Privacy

Privacy

Privacy Policy

Last updated: 9 May 2026 · Effective: 9 May 2026

This Privacy Policy explains how Domato AI Pty Ltd (ABN 94 695 794 346) ("we", "us", "our") handles personal information collected through the Public IQ website and related services at publiciq.domato.ai (the "Service").

We are bound by the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We also observe the obligations imposed by the Spam Act 2003 (Cth) for any electronic marketing communications we send.

1. Anonymous-by-default design

Public IQ is built so that the core experience — searching suburbs, viewing profiles, comparing, exploring, and saving a watchlist locally — does not require you to identify yourself. You can use the Service without signing in.

Where you do choose to identify yourself (creating an account, submitting the contact form, joining the newsletter, sending us a request, or asking us to email you a report), we collect only what is reasonably necessary to provide that function.

2. The kinds of personal information we collect

We may collect the following categories of personal information:

  • Account information — email address, display name, password hash (or Google sub-identifier), and verification status — when you sign up using email + password or Google sign-in.
  • Workspace information — your saved watchlist, recently-viewed suburbs, private suburb notes, saved Explore filters, and indicative preferences (deposit, income, intent, role) — when you choose to save these to your account.
  • Lead information — your email and any context you submit through "Email me this report", the newsletter subscribe widget, the capacity-calculator email-scenario form, the buyers-agent / mortgage-broker professional contact form, or the contact form.
  • Communication content — the contents of any message you send us via the contact form or by email.
  • Technical information — IP address, user-agent string, approximate location (city / state, derived from IP), referring URL, page visited, and timestamps. Collected automatically by our analytics + log infrastructure.

We do not knowingly collect or store sensitive information (as defined by APP 3.3 — health, racial origin, political views, religious beliefs, sexual orientation, criminal record, biometrics or genetic data) and you should not submit any such information to us.

3. How we collect personal information

  • Directly from you — when you fill in a form, sign up for an account, send us an email, or save data to your account.
  • Automatically — when you interact with the Service, we (and our analytics provider) record technical information via cookies, log files, and the analytics beacon.
  • From Google — if you use Sign in with Google, Google provides us with your verified email address, display name and profile picture URL. We do not receive your Google password.

4. Why we collect it (purposes of use and disclosure)

  • To operate, maintain and improve the Service.
  • To deliver the artefacts you ask for — emailed reports, scenario summaries, watchlist sync, exported CSVs.
  • To authenticate you, secure your account, and detect / prevent fraud or abuse.
  • To send you the weekly suburb-pulse newsletter only if you have ticked the consent box.
  • To respond to enquiries, fulfil partnership requests, and provide customer support.
  • To produce de-identified aggregate analytics about how the Service is used.
  • To comply with legal obligations or enforce our Terms.

5. Disclosure to third parties

We disclose personal information to a small set of carefully-chosen service providers:

  • Microsoft Azure (cloud hosting and storage, Australia East region) — application servers, databases, file storage.
  • Email delivery providers — to deliver transactional emails (verification codes, requested reports, reset links) and the newsletter.
  • Google — for Sign in with Google, and for analytics if you have not opted out of analytics cookies.
  • brokeriq — when you click a brokeriq referral link from Public IQ, we pass through limited context (suburb name, indicative deposit + income from your saved profile, watchlist size). brokeriq is operated by Domato AI Pty Ltd under its own privacy policy.

We do not sell personal information. We do not share personal information with third parties for their independent marketing purposes.

6. Cross-border disclosure

Public IQ is hosted in Australia. However, some of our service providers process personal information outside Australia:

  • Email delivery and analytics providers may process data in the United States and Europe.
  • Google's authentication servers process sign-in metadata in the United States.

Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs (for example, by relying on contractual terms or the recipient's own equivalent privacy framework).

7. Cookies and similar technologies

  • Essential cookies — to keep you signed in (auth tokens stored in localStorage) and to remember your watchlist, recents, Explore filters and theme preference. These cannot be disabled without breaking the Service.
  • Analytics cookies — to understand aggregate usage. You can opt out by blocking third-party cookies or by using your browser's "Do Not Track" setting; we honour DNT where technically feasible.

We do not use cookies for cross-site advertising, retargeting, or behavioural ad networks.

8. Marketing communications (Spam Act 2003)

We will only send you the weekly suburb-pulse newsletter or other marketing emails if you have given us express consent by ticking the consent box on the newsletter form. Every marketing email contains a working unsubscribe link and clearly identifies us as the sender. Transactional emails (e.g. requested suburb reports, account verification codes) are not subject to the unsubscribe requirement but you can stop requesting them at any time.

9. How we secure your information

  • Passwords are stored as bcrypt hashes only — we never store plaintext passwords.
  • All data in transit uses HTTPS with modern TLS.
  • Database backups are encrypted at rest using Microsoft Azure managed keys.
  • Access to production data is limited to authorised personnel and logged.

No internet transmission or storage method is 100% secure. While we take reasonable steps in line with APP 11, we cannot guarantee absolute security.

10. Retention

  • Account + workspace data — retained until you delete your account, after which it's removed within 30 days.
  • Lead submissions — retained for up to 24 months for support and follow-up purposes.
  • Server logs — rolled / purged within 90 days.
  • De-identified aggregate analytics — retained indefinitely.

11. Your rights

Under the Australian Privacy Principles, you have the right to:

  • Access — request a copy of any personal information we hold about you (APP 12).
  • Correct — request that we correct any inaccurate, out-of-date or incomplete information (APP 13).
  • Delete your account — at any time. Email us at support@domato.ai from the email address on the account.
  • Withdraw marketing consent — by clicking unsubscribe in any marketing email or emailing us.
  • Complain — see "Complaints" below.

12. Children

The Service is not intended for use by anyone under the age of 16. If you believe a child has submitted personal information to us, please contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. The version date at the top of this page reflects the latest change. Material changes will be highlighted on the home page for at least 30 days, and we will email account-holders if we believe a change materially affects them.

14. Complaints

If you believe we have breached the APPs, please first contact us at support@domato.ai withPrivacy complaint in the subject. We aim to acknowledge complaints within five business days and resolve them within 30 days.

If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au/privacy/privacy-complaints or by phone on 1300 363 992.

15. How to contact us

Privacy Officer
Domato AI Pty Ltd (ABN 94 695 794 346)
Email: support@domato.ai
Or use the contact form.