PRIVACY POLICY
This Privacy Policy explains how RCSS Australia Pty Ltd trading as On The Tools (On The Tools, we, us or our) collects, holds, uses, discloses, protects and disposes of personal information in connection with the On The Tools service, websites and related communications.
On The Tools provides Australian trade businesses with AI-assisted missed-call response, SMS enquiry handling, job qualification, customer-approved pricing information, quote and site-visit workflows, booking support, customer updates, usage reporting and administrative tools.
We aim to handle personal information consistently with the Australian Privacy Principles (APPs), whether or not a small-business exemption may apply to us at a particular time. This commitment does not amount to a formal statutory opt-in under the Privacy Act 1988 (Cth) unless we separately complete that process.
1. Who this policy applies to
This policy applies to:
- trade business owners, directors, employees, contractors and authorised users who register interest in, open, configure or use an On The Tools account;
- people who call or message an On The Tools customer, receive an automated or AI-assisted response, request a quote or site visit, make a booking, or otherwise communicate through the Service;
- website visitors, beta or expression-of-interest contacts, prospective customers, support contacts, suppliers, advisers and other business contacts; and
- personal information handled through our websites, application, telecommunications and SMS workflows, AI systems, booking tools, support channels, billing systems, logs and approved service providers.
2. Our role and the trade business’s role
For account, billing, security, product, support and service-administration information, On The Tools determines why and how the information is handled.
For many end-customer conversations and job records, On The Tools processes information to provide services to the relevant trade business. That trade business determines its services, prices, booking rules, customer commitments and many of the purposes for which the information is used. The trade business may have its own privacy policy and legal obligations.
A request about the underlying trade job, quote, property, site visit or booking may need to be handled by the relevant trade business. We will assist with, route or respond to privacy requests that relate to information in our systems.
On The Tools is not a trade licensing authority, accreditation body or KYC provider. We do not verify trade licences, professional standing or regulatory eligibility as part of the standard Service. The trade business is responsible for the truth and lawfulness of the business information and eligibility declarations it provides.
3. How to contact us
When contacting us about privacy, include enough information for us to identify the relevant account or interaction, such as the trade business name, your telephone number, approximate dates and the nature of your request. Do not send passwords, one-time codes or unnecessary identity documents by ordinary email.
4. Personal information we collect and hold
4.1 Account, expression-of-interest and trade-business information
- name, role, business name, ABN where supplied, profession or trade, state or territory, suburb, service area and business contact details;
- expression-of-interest, beta-access and waitlist information, including the trade, jurisdiction, contact details and comments voluntarily supplied;
- eligibility declarations made during signup or use of the Service, without requiring copies of trade licences or professional credentials as part of the standard Service;
- login, authentication, account role, access, security-event and preference information;
- subscription, invoice, payment status, transaction references, top-up purchases and customer-support history; and
- business configuration, including approved services, job descriptions, fixed-price or hourly settings, call-out fees, availability, business hours, excluded numbers, escalation rules, team members and enabled integrations.
Full payment-card details are handled by the payment processor and are not intended to be stored by On The Tools.
4.2 Missed-call, SMS, quote and booking information
- caller or sender telephone number, name, email address and contact preferences;
- missed-call event metadata, forwarding or routing information, timestamps, SMS content, conversation transcript, delivery status, opt-out status and human-takeover status;
- requested work, service address or general location, access details, photos or documents voluntarily supplied, preferred times, job notes and urgency or safety information;
- customer-approved pricing information shown or discussed, quote mode, site-visit status, booking details, changes, cancellations and communications with the trade business; and
- message-segment counts, usage events, outbound-message identifiers, delivery receipts, provider-cost estimates, reconciled provider charges and related billing, service-quality or forecasting data.
On The Tools receives missed-call event information for the automated response workflow. It does not routinely record, transcribe or store the audio content of missed calls. If call-audio functionality is introduced later, we will complete a privacy review and provide any notice or consent required before enabling it.
4.3 Technical, website and support information
- IP address, browser and device information, session identifiers, application events, diagnostic logs, audit records and security telemetry;
- support requests, troubleshooting information, feedback, survey responses and screenshots or screen recordings voluntarily supplied; and
- cookies and similar technologies used for authentication, security, preferences, performance and approved analytics.
