Privacy Policy

Hey Sharon — A product of MD Consultancy Pty Ltd
ABN: 34 790 148 584
PO Box 3015, Allambie Heights NSW 2100, Australia
Contact: privacy@heysharon.ai

Effective date: 23rd Of February 2026
Last updated: 23rd Of February 2026

1. About This Policy

Hey Sharon is a virtual office management service for residential builders, operated by MD Consultancy Pty Ltd ("we", "us", "our"). Hey Sharon is accessible via WhatsApp and SMS messaging.

This Privacy Policy explains how we collect, use, store, disclose and protect your personal information when you use Hey Sharon. It applies to all subscribers ("you", "your") and is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using Hey Sharon, you agree to the collection and use of your information as described in this Policy.

2. What Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected via Gmail Integration

If you choose to connect your Gmail account, Hey Sharon requests read-only access to your Gmail account via Google's OAuth 2.0 protocol. This means we can read your emails but cannot send, delete, modify, or access your account in any other way.

Through this integration we collect:

Important: When you connect your Gmail account, Hey Sharon processes emails that may contain information about third parties including your subcontractors, suppliers, and clients. These individuals have not directly interacted with Hey Sharon. We process their information solely to provide the service to you and do not use it for any other purpose.

2.3 Information Generated by Our Service

2.4 Technical Information

3. How We Use Your Information

We use your information solely to provide and improve the Hey Sharon service. Specifically:

We do not use your information for advertising, marketing to third parties, or any purpose unrelated to delivering the Hey Sharon service to you.

4. How We Store Your Information

4.1 Storage Infrastructure

Your data is stored on infrastructure provided by Amazon Web Services (AWS) in Australian or Asia-Pacific regions. Specifically:

4.2 Tenant Isolation

Hey Sharon is built with strict data isolation. Your data is completely separated from every other subscriber's data at the database, storage, and application level. No subscriber can ever access another subscriber's data. This is enforced structurally, not just by policy.

4.3 Security

We implement industry-standard security measures including:

5. Data Retention and Deletion

5.1 While You Are a Subscriber

We retain your data for as long as you are an active subscriber to provide you with the service.

5.2 After Cancellation

When your subscription ends, we retain your data for 30 days to allow you to request an export or reactivate your account. After 30 days, all your personal data is permanently deleted from our systems including:

5.3 Anonymised Data

After deletion of your personal data, we may retain anonymised, de-identified signals derived from your usage (for example, that a particular email domain pattern is associated with a particular document type). This anonymised data contains no personal information and cannot be used to identify you or your business.

5.4 Requesting Deletion

You may request deletion of your data at any time by contacting privacy@heysharon.ai. We will action deletion requests within 30 days.

6. The Global Learning Engine — How Anonymised Data Is Used

Hey Sharon uses a shared classification system to improve document recognition accuracy across all subscribers. This system works as follows:

When you confirm or correct a document classification (for example, confirming that an email from a particular supplier is a receipt), we record an anonymised signal. This signal contains only:

This signal contains no email content, no financial amounts, no personal names, no job addresses, and no information that could identify you or your business. It is used only to improve classification accuracy for all subscribers.

Your private job data, email content, documents, and contact information are never shared with or used to benefit other subscribers.

7. Disclosure of Your Information

7.1 We Do Not Sell Your Data

We do not sell, rent, or trade your personal information to any third party under any circumstances.

7.2 Subprocessors

To provide the Hey Sharon service we share data with the following subprocessors. Each is bound by their own privacy obligations and data processing agreements:

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure, storage, document OCR (Textract)Australia / Asia-Pacific
AnthropicAI language model processing for classification and natural language responsesUnited States
OpenAI / Voyage AIGeneration of vector embeddings for semantic searchUnited States
Google LLCGmail API (email ingestion), Google WorkspaceUnited States
Twilio IncSMS and WhatsApp message deliveryUnited States
Meta Platforms (WhatsApp)WhatsApp messaging channelUnited States

When data is processed by subprocessors in the United States, it is subject to those providers' data processing agreements and privacy policies. We only share the minimum data necessary for each subprocessor to perform their function.

7.3 Legal Requirements

We may disclose your information if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7.4 Business Transfers

If MD Consultancy Pty Ltd is acquired, merged, or sells its assets, your personal information may be transferred as part of that transaction. We will notify you via WhatsApp or email before your data is transferred and becomes subject to a different privacy policy.

8. Gmail Data — Specific Disclosures

In addition to the general disclosures above, we make the following specific commitments regarding your Gmail data:

These commitments are consistent with Google's API Services User Data Policy, including the Limited Use requirements.

9. Your Rights Under the Australian Privacy Act

You have the following rights regarding your personal information:

Access — You may request a copy of the personal information we hold about you by contacting privacy@heysharon.ai. We will respond within 30 days.

Correction — If you believe information we hold is inaccurate, incomplete, or out of date, you may ask us to correct it.

Deletion — You may request deletion of your personal information as described in Section 5.4.

Complaints — If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by contacting privacy@heysharon.ai. We will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10. Cookies and Tracking

Hey Sharon operates primarily via WhatsApp and SMS messaging and does not use cookies. If you visit heysharon.ai, standard web server logs may record your IP address and browser type. We do not use tracking pixels, advertising cookies, or third-party analytics on our website.

11. Children's Privacy

Hey Sharon is a business service intended for use by adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected information from a minor, please contact privacy@heysharon.ai and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via WhatsApp message to your registered number at least 14 days before the changes take effect. Continued use of Hey Sharon after the effective date constitutes acceptance of the updated policy.

13. Contact Us

For any privacy questions, access requests, correction requests, or complaints:

Privacy Officer
MD Consultancy Pty Ltd (trading as Hey Sharon)
PO Box 3015, Allambie Heights NSW 2100
privacy@heysharon.ai

We aim to respond to all privacy enquiries within 5 business days.