Part A - Privacy
1. Who we are
Sales Intellect is a customer relationship management system built and operated by Intellecta Pty Ltd (ABN 42 968 426 645), an Australian company. In this document "we", "us" and "our" mean Intellecta Pty Ltd, and "the platform" means the Sales Intellect service at salesintellect.com.au together with its forms, booking pages, tracking script, API and email sending.
"Your organisation" means the business, club, branch or other entity that holds an account with us. "You" means whoever is reading this: a person using the platform on behalf of an organisation, or a member of the public whose details an organisation has recorded in it.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. So, in most cases, is your organisation, and the two sets of obligations are not the same. Section 2 explains which is which.
2. The two kinds of information here
This is the most important section on the page, and nearly every other question about privacy on this platform is answered by deciding which of the two it concerns.
Customer data is what an organisation collects and records for its own purposes: its contacts, their email addresses and phone numbers, form answers, notes, deals, files and history. It belongs to that organisation. We hold it on the organisation's behalf and act on its instructions. We do not own it, sell it, rent it, mine it, use it to train artificial intelligence, or use it to market anything to anybody.
Account data is what we collect in order to run the platform: who signed in and when, which organisation they belong to, support conversations, how much the account has used, billing details, and the ordinary technical records a hosted service produces. This is ours, we decide what to do with it, and this policy is the statement of what we do.
The practical consequences are worth stating plainly:
- An organisation decides what it collects. Which fields exist, what a form asks, whether its website is tracked, how long records are kept and who on its team can see them are all settings inside its own account. We do not set them and cannot answer for them.
- Each organisation needs its own privacy policy. If you collect personal information from the public through a Sales Intellect form, booking page or tracking script, you are the entity that has collected it, and your own privacy notice has to cover it. This page covers our handling, not yours.
- If you are a member of the public, ask the organisation first. If a business holds your details in Sales Intellect and you want to see them, correct them or have them deleted, the request goes to that business. They control the record, and we will direct you to them. See section 11.
- One organisation cannot see another's data. Every record on the platform is scoped to the organisation that owns it, and that scoping is enforced on every read and every write. Sharing an email sending domain with another organisation does not share contacts, campaigns, lists or statistics with it.
- We look at customer data only when we need to. That means to operate, maintain or repair the platform, to investigate a fault or suspected misuse, when your organisation asks us for support, or where the law requires it. Access by our staff is restricted and controlled.
3. What your organisation collects
Depending on the features it uses, an organisation may record any of the following in its account. The list is what the platform is capable of holding, not a statement that every organisation holds all of it.
- Contacts and companies. Names, email addresses, phone numbers, postal addresses, business names, and any custom fields the organisation has created. Field definitions are the organisation's own, so the platform cannot limit what is recorded in them.
- Form submissions. Every answer given on a hosted or embedded form, together with any files uploaded with it. Files are stored outside the public web root and are served only through an authenticated route.
- Sales activity. Opportunities and their values, expected close dates, notes, revisions showing what changed and who changed it, sales process status, contact attempts and follow-up dates.
- Tags, lists and segments, including the history of when a contact was added to or removed from a list and why.
- Email activity. Campaigns and messages sent to contacts, whether they were delivered, bounced or complained, whether they were opened, which links were clicked, unsubscribe records and the trail behind them.
- Website behaviour, where the organisation has installed the tracking script on its own website. See section 5.
- Calendar bookings made through a public booking page: the booker's name, email address, chosen time and anything they wrote in the booking form.
- Audit records. Changes to field values, and a general activity history per contact, so the organisation can see how a record reached its current state.
All of this is customer data as defined in section 2. The organisation chooses to collect it, chooses why, and is responsible for having a lawful basis to do so.
4. What we collect to run the service
Separately from anything an organisation records about its own contacts, we collect the following in order to provide, secure, support and bill for the platform.
- Account and user details. The organisation's name and contact details, and for each person using it their name, email address, role and a securely hashed password. A person may belong to more than one organisation with a single sign-in.
- Sign-in records. Every sign-in attempt, successful or not, with the date and time, the IP address it came from and the browser's user agent string, plus sign outs and moves between organisations. This is a security record: it is what lets an account owner see an unexpected sign-in, and it is shown to the organisation's administrators on their own team page.
- Support conversations. Tickets raised from inside the platform and the messages on them, including anything you choose to tell us in one.
- Usage and billing information. Number of user seats, contacts stored, emails sent per month, plan and subscription status, and a record of plan changes. Payment arrangements are handled directly with us; we do not store card numbers on the platform.
