Briefi is built and operated in Sydney by Trimorph Pty Ltd, an Australian company. This page is a one-page desk-check for AU customers and their procurement / privacy officers — what we do for the Australian Privacy Principles, the Notifiable Data Breaches scheme, the Spam Act, Australian Consumer Law, and where the data physically lives. Everything below is reflected in the Privacy Policy, Terms of Service, DPA, and Security pages — this page just makes the AU lens fast.
Who we are, in AU terms
Briefi is operated by Trimorph Pty Ltd, a New South Wales company. We are the APP entity for the personal information we hold on Customer's behalf. ABN to be issued before public launch and published on this page. Registered office: Sydney, NSW. Privacy contact: privacy@briefi.sh.
The Australian Privacy Act 1988 (Cth) applies to our handling of personal information regardless of where Customer or Data Subjects are located, because we are an Australian-incorporated APP entity.
Australian Privacy Principles — how we satisfy each
We map our practices to the 13 Australian Privacy Principles (APPs) issued by the OAIC under Schedule 1 of the Privacy Act:
- APP 1 — Open + transparent management. A clearly expressed Privacy Policy is maintained at /privacy; the sub-processor list at /security is updated whenever a vendor is added or removed.
- APP 2 — Anonymity + pseudonymity. Briefi requires authentication to use the service (we hold sensitive material on your behalf, so attribution matters), but visitors to the marketing site can browse anonymously and the public scheduling pages do not require an account to book.
- APP 3 — Collection of solicited personal information. We collect only what's necessary to operate the service — listed exhaustively in section 02 of the Privacy Policy. No advertising trackers, no shadow profiles. Sensitive information (APP 3.3) is not solicited by Briefi.
- APP 4 — Unsolicited personal information. If a third party sends us personal information we did not solicit (for example, an unsolicited email about you), we either destroy it within a reasonable period or treat it under APP 5 if retention is lawful and necessary.
- APP 5 — Notification of collection. The Privacy Policy is the standing APP 5 notice. Material changes are emailed to every workspace owner at least 30 days before they take effect.
- APP 6 — Use or disclosure. We use Customer Data only to operate the contracted service. We do not sell, rent, or share data with advertising networks. AI providers are configured to not train on customer inputs.
- APP 7 — Direct marketing. Marketing emails (digests, product updates) are opt-in, identified, and include a one-click unsubscribe. Transactional emails (invoices, security alerts) are sent under APP 7.4.
- APP 8 — Cross-border disclosure. See section 5 below. Each overseas recipient is bound by contractual obligations that are no less protective than the APPs.
- APP 9 — Government identifiers. Briefi does not use government-issued identifiers (TFN, Medicare number, etc.) as the primary way to identify any Data Subject.
- APP 10 — Quality. Most fields are editable directly in product. For fields you can't reach, write to privacy@briefi.sh and we'll correct.
- APP 11 — Security. See the Security Measures schedule in the DPA and the public summary at /security. Data we no longer need is destroyed or de-identified.
- APP 12 — Access. Settings → Data & Export ships a single-click JSON + CSV export of all your data. We respond to APP 12 access requests by referring you there; if a record isn't covered, we follow up by email within 30 days.
- APP 13 — Correction. Edit in product where possible; otherwise email privacy@briefi.sh. We respond inside 5 business days and confirm the correction.
Notifiable Data Breaches scheme (Part IIIC)
The NDB scheme requires APP entities to notify affected individuals and the OAIC of "eligible data breaches" — those involving personal information likely to result in serious harm — within 30 days of becoming aware. Briefi's commitments:
- We will internally assess any suspected breach within 72 hours of discovery.
- If the assessment confirms an eligible data breach, we will notify affected individuals and the OAIC as soon as practicable, and in any case within the 30-day statutory window.
- The notification will describe what happened, what information was involved, what steps we are taking, and what affected individuals can do to protect themselves.
- If the breach affects Customer Data Briefi processes on Customer's behalf, we will notify Customer's workspace owner within 48 hours so Customer can run its own NDB obligations as the controller (see DPA section 10).
Data residency + hosting
Customer Data is stored primarily in Australia:
- Supabase Postgres + Storage in the
ap-southeast-2(Sydney) AWS region — primary database, recordings, encrypted attachments. - Vercel edge hosting with Sydney (
syd1) as the primary serverless region for AU traffic; static assets are served from the global edge cache. - Stripe bills via the AU subsidiary (Stripe Payments Australia Pty Ltd) for AU customers.
Some processing necessarily occurs outside Australia (AI providers, telemetry, CRM destinations Customer chooses to push to). The full sub-processor list with region is at /security.
Cross-border disclosure (APP 8 + IRAP-equivalent posture)
Briefi takes reasonable steps to ensure overseas recipients of personal information do not breach the APPs. Each Sub-processor that handles Customer Data is contractually bound by terms no less protective than the APPs (and, for EEA / UK transfers, the EU Standard Contractual Clauses module 2 plus the UK Addendum, automatically incorporated via section 7 of the DPA).
