Google API disclosure
FG Toolkit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Section 18 sets out in full what FG Toolkit does and does not do with Google user data.
1. General
This policy applies to Fluent Partners Pty Ltd (ABN 48 627 769 902) trading as Fluent Group, and Fluent Enterprises Pty Ltd (ABN 49 640 566 632).
In this policy, "Fluent Group", "we", "us" and "our" refer to each of these entities, as applicable to the entity providing the relevant part of the Applications or the Services. These entities commit to complying with the Privacy Act 1988 (Cth) and Australian Privacy Principles.
The policy explains how personal information is collected, used, disclosed and controlled. Using the website or services constitutes consent to these practices. Disagreement means you should not use their services.
Where Fluent Group holds or uses personal information provided by a Client about that Client’s own clients (Customer Personal Information), Section 6 sets out how that information is handled and takes precedence over the general provisions of this policy to the extent of any inconsistency.
2. Definitions
Key terms include:
Personal information covers anything that identifies you or could reasonably do so.
FG Toolkit means the collection of software services and utilities that Fluent Group builds and maintains, currently made available at the Website.
Fluent Care means Fluent Group’s Salesforce managed support and monitoring service, comprising instance monitoring, outage alerts, Salesforce release management and platform management. Fluent Care is delivered in part through a technical connection to a Client’s Salesforce org for monitoring and support purposes, and does not involve Fluent Group accessing or processing any Customer Personal Information held within that org.
Applications means, collectively, FG Toolkit and Fluent Care.
Services means the implementation and ongoing support Fluent Group provides to Clients in connection with the Applications.
Website means www.fgtoolkit.com and any other web address through which FG Toolkit is made available, including Client tenants within the Application.
Client means a business or organisation that has entered into an agreement with Fluent Group for the supply of the Services.
Customer Personal Information means personal information that a Client, or someone acting on a Client’s behalf, submits, uploads, enters or otherwise provides to Fluent Group through the Services about the Client’s own clients, customers, contacts or other individuals. It is distinct from personal information Fluent Group collects about individuals in its own right, including a Client’s own personnel who deal directly with Fluent Group.
Sub-processor means a third party engaged by Fluent Group to store, host or otherwise process personal information in order to provide the Services.
3. What types of personal information do we collect?
The company collects personal details (name), contact details (email, address, phone), profile details (username, password, preferences), technical details (IP address, browser type, location), usage records (cookies, website activity) and marketing preferences.
Where possible, anonymous or pseudonymous interaction is allowed, though this may limit access. Information is generally collected directly from individuals, though third-party sources may be used for legislative compliance (verification services, publicly available sources).
Personal information is collected when you access services, communicate with staff, or otherwise deal with the company. Only necessary non-sensitive information or consented sensitive information is solicited. Where collected from third parties without prior consent, the company takes reasonable steps to inform you.
This section describes personal information Fluent Group collects about individuals who deal with it directly. Customer Personal Information (personal information a Client provides to Fluent Group about the Client’s own clients through use of the Services) is addressed in Section 6.
4. How do we store and protect personal information?
Physical files are secured in access-controlled premises. Electronic files are stored on protected systems accessible only through secure networks. All staff and contractors have confidentiality provisions in employment contracts.
The company takes reasonable steps to ensure collected information is accurate, up-to-date, complete and relevant. Information used or disclosed must meet these standards. Protection from misuse, loss, and unauthorised access is maintained. Information no longer needed is destroyed or de-identified, except where client records must be maintained.
Internet transmission cannot be guaranteed secure, so transmission risk rests with you. Third-party information supply and receipt are also at your own risk, with no warranties regarding their privacy practices.
The security measures described in this section apply equally to Customer Personal Information.
5. Why do we collect, hold, use and disclose personal information?
Information is collected for stated purposes: facilitating interactions, responding to enquiries, providing services to clients, processing forms, storing information at third-party data centres, performing quality assurance and IT security, updating information, and complying with legal obligations.
Secondary use is permitted where reasonable to expect and related to primary purposes. Consent for other purposes is obtained when needed.
Information is disclosed to supply services to third parties, facilitate interactions, share with employees and contractors assisting with services, run anonymised analytics, improve services through anonymised reporting, respond to enquiries, update information, meet regulatory reporting requirements, comply with law, and for purposes identified at collection time.
