Privacy Policy
This Privacy Policy explains how Mauxie Pty Ltd ACN 689 232 362 (we, us or our) collects, holds, uses, discloses and otherwise handles your personal information in connection with the Tenor mobile application, the website at mauxie.com.au/tenor and any related services (together, the App). It applies to your use of the App.
ABOUT THIS PRIVACY POLICY
We are committed to protecting your privacy and to handling personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act), the Australian Privacy Principles (APPs), and, in relation to financial data accessed through the Consumer Data Right, Part IVD of the Competition and Consumer Act 2010 (Cth) and the Competition and Consumer (Consumer Data Right) Rules 2020 (the CDR Rules).
By creating an account or otherwise using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we handle personal information, you should not use the App.
This Privacy Policy forms part of, and should be read together with, our Collection Notice, our Consent Form and the App Terms and Conditions.
DEFINITIONS
In this Privacy Policy:
APPs means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act.
Basiq means Basiq Pty Ltd ABN 95 616 592 011, an accredited data recipient under the Consumer Data Right whom we engage to collect CDR Data on our behalf.
CDR means the Consumer Data Right established under Part IVD of the Competition and Consumer Act 2010 (Cth).
CDR Data means information about you or your banking products and transactions that is accessed through the CDR and disclosed to us, and any data derived from it.
Partner means a person you link with in the App to form a couple and with whom you share selected information.
Personal information has the meaning given in the Privacy Act, and generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive information has the meaning given in the Privacy Act, and includes information about a person's health.
We, us and our mean Mauxie Pty Ltd, and you and your mean the individual using the App.
THE KINDS OF PERSONAL INFORMATION WE COLLECT
The kinds of personal information we collect depend on how you use the App. They include the categories described in this clause.
Account and profile information: your email address, display name and, if you choose to provide it, a profile picture and other profile details you enter.
Partner linkage and relationship content: the identifier that links your account to your Partner's account, and the content you create or share in the App, including tasks, reminders, notes, appreciation messages, milestones, dates and events.
Financial data (CDR Data): if you choose to connect a bank account, information about your accounts and transactions accessed through the CDR, as described in clause 6. We do not receive or store your banking log-in credentials.
Calendar data: if you connect a calendar, event details such as titles, start and end times, location and attendees, used to display your schedule and detect overlaps.
Technical and usage data: information about your device and how you use the App, including device model, operating system version, app version, in-app activity, crash reports and performance data.
Communications: the content of any enquiry, support request or other communication you send us.
Some relationship content and financial information may constitute sensitive information. We only collect sensitive information where you have consented to that collection and it is reasonably necessary for a function of the App, or where the collection is otherwise permitted by law.
HOW WE COLLECT PERSONAL INFORMATION
We collect personal information in the following ways:
directly from you, when you create an account, complete your profile, enter content, connect a service or contact us;
from your Partner, to the extent they share content with you or link their account to yours;
from Basiq, when you connect a bank account and CDR Data is disclosed to us as described in clause 6;
from third-party platforms you connect, such as your calendar provider; and
automatically, through your use of the App, using the analytics and infrastructure tools described in clause 9.
Where it is reasonable and practicable, we collect personal information about you directly from you. If we receive personal information about you that we did not solicit, we will deal with it in accordance with the APPs.
WHY WE COLLECT, HOLD, USE AND DISCLOSE PERSONAL INFORMATION
We collect, hold, use and disclose personal information for the following purposes:
to create and administer your account and verify your identity;
to provide the core features of the App, including task coordination, shared calendars, appreciation flows, relationship milestones, the Spending and Values dashboard and the Tenor Score;
to enable you to link with, and share selected information with, your Partner;
to provide optional financial features using CDR Data, as described in clause 6;
to provide the artificial intelligence features described in clause 8;
to process your subscription and manage billing;
to respond to your enquiries and provide support;
to maintain, secure, test and improve the App, including diagnosing faults and analysing usage;
to send you service messages and, where permitted, communications about the App, as described in clause 11; and
to comply with our legal obligations and to establish, exercise or defend legal claims.