- Email delivery records. For each message sent through the platform, the recipient address, subject, timestamp and delivery outcome, and a stored copy of the message as it went out. Bounce and complaint notifications from the mail provider are recorded against it. These serve both purposes at once: they are the organisation's record of what it sent, and ours of what the platform sent.
- Technical records. Web server logs, application error logs, queue and job records, and backups. Logs contain IP addresses and requested URLs, and we deliberately strip credentials out of recorded URLs before they are stored.
- Enquiries from our public pages. If you fill in the registration or contact form on salesintellect.com.au, we record what you sent so we can reply. We use our own product to do this, so your enquiry becomes a contact record in Intellecta's own Sales Intellect account.
We use account data to run and secure the platform, to provide support, to bill correctly, to tell you about changes that affect your account, and to meet our legal obligations. We do not sell it, and we do not disclose it to third parties for their marketing.
5. Website tracking and forms
An organisation can install a small script on its own website so that page visits and form submissions there are recorded against contacts in its account. Where that has been done, the organisation is the entity collecting that information, and the notice to visitors is its responsibility, not ours.
Because the script sees whatever a page contains, we filter it deliberately rather than trusting it. The following are never stored, and are removed both in the browser before anything is sent and again on our servers before anything is written:
- Password fields, of any name, on any form.
- Payment card details. These are caught by field name and also by value, so a number that passes a card checksum and matches a real card issuer is discarded whatever the field was called, along with expiry dates and security codes.
- Session tokens, API keys, one-time codes and similar secrets, whether they appear in a form field or in the address of the page.
- Credentials that form part of a web address - password reset links, invitation links, unsubscribe keys and the like. The address is kept, the secret inside it is replaced.
Ordinary campaign parameters, such as the standard utm_ tags and
advertising click identifiers, are kept, because they are the reason the feature
exists.
A public form matches the person filling it in against an existing contact by email address. Because a typed email address is not proof of identity, a submission that matches an existing contact fills in only the details that were previously blank; it cannot overwrite what is already recorded and does not attach the visitor's browsing history to that contact, unless the visitor arrived through a signed link that identified them.
If your organisation has enabled a captcha on its forms, the visitor's browser also contacts the captcha provider it has chosen - Google reCAPTCHA or Cloudflare Turnstile - and that provider's own privacy terms apply to that interaction.
7. Where information is held
The platform runs on servers located in Sydney, Australia, and email is sent through Amazon Web Services in its Sydney region. Backups are held in Australia. Your organisation's data is stored in Australia in the ordinary course of operating the service.
Some of the suppliers we use to do this are companies incorporated overseas operating Australian facilities. Support and administration of those services can, in principle, involve access from outside Australia by the supplier. We choose Australian regions precisely to keep the data here, but we would rather say this plainly than imply that no overseas entity is involved anywhere in the chain.
8. Who else handles it
We disclose information to the following categories of third party, and only as needed for them to do their part:
- Hosting. Our servers are provided by a commercial hosting company in its Sydney facility.
- Email delivery. Outbound email is relayed through our own mail server and then through Amazon Simple Email Service in the Sydney region, which handles delivery, bounces and complaint reports.
- Captcha providers, where an organisation has enabled one on its forms.
- Calendar providers, where a person has connected a calendar. See Part B.
- Analytics on our public marketing pages, as described in section 6.
- Professional advisers, and law enforcement or regulators, where we are required by law to disclose information or where it is reasonably necessary to protect the platform or somebody's safety.
We do not sell personal information. We do not disclose it to anybody for their own marketing. If we were ever to be acquired, or to merge with or sell the business to another party, information held on the platform would form part of that transaction, and we would tell affected organisations before it took effect.
An organisation may itself connect the platform to other services, for example through the API, a webhook or an integration it configures. Where it does, it is sending its own data to a party of its choosing, and this policy does not govern what that party does with it.
9. How long we keep it
Customer data is kept for as long as the organisation keeps it. Deleting a contact deletes its record, its field history and its files. An organisation can ask us to clear its data entirely; for safety that is deliberately not a button in the browser, and is carried out by us on the server after the request is confirmed by a one-time code sent by email.
Records we keep to run the platform have their own retention rules, which are set platform-wide and applied by a nightly job:
- Field change history: 24 months by default.
- Sign-in records: 12 months by default.
- Stored copies of sent email: 24 months by default.
- Form abuse and rate-limit records: 90 days.
- Backups: a rolling window of roughly two weeks, after which older backups are removed. Deleted data can survive in a backup until that window passes.
