Privacy Policy
Effective from: 10 August 2026. This Privacy Policy explains how Cloudrms Pty Ltd handles personal information in connection with the operation of the shop at cloudrms.org and the modules distributed through it. It is drafted to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) in Schedule 1 to that Act.
Independence and non-affiliation
Cloudrms is an independent third-party shop for third-party modules and extensions and is not affiliated with, sponsored by or endorsed by RMS Cloud Pty Ltd or its parent company. References to RMS Cloud in this policy describe technical interoperation only. All trademarks are the property of their respective owners.
1. Identity of the APP entity
The APP entity responsible for personal information collected on cloudrms.org is Cloudrms Pty Ltd, a proprietary limited company incorporated under the Corporations Act 2001 (Cth), ABN 47 856 234 891, ACN 654 789 123, with its registered office at 42 Pitt Street, Level 8, Sydney NSW 2000, Australia, represented by its sole director James Whitmore. When Cloudrms processes reservation, guest or operational data on behalf of a Customer hotel through a module, it does so under the terms of the Data Processing Agreement referenced at /dpa.
You may contact us at any time: email support@cloudrms.org, telephone +61 2 8756 3421, or by post at the registered office address above.
2. Kinds of personal information we collect (APP 3)
We collect only the personal information reasonably necessary for one or more of the functions listed in section 3, or to which you have expressly consented. The categories are:
- Account and contact information: business email address, first and last name of the authorised representative, hotel legal name, postal address, telephone (optional), ABN (optional).
- Billing information: order history, amounts invoiced, GST applied, tokenised payment reference issued by our payment service provider. We never store full card numbers, expiry dates, CVV codes or bank account numbers of the payment instrument.
- Client Area session data: passwordless magic-link tokens, session identifier, CSRF token, and the timestamp and IP address of each successful sign-in.
- Module usage logs: timestamp and endpoint of API calls made to the RMS Cloud API on your behalf, HTTP status code returned, and error messages. No payload data is stored beyond what is required to reproduce a failed operation for support.
- RMS Cloud API credentials: the API key you provide when activating a module, encrypted at rest using AES-256 and decrypted only in memory at the moment of each API call.
- Technical data: IP address, user-agent string, browser type and version, operating system, HTTP referrer, pages visited, duration of visit.
- Support correspondence: the content of any message you send to our support address and any attachments.
We do not solicit or collect sensitive information within the meaning of APP 3.3 unless expressly required by a specific module you activate (for example, dietary preferences in a Guest CRM record), in which case we rely on your consent under APP 3.3(a).
3. Purposes of collection, use and disclosure (APP 6)
| Purpose | Data categories | Basis |
|---|---|---|
| Providing the modules and the Client Area | Account, session, API credentials, usage logs | Primary purpose — performance of contract |
| Invoicing and payment collection | Billing data | Primary purpose — legal obligation under Australian tax law |
| Statutory retention of tax invoices | Billing data | Legal obligation — s. 262A Income Tax Assessment Act 1936 (Cth); GST Act 1999 (Cth) |
| Fraud prevention and security monitoring | IP, user-agent, session logs | Related secondary purpose — legitimate business interest |
| Service emails (incident notices, invoices) | Contact data | Primary purpose — performance of contract |
| Marketing emails and newsletters | Contact data | Express opt-in consent under APP 7 and the Spam Act 2003 (Cth) |
| Product analytics (aggregated) | Pseudonymised usage data | Related secondary purpose — legitimate business interest |
Our notification obligations under APP 5 are met by this policy, by the Order confirmation email, and by contextual notices in the Client Area.
4. Disclosure to third parties (APP 6)
Personal information is disclosed strictly on a need-to-know basis to the following recipients:
- Payment service provider — for processing card payments. Data received: billing details, tokenised card reference, amount, currency.
- Australian cloud hosting provider — production hosting in Sydney. Purpose: running the application and database. Data received: all data stored on our servers, encrypted at rest.
- Transactional email provider — Australia-based. Purpose: delivering magic-link sign-in emails, tax invoices and service notices.
- External auditors and tax advisers — bound by professional secrecy. Purpose: statutory audit and tax reporting to the Australian Taxation Office.
- Competent public authorities — where required by law, court order or a valid request from a regulator such as the Office of the Australian Information Commissioner (OAIC) or the Australian Federal Police.