Disclosure extends to related bodies corporate, professional associations, and registration bodies with proper interest in the disclosure.
This section does not apply to Customer Personal Information, which Fluent Group collects, uses and discloses only as described in Section 6.
6. Personal information we process on behalf of Clients
(a)Our role FG Toolkit is how a Client submits, uploads or otherwise captures personal information about its own clients, customers or other contacts (for example, through forms and account administration functionality). In relation to that Customer Personal Information, Fluent Group acts as a service provider to the Client. The Client remains responsible for its own relationship with, and obligations to, the individuals whose Customer Personal Information it provides to Fluent Group, including under the Privacy Act 1988 (Cth) and any other applicable law.
This section 6 applies to Customer Personal Information provided through FG Toolkit. Fluent Care’s technical connection to a Client’s Salesforce org is for platform monitoring and support purposes only. It does not involve Fluent Group accessing or processing Customer Personal Information held within that org, so this section does not apply to Fluent Care.
(b)How we use and disclose Customer Personal Information Fluent Group only collects, uses, holds and discloses Customer Personal Information to provide, maintain, support and improve the Services, in accordance with the instructions of the relevant Client and the applicable services agreement, or as required or authorised by law. Fluent Group does not use Customer Personal Information for its own direct marketing, does not sell it, and does not otherwise use or disclose it for purposes unrelated to supplying the Services, except with the Client’s consent or on a de-identified or aggregated basis for product improvement and analytics.
(c)Notice and consent The Client is responsible for ensuring it has all necessary notices, consents and legal grounds to provide Customer Personal Information to Fluent Group, including for any sensitive information (such as health information) contained in that data. Fluent Group relies on the Client’s representations in the applicable services agreement that it holds these rights.
(d)Sub-processors and overseas transfer Fluent Group hosts FG Toolkit, and stores Customer Personal Information, using Amazon Web Services (AWS) and Laravel Cloud as its primary infrastructure Sub-processors. Depending on your configuration, Customer Personal Information may be processed and stored in Australia, the United States, the United Kingdom and Germany. Fluent Group requires its Sub-processors to protect Customer Personal Information consistently with this policy and applicable law, and remains accountable for their handling of that information as required by the Privacy Act 1988 (Cth). A current list of Sub-processors, including any change to the providers or countries named above, is available to a Client on request.
(e)Data breach notification If Fluent Group becomes aware of a data breach that has affected, or may have affected, Customer Personal Information, it will notify the relevant Client without undue delay and provide reasonably requested information and assistance to enable the Client to assess and, if required, notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
(f)Retention, return and deletion Fluent Group retains Customer Personal Information for as long as needed to provide the Services and in accordance with the applicable services agreement. On expiry or termination of a Client’s agreement, Fluent Group will delete or return Customer Personal Information within the period specified in that agreement (or, if none is specified, within 90 days), except to the extent retention is required by law or the information exists in routine backups pending their scheduled deletion.
(g)Access, correction and complaints An individual who believes Fluent Group holds Customer Personal Information about them, and who wishes to access or correct that information or complain about how it has been handled, should in the first instance contact the relevant Client, which is best placed to respond given its direct relationship with that individual. Fluent Group will give the Client reasonable assistance to respond to such requests. If it isn’t clear which Client to contact, or the Client can’t be identified, contact Fluent Group using the details in Section 14 and Fluent Group will assist so far as reasonably practicable.
(h)Data processing addendum The detailed terms governing Fluent Group’s handling of Customer Personal Information (including security standards, audit rights and specific sub-processor arrangements) are set out in the data processing terms incorporated into each Client’s services agreement. This section summarises those arrangements and does not limit them.
7. Direct marketing
Marketing communications via mail, email and social media require consent. Non-consent allows opt-out through contact details or opt-out facilities in communications. Personal data is not provided to other organisations for their direct marketing. Practices comply with Australia’s Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth). Suspected violations should be reported to the company.
This section applies to marketing communications from Fluent Group to individuals with whom it has a direct relationship. It does not apply to Customer Personal Information, which Fluent Group does not use for its own direct marketing (see Section 6(b)).
8. Unsolicited information
Unsolicited information is retained only where reasonably necessary for services and you’ve consented or consent was impractical. Otherwise it’s destroyed. Sensitive unsolicited information always requires consent before retention.
