Hey Sharon is a virtual office management service for residential builders, operated by MD Consultancy Pty Ltd ("we", "us", "our"). Hey Sharon is accessible via WhatsApp and SMS messaging.
This Privacy Policy explains how we collect, use, store, disclose and protect your personal information when you use Hey Sharon. It applies to all subscribers ("you", "your") and is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using Hey Sharon, you agree to the collection and use of your information as described in this Policy.
If you choose to connect your Gmail account, Hey Sharon requests read-only access to your Gmail account via Google's OAuth 2.0 protocol. This means we can read your emails but cannot send, delete, modify, or access your account in any other way.
Through this integration we collect:
Important: When you connect your Gmail account, Hey Sharon processes emails that may contain information about third parties including your subcontractors, suppliers, and clients. These individuals have not directly interacted with Hey Sharon. We process their information solely to provide the service to you and do not use it for any other purpose.
We use your information solely to provide and improve the Hey Sharon service. Specifically:
We do not use your information for advertising, marketing to third parties, or any purpose unrelated to delivering the Hey Sharon service to you.
Your data is stored on infrastructure provided by Amazon Web Services (AWS) in Australian or Asia-Pacific regions. Specifically:
Hey Sharon is built with strict data isolation. Your data is completely separated from every other subscriber's data at the database, storage, and application level. No subscriber can ever access another subscriber's data. This is enforced structurally, not just by policy.
We implement industry-standard security measures including:
We retain your data for as long as you are an active subscriber to provide you with the service.
When your subscription ends, we retain your data for 30 days to allow you to request an export or reactivate your account. After 30 days, all your personal data is permanently deleted from our systems including:
After deletion of your personal data, we may retain anonymised, de-identified signals derived from your usage (for example, that a particular email domain pattern is associated with a particular document type). This anonymised data contains no personal information and cannot be used to identify you or your business.
You may request deletion of your data at any time by contacting privacy@heysharon.ai. We will action deletion requests within 30 days.
Hey Sharon uses a shared classification system to improve document recognition accuracy across all subscribers. This system works as follows:
When you confirm or correct a document classification (for example, confirming that an email from a particular supplier is a receipt), we record an anonymised signal. This signal contains only:
This signal contains no email content, no financial amounts, no personal names, no job addresses, and no information that could identify you or your business. It is used only to improve classification accuracy for all subscribers.
Your private job data, email content, documents, and contact information are never shared with or used to benefit other subscribers.
We do not sell, rent, or trade your personal information to any third party under any circumstances.
To provide the Hey Sharon service we share data with the following subprocessors. Each is bound by their own privacy obligations and data processing agreements:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, storage, document OCR (Textract) | Australia / Asia-Pacific |
| Anthropic | AI language model processing for classification and natural language responses | United States |
| OpenAI / Voyage AI | Generation of vector embeddings for semantic search | United States |
| Google LLC | Gmail API (email ingestion), Google Workspace | United States |
| Twilio Inc | SMS and WhatsApp message delivery | United States |
| Meta Platforms (WhatsApp) | WhatsApp messaging channel | United States |
When data is processed by subprocessors in the United States, it is subject to those providers' data processing agreements and privacy policies. We only share the minimum data necessary for each subprocessor to perform their function.
We may disclose your information if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
If MD Consultancy Pty Ltd is acquired, merged, or sells its assets, your personal information may be transferred as part of that transaction. We will notify you via WhatsApp or email before your data is transferred and becomes subject to a different privacy policy.
In addition to the general disclosures above, we make the following specific commitments regarding your Gmail data:
These commitments are consistent with Google's API Services User Data Policy, including the Limited Use requirements.
You have the following rights regarding your personal information:
Access — You may request a copy of the personal information we hold about you by contacting privacy@heysharon.ai. We will respond within 30 days.
Correction — If you believe information we hold is inaccurate, incomplete, or out of date, you may ask us to correct it.
Deletion — You may request deletion of your personal information as described in Section 5.4.
Complaints — If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by contacting privacy@heysharon.ai. We will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Hey Sharon operates primarily via WhatsApp and SMS messaging and does not use cookies. If you visit heysharon.ai, standard web server logs may record your IP address and browser type. We do not use tracking pixels, advertising cookies, or third-party analytics on our website.
Hey Sharon is a business service intended for use by adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected information from a minor, please contact privacy@heysharon.ai and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via WhatsApp message to your registered number at least 14 days before the changes take effect. Continued use of Hey Sharon after the effective date constitutes acceptance of the updated policy.
For any privacy questions, access requests, correction requests, or complaints:
Privacy Officer
MD Consultancy Pty Ltd (trading as Hey Sharon)
PO Box 3015, Allambie Heights NSW 2100
privacy@heysharon.ai
We aim to respond to all privacy enquiries within 5 business days.