Privacy Policy
Privacy Policy
Last updated: 23 June 2026 · Version 1.1
This Privacy Policy explains how Ways of Working Pty Limited (ABN 37 647 816 537), facilitator of Lender-Wise.com (“Lender-Wise.com”, “we”, “us”, “our”), handles personal information when you use the Lender-Wise.com platform and our website at lender-wise.com (together, the “Service”).
Lender-Wise.com is a Software-as-a-Service platform that helps certain Consumer Data Right (CDR) data holders prepare to meet their obligations under the CDR, including Rule 9.4 reporting. We provide the software; our customers (e.g. the lending organisations) decide what information they put into it.
We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). We have adopted the APPs, which govern how we collect, use, disclose, store, secure and dispose of personal information. A copy of the APPs is available from the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
1. Our role: controller and processor
Lender-Wise.com handles personal information in two capacities:
- As a processor (on our customers’ behalf). Most personal information in the platform — data holder organisation’s users, and the records you enter for CDR compliance (such as complaint records and reporting data) is information our customer controls. We process it under our customer agreement and only on the customer’s instructions, to provide the Service. The customer organisation is responsible for its own privacy obligations to the individuals whose information it enters.
- As a controller (in our own right). For information we decide the purposes of — for example, account administration, billing, security logging, and website enquiries — we are the entity responsible under the Privacy Act.
If you are an individual whose information our customer, your organisation, has entered into Lender-Wise.com and you wish to access or correct it, please contact that organisation directly; we will assist them in responding if they seek such assistance.
2. The kinds of personal information we collect and hold (APP 1.4(a))
We aim to collect only what is reasonably necessary to provide the Service (APP 3). The categories are:
- Account and identity data — name, business email address, position/title, and an employer-assigned employee ID for each user we set up or who is invited to the platform.
- Authentication data — sign-in identifiers and tokens managed through our identity provider (Microsoft Entra External ID). We do not store user passwords; sign-in is handled by the identity provider.
- Contact and notification data — where you choose to enable them, a mobile number (for SMS alerts) and a browser/device push subscription, used only to deliver the notifications you have turned on. Mobile numbers are encrypted at the field level, and you can remove them or switch a channel off at any time.
- Agreement and authority data — the name, position and confirmation of authority of the person who signs a master subscription or organisation agreement.
- Compliance content you enter — records you create for CDR obligations, which may include complaint records, evidence files you upload (such as gateway logs), and reporting figures. Where this content contains personal information, it is the customer’s content and is protected as described in section 6.
- Usage and audit data — a record of significant actions taken in the platform (who did what, and when), retained as an append-only audit log for security and compliance.
- Technical data — IP address, browser type, device and session information, and similar data generated when you use the Service.
- Enquiry data — information you give us when you request a demo, contact support, or correspond with us.
Sensitive information. We do not seek to collect sensitive information (as defined in the Privacy Act, e.g. health, biometric or racial data). Please do not enter sensitive information into free-text fields unless it is strictly necessary for a compliance record.
Identifiers. Internal user and record identifiers in Lender-Wise.com are system-generated and do not embed personal information.
3. How we collect and hold personal information (APP 1.4(b), APP 5)
We collect personal information:
- directly from you — when an account is created, an agreement is signed, you use the platform, or you contact us;
- from your organisation — when a Principal or Organisation Administrator sets up or invites users, or configures the organisation; and
- automatically — technical and usage data generated as you use the Service.
At or around the time we collect personal information, we (or the customer who invites you) make this policy available so you understand who is collecting the information, why, and what happens if it is not provided. We hold personal information in the secured, Australian-hosted systems described in section 6.
