Operator. Realay.io is operated by Shamir Holdings Pty Ltd (ACN 141 917 704) of 1133–1145 Malvern Rd, Malvern VIC 3144, as trustee for the SEA Discretionary Trust ("Realay", "we", "our", "us"). This Privacy Policy explains how Realay handles Personal Information that we collect in our own right — for example, from prospective and existing customers, their representatives and account holders, billing contacts, recipients of our marketing, and visitors to our website. We are committed to handling Personal Information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the "APPs"), and other applicable data protection laws.
What this policy does not cover. Where Realay processes Personal Information on behalf of a Realay customer in order to deliver the Realay Services (for example, recipient phone numbers, message content, and delivery metadata that a customer routes through our platform), the customer is the controller of that information and Realay acts as a processor. That processing is governed by Realay's Terms of Service and the Data Processing Addendum at Annex 1 of those Terms — not by this Privacy Policy.
1. About this policy
1.1 Application
This Privacy Policy applies to Personal Information that Realay collects, holds, uses or discloses as an APP entity. "Personal Information" has the meaning given in the Privacy Act 1988 (Cth), and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true and whether or not it is recorded in a material form.
1.2 Sensitive information
Realay does not generally collect or solicit sensitive information (such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data). Customers and visitors should not include sensitive information in support tickets, contact forms, or other unsolicited communications with us.
1.3 Anonymity and pseudonymity
Where it is lawful and practicable, you may interact with us anonymously or under a pseudonym (for example, when browsing our public website). This is not generally practicable when you create an account, transact with us, or seek support, because we need to identify you in order to provide and bill the Services.
2. Information we collect
2.1 Information you provide directly
- Account information: name, email address, telephone number, employer, role, and account credentials.
- Billing information: business name, business number (ABN/ACN/equivalent), billing address, billing contact details, and (where applicable) payment instrument tokens. We do not store full payment card numbers; card details are handled by our payment processors and tokenised.
- Identity verification: information required to comply with our anti-fraud, sanctions screening and "know your customer" obligations, where applicable.
- Support and communications: the contents of emails, support tickets, contact form submissions, and any other communications you send to us.
- Marketing subscriptions: the email address (and any preferences) you provide when subscribing to Realay updates.
2.2 Information we collect automatically
- Service usage: API request logs, message metadata (timestamps, sender, recipient, status, channel), feature usage, and login activity.
- Device and connection data: IP address, user agent, device identifiers, operating system and browser version, language, and approximate location derived from IP.
- Cookies and similar technologies: see clause 8.
- Security and audit logs: error reports, suspected abuse, multi-factor authentication events, and other security-related events.
2.3 Information we receive from third parties
- Telecommunications suppliers and aggregators: message delivery receipts, recipient validation, fraud signals, and similar operational data.
- Payment processors: payment status, chargeback notifications, and tokenised instrument references.
- Identity, fraud and sanctions providers: verification and screening results.
- Publicly available sources: business directories, professional networks and similar sources, used to identify prospective customers.
3. How we use Personal Information
We use Personal Information for the following purposes:
- to provide, operate, maintain and develop the Realay platform and Services;
- to create and administer accounts, authenticate users, and manage access;
- to process payments, issue invoices, manage credit, and pursue collections;
- to provide technical support, respond to enquiries, and communicate service messages and security alerts;
- to detect, investigate, prevent and respond to fraud, abuse, spam, scam communications, and security incidents, including by sharing information with telecommunications suppliers, network operators and law enforcement;
- to comply with legal, regulatory, tax, audit, anti-money-laundering, and sanctions obligations, and to respond to lawful requests from regulators and courts;
- to analyse and improve the Services, including by generating de-identified, aggregated insights;
- to send marketing communications about Realay (subject to your consent and the opt-out rights described in clause 10);
- to protect Realay's legal rights and interests, including in connection with legal claims, audits and corporate transactions;
- for any other purpose authorised or required by Applicable Law.
4. Sharing and disclosure
We disclose Personal Information to the following categories of recipients:
- Suppliers and service providers who help us deliver the Services, including hosting and infrastructure providers, telecommunications carriers and aggregators, email providers, payment processors, customer support tooling, analytics tooling, and identity and fraud screening providers. We do not publish a list of these providers but will make a current list available to existing customers on request, subject to confidentiality obligations.
- Professional advisers: our accountants, auditors, lawyers, insurers, and other professional advisers, where they are bound by confidentiality obligations.
- Regulators and law enforcement: where we are required or permitted by law, including in response to lawful requests, subpoenas, court orders, or to investigate suspected unlawful activity.
- Corporate transactions: in connection with the proposed or actual sale, merger, restructure, or financing of Realay, in which case we will require the recipient to handle Personal Information consistently with this Policy.
- With your consent: any other recipient where you have authorised the disclosure.
We do not sell Personal Information.
5. Overseas disclosure
5.1 Jurisdictions
Realay may disclose Personal Information to recipients located outside Australia, including in jurisdictions across the Asia-Pacific, Europe, the United Kingdom, and the Americas, depending on the suppliers used to deliver the Services. The specific countries may change as we add or replace suppliers.
5.2 Safeguards
Where we disclose Personal Information overseas, we take reasonable steps in the circumstances to ensure that the recipient handles the information consistently with the APPs and any other applicable data protection law, including by using contractual safeguards (such as the European Standard Contractual Clauses, the UK addendum, or equivalents) where appropriate.