We will not use or disclose your personal information for a purpose other than the purpose for which it was collected, unless you would reasonably expect us to do so for a related purpose, you have consented, or the use or disclosure is otherwise permitted or required by law.
CONSUMER DATA RIGHT AND FINANCIAL DATA
The App offers optional features that use financial data to power the Spending and Values dashboard. Where you choose to connect an Australian bank account, that data is accessed under the CDR.
We access CDR Data through Basiq, which is an accredited data recipient under the CDR. We act as a CDR representative of Basiq. This means Basiq collects CDR Data on our behalf under the CDR framework, and we handle that CDR Data in accordance with the CDR Rules.
We will only collect, use or disclose CDR Data where you have given a valid consent through the consent process presented to you, and only to the extent needed to provide the features you have asked for. This reflects the data minimisation principle under the CDR Rules, which requires that we do not collect more CDR Data, or hold it for longer, than is reasonably needed.
When you connect an account, the information disclosed to us may include your account names, types and balances, and transaction details such as amounts, dates, categories and merchant names. We do not receive or store your online banking log-in credentials.
In handling CDR Data, we comply with the privacy safeguards in the CDR Rules that apply to us as a CDR representative, and we store CDR Data in Australia.
We will not use CDR Data for credit scoring, for advertising, or to make decisions that would produce legal or similarly significant effects about you, and we will not sell CDR Data.
You can withdraw your consent and disconnect your financial accounts at any time in the App. When you do, we will stop collecting new CDR Data and will, within 30 days, delete or de-identify the CDR Data we hold in accordance with the CDR Rules, unless we are required to retain it by law.
If you have a complaint that relates to CDR Data, please contact us using the details in clause 20. We may be required to involve Basiq in handling that complaint.
LINKED ACCOUNTS, SHARING WITH YOUR PARTNER AND SEPARATION
The App is designed for couples. When you link with a Partner, you each keep your own account and control what you share. Content you choose to share, such as tasks, calendar overlaps, appreciation messages and Spending and Values information, becomes visible to your Partner.
Once information has been shared with your Partner, your Partner may have seen, saved or recorded that information. We cannot retrieve or delete information that your Partner has already accessed or exported.
You and your Partner each control, and are responsible for, the information you each choose to connect and share, including your own financial data. Connecting your own bank account does not give your Partner access to your underlying transaction detail unless you choose to share it.
You can unlink from your Partner at any time. When you unlink:
you and your Partner each retain your own account and the content you each created;
shared couple content stops being updated between the accounts from the time of unlinking;
any connected financial accounts are treated as disconnected for the couple's shared features, and CDR Data is dealt with under clause 6.7; and
historical shared content that already exists in each account may remain in that account unless you or your Partner deletes it.
If you are concerned about a former Partner's continued access to shared content, or you need to remove shared content urgently (for example, following a relationship breakdown or a safety concern), please contact us using the details in clause 20 and we will assist you as quickly as we reasonably can.
ARTIFICIAL INTELLIGENCE FEATURES
Artificial intelligence is an integral part of the App. It operates as an underlying layer that provides suggestions, prompts and insights across the App, and it cannot be switched on or off separately. These features are powered by Claude, a service provided by Anthropic, PBC.
When you use the App, limited information is sent to the AI service for processing, such as summaries of your in-app activity and text you enter into features that use AI. We do not send raw CDR Data, full calendar event details or the content of messages between you and your Partner to the AI service.
Because these features are an integral part of the App, they cannot be switched off separately. If you do not want your information to be handled in this way, you should not use the App.
DISCLOSURE OF PERSONAL INFORMATION
We do not sell your personal information. We disclose personal information only as described in this Privacy Policy, including:
to your Partner, to the extent you choose to share it;
to our service providers, who help us operate the App, including Google LLC (for the Firebase authentication, database, messaging, crash reporting and performance tools, and, for the Android version of the App, app distribution and subscription billing), Apple Inc. (for app distribution and subscription billing), Basiq (for CDR Data) and Anthropic, PBC (for AI features);
to professional advisers, such as our lawyers and accountants, where reasonably necessary;
to a purchaser or potential purchaser if we sell or reorganise our business, subject to equivalent privacy protections; and
to a person or body where we are required or authorised by law to do so, including to a court, tribunal or regulator.