Unsubscribe records are kept indefinitely and are never deleted, including when the contact they relate to is deleted. This is deliberate: if we forgot that somebody had unsubscribed, a later import would start emailing them again. A removal from an organisation's unsubscribe list is recorded as a change of state, not as an erasure.
After an account is closed we keep what we need to for our own legal, accounting and dispute-resolution obligations, and no longer.
10. Security
We take reasonable steps to protect information from misuse, loss and unauthorised access. In practice that includes encrypted connections for everything served from the platform, passwords stored only as salted hashes, every database read and write scoped to a single organisation, roles that limit what each person on a team can see and do, an administrative mode for our own staff that is restricted to specific approved network addresses and is not reachable from the public internet at large, credentials for connected calendars stored encrypted with a separate key, rate limiting on public forms and sign-in attempts, and nightly backups.
No system is perfectly secure, and we do not claim otherwise. Your side of this matters too: choose strong, unique passwords, do not share accounts between people, remove team members who have left, and treat API tokens as the credentials they are.
11. Access, correction and complaints
If you use the platform for your organisation
Most of what you want is in the product: your profile, your team's accounts, your organisation's contacts and their history. For anything else, or to ask what account data we hold about you, email support@salesintellect.com.au.
If an organisation holds your details in its account
Contact that organisation. It decided to collect your information, it controls the record and only it can change or delete it. If you are not sure who to ask, or they will not respond, write to us and we will identify the organisation for you where we properly can, and pass the request on. We will not alter or delete another organisation's records on a third party's instruction, because we cannot verify that instruction and the record is not ours to change.
Unsubscribing
Every marketing email sent through the platform carries an unsubscribe link, and where the sender has not included one we add it automatically before the message leaves. Marketing messages also carry the one-click unsubscribe headers modern mail clients use. Unsubscribing applies to the organisation that sent the email; it does not unsubscribe you from other organisations that happen to use the same platform.
Complaints
If you think we have mishandled personal information, email support@salesintellect.com.au with the details and we will investigate and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. Data breaches
We maintain a process for responding to suspected data breaches. If a breach occurs that is likely to result in serious harm, we will notify the affected organisations and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we will tell the organisation what we know, when we know it, including where the facts are still incomplete.
Where the breach concerns an organisation's own contacts, that organisation may have its own notification obligations to those individuals. We will give it what it needs to meet them.
Part B - Calendar connections
13. Connecting a calendar
A person using Sales Intellect can connect their work mailbox calendar so that bookings made through the platform appear in it, and events in it are visible as busy time when somebody is choosing a booking slot. The connection belongs to the person, not to the organisation: one live connection per person, and it follows them across any organisations they belong to.
Today this is available for CalDAV mailboxes, including Zimbra. Connectors for Google Calendar, Microsoft 365 and Exchange are being built, and section 14 sets out the terms that will apply to the Google one when it is available.
What a connection gives us access to
- Read: the title, time, location, description and organiser of events in the one calendar you select, within a limited window of time around today. We read that calendar to know when you are busy and to notice changes you made in your mailbox to a booking that came from us.
- Write: events that the platform itself creates, updates or cancels, which are the bookings made through your booking page. We write the meeting time, title, location, and the meeting link and booker's details in the description.
What we do not do
- We do not modify or delete events we did not create. Events that already existed in your calendar are read-only to us and appear in the platform as busy time.
- We do not invite anybody from your calendar. Events the platform files in your mailbox carry no attendee list.
- We do not use the contents of your calendar for advertising, profiling, analytics, or to train artificial intelligence or machine learning models.
- We do not share your calendar contents with other organisations on the platform, or with any third party.
- We do not read mail. A mailbox calendar connection is a calendar connection; it gives us no access to your email.
Credentials and disconnecting
Credentials for a connection are stored encrypted, using an encryption key kept separately from the rest of the platform's configuration. You can disconnect at any time from Calendar Settings in your account, and your organisation's administrators can disconnect one on your behalf. Disconnecting stops all reading and writing immediately and discards the stored credentials. Events already filed in your calendar stay where they are; they are yours.
14. Google Calendar and Google user data
This section applies when you connect a Google account to Sales Intellect. It is in addition to section 13, and where the two differ on Google data, this one governs.
What we ask for and why
We ask for access to your Google Calendar so that the platform can do two things, and only these two: show your existing appointments as busy time when somebody is picking a booking slot with you, and keep the bookings made through Sales Intellect in step with your calendar in both directions. We request the narrowest scope that allows this, and we ask for it at the moment you choose to connect, not before.
We also receive your Google account's email address and basic profile information as part of signing in, which we use to identify the connection and show you which account is connected.