We do not sell personal information. We do not disclose personal information to advertising networks. We do not make automated decisions with legal or similarly significant effects.
5. Cross-border disclosure of personal information (APP 8)
All personal information is stored and processed within Australia (Sydney data centre). We do not disclose personal information to overseas recipients within the meaning of APP 8. Should we ever need to change this, we will update this policy and take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs, in accordance with APP 8.1.
6. Retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Active account data | For the duration of the subscription and 3 years after the last activity | Contract, limitation period defence |
| Tax invoices and accounting records | 7 years | s. 262A Income Tax Assessment Act 1936 (Cth) and GST Act 1999 (Cth) |
| Client Area session logs | 12 months | Security and audit |
| Module usage logs | 90 days for debug logs; 24 months aggregated | Operational reliability and product analytics |
| RMS Cloud API keys | Deleted within 30 days of subscription termination | Contract |
| Marketing consent record | Duration of consent + 3 years after withdrawal | Proof of consent under the Spam Act 2003 (Cth) |
| Support correspondence | 3 years from last exchange | Legitimate business interest |
7. Your rights under the Australian Privacy Principles
You have, at any time and free of charge, the following rights over your personal information:
- APP 12 — right of access: to obtain confirmation that we hold personal information about you and a copy of that information.
- APP 13 — right to correction: to have inaccurate, out-of-date, incomplete, irrelevant or misleading personal information corrected without undue delay.
- Right to withdraw consent: where processing is based on your consent (for example, marketing emails), you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
- Right to complain: to complain to us directly and, if unsatisfied with our response, to the OAIC (see section 12 below).
8. How to exercise your rights
Send a written request to privacy@cloudrms.org, including sufficient information for us to verify your identity (typically the email associated with your account) and a clear description of the right you wish to exercise. We reply within thirty (30) days of receipt.
9. Cookies
cloudrms.org uses only the cookies strictly necessary to operate the site and, subject to your prior consent, functional and analytics cookies. A full description of every cookie set, its purpose, its retention and how to opt out is available in the Cookie Policy.
10. Security of personal information (APP 11)
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. In particular:
- All connections to cloudrms.org are encrypted with TLS 1.3; older TLS versions are refused.
- Personal information at rest, including RMS Cloud API keys, is encrypted with AES-256.
- Access to production systems is restricted to a named list of engineers, protected by multi-factor authentication and logged on every session.
- Passwords are not used for the Client Area; the magic-link workflow eliminates password reuse and credential-stuffing risks.
- Vulnerability scans are performed weekly and dependencies are patched within a defined SLA.
- An incident response plan is maintained and tested annually.
- Backups are encrypted, stored in a separate Australian region (Melbourne) and tested for recoverability.
11. Notifiable Data Breaches scheme (Part IIIC of the Privacy Act)
Where there are reasonable grounds to believe that an eligible data breach has occurred (unauthorised access to, unauthorised disclosure of, or loss of personal information likely to result in serious harm), we will assess the incident within 30 days and, if the breach is confirmed as an eligible data breach, we will:
- notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable via the OAIC notification form; and
- notify affected individuals directly, or by publishing a statement on cloudrms.org where direct notification is not practicable.
Our internal notification target is 72 hours from becoming aware of the breach, in line with international best practice.
12. Privacy Officer and complaints
Cloudrms has designated a Privacy Officer as the single contact point for privacy matters. You may reach them at privacy@cloudrms.org. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner (OAIC)
GPO Box 5218, Sydney NSW 2001
Telephone: 1300 363 992
Website: www.oaic.gov.au
13. Changes to this policy
This Privacy Policy may be updated to reflect changes in law, our processing operations or our security posture. The current version and its effective date are always accessible at cloudrms.org/privacy. Material changes are notified by email to the address on file at least thirty (30) days before they enter into force.
14. Contact
Cloudrms Pty Ltd
42 Pitt Street, Level 8, Sydney NSW 2000, Australia
Director: James Whitmore
Telephone: +61 2 8756 3421
Email: privacy@cloudrms.org · support@cloudrms.org
ABN: 47 856 234 891 — ACN: 654 789 123
Bank: Westpac Banking Corporation, BSB 032-123, Account 456789012
Regulator: Office of the Australian Information Commissioner (OAIC).
Effective from 10 August 2026. Next scheduled review: 10 February 2027.