PolicySense
Privacy policy
Effective 6 August 2026 · Version 2026-08-06
This policy explains how Harmonic Futures Pty Ltd (ACN 688 599 537; ABN 88 688 599 537), operating PolicySense as part of ZAK from 33 Elizabeth Street, Mundubbera Queensland 4626, Australia, handles personal information and service data. It applies alongside any organisation agreement and does not assume every organisation or activity is governed by the same privacy law.
1. Information we handle
- Account information: name, email address, sign-in identifiers and account security events.
- Organisation information: membership, role, permissions and organisation branding.
- Policy work: documents, drafts, comments, questions, explanations, approvals, publication actions, source references and records needed to explain controlled actions.
- Service information: page, device and diagnostic information, timestamps, feature use and errors.
- Communications: support requests, product feedback and delivery status for service emails.
- Connections: identifiers and permissions needed for an optional connected service. We do not ask you to give us your third-party password.
2. How we use information
We use information to provide and secure PolicySense, confirm authority, maintain evidence and approval records, deliver requested notices, support users, diagnose problems, improve the service, prevent misuse and meet lawful obligations.
PolicySense does not turn product feedback into a hidden copy of your open document. The feedback form adds the page area, your role and a safe document reference; it does not automatically capture document text, client names, screenshots, tokens, hidden page state or browser storage.
3. Explanations, AI-assisted processing and human decisions
PolicySense may use configured AI or model services to produce explanations, classifications or recommendations requested through the service. These outputs support human review. They do not replace the approved policy or authoritative source, create organisational authority, or automatically decide a person's legal rights, access to a significant service or entitlement.
The provider used can depend on the feature and organisation configuration. We apply the organisation's service settings and disclose relevant provider categories below; an organisation should not submit information that its agreement or policy does not permit an external processor to handle.
4. Your organisation's role
Your organisation controls its PolicySense workspace, user access and policy content. It is normally the first contact for questions about why organisational information is in PolicySense, who may see it, or how long it must be kept. Harmonic Futures Pty Ltd operates the service as ZAK and supports the organisation under the applicable service arrangements.
5. When information is shared
Information may be shared with authorised members of your organisation and with service providers used to host, secure, authenticate, communicate, back up, analyse and support PolicySense. Current provider categories include Supabase for database and authentication services; Netlify and Cloudflare for site, network, security, edge and backup services; Resend for service email; Google when an organisation chooses a Google connection; and configured AI or model-routing providers when a requested feature requires them.
We may also disclose information when required by law, to protect people or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal information or use PolicySense workspace content for third-party advertising.
6. Location, subprocessors and cross-border handling
Harmonic Futures is an Australian company, but PolicySense is not represented as Australian-only hosting. Service providers may process, route, support or store information in Australia, the United States and other countries in which their relevant services operate. The location and legal character of handling can vary by provider, service configuration, support access, connection and backup process.
Current named services include Supabase, Netlify, Cloudflare and Resend; optional connections may include Google; configured AI processing may use providers such as OpenAI, Anthropic, Google or OpenRouter when enabled for the relevant feature. Contact security@zakgov.com for the current provider and location schedule relevant to your organisation before submitting information subject to location restrictions.
7. Retention, deletion and legal holds
Retention depends on the type of record, organisation instructions, service arrangements, security needs and lawful obligations. Account and workspace information is generally kept while the account or organisation relationship is active and for a reasonable period afterwards. Approval, publication and security records may be kept longer to preserve an accountable history, resolve disputes and meet lawful obligations.
Deletion requests are assessed so they do not silently break retained evidence, a legal hold or another person's rights. Encrypted production backups are currently configured for a recovery cycle of up to 35 days before expiry, unless a recovery incident, legal hold or lawful obligation requires a bounded longer retention. When information is no longer needed and no exception applies, we delete or de-identify it where required by applicable law.
8. Security
We use access controls, authentication, tenant boundaries, audit records and diagnostic or security logging where configured to protect information. No system is completely secure. If you believe an account or information may have been exposed, use the security route on our support page promptly and do not include passwords, tokens or sensitive client details in email.
9. Data incidents and notification
We assess suspected data incidents promptly and take reasonable steps to contain harm. Where the Notifiable Data Breaches scheme or another applicable law requires notification of an eligible breach, we will notify affected individuals and the relevant regulator as required. Where an organisation is responsible for the affected information, we will also work with its authorised contact in accordance with the applicable service arrangement and law.
10. Access, correction and privacy questions
You can update basic profile information in your account. For access, correction, deletion or another privacy request, contact your organisation administrator or email support@zakgov.com. We may need to confirm your identity and your relationship to the relevant organisation before acting.
11. Cookies and local storage
PolicySense uses browser storage and similar technologies needed for sign-in, session continuity, security and product preferences. Blocking required storage may stop the service from working correctly.
12. Concerns and complaints
Send a privacy or security concern to security@zakgov.com with a safe summary and a way to contact you, or write to Harmonic Futures Pty Ltd at 33 Elizabeth Street, Mundubbera Queensland 4626, Australia. Do not email passwords, access tokens or client records.
We will acknowledge the concern, identify the responsible organisation or operator, investigate as appropriate and explain the next step. You may also have the right to contact an applicable privacy regulator, including the Office of the Australian Information Commissioner.
13. Changes to this policy
We may update this policy as PolicySense, its providers or relevant practices change. The effective date above shows the latest published version. We will use a reasonable notice method for material changes.