Limited Use. Sales Intellect's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, that commitment means all of the following about data we obtain from Google APIs:
- We use it only to provide and improve the calendar features described above, which are the features you connected the account for.
- We do not use it for advertising of any kind, including personalised, retargeted or interest-based advertising.
- We do not sell it, and we do not transfer it to others, except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to you.
- We do not allow humans to read it, unless you have given us specific permission, it is necessary for security purposes such as investigating abuse, it is necessary to comply with applicable law, or the data has been aggregated and anonymised.
- We do not use it to develop, improve or train generalised artificial intelligence or machine learning models.
Storage and retention of Google data
We store the access and refresh tokens that keep the connection alive, encrypted; the identifier and name of the single calendar you chose; and, for events relevant to bookings, the minimum detail needed to show busy time and to reconcile a booking. We do not take a copy of your whole calendar.
When you disconnect, the stored tokens and the cached calendar detail are deleted, and the connection stops at once.
Revoking access
You can disconnect from Calendar Settings inside Sales Intellect. You can also revoke our access directly from your Google account at myaccount.google.com/permissions, which takes effect immediately whatever the platform shows.
Part C - Terms of use
15. The agreement
These terms are an agreement between Intellecta Pty Ltd and the organisation holding the account. By registering for, accessing or using Sales Intellect, your organisation accepts them, and the person accepting them confirms they are authorised to do so on the organisation's behalf.
Where we have signed a separate written agreement or order form with your organisation and it conflicts with these terms, that agreement prevails to the extent of the conflict.
Part A of this page forms part of these terms. These terms are effective from 12 September 2026.
16. Accounts and your team
Your organisation is responsible for its account and for everything done through it, including by its team members and by anything connected to it through the API.
- Accounts are for named people, not shared logins. Each person gets their own, with a role that determines what they can see and do.
- An account must always have at least one active owner. The platform will refuse any change that would leave it without one.
- Keep sign-in details confidential, and tell us promptly if you believe an account or an API token has been compromised.
- Remove people who leave. Signing out ends that person's sessions everywhere, on every device and in every organisation they belong to, but only deactivating the account removes their access.
- You must be at least 18 and using the platform for a business, club or other organisational purpose. Sales Intellect is not offered for personal or household use.
17. Acceptable use
You must not use the platform to:
- break any law, or infringe anybody's rights;
- send unsolicited commercial messages, or messages that mislead about who sent them or how to stop them;
- upload or send malware, or content that is unlawful, defamatory, harassing or obscene;
- attempt to reach data belonging to another organisation, probe or test the security of the platform without our written permission, or interfere with its operation;
- resell, white-label or provide the platform as a service to others without our written agreement;
- place load on the platform that is unreasonable or disproportionate, including through the API, or work around a rate limit, sending limit or plan allowance;
- reverse engineer, copy or create a competing product from the platform, except to the extent that restriction is not permitted by law.
18. Your obligations for contact data
This section is the counterpart of section 2. The information your organisation puts into Sales Intellect is yours, which means the responsibility for it is also yours. You warrant that:
- you have the right to collect, hold and use the personal information you record in the platform, and to have us hold it on your behalf;
- you have given the people concerned whatever privacy notice the law requires, and you maintain your own privacy policy covering it;
- you have consent, or another lawful basis, to send the marketing messages you send, as required by the Spam Act 2003 (Cth), and you honour unsubscribes promptly;
- if you use the tracking script on your website, you disclose that tracking to visitors in your own privacy notice and obtain any consent your jurisdiction requires;
- you only send from email domains and addresses you are entitled to use, and where a domain is shared with other organisations, only from addresses you have verified as yours;
- you comply with the laws applying to your contacts, including where they are outside Australia.
You indemnify us against claims arising from a breach of this section, other than to the extent they arise from our own breach or negligence.
The platform has safeguards, but they are not a substitute for your compliance. Unsubscribed contacts are excluded from campaigns automatically, and adding one back requires a senior team member to confirm it explicitly and is recorded against the campaign. That record exists so that if such a message is ever questioned, it is clear who authorised it.
19. Sending email
Email sent through the platform goes out through our mail infrastructure and shares its reputation with other organisations, so we manage it actively:
- Sending is rate limited. A message that exceeds the rate is delayed and sent later, not discarded.
- Campaigns can be spread over hours or days and limited to chosen days of the week. A delay in sending is normal and not a fault.
- Every marketing message carries an unsubscribe link. If your content does not include one, we add it before the message leaves. You must not remove, disable or misdirect it.
- Bounces and complaints are recorded, and we may pause or restrict sending for an account whose rates threaten delivery for everybody else. We will tell you if we do.