5.3 Accountability
Under APP 8, we remain accountable for acts or practices of overseas recipients that would breach the APPs unless an exception in section 16C of the Privacy Act applies. This Policy does not limit any non-excludable rights you have under the Privacy Act.
6. Security
6.1 Technical and organisational measures
We take reasonable steps to protect Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include encryption in transit, encryption at rest where appropriate, access controls, network segregation, monitoring and audit logging, secure development practices, personnel training, and background checks for personnel with privileged access.
6.2 No security is perfect
No method of electronic transmission or storage is completely secure. While we work to protect Personal Information, we cannot guarantee its absolute security. You are responsible for safeguarding your own credentials and for enabling available security features (including multi-factor authentication where offered).
6.3 Independent assurance
Where reasonably available, Realay obtains and maintains independent third-party security attestations (such as SOC 2 or equivalent) and makes summaries available to customers under appropriate confidentiality terms.
7. Retention
We retain Personal Information for as long as is reasonably necessary for the purposes for which it was collected, or as required by law. The general framework is:
- Minimum retention: Realay retains Personal Information collected in connection with the operation of the Services (including account data, service usage data, message metadata, and security and audit logs) for a minimum of three (3) months from collection or last use, except where Applicable Law requires a shorter period.
- Beyond the minimum: Realay does not guarantee retention of Personal Information beyond the three-month minimum and may delete, sample, archive, anonymise or aggregate such information at any time at its discretion. You should not rely on Realay as a long-term archive for any data you wish to preserve.
- Billing and tax records: retained for at least seven (7) years from the relevant transaction, as required by Australian tax and corporations law. Realay has no discretion to delete these records earlier.
- Marketing subscriber data: retained until you unsubscribe, plus a short suppression period to ensure we honour your opt-out.
- Backup copies: retained for the duration of our backup rotation cycle, after which they are overwritten or destroyed.
When Personal Information is no longer needed for a permitted purpose and is not required to be retained by law, we will take reasonable steps to destroy or de-identify it. If you require longer-term retention of your data for your own compliance, audit or business continuity needs, you should export and store the data on your own systems.
8. Cookies and similar technologies
Our website and portal use cookies and similar technologies for the following purposes:
- Strictly necessary: session, authentication, and security cookies that are required for the site or portal to function;
- Functional: cookies that remember your preferences (such as language or display options);
- Analytics: cookies that help us understand how the website and portal are used, in aggregate, so we can improve them.
You can configure your browser to refuse cookies or to alert you when they are being set; however, parts of the site or portal may not function correctly without cookies. We do not currently use third-party advertising or cross-site tracking cookies.
9. Your rights
9.1 Access (APP 12)
You may request access to the Personal Information we hold about you. We will respond within a reasonable period (and in any event within 30 days), and may charge a reasonable cost-recovery fee for access in some circumstances. We may decline access in the limited circumstances permitted by the Privacy Act, in which case we will explain our reasons and your options for review.
9.2 Correction (APP 13)
If you believe that any Personal Information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it. We will take reasonable steps to do so within a reasonable period and free of charge.
9.3 Deletion
You may request deletion of Personal Information. We will action requests in accordance with Applicable Law, but may need to retain certain information to comply with legal obligations (for example, tax records), to resolve disputes, or to enforce agreements.
9.4 Direct marketing opt-out
You may opt out of direct marketing at any time, free of charge, by following the unsubscribe instructions in any marketing email or by emailing [email protected]. We will action opt-outs as soon as practicable and in any event within the timeframes required by the Spam Act 2003 (Cth).
9.5 How to make a request
To exercise any of these rights, contact us using the details in clause 15. We may need to verify your identity before actioning a request.
10. Direct marketing
From time to time, we may send marketing communications about Realay's services to existing and prospective customers, in accordance with the Spam Act 2003 (Cth) and the Privacy Act. Every marketing email we send identifies the sender, includes accurate contact details, and includes a functional unsubscribe facility. You can also opt out at any time by emailing [email protected].
11. Children
The Services are intended for businesses and their authorised personnel, and are not directed at individuals under 18 years of age. We do not knowingly collect Personal Information from individuals under 18. If you believe we have inadvertently collected such information, please contact us using the details in clause 15 and we will take reasonable steps to delete it.
12. Notifiable Data Breaches
Realay maintains an incident response process to detect, contain, investigate and remediate suspected security incidents involving Personal Information. Where we determine that an "eligible data breach" within the meaning of Part IIIC of the Privacy Act has occurred, we will:
- notify affected individuals as soon as practicable, where required by the Notifiable Data Breaches scheme; and
- notify the Office of the Australian Information Commissioner (the "OAIC") as required.
Where Realay processes Personal Information on behalf of a customer in delivering the Services (so that the customer is the controller and Realay is the processor), breach handling is governed by the Data Processing Addendum at Annex 1 of the Terms of Service; in those cases the customer is primarily responsible for notifications to regulators and affected individuals, but this does not limit Realay's own statutory obligations where they apply to Realay in its own right.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Where a change is material, we will take reasonable steps to notify you in advance — for example, by email to your registered account address, or by an in-portal notice — and (where required by law) seek your consent. We encourage you to review this page periodically.
14. Complaints
14.1 How to complain
If you believe Realay has handled your Personal Information in breach of the APPs or any other applicable data protection law, please contact our Privacy Officer at [email protected] with details of your complaint. We will acknowledge your complaint within a reasonable period and aim to provide a substantive response within 30 days.
14.2 Escalation to the OAIC
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Online: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5288, Sydney NSW 2001
15. Contact us
You can contact our Privacy Officer at:
- Email: [email protected]