1. Who we are and when this policy applies
Proe Ai Pty Ltd (ABN 55 696 128 631) operates PROE, an AI communication platform for real estate professionals.
This policy applies when we collect personal information directly through our website, sales, support and account administration, and when we process information through PROE. We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable privacy laws.
When an agency connects its email, messaging, calendar or CRM account, Proe generally processes the information in those systems on the agency's behalf and under its instructions. The agency decides why that information is collected and used. People dealing with a PROE customer should usually direct privacy requests to that agency first; we will assist the agency to respond.
2. Information we collect
Depending on how you interact with us, we may collect:
- Account and business information: name, agency, work email, phone number, role, authentication records and account preferences.
- Customer Data: information submitted to, stored in, transmitted through or made available to PROE by or for a Customer, including communications, attachments, contacts, CRM records, property references, calendar details, knowledge files and instructions.
- Information about correspondents: details about vendors, buyers, tenants, landlords, solicitors, tradespeople and others that naturally appear in communications and CRM records.
- Customer-specific derived data: prompts, outputs, classifications, tags, property links, priority scores, summaries, drafts, extracted fields, embeddings, retrieval indexes, account-specific profiles and any customer-specific fine-tuned model or other model artefact. These are Customer Data whether generated from Customer content or for the Customer.
- Service Data: content-free technical and operational information generated through use of PROE, such as IP address, browser and device details, app version, timestamps, feature events, job metadata, performance, crash and security signals. Service Data excludes Customer content, customer-specific outputs and information derived from either.
- Commercial information: plan, billing contact, invoices and payment status. If card payments are introduced, card details will be handled by a payment provider and Proe will not store full card numbers.
- Communications with Proe: demo requests, support tickets, feedback, survey responses and other correspondence.
PROE is not designed to collect sensitive information as a separate category. Customer communications may nevertheless contain sensitive or confidential material. Customers should only connect or upload information they are authorised to process and that is reasonably necessary for their use of the service.
3. How we collect information
We collect information directly from users and Customers, automatically from use of our website and applications, and from third-party services a Customer deliberately connects, including Google, Microsoft, WhatsApp through Unipile, Reapit Sales and Agentbox.
Property-portal enquiries may reach PROE through a connected mailbox. We do not obtain access to a connected account until an authorised user completes the provider's consent flow.
4. How we use information
We use personal information where reasonably necessary to:
- create, administer and secure accounts;
- mirror and organise connected communications and provider state;
- classify, prioritise, associate and summarise communications;
- prepare drafts, extractions and actions for user review;
- perform configured CRM, calendar, messaging and notification workflows;
- personalise and improve PROE for the relevant Customer's account or organisation;
- provide support, investigate incidents and recover the service;
- manage billing, contracts and business communications; and
- comply with law and protect the rights, safety and integrity of Customers, users, Proe and third parties.
We do not sell Customer Data or personal information, use it for third-party advertising, or disclose it to data brokers.
5. Customer Data, ownership and Service Data
As between Proe and the Customer, all rights in Customer Data remain with the Customer. Proe acquires no ownership interest in Customer Data. We process it only to provide, secure, maintain, troubleshoot, support and improve PROE for that Customer's account or organisation, follow the Customer's lawful instructions, enforce the customer agreement and comply with law.
Proe does not use Customer Data, including customer-specific derived data, to train, fine-tune, evaluate, benchmark or otherwise improve any model, dataset, algorithm or feature that serves another customer. We do not use it for cross-customer analytics, benchmarks, research, market intelligence or advertising.
Proe may use content-free Service Data to secure, operate, measure, support and improve the shared PROE platform. If technical or operational data contains Customer content, a customer-specific output or information derived from either, it is Customer Data rather than Service Data. We may use voluntary feedback for general platform improvement only where it does not contain Customer Data or Customer Confidential Information, or where the Customer separately authorises that use.
6. AI processing and human responsibility
PROE may use relevant Customer Data to classify messages, rank priority, associate communications with a property, extract information, generate summaries, prepare draft replies and support configured CRM workflows for the relevant Customer. Relevant excerpts may be sent securely to approved AI API providers solely for that inference.
Neither Proe nor its AI providers uses Customer Data to train, fine-tune, evaluate, benchmark or improve a public, foundation, private or proprietary model, dataset, algorithm or feature serving another customer. This restriction applies to message content, attachments and all customer-specific derived data, including prompts, outputs, embeddings, retrieval indexes, account-specific profiles and any customer-specific fine-tuned model or other model artefact.
