VariationGuardby PrimX

Trust & legal

Privacy Policy

How VariationGuard handles your information.

Last updated: Private beta draft — 4 July 2026

About this policy

This policy explains how Consolidated Cost Consulting Pty Ltd handles information in connection with VariationGuard.

Information we may collect

  • Account and contact information (name, email, company name).
  • Demo request contact and business details (name, business, work email, optional phone, trade or package, optional business size and optional enquiry message).
  • Company and project information you set up.
  • Builder emails and instructions you forward or paste in.
  • Field capture notes recorded onsite.
  • Subcontract clause text you enter for time-bar configuration.
  • Cost workbook data (line items, rates and figures).
  • Usage and analytics events (see below).
  • Payment-related information handled by Stripe (we do not store full card numbers).

Demo requests

We use demo request details to assess and respond to the request. Submitting the form does not create a product account, book a demo automatically or provide consent for unrelated marketing.

The demo request form is provided by HubSpot, our customer relationship management (CRM) provider. The details you enter are submitted to and stored in HubSpot on our behalf so we can review and respond to the request.

We do not add demo-request details to a marketing list unless the person gives separate optional marketing consent through an approved process.

What analytics intentionally excludes

Our analytics are designed to measure how the product is used, not to capture the content of your work. Analytics should not intentionally collect raw email bodies, subcontract clause text, notice bodies, cost line descriptions or invite tokens.

  • We track events such as 'instruction assessed' or 'notice preview opened', with coarse buckets (for example, a confidence band) rather than raw content.
  • We do not intentionally send the text of your instructions, clauses, notices or cost descriptions to analytics.

Marketing and advertising cookies

Our public marketing pages use HubSpot and Meta tools that set cookies and collect information about the visit, separately from product content. On signed-in routes, only the small activation-event boundary described below may be sent.

  • HubSpot (our CRM) records the pages you view on our website and links that activity to your contact record if you submit the demo request form.
  • The Meta pixel records public marketing page views and approved conversion events so campaign performance can be measured. VariationGuard's launch policy does not authorise advertising spend.
  • On signed-in routes, HubSpot and Meta may receive only an approved activation event name, an opaque event/user/company identifier, timestamp, environment and campaign attribution. The approved events are company setup, project creation, instruction capture, assessment completion, variation creation and submission-package build.
  • Contract text, instruction text, evidence, pricing, notice content, project names and recipient details are never within this marketing boundary.
  • You can limit this collection using your browser's cookie and tracking-protection settings, or Meta's own advertising preferences. Blocking them does not affect your ability to use the Service or to request a demo.

Payment information

Card and payment data is handled by Stripe under its own terms and security. We receive limited billing status information (such as plan and subscription state), not full card details.

Infrastructure we use

The Service relies on third-party infrastructure, which may include Firebase (authentication and database), hosting providers and email processing for inbound forwarding and internal demo-request delivery. These providers process data on our behalf to operate the Service.

AI features and third-party AI providers

Some features of the Service use artificial intelligence models operated by third-party AI providers — currently Anthropic and OpenAI. When these features are enabled, the content needed for the check is sent to the provider to produce the result: this can include the instruction or builder-email text you captured or forwarded, subcontract clause text you pasted for set-up, and your scope descriptions. This content is commercially sensitive, so please only enter information you are permitted to process.

These providers process the content on servers that may be located outside Australia, and handle it under their own terms. We send only what the feature needs, and the result you see is checked against the Service's built-in rules before it is shown.

AI features can be switched off for the Service. When they are off (or unavailable), nothing is sent to an AI provider — the built-in deterministic checks still run entirely within our own infrastructure.

How we use information

  • To provide, operate and secure the Service.
  • To generate your drafts, register and workbook outputs.
  • To process subscriptions and manage your plan.
  • To understand product usage and improve the Service.
  • To provide support and respond to your requests.
  • To assess and respond to a demo request.

How information is stored

Information is stored in our database and infrastructure providers' systems. Access controls and security rules are applied to limit access to your company's data.

Who information may be shared with

  • Service providers that help us operate the Service (such as hosting, database, payment and email-processing providers).
  • Third-party AI providers, only when AI features are enabled (see 'AI features and third-party AI providers' above).
  • Our CRM and advertising providers — HubSpot and Meta — only within the public-page and minimum-data activation boundary described above.
  • Users you invite to your own company workspace.
  • Authorities where required by law.
  • We do not sell your personal information.

Access, export and deletion

You can export your register and cost workbook as CSV within the product. You can also request a copy or deletion of your account/company data by contacting privacy@variationguard.com.au. Some information may need to be retained to meet legal, accounting or backup obligations. See the Data page for more detail.

Data retention

We retain information for as long as needed to provide the Service and to meet legal, tax and backup obligations.

International storage and processing

Some providers — including the third-party AI providers described above, and the CRM and advertising providers described under 'Marketing and advertising cookies' — may store or process data outside Australia.

Security

We use reasonable technical and organisational measures to protect information, including authentication and database security rules. No system is completely secure; you are responsible for keeping your credentials and invite links safe.

Contact

Privacy enquiries: privacy@variationguard.com.au. Consolidated Cost Consulting Pty Ltd · ACN 611 091 653.