be viewed, read, recorded or retrieved by Service Assistant staff, administrators or support personnel.

Staff cannot:

  • open a private conversation through the administrator console;
  • decrypt private messages;
  • view the genuine message hidden behind cover text;
  • access or display a user’s Safety Code;
  • access a private room key or decryption details;
  • create a readable transcript of a private conversation;
  • record private chat content;
  • copy private chat content into a staff-accessible record;
  • reconstruct a private conversation from system records; or
  • recover a deleted or expired private conversation.
No staff-accessible conversation record

No readable copy, transcript or staff-accessible record of a private chat is created or retained by Service Assistant.

The administrator console contains only the limited account, membership, payment and technical information required to operate the service. It does not contain private conversations, decrypted messages, Safety Codes, room keys or readable message content.

Technical records may identify that a system event occurred, such as a room being created, terminated or marked as potentially compromised. These records do not contain the private message that caused the event and cannot be used to reconstruct the conversation.

Once private chat information is removed or expires according to the system’s operating rules, Service Assistant staff cannot restore or recover the conversation.

07

Private room information

Service Assistant may process limited technical information required to create, operate and protect a private room, including:

  • a non-readable room identifier;
  • room creation and expiry times;
  • invitation status;
  • whether authorised participants joined the room;
  • whether the room is active, expired or terminated;
  • whether a security or compromise event occurred; and
  • technical information required to prevent unauthorised access.

This technical information does not include a readable record of the private conversation.

Room names, invitation codes, Safety Codes, message content and decryption information must not be displayed in the administrator member console.

08

Safety Code information

Where a user enables the optional Safety Code feature:

  • the user chooses their own code;
  • the feature is disabled by default;
  • the code is protected when stored;
  • the code is not displayed to other room users;
  • the administrator console does not reveal the code;
  • a missing code may trigger a concealed compromise state; and
  • security records identify only that an event occurred and do not record the readable Safety Code or private message.

Users should not provide their Safety Code to Service Assistant support.

09

Important privacy limitations

Although Service Assistant staff cannot view, record or recover private chats, a participant may still photograph, copy, record, screenshot or disclose information visible on their own device.

A person who has access to a user’s phone, computer, browser, email account, keyboard, screen, cloud account or network may also be able to observe activity outside Service Assistant’s control.

Use a trusted device where possible

Users who believe their device or account may be monitored should consider using a trusted device and seeking assistance from an appropriate specialist support service.

Service Assistant cannot prevent another authorised participant from copying or disclosing information after that participant has viewed it.

10

How information may be used

Information may be used to:

  • process a membership purchase;
  • create and administer a member account;
  • verify and record payment status;
  • provide monthly or yearly membership access;
  • provide organisation or complimentary memberships;
  • manage renewals, cancellations and expiry;
  • authenticate users;
  • operate private rooms and invitation links;
  • apply privacy and security settings;
  • respond to support enquiries;
  • investigate suspected misuse or unauthorised access;
  • protect users, accounts and the platform;
  • maintain transaction and administrative records;
  • comply with legal obligations; and
  • improve the reliability and security of the service.

Private chat content is not used for advertising, profiling, marketing, staff review or customer-support analysis because staff cannot access that content.

11

Disclosure of information

Limited account, payment or technical information may be disclosed where reasonably required to:

  • process payments;
  • provide website hosting and technical infrastructure;
  • deliver account or service emails;
  • provide professional, legal or security assistance;
  • investigate fraud, misuse or unauthorised access;
  • comply with a lawful court order or legal requirement;
  • protect the safety or legal rights of a person; or
  • transfer the service as part of a lawful business sale, restructure or change of ownership.

Service providers should receive only the information reasonably required to perform their functions.

Service Assistant cannot disclose readable private chat content because Service Assistant staff cannot access or recover it.

12

Overseas service providers

Some hosting, email, payment, security or technical service providers may operate outside Australia or store limited account or technical information in overseas locations.

Where information may be disclosed overseas, Service Assistant will take reasonable steps required by applicable privacy law to address the handling of that information.

Private chat content should not be made available to third-party support or administrative providers in readable form.

13

Cookies and technical information

The website may use cookies, session identifiers and similar technologies to:

  • keep users signed in;
  • maintain secure sessions;
  • remember necessary service settings;
  • prevent unauthorised requests;
  • route users to the correct member pages;
  • identify technical errors; and
  • protect the website against misuse.

Disabling required cookies may prevent login, checkout, private rooms or other member functions from operating correctly.