4.4 Sensitive and unsolicited information
On The Tools is not designed to collect detailed health, biometric, racial or ethnic, political, religious, sexual-orientation or criminal-record information. A person may nevertheless volunteer sensitive or highly personal information when describing an urgent situation or job. We handle such information only where reasonably necessary, lawful and relevant, restrict access, and avoid using it for unrelated purposes.
If we receive personal information that we did not request, we assess whether we could lawfully have collected it. If not, and if it is lawful and reasonable to do so, we delete or de-identify it.
5. How we collect personal information
- directly from account holders, authorised users and expression-of-interest contacts during signup, beta registration, onboarding, configuration, billing, support and service use;
- from end customers when they call, send or reply to an SMS, provide job information, request a quote or site visit, make a booking, or communicate with the trade business through On The Tools;
- from the relevant trade business, including customer details, service settings, approved pricing, availability and job information;
- from customer-authorised providers and integrations, including telecommunications, SMS, calendar, payment, authentication, hosting, monitoring and email services;
- automatically through websites, applications, security systems, logs and cookies; and
- from publicly available business contact information, referrals or advisers where collection and use are lawful and reasonably expected.
We do not seek trade-licence documents, identity documents or professional-accreditation records for routine account onboarding. If identity verification is reasonably required for a privacy or security request, we use information proportionate to the risk and avoid collecting more information than necessary.
6. When you may deal anonymously or by pseudonym
You may browse public information or make a general enquiry without giving your full identity where practical. You may use a preferred name or pseudonym where this does not prevent us or the trade business from safely and accurately handling the matter.
Identification is usually required to create and secure a business account, manage billing, investigate a specific complaint, verify an access or correction request, complete a booking, attend a site, or prevent fraud and misuse. SMS interactions necessarily reveal the sending telephone number to the messaging systems involved.
7. Why we collect, hold, use and disclose information
- provide, configure, secure, operate, measure and support the On The Tools service;
- manage expressions of interest, beta access, launch communications and requested product information;
- identify the correct trade business and apply the correct account, profession, jurisdiction, job-library, pricing, booking and escalation settings;
- respond to missed calls and customer enquiries, ask relevant clarifying questions, provide customer-approved service or pricing information, arrange site visits or bookings, send updates and support human takeover;
- authenticate users, enforce tenant and role boundaries, prevent unauthorised use, detect faults, investigate incidents and protect people and property;
- manage subscriptions, invoices, usage allowances, top-ups, message usage, provider costs, credits, forecasting, disputes and account administration;
- improve conversation quality, workflows and AI performance through controlled testing, quality review, minimisation, redaction and access restrictions;
- send account, service, security, billing and support communications, and permitted marketing communications;
- comply with law, respond to valid legal requests, enforce agreements and establish, exercise or defend legal claims; and
- create aggregated or de-identified analytics that do not reasonably identify an individual.
8. AI and automated processing
On The Tools uses artificial intelligence together with deterministic rules, customer-approved configuration and software tools. Personal information may be used to:
- identify the relevant business account and apply tenant, profession and jurisdiction restrictions;
- classify the enquiry, requested job type, urgency and whether a safety or human-escalation rule applies;
- select qualification questions, service descriptions, customer-approved pricing information, quote or site-visit pathways and available booking options;
- generate or assemble SMS replies, summaries, booking updates and handover information;
- detect opt-out language, suspected abuse, delivery failures and situations requiring human review; and
- measure service usage, message segments, counted quote or booking outcomes and estimated or reconciled communication costs.
These automated processes can affect the questions a person receives, whether the Service presents a quote pathway or site-visit pathway, which booking options are shown, and whether an enquiry is escalated. They are not intended to determine a person’s legal rights, trade licence status, credit, insurance, employment, government benefit eligibility or access to emergency services.
From 10 December 2026, additional APP 1 transparency obligations apply in specified circumstances where personal information is used in computer programs to make, or do something substantially and directly related to making, decisions that could reasonably be expected to significantly affect an individual’s rights or interests. We will keep our automated-processing practices under review and update this policy if our Service begins making decisions of that kind.
