Privacy Policy
This Privacy Policy explains how TomoBroker collects, uses, discloses, stores, and protects personal information when providing software to brokerages, their users, clients, and partners.
Last updated 26 May 2026
1. Scope
This Privacy Policy applies to personal information collected through the TomoBroker website, TomoBroker application, broker-branded client experiences, support, sales, billing, onboarding, integrations, automation, AI, voice, messaging, and analytics features.
TomoBroker is an Australian business-to-business SaaS platform for brokerages. Where a brokerage uses TomoBroker to collect information from or about a client, the brokerage usually has the direct client relationship and remains responsible for its own privacy notices and collection practices. Clients should also read the privacy policy and collection notices provided by their broker or brokerage.
2. Personal information we collect
We may collect personal information about brokerage users, clients, partners, website visitors, and people who contact us. Depending on the feature and the brokerage's settings, this may include:
- Name, email address, phone number, business name, role, account login, authentication, access, and permission details;
- Billing, subscription, payment, tax, support, sales, onboarding, and correspondence records;
- Usage data, device data, browser data, IP address, cookies, logs, analytics events, and security telemetry;
- Client enquiry details, financial circumstances, goals, preferences, property details, employment information, income, expenses, assets, liabilities, and fact-find information;
- Uploaded documents, identity documents, bank statements, payslips, tax documents, provider documents, and supporting evidence; and
- Communications sent through TomoBroker, including email, SMS, chat, call, transcript, voice, referral, settlement, provider, and integration records.
Some workflows may involve sensitive, confidential, or regulated information, including credit-related information, identity information, financial documents, or health-related information.
3. How we collect information
We collect personal information directly from brokerages, users, clients, and partners; when information is entered into forms, widgets, portals, chat interfaces, upload flows, or other TomoBroker features; through integrations authorised by a brokerage; and from service providers that support billing, communications, analytics, hosting, security, and support.
We also collect information from automated systems, logs, cookies, analytics tools, AI tools, voice systems, monitoring systems, public sources, or third-party data sources where lawful and relevant to providing TomoBroker.
4. Why we use personal information
We use personal information to:
- Provide, operate, secure, maintain, and improve TomoBroker;
- Provision and manage brokerage accounts, features, subscriptions, payments, invoices, and billing administration;
- Support brokerage workflows and client-facing experiences, including lead capture, client engagement, fact-find, document collection, research, automation, and reporting;
- Enable integrations with authorised partners, providers, and third-party services;
- Send service messages, security alerts, administrative notices, support responses, and permitted marketing communications;
- Monitor performance, usage, reliability, fraud, abuse, security, and platform quality, including automated screening of enquiry and contact-form submissions for spam and abuse, which may involve overseas AI and security providers;
- Train, test, evaluate, or improve systems where permitted by law and contract; and
- Comply with legal, regulatory, tax, audit, dispute-resolution, and record-keeping obligations.
5. Client information processed for brokerages
When a brokerage collects client information through TomoBroker, the brokerage is responsible for ensuring it has given appropriate notices and obtained required consents. TomoBroker uses client information to provide services to the brokerage, including hosting, storage, workflow automation, document collection, matching, analysis, communications, AI assistance, reporting, support, security, and integration services.
We do not sell client personal information. We do not use client information to provide broking, credit, financial, insurance, or legal advice to clients.
6. AI, automation, and voice data
TomoBroker may process information using AI, automation, speech-to-text, text-to-speech, transcription, chatbots, and voice systems. This may involve processing messages, prompts, client responses, call audio, transcripts, summaries, extracted data, and system-generated outputs.
Where call recording, transcription, automated messaging, or AI interaction requires consent or notice, the brokerage is responsible for obtaining that consent or providing that notice unless TomoBroker expressly agrees otherwise in writing. AI and automation outputs may be inaccurate or incomplete and should be reviewed by authorised users before being used for regulated or important decisions.
7. Credit-related and sensitive information
Some brokerages may use TomoBroker for workflows involving credit-related information, identity verification, financial documents, or other sensitive information. We handle this information carefully and only as reasonably necessary to provide TomoBroker, comply with law, protect security, or as otherwise authorised.
Brokerages remain responsible for complying with the Privacy Act 1988 (Cth), Australian Privacy Principles, Part IIIA of the Privacy Act, credit reporting requirements, industry codes, and any required client consents or disclosures.
8. Disclosure of personal information
We may disclose personal information to:
- The relevant brokerage, authorised users, or clients where required to provide the relevant experience;
- Service providers that help us host, secure, operate, support, analyse, bill, communicate, or improve TomoBroker;
- Payment processors, billing providers, communications providers, AI providers, transcription providers, analytics providers, and security providers;
- Integration providers, partners, providers, referral partners, settlement partners, or other third parties where configured or authorised by the brokerage;
- Professional advisers, insurers, auditors, legal representatives, regulators, courts, law enforcement, or government agencies where required or permitted by law; and
- Parties involved in a merger, acquisition, financing, restructure, or sale of our business or assets.
9. Overseas disclosures
Some service providers may store or process information outside Australia. Countries may include the United States, New Zealand, the United Kingdom, the European Economic Area, Singapore, and other locations depending on our hosting, infrastructure, AI, communications, support, billing, and analytics providers.
Where we disclose personal information overseas, we take reasonable steps required by the Privacy Act to protect that information unless an exception applies. Brokerages should consider whether their own client notices need to identify overseas disclosure locations based on their TomoBroker settings and enabled integrations.
10. Security, retention, and deletion
TomoBroker uses technical and organisational safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. These measures may include access controls, encryption, monitoring, logging, secure infrastructure, account isolation, backup controls, and staff access restrictions.
We retain personal information for as long as reasonably necessary to provide TomoBroker, comply with legal and regulatory obligations, resolve disputes, maintain security, support backups, and meet tax, audit, and operational requirements. When information is no longer required, we will take reasonable steps to delete or de-identify it unless we are required or permitted to retain it.
11. Access, correction, and complaints
Individuals may request access to or correction of personal information held by TomoBroker. If the information is controlled by a brokerage, we may refer the request to that brokerage or work with the brokerage to respond. We may need to verify identity before responding and may refuse access or correction where permitted by law.
If you have a privacy concern, please contact us first so we can investigate and respond. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
13. Contact
For privacy requests, access or correction requests, complaints, or legal notices, contact the TomoBroker Privacy Officer at privacy@tomobroker.com.au.