14

Account and membership records

Service Assistant may retain records including:

  • alias, chosen name or supplied account name;
  • email address;
  • membership type and plan;
  • subscription start and expiry dates;
  • payment and transaction references;
  • renewal and cancellation history;
  • complimentary or organisation membership details;
  • administrator notes;
  • account status; and
  • support and security-event history.

These records help Service Assistant confirm membership access, investigate payment issues and provide account support.

These records do not include readable private chat content.

15

Data retention

Account, payment and membership information may be retained for as long as reasonably required to:

  • provide the service;
  • maintain the person’s account;
  • administer an active membership;
  • meet taxation, accounting and transaction obligations;
  • resolve disputes;
  • investigate security incidents;
  • enforce agreements; and
  • comply with legal requirements.

Information that is no longer reasonably required should be destroyed, deleted or de-identified where appropriate and where lawful to do so.

Private chat data is temporary and is not retained as a readable staff-accessible conversation record.

Once private chat data expires or is removed, it cannot be recovered by Service Assistant staff.

16

Security of information

Service Assistant may use administrative, technical and physical safeguards designed to protect account, membership and technical information against:

  • loss;
  • misuse;
  • interference;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Measures may include account controls, restricted administrator access, encryption, access tokens, security logging, secure hosting practices and software updates.

Despite these measures, no online service, device, transmission or storage system can be guaranteed completely secure.

17

Data breaches

If Service Assistant becomes aware of suspected unauthorised access, disclosure or loss of account, membership or technical information, the incident may be assessed and contained.

Where required by applicable law, affected individuals and the Office of the Australian Information Commissioner may be notified.

A notice may explain:

  • what occurred;
  • what information was involved;
  • the possible consequences;
  • steps already taken; and
  • steps the affected person should consider taking.

Because Service Assistant staff cannot access readable private chats, a breach assessment should not assume that staff-held records contain readable conversation content.

18

Access to personal information

A person may request access to account, membership, payment or support information Service Assistant holds about them.

Before providing access, Service Assistant may need to verify the requester’s identity.

Access may be refused or limited where permitted or required by law, including where providing access would unreasonably affect another person’s privacy or reveal protected security information.

Service Assistant cannot provide a staff-generated copy or transcript of a private conversation because no readable staff-accessible record of that conversation is created.

19

Correction of information

A member may request correction of account information they believe is inaccurate, incomplete, out of date, irrelevant or misleading.

Members may be able to update some account information through the My Account area. Other changes may require assistance from Service Assistant support.

A user who intentionally uses an alias for personal safety is not required to replace it with a legal name merely because the alias differs from their legal identity.

20

Account deletion requests

A person may ask Service Assistant to close or delete their account.

Some information may need to be retained after account closure, including:

  • financial transaction records;
  • tax and accounting records;
  • records of membership purchases;
  • fraud or security-event records;
  • legal dispute information; and
  • information required to meet another lawful obligation.

Account closure does not necessarily result in immediate deletion of every administrative or financial record.

Private chat content cannot be supplied or restored as part of an account deletion request because staff cannot access or recover that content.

21

Organisation memberships

An organisation may provide a person’s chosen name, alias, email address and membership details so Service Assistant can create or administer an organisation membership.

The organisation should ensure it has authority to provide that information.

The organisation does not automatically receive access to the member’s private room content merely because it purchased or arranged the membership.

An organisation must not be given access to readable private chat content, Safety Codes, room keys or decrypted messages.

22

Children and young people

Service Assistant is not intended to replace emergency, legal, medical, counselling, child-protection or domestic-violence services.

Where the service is made available to a person under 18, the account and membership arrangement must comply with applicable law and any age or consent requirements imposed by Service Assistant.

23

Privacy complaints

A person who has a concern about the handling of their information should contact Service Assistant and provide:

  • their supplied account name or alias;
  • their account email, where relevant;
  • a description of the concern;
  • relevant dates;
  • any relevant transaction or support reference; and
  • the outcome they are seeking.
Do not include private access information

Do not include passwords, room codes, invitation codes, Safety Codes, encryption keys or decrypted private messages in a privacy complaint.

24

Changes to this Privacy Notice

Service Assistant may update this Privacy Notice when the platform, membership model, service providers, security features or legal obligations change.

The current version will be published on this page with its updated date.

Privacy enquiries

Have a question about your information?

Contact Service Assistant without including passwords, private room codes, Safety Codes or private conversation content.

Submit a privacy enquiry