AI output may be incomplete or inaccurate. It is not a substitute for emergency services, licensed technical advice, professional judgement or the trade business’s legal obligations. A person may ask for clarification, correction or human assistance. Material uncertainty, safety concerns, unsupported requests and configured escalation events should be redirected or escalated rather than answered conclusively.
We do not sell personal information. We do not permit customer or end-customer message content to be used to train general-purpose AI models unless the affected customer has expressly authorised that use in writing and any required notice or consent has been obtained.
At the date of this policy, On The Tools uses Anthropic’s commercial Claude API for certain AI processing. Anthropic states that commercial API inputs and outputs are not used to train its models by default and that standard API inputs and outputs are automatically deleted from its backend within 30 days, subject to exceptions such as agreed alternative retention, usage-policy enforcement or legal requirements. Provider arrangements may change, and we will update this policy where a material change affects how personal information is handled.
9. Disclosure to other parties
We may disclose or make personal information available only to the extent reasonably required to:
- the relevant trade business and its authorised users;
- telecommunications, SMS, hosting, database, AI, authentication, monitoring, analytics, email, calendar, payment, accounting and customer-support providers;
- professional advisers, insurers, auditors, financiers, investors or prospective acquirers under appropriate confidentiality and due-diligence controls;
- regulators, courts, law-enforcement agencies, emergency services or other parties where required or authorised by law, or where another permitted situation applies; and
- a successor entity in a lawful restructure, merger, acquisition or sale, subject to appropriate privacy and confidentiality protections.
Not every provider receives every category of information. Optional integrations receive information only when enabled or used for the relevant workflow. We do not disclose personal information to advertisers or data brokers for them to sell or independently monetise the information.
10. Overseas processing and disclosure
Some approved technology providers or their subprocessors process or access personal information outside Australia. The United States is the principal overseas location we currently expect for parts of the Service, particularly certain AI, communications, cloud or software-provider operations. Provider and subprocessor locations can change over time.
Where it is practicable to identify other countries in which overseas recipients are likely to be located, we will update this policy or an associated provider notice. Before disclosing personal information overseas, we take reasonable steps appropriate to the circumstances to assess providers, use contractual and security protections, minimise the information disclosed, and manage cross-border risk. Overseas recipients may be subject to foreign laws requiring access to information. Where applicable, On The Tools may remain accountable under Australian privacy law for an overseas recipient’s handling of personal information.
11. Google Calendar and Google API data
If an account holder chooses to connect Google Calendar, On The Tools accesses only the Google Calendar data and permissions needed for the enabled scheduling features, such as checking availability, preventing conflicting bookings and creating, updating or removing booking-related calendar events where authorised.
Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for unrelated advertising, data-brokerage or general-purpose model training. Access is limited to providing or improving the user-facing calendar and booking features, security, support and other uses permitted by Google’s policies and applicable law.
An account holder can disconnect the Google integration using available account or Google controls. Disconnecting stops future API access, but does not automatically delete information that On The Tools is otherwise permitted or required to retain, such as booking records, security records or records required by law.
12. Direct marketing and electronic messages
Service messages sent to respond to a missed call, answer a requested enquiry, progress a quote or site visit, manage a booking, provide an account notice or address a security issue are not to be disguised as unrelated marketing.
If you register an expression of interest, join a beta or waitlist, request information or otherwise ask us to contact you, we may use the contact details you provide to respond to that request and provide relevant launch or product updates. Marketing choices are separate from essential service or security communications.
Where On The Tools or a trade business sends a commercial electronic message, the sender must have the required consent or other lawful basis, accurately identify the sender, provide valid contact details and include a functional unsubscribe method. Trade businesses are responsible for the lawfulness of marketing they instruct or send using the Service, including contact lists, consent evidence, message content and suppression obligations.
13. Cookies, analytics and tracking choices
We may use essential cookies and similar technologies for authentication, account security, fraud prevention, session continuity and preferences. These technologies may be necessary for the website or account to function properly.
We may use limited performance or analytics technologies to understand website and service reliability, usage and product performance. Where optional analytics, advertising pixels or other non-essential tracking technologies require consent or another choice under applicable law, we will provide an appropriate notice or control before using them.
You can also control cookies through your browser settings. Blocking essential cookies may affect login or account functionality. We do not use tracking technologies to sell personal information.