4. Why we collect, hold, use and disclose personal information (APP 1.4(c), APP 6)
We use personal information only for the purpose for which it was collected, for a related purpose you would reasonably expect, or where you have consented or the law permits or requires it. Our purposes are:
| Provide the Service | Account/identity data, authentication data, compliance content — to run accounts, deliver CDR readiness and Rule 9.4 reporting features, and generate board-pack outputs. |
| Notify you | Email address, and — with your consent — mobile number and device push subscription, to send the in-app, email, SMS and push notifications you and your organisation have enabled (for example review and approval alerts). |
| Administer and support | Account, agreement and enquiry data — to set up organisations, respond to support requests, and manage agreements. |
| Security and integrity | Authentication, usage, audit and technical data — to authenticate users, isolate each organisation’s data, detect and investigate misuse, and maintain the audit trail. |
| Billing and administration | Account and agreement data — to administer subscriptions (billing itself is conducted off-platform). |
| Improve and communicate | Usage and enquiry data — to improve the Service and send service-related communications. |
| Comply with law | Any of the above — where we are required or authorised by law, or to assist a customer to meet their own legal obligations. |
We do not sell personal information, and we do not use it for third-party advertising.
5. Disclosure and our service providers (APP 6, APP 8)
We disclose personal information only as needed to provide the Service:
- To the customer organisation whose data it is (for content they control).
- To service providers (sub-processors) who help us run the platform under contractual obligations of confidentiality and security, and who may only use the information on our instructions. Our key sub-processors are:
- Microsoft Azure — cloud hosting and database infrastructure (Australian regions).
- Microsoft Azure Communication Services — delivery of email and SMS notifications.
- Microsoft Entra External ID — identity and sign-in management.
- Browser / operating-system push services (such as Google, Apple, Microsoft or Mozilla) — used only if you enable push notifications, to deliver them to your device; we transmit only the alert content you have enabled.
- To professional advisers, or where required by law — for example to a regulator, court, or in connection with a legal claim.
- In a business transfer — if our business or assets are reorganised, sold or merged, subject to this policy.
We maintain a current list of sub-processors and will make it available on request.
6. How we keep personal information secure (APP 11.1)
Security is built into the platform. We take the following reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure:
- Encryption in transit. All connections to the Service are encrypted using TLS (HTTPS). Data moving between you and Lender-Wise.com, and between our internal systems, is encrypted in transit.
- Encryption at rest. Data stored in our infrastructure is encrypted at rest. In addition, personal and other sensitive fields receive application-level, field-by-field encryption using AES-256-GCM before they are written to the database, so that the underlying values are not stored in readable form. Searchable encrypted fields use blind indexes, allowing look-ups without exposing the underlying value.
- Organisation isolation. Lender-Wise.com is multi-tenant, but each customer organisation’s data is logically isolated at the database layer (row-level security), so one organisation cannot access another organisation’s data. Access within an organisation is further restricted by role (for example Principal, Organisation Administrator, Editor, Viewer).
- Strong authentication. Sign-in is handled by Microsoft Entra External ID; we do not store passwords. Access is gated by role-based permissions enforced on the server.
- Append-only audit logging. Significant actions are written to an audit log that is designed to be append-only (it cannot be silently edited or deleted), supporting detection and investigation of unauthorised activity.
- Australian hosting. The platform and its data are hosted in Australian data-centre regions of Microsoft Azure.
- Operational controls. We apply least-privilege access for our personnel, network-level protections, monitoring, secure secret management, and change controls, and we keep our software and dependencies maintained.
No method of transmission or storage is completely secure, but we work to protect personal information using measures appropriate to its sensitivity.
7. Cross-border disclosure and data location (APP 8)
We host customer data in Australia. Our identity and cloud providers are global organisations, and in limited circumstances (for example administrative metadata, authentication, or support tooling) information may be processed outside Australia — most likely in the United States. We have therefore encrypted and de-identified all data to the maximum extent possible. For example, identifiers in tables have replaced personal identity information with a system-generated identifier.
8. Data quality (APP 10)
We take reasonable steps to ensure the personal information we hold is accurate, up to date and complete. Organisation Administrators can update their users’ details, and you can ask us to correct information we hold about you (section 10).