- To send from your own domain you must complete domain verification, which requires DNS records you control. Where several organisations share one domain, only the organisation that completed the verification may send from any address at it; others send only from addresses they have separately proved.
20. Plans, seats and allowances
Your plan sets what the account may hold and do: the number of user seats, contacts, forms, workflows and the monthly email allowance. Allowances are calculated per calendar month in your organisation's timezone.
- Seats are a set number, not a count of who happens to be active. An invitation reserves a seat.
- Where a plan prices additional email, sending continues past the allowance and the excess is charged. Where it does not, sending pauses until the next month; campaigns wait rather than fail, and nothing is lost.
- Public forms and website tracking keep working past an allowance. New contacts they would create are held rather than refused, so you do not lose an enquiry because of a limit.
- Moving to a smaller plan can leave you over its limits. Where that happens the platform pauses the excess - the newest workflows and forms, keeping the oldest active - tells your owners what was paused, and shows a notice for 30 days. Nothing is deleted by a plan change.
- Fees, payment terms and any trial arrangements are as agreed with us. We may change prices with at least 30 days notice before they take effect for your organisation.
21. Availability and support
We work to keep the platform available and to respond to support requests promptly, but we do not offer a guaranteed uptime figure unless we have agreed one with your organisation in writing. The platform can be unavailable for maintenance, and we try to keep planned maintenance short and outside business hours.
Support is provided through the help panel inside the platform, by email and by phone during Australian business hours. Some functions run in the background or on a schedule and are not instantaneous by design.
22. Your data, export and leaving
Your data stays yours. We claim no ownership of it and acquire no right to use it beyond what is needed to run the platform for you and what this page describes.
You can export your contacts and related records to a spreadsheet at any time from inside the platform, and the API can read them programmatically. Do this before you close an account.
When an account is closed, we will keep its data for a reasonable period so it can be retrieved if the closure was a mistake, and then delete it, subject to what section 9 says about backups and about records we must keep. If you want your data cleared while the account remains open, ask us and we will do it after confirming the request.
23. Intellectual property
The platform, its software, design, documentation and the Sales Intellect and Intellecta names and logos are ours or our licensors'. Your organisation is granted a non-exclusive, non-transferable right to use the platform for its own business purposes while its account is active and its fees are paid.
Content you create in the platform - your fields, forms, workflows, templates and copy - remains yours. If you send us feedback or a suggestion, we may use it to improve the product without obligation to you.
24. Liability
Nothing in these terms excludes, restricts or modifies any guarantee, right or remedy you have under the Australian Consumer Law or other law that cannot lawfully be excluded. Where our liability under that law can be limited, it is limited, at our option, to supplying the service again or paying the cost of having it supplied again.
Subject to that, to the extent permitted by law: the platform is provided as it is; we are not liable for indirect or consequential loss, loss of profit, loss of business, or loss of data or goodwill; and our total liability to your organisation for all claims in any 12 month period is limited to the fees paid by it to us in that period.
We are not responsible for the deliverability decisions of third-party mail systems, for content your organisation sends, or for services you connect to the platform yourself.
25. Suspension and termination
Your organisation can stop using the platform and close its account at any time by telling us. Fees already paid are not refundable except where the law requires it.
We may suspend or limit an account immediately where it is being used in breach of section 17 or 18, where it threatens the security or delivery reputation of the platform, or where fees are unpaid after notice. We will tell you why, and where the problem is fixable we will say what would resolve it. We may terminate for a material breach that is not remedied within 14 days of notice.
We may also discontinue the service as a whole on at least 90 days notice, in which case we will refund fees paid for the period after it ends and give you time to export your data.
26. Changes
We may update this page as the platform changes or the law does. The effective date at the top says when the current version took effect. For changes that materially reduce your rights or increase your obligations, we will give at least 30 days notice by email to your account owners or in the platform before they take effect; continuing to use the platform after that date means the new version applies.
Corrections, clarifications and changes describing a new feature take effect when published.
27. Governing law and contact
These terms are governed by the laws of Victoria, Australia. Your organisation and we submit to the non-exclusive jurisdiction of the courts of Victoria and the courts able to hear appeals from them.
If any provision is found unenforceable, it is severed and the rest continues to apply. A failure to enforce a term is not a waiver of it.
Questions about this page, about privacy, or about anything else here:
- Email: support@salesintellect.com.au
- Phone: +613 8899 7868
- Post: Intellecta Pty Ltd, PO Box 468, Williamstown VIC 3016, Australia
Privacy Policy and Terms of Use, version of 12 September 2026. Intellecta Pty Ltd, ABN 42 968 426 645.