14. Data quality
We take reasonable steps to keep personal information accurate, complete, current and relevant for the purpose for which it is used or disclosed. Account holders must keep business details, approved services, prices, availability, escalation contacts and integration settings current. End customers and account users should tell us or the relevant trade business when information is incorrect.
15. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information and risks. These may include role-based access, tenant separation, server-side authorisation, encryption in transit, secrets management, logging, monitoring, backups, provider controls, incident response and secure disposal. Controls vary by system and evolve over time.
No internet, telecommunications, cloud or AI service can guarantee absolute security. Account users must protect credentials, use approved devices and access methods, and promptly report suspected compromise or incorrect access.
We do not represent that the Service holds a particular security certification or uses a particular security control unless we expressly state that the representation is current for the relevant Service.
16. Retention and disposal
We keep personal information only for as long as reasonably required for the purpose collected, customer instructions, account administration, support, security, dispute resolution, backup integrity and legal, tax or regulatory obligations.
Retention periods vary by record type. Billing, tax, corporate, fraud-prevention, security and legal records may need to be retained for the period required by applicable law or while a claim, investigation or legal hold remains relevant. We do not apply a blanket seven-year retention period to every category of personal information.
At the end of the approved retention period, information is deleted, de-identified or rendered inaccessible, subject to documented legal holds, unresolved incidents, contractual obligations and normal backup-expiry processes. Closing an account or ending a conversation does not always cause immediate deletion where information must be retained for billing, security, legal claims, audit evidence or lawful recordkeeping.
A customer’s contractual right to request a structured CSV export after cancellation is separate from an individual’s privacy access rights. The current Customer Terms of Use explain the customer-data export window and exclusions.
17. Access, correction and deletion requests
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also request deletion where the information is no longer required and no lawful basis requires retention.
We verify the requester’s identity using information proportionate to the request and risk. We aim to respond within 30 calendar days, or explain any reasonable delay. We do not charge for making an access or correction request. A reasonable, non-excessive charge may apply for providing access where permitted by law and disclosed in advance; correction requests are not charged.
We may refuse or limit access or deletion where permitted or required by law, including to protect another person’s privacy, safety, legal privilege, security or existing legal proceedings. Where required, we will provide written reasons and information about how to complain. If we refuse a correction request and the law requires it, you may ask us to associate a statement with the information indicating that you consider it inaccurate, out of date, incomplete, irrelevant or misleading.
18. Privacy complaints
Contact the Privacy Officer using section 3 and explain the issue, the relevant account or telephone number, approximate dates and the outcome sought.
We will acknowledge the complaint, assess any urgent security or safety implications, investigate fairly, consult relevant parties where appropriate and provide a written outcome within a reasonable period.
If you are dissatisfied and the Privacy Act applies, you may be entitled to complain to the Office of the Australian Information Commissioner (OAIC). The OAIC generally expects a person to complain to the organisation first and allow a reasonable opportunity to respond.
19. Data breaches
Suspected loss, unauthorised access or unauthorised disclosure is handled under our incident and data-breach response procedures. Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches reasonably and expeditiously and take all reasonable steps to complete the assessment within the statutory period.
If there are reasonable grounds to believe an eligible data breach has occurred and no exception applies, we will notify affected individuals and the Australian Information Commissioner as required. We may take remedial action to reduce or prevent the risk of serious harm and coordinate with affected providers, customers, regulators or law-enforcement agencies where appropriate.
20. Children and vulnerable people
On The Tools is a business service and is not directed to children. A child or vulnerable person may nevertheless be mentioned in a trade enquiry. We minimise information, avoid unnecessary inferences about sensitive characteristics, do not exploit vulnerability and escalate safety concerns where appropriate. On The Tools is not an emergency service and messages are not guaranteed to be monitored continuously.
21. Changes to this policy
We may update this policy when our services, data practices, providers or legal obligations change. The current version, document code and effective date will be published. Material changes will be communicated through the website, application, account notice or another appropriate channel.
22. Further information
This policy should be read with the On The Tools Customer Terms of Use, relevant collection notices, AI disclosures and any privacy notice issued by the trade business using On The Tools.
Australian privacy information is available from the Office of the Australian Information Commissioner at www.oaic.gov.au. Australian electronic-message information is available from the Australian Communications and Media Authority at www.acma.gov.au.