We require our service providers to handle personal information consistently with this Privacy Policy and applicable law, and to use it only for the purpose of providing their services to us.
OVERSEAS DISCLOSURE
Some of our service providers, or their infrastructure, may be located outside Australia, including in the United States. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs.
CDR Data is stored in Australia and is handled in accordance with the CDR Rules, as described in clause 6.
COMMUNICATIONS AND DIRECT MARKETING
We may send you service messages that are necessary to operate the App, such as account, security and billing notices. You cannot opt out of these while you hold an account.
We will only send you promotional communications where you have consented or where we are otherwise permitted to do so under the Spam Act 2003 (Cth) and the Privacy Act. You can opt out of promotional communications at any time using the unsubscribe function or by contacting us. We do not use CDR Data for direct marketing except as permitted by the CDR Rules.
HOW WE KEEP PERSONAL INFORMATION SECURE
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include encrypting data in transit using TLS 1.2 or higher and data at rest using AES-256, access controls through Firebase Security Rules that restrict couple data to the linked accounts, storing API keys and credentials in the iOS Keychain rather than in plain text, and support for device-level authentication such as Face ID and Touch ID.
No method of transmission or storage is completely secure. While we work to protect your personal information, we cannot guarantee absolute security.
You are responsible for keeping your device and account secure, including keeping your log-in details confidential.
DATA BREACHES
We maintain procedures to detect, assess and respond to data breaches. If we become aware of an eligible data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a breach involves CDR Data, we will also comply with the notification requirements under the CDR Rules.
RETENTION AND DESTRUCTION
We hold personal information only for as long as it is needed for the purposes described in this Privacy Policy, or as required by law. When personal information is no longer needed, we take reasonable steps to destroy it or to ensure it is de-identified.
When you delete your account, we will delete or de-identify your personal information as set out below, except where we are required to retain certain information by law or need it to resolve a dispute or enforce our agreements:
profile and account data: within 7 days of deletion;
shared couple data: within 30 days of deletion, or immediately if both partners delete their accounts;
financial data: within 30 days of disconnection or account deletion, and otherwise dealt with under clause 6.7; and
anonymised or aggregated data that does not identify you: may be retained indefinitely.
ACCESS AND CORRECTION
You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Many of these details can be viewed and updated directly in the App.
To make an access or correction request, contact us using the details in clause 20. We will respond within a reasonable period. There is no charge for making a request, although we may charge a reasonable amount for giving access in some cases. If we refuse a request, we will tell you why in writing and how you can complain.
COMPLAINTS
If you have a concern or complaint about how we have handled your personal information, please contact us using the details in clause 20. We will acknowledge your complaint and aim to resolve it within a reasonable period.
If you are not satisfied with our response, you may complain to the OAIC at oaic.gov.au or by telephone on 1300 363 992. If your complaint relates to CDR Data, you may also complain to the OAIC as the recognised external dispute resolution body for the CDR.
CHILDREN
The App is intended for adults. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a person under 18 has provided us with personal information, please contact us and we will take reasonable steps to delete it.
OUR WEBSITE
Our website may use cookies and similar technologies to help it function and to understand how it is used. You can manage cookies through your browser settings. Our website may link to third-party sites, which have their own privacy practices that we do not control.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. If we make a material change, we will take reasonable steps to notify you, such as through the App or by email, and we will update the effective date at the top of this Privacy Policy. The version that applies is the one in effect when you use the App.
HOW TO CONTACT US
If you have any questions about this Privacy Policy, or wish to make a request or complaint, please contact us:
Privacy contact: Mauxie Pty Ltd
Email: privacy@mauxie.com.au
This Privacy Policy is governed by the laws of Queensland, Australia.