HospoTek only uses personal information to provide, secure, support and improve the service, respond to enquiries and meet legitimate business or legal obligations. We do not sell personal information.
1. Scope and who we are
HospoTek is an Australian hospitality technology service operated by Hospo Tek. This policy applies to visitors, prospective customers, customers, authorised platform users, support contacts, resource and newsletter registrants, prospective community members, service buyers and providers, talent professionals and venue talent contacts, and people whose information a customer records in the platform.
HospoTek seeks to handle personal information consistently with the Australian Privacy Principles where they apply. A customer venue remains responsible for deciding what information its authorised users enter into HospoTek and for giving any notices or obtaining any authority required for that collection.
2. Our role for customer venue data
For information entered into the application by a venue, HospoTek generally provides the platform and processes that information for the customer. The customer controls its operational purpose, authorised users and venue records. HospoTek directly controls information used for account security, billing, support, service delivery, legal compliance and the public website.
If you are a staff member, patron, witness or function contact and your information was entered by a venue, contact that venue first. We will assist the venue with an authorised request.
3. Information we may collect
- Identity and contact information: name, email, phone number, role, venue and account identifiers.
- Venue and team information: venue details, departments, memberships, roster shifts, assignments and training activity.
- Operational records: tasks, checklist responses, notes, flags, completion times and supporting photographs.
- Incident information: descriptions, people involved, witnesses, management actions, follow-up and private evidence files.
- Function information: booking contacts, event details, guest numbers, dietary information, catering selections and notes.
- Security and technical information: authentication events, session and device information, IP address, audit records, service diagnostics, browser performance and error information.
- Commercial information: enquiries, demonstrations, support conversations, agreement contacts and billing-related records.
- Ecosystem registration information: community interests, service categories, professional experience, business or venue needs, preferred hospitality roles, location, availability, engagement preferences and qualifications described in an expression of interest.
- Marketing preferences and attribution: marketing consent, registration source and bounded campaign parameters such as UTM source, medium and campaign.
4. How information is collected
We collect information directly when someone submits an enquiry or ecosystem expression of interest, registers for resource or newsletter updates, creates or uses an authorised account, contacts support or enters information into the platform. We also receive information from a customer venue, its authorised managers, roster exports and the service providers needed to operate HospoTek.
Technical information is collected when the website or application is requested so that the service can authenticate users, prevent abuse, diagnose failures and measure performance. HospoTek does not currently use third-party advertising cookies or sell website browsing profiles.
5. Why we use information
- provide and administer the website, application and customer relationship;
- authenticate users and enforce venue-specific roles and permissions;
- deliver tasks, checklists, incident workflows, function records, rosters, training and notifications;
- respond to sales, demonstration, privacy and support requests;
- respond to community, resource, services marketplace and talent expressions of interest, keep separately consented registrants informed and understand which future pathways have genuine demand;
- design and test future ecosystem features without representing an expression of interest as a live profile, listing, job application, provider match or transaction;
- protect customers, users and HospoTek from misuse, fraud, security incidents and unauthorised access;
- operate audit, recovery, troubleshooting and service-improvement processes;
- meet contractual, insurance, accounting, regulatory and legal obligations; and
- establish, exercise or defend legal claims.
6. Sensitive information
Incident reports, evidence, dietary details and free-text notes may contain sensitive information. Customers should only collect information that is reasonably necessary for a legitimate venue purpose and must not use HospoTek as a substitute for emergency, medical, workplace, licensing or legal reporting obligations.
Pre-launch community, provider and talent forms are not a secure credential-verification channel. Do not submit identity documents, right-to-work evidence, background checks, private references, health information or copies of licences unless HospoTek later provides a specific secure and legally reviewed process.
HospoTek restricts incident reports and evidence to authorised users and does not include private evidence files in ordinary notification emails.
7. When information is shared
We may disclose or make information available:
- to the customer venue and its authorised users according to their roles;
- to infrastructure, authentication, hosting, email and support providers that help deliver HospoTek;
- to professional advisers, insurers or auditors where reasonably necessary and subject to confidentiality;
- where required or authorised by law, court order or a lawful government request;
- to protect safety, rights, security or the integrity of the service; or
- as part of a proposed business transaction, subject to appropriate confidentiality and privacy protections.
Our current direct service providers and their purposes are listed on the Subprocessors page.
8. Overseas processing
HospoTek's primary production database and private file storage are configured in Australia. Some hosting, email, support, security and provider-level processing may occur in the United States and other locations used by our service providers and their subprocessors.
We assess providers, use contractual and technical controls appropriate to the service, and keep a current public provider register where practicable. Provider locations can change, so the Subprocessors page is the most current source.
9. Security
HospoTek uses role-based access, venue isolation, row-level database security, private file storage, server-side authorisation, privileged multi-factor authentication, audit records, dependency checks, encrypted transport, backups and tested recovery procedures. No internet service can guarantee absolute security.
Learn more in our Security overview. Do not send passwords, payment-card details or private incident evidence through an ordinary support email.
10. Retention, legal holds and deletion
We retain information only for as long as it is reasonably needed for the purpose for which it is held, customer instructions, security, dispute resolution and applicable legal obligations. Different records require different periods. Incident, employment, audit and venue records may need to be preserved for longer than routine telemetry or an unsuccessful sales enquiry.
A legal hold overrides ordinary deletion when records are needed for a dispute, investigation or legal obligation. Customer offboarding includes a controlled export and cooling-off process. Backup copies may remain protected and beyond ordinary use until their scheduled expiry.
11. Access, correction and deletion requests
You may ask to access or correct personal information HospoTek controls, or request deletion where appropriate. We may need to verify your identity and authority before acting. Some requests must be referred to the customer venue that controls the record, and some information may need to be retained where an exception or legal obligation applies.
Send requests to privacy@hospotek.com.au. Include enough information to identify the relevant account, venue and record, but do not send identity documents until we provide a secure method.
12. Data breaches
HospoTek maintains a response process to contain, assess, notify and review suspected data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach is identified, HospoTek will notify the Office of the Australian Information Commissioner and affected individuals as required.
13. Direct marketing
A request for a demonstration, resource notification, community registration, marketplace expression of interest or talent registration authorises us to respond to that specific request. Separate marketing messages are sent only where the form asks for and receives the required marketing consent. We will identify the sender and provide an effective unsubscribe method when production newsletter delivery is connected. Transactional account, security and service messages are not marketing subscriptions.
14. Privacy complaints
Send a privacy complaint to privacy@hospotek.com.au with a description of the concern and the outcome you are seeking. We will acknowledge the complaint, investigate it and aim to provide a written response within 30 days.
If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner.
15. Changes and contact
We will update this policy when our services or information-handling practices materially change. The current version and effective date will remain available on this page.
Privacy contact: privacy@hospotek.com.au
General contact: hello@hospotek.com.au
Operator: Hospo Tek, trading as HospoTek, Australia