9. How long we keep information, and destruction (APP 11.2)
We keep personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it by law (including any record-keeping obligations relevant to CDR compliance). When personal information is no longer needed and is not required to be retained, we take reasonable steps to destroy it or permanently de-identify it.
- When a user is removed from an organisation, their access ends; limited audit records of their past actions are retained for security and compliance integrity.
- On termination of a customer’s subscription, we make customer data available for export for three months (or a longer period if required under contract with the customer organisation), after which we delete or de-identify it in accordance with our retention schedule, unless law requires us to keep it.
10. Accessing and correcting your information (APP 12, APP 13)
We do not enter personal information into our systems directly. Personal information in our systems usually pertains to the employees or agents of a customer organisation. However, you have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
- If your information was entered by a customer organisation, contact that organisation; as its processor we will help it respond if the organisation seeks us to do so.
- For information we hold as controller, contact us using the details in section 14. We will respond within a reasonable period (generally within 30 days) and will verify your identity first. If we cannot give access or make a correction, we will tell you why in writing.
There is normally no charge to ask; we will tell you in advance if a cost applies to providing access.
11. Complaints (APP 1.4(e))
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact our Privacy Officer (section 14) with details. We will acknowledge your complaint, investigate it, and respond — usually within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC): online at oaic.gov.au, by phone on 1300 363 992, or by mail to GPO Box 5288, Sydney NSW 2001.
12. Data breaches
We maintain a data-breach response capability. If we suspect a data breach that may involve personal information, we will assess it promptly (and in any event within the maximum period the law allows). Where a breach is an eligible data breach likely to result in serious harm under the Notifiable Data Breaches scheme, we will notify the affected individuals and the OAIC as required, and tell affected individuals the steps we recommend they take. Where we are a processor, we will also notify the affected customer organisation without undue delay so it can meet its own obligations.
13. Automated decision-making, children, and cookies
Automated decision-making. From 10 December 2026, APP 1 requires policies to disclose qualifying automated decision-making. Lender-Wise.com computes reporting figures from the records you enter (for example, totalling complaint counts). It does not make automated decisions that produce legal or similarly significant effects about an individual.
Children. The Service is a business tool intended for use by professional staff of our customers; it is not directed at children and we do not knowingly collect children’s personal information.
Cookies and website. Our website uses cookies and similar technologies that are necessary for the site to function and to understand usage. The cookies and browser storage we use are limited to the following essential and functional items:
- lr_session (essential) — keeps you signed in; encrypted and HTTP-only.
- lr_pkce, lr_state (essential) — protect the sign-in exchange; short-lived.
- lr_locale (functional) — remembers your chosen language.
- Display & accessibility preferences (functional) — theme, text size and similar settings stored in your browser; for signed-in users these are saved to your account instead.
- Microsoft sign-in cookies (essential) — set by Microsoft Entra during sign-in and multi-factor authentication.
Installable app and push notifications. Lender-Wise.com can be installed as an app (a progressive web app). Installing it registers a service worker — a small script in your browser — which also delivers push notifications if you opt in. Your push subscription is saved to your account so we can send the alerts you have enabled, and is removed when you turn push off in your notification preferences or your browser. These are functional technologies, not cookies, and we use no advertising, analytics or tracking technologies.
Because these are essential or functional, no consent banner is required. You can clear them in your browser settings — doing so will sign you out and reset your preferences. If we ever introduce analytics or marketing cookies, we will ask for your consent first.
14. Contact us
Privacy Officer — Ways of Working Pty Limited, facilitator of Lender-Wise.com.
Email: privacy@ways.net.au or info@ways.net.au
15. Changes to this policy
We may update this policy from time to time. The current version is always available at lender-wise.com/privacy, free of charge, and we will indicate the “Last updated” date above. Where required, we will give additional notice of material changes. On request, we will provide this policy in an alternative form.