9. Overseas disclosure
Personal information may be shared with overseas service providers (IT, insurance, storage), representatives with consent, government bodies, regulators, law enforcement, and other entities identified at collection time.
Fluent Group’s primary hosting and infrastructure providers are Amazon Web Services (AWS) and Laravel Cloud. Personal information is likely to be processed and stored in Australia, the United States, the United Kingdom and Germany.
Transfers use safeguards: agreements with overseas recipients confirming Privacy Act compliance and standard contractual clauses for transfers. Comparable obligations are imposed on overseas recipients.
You may refuse overseas transfer by contacting the privacy officer, acknowledging this may prevent website or service use.
Overseas transfer of Customer Personal Information is addressed specifically in Section 6(d).
10. Using our website and cookies
Cookies are small data files stored on your device to improve experience. Three categories are used: functional cookies (operational improvement), analytics cookies (usage statistics), and advertising cookies (targeted advertising).
Cookies can be refused through browser settings, though this may limit website functionality.
11. Third parties
The website contains third-party links. These entities manage their own privacy practices, and you should review their policies. The company makes no representations about accuracy or completeness of third-party information and accepts no responsibility for third-party privacy practices. Integration with third parties doesn’t imply endorsement.
A list of the Sub-processors engaged to help deliver the Services is available to a Client on request, see Section 6(d).
12. Data retention
Personal information is retained as long as reasonably necessary for collection purposes, including legal, regulatory, tax and reporting requirements. Retention may extend if complaints or litigation prospects exist.
Retention periods consider information sensitivity, unauthorised use harm risks, processing purposes, alternative means availability, and applicable legal requirements. Anonymised information for research or statistics may be used indefinitely without notice.
Retention, return and deletion of Customer Personal Information on expiry or termination of a Client’s agreement is addressed in Section 6(f).
13. Age of consent
Websites and services are not intended for persons under 18. The company doesn’t knowingly collect personal data from children. Inadvertent child information is deleted in accordance with law.
14. How you can access or correct personal information
This section applies to personal information Fluent Group holds about you as a result of your own dealings with Fluent Group. If your personal information has been provided to Fluent Group by a Client through its use of the Services, see Section 6(g).
The company maintains accurate, timely, relevant information. Requested copies of held personal information are provided per Australian Privacy Principles. Inaccurate, outdated, incomplete, irrelevant or misleading information is corrected on notification.
No charges apply for access or correction requests, though excessive volume may incur reasonable administration fees. Access or correction requests contact:
Privacy Officer for Fluent Group
Post: GPO Box 3645, Sydney, NSW Australia 2001
Email: [email protected]
Responses follow reasonable timeframes per the Act. Refused requests include reasons and complaint information where reasonable.
Identity confirmation documentation may be requested before information is released.
15. Making a complaint
Complaints about the policy or information handling should initially be directed to the company at the above details. Investigation follows the Act. Unsatisfied complainants may contact the Office of the Australian Information Commissioner. Complaints concerning Customer Personal Information should be directed as set out in Section 6(g).
16. Privacy policy changes
The company may change this policy. The latest version on the website applies to all held personal information.
17. Further information
Further queries about the policy should contact the company. More information on the Act is available at www.oaic.gov.au.
18. Google APIs and limited use
This section is specific to FG Toolkit’s connection to Google. Where a Client connects a Google account, FG Toolkit uses that access for a narrow purpose: sending conversion data from the Client’s own CRM back to the Client’s own Google Ads account, and reading back the result of that upload so failures can be reported and retried.
FG Toolkit does not request, access or store the content of a person’s Gmail, Google Drive files, contacts, calendar or photos.
Information received from Google APIs is:
(a)used only to provide and improve the features the account owner has configured;
(b)never sold, and never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition or sale of assets with the user’s prior notice;
(c)never used for advertising purposes, including personalised, retargeted or interest-based advertising;
(d)never used to train, retrain or improve generalised or non-personalised artificial intelligence or machine learning models; and
(e)never read by a human, except with the account owner’s express consent, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.
FG Toolkit’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
An account owner can review and revoke FG Toolkit’s access at any time at myaccount.google.com/permissions. The same principles apply to every other platform FG Toolkit connects to: data retrieved is used only to run the relays the account owner has configured, is never sold, and is never used to train any artificial intelligence model.