Briefi has not sought IRAP assessment for Australian government workloads; we are not currently positioned for PROTECTED-classified workloads. AU government tenants whose use case requires IRAP can register interest at privacy@briefi.sh and we will discuss timing.
Spam Act 2003 (Cth)
Briefi sends two categories of email on Customer's behalf:
- Outgoing email Customer composes (replies, follow-ups, drafts that Customer sends through Briefi). Customer is the sender for Spam Act purposes — Customer is responsible for express or inferred consent of the recipients, identification of the sender in the email, and a working unsubscribe path.
- Briefi product email (digests, weekly review, security alerts). These are sent under Section 16(2) "designated commercial electronic messages" exception or with Customer's express consent collected at signup. Each marketing email includes one-click unsubscribe; transactional alerts (security, billing) are sent under the consent inferred from the contractual relationship and labelled clearly.
Briefi's outbound mail uses authenticated SPF + DKIM + DMARC (Resend handles the signing); we do not relay mail on behalf of unauthenticated senders.
Australian Consumer Law (ACL)
Where the ACL applies and you are a "consumer" within its meaning, the consumer guarantees in Schedule 2 of the Competition and Consumer Act 2010 (Cth) cannot be excluded. Our Terms of Service do not attempt to exclude them. Where the consumer guarantees apply, our liability is limited to (at our option) re-supply of the service or refund of the fees paid for the affected period (Terms section 15).
Plan pricing on the /pricing page is in Australian dollars and exclusive of GST where applicable; tax invoices are issued by Stripe on Briefi's behalf for every charge.
Telco + e-safety
Briefi is not a carriage service provider and does not hold a telecommunications licence. We do not place outbound calls or send SMS messages on Customer's behalf. Optional notetaker integrations (Fireflies, Fathom, Read.ai, Grain) and CRM destinations may interact with telephony separately under their own licences.
Online safety obligations under the Online Safety Act 2021 (Cth) are not engaged by Briefi's product (we do not host user-generated public content). Public booking pages at briefi.sh/b/<slug> contain only the page configuration Customer publishes and do not allow third-party comment.
Recordings + transcripts
Recording laws differ by state. In NSW, VIC, QLD, WA, SA, TAS, ACT and NT, recording a conversation generally requires the consent of all parties unless an exception applies. Briefi does not start recordings automatically; the meeting host must affirmatively start a recording, and the in-product UI surfaces a prominent recording indicator.
Customer is responsible for obtaining the consent of all participants before starting a recording, captioning a meeting via Deepgram live captions, or routing the meeting through a third-party notetaker. Briefi's role is processor; Customer is the controller and the data discloser to participants.
Recording audio defaults to a 7-day retention window (configurable up to 90 days in Settings → Workspace → "Recording retention"). After the window elapses, the audio blob is deleted; transcripts persist on the meeting record and can be exported at any time.
Industry-specific overlays
Several industries that Briefi supports have additional regulatory layers. We surface them below as a heads-up; Customer remains responsible for compliance with the regimes that apply to their own work.
- Financial advisers + mortgage brokers — Corporations Act 2001 (Cth), AFSL / ACL obligations, Best Interests Duty, ASIC RG 175. Records of advice meetings are commonly retained for 7 years; configure your workspace's sync window to match.
- Healthcare providers (physio, mental health, nutrition) — My Health Records Act 2012, state-specific health records legislation (HRIPA in NSW, HRA in VIC), and AHPRA obligations. Briefi is not designed as a clinical record system and is not certified to ADHA / RACGP standards; clinical content should remain in your practice management software.
- Lawyers — Legal Profession Uniform Law (Australia) and Solicitors' Rules. Privileged material remains privileged when stored in Briefi; we will only respond to lawful subpoenas after notifying Customer (unless prohibited from doing so by court order).
- Real estate agents — Trust account material does not belong in Briefi; keep it in your trust accounting software. Customer information and pipeline status are fine.
OAIC complaints + escalation
If you have a complaint about how Briefi has handled your personal information, write to privacy@briefi.sh. We respond inside 5 business days and aim to resolve within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au or by phone on 1300 363 992. The OAIC will normally require you to have first attempted to resolve the issue with us.
For consumer law disputes, the relevant pathway is the Australian Competition and Consumer Commission (accc.gov.au) or your state fair trading body. For Spam Act issues, the Australian Communications and Media Authority (acma.gov.au) accepts reports.
Reviewing + updating this page
This page reflects our position as of the effective date at the top. We review it whenever we add a sub-processor, change a region, ship a feature with a new privacy footprint, or when AU regulators issue meaningful guidance. Material changes are emailed to every workspace owner at least 30 days before they take effect.