Our AI providers are used through commercial business/API services under terms that do not permit training on or model improvement from Proe API inputs or outputs. Standard provider safety and abuse-monitoring processes may retain submitted inputs and outputs for up to 30 days unless a zero-data-retention arrangement or shorter period applies. OpenAI requests explicitly disable application-state storage where supported.
PROE is a decision-support tool. It does not autonomously accept or reject an offer, allocate housing, enter a contract, decide whether a person may buy, lease or receive a service, or send an outbound customer communication without a deliberate user action. Users remain responsible for substantive decisions and outbound communications. A configured workflow may write an activity note to an already matched CRM contact; contact creation or material enrichment remains human-approved.
7. Google Workspace data
PROE accesses Google Workspace data only after an authorised user grants the requested OAuth permissions and only to provide the visible Gmail and Google Calendar features described in the service.
PROE's use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google-derived data is not sold, used for advertising, transferred to data brokers, or used to train, evaluate or improve a model, dataset, algorithm or feature serving another customer. It is not used for cross-customer analytics, benchmarks, research or market-intelligence products. Calendar data is used to display availability and events and to perform scheduling actions the user confirms.
Personnel do not read Google-derived content except with the user's specific consent, where necessary for authorised support, security, abuse investigation or recovery, or where required by law.
8. When we disclose information
We disclose information only where reasonably necessary:
- to approved subprocessors that host or support PROE, process AI requests, deliver notifications, or operate a Customer-connected service, and to analytics or diagnostics providers that receive only Service Data;
- to a connected provider when a user asks PROE to read, update, send or synchronise information;
- to professional advisers, insurers or auditors under confidentiality obligations;
- where required or authorised by law, court order or a regulator.
Our current material subprocessors and processing locations are listed in the Data Processing Addendum. A more detailed subprocessor register is available in the full security pack.
9. Overseas processing
Our primary production database, authentication, file storage, application compute and private job infrastructure are hosted in Australia. Some approved providers process limited information overseas, including in the United States, European Union and global provider infrastructure.
This includes AI inference in the United States; global email, calendar and mobile-push infrastructure; and analytics and error diagnostics in the United States. We take reasonable steps appropriate to the relationship and applicable law when selecting and using overseas providers, including reviewing contractual, privacy, security, location and permitted-use terms.
10. Security
We take reasonable technical and organisational steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit, managed platform encryption at rest for stored Customer Data, additional AES-256-GCM application-layer encryption for selected credentials and secret fields, organisation-scoped authorisation, least-privilege production access, personnel MFA for administrative systems, controlled secrets, dependency monitoring and an incident-response process.
No service can guarantee absolute security. Security issues may be reported privately to our CTO at alex@proe.ai.
11. Retention, export and deletion
We retain information only for as long as reasonably needed to provide the service, meet legal and contractual obligations, resolve disputes and protect the service.
Raw AI prompts, model responses and diagnostic traces retained by Proe are kept for no more than 30 days. User-visible outputs and customer-specific learning needed to provide the configured service may be retained while the account is active; they remain Customer Data and are used only for that Customer's account or organisation.
Customers may request an export of their Customer Data in a commonly used machine-readable format before termination. Following termination or a valid deletion instruction, Proe deletes Customer Data from active systems within 30 days unless applicable law requires retention. Deleted information may remain temporarily in protected rolling provider backups until it ages out under the provider's normal backup lifecycle; it will not be restored except for disaster recovery and remains subject to this policy while retained.
Disconnecting a connected account initiates removal of its local mirror through the applicable product workflow. Limited account, billing, security and legal records may be retained where reasonably necessary.
12. Access, correction and complaints
You may ask to access or correct personal information Proe holds about you. We may need to verify your identity and may decline or limit a request where permitted by law. If the information is controlled by a Customer agency, we will direct the request to that Customer and assist it as required.
Privacy questions and complaints may be sent to our Privacy Officer at nick@proe.ai. Please describe the issue and the outcome you seek. We will investigate and respond within a reasonable period, usually within 30 days.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner on 1300 363 992.
13. Marketing, cookies and analytics
We may send business contacts information about PROE where permitted by law. Marketing messages include an unsubscribe method, and you can opt out at any time.
Our website and applications use essential storage and cookies for sessions and preferences and may use PostHog to understand performance and feature use. Analytics and session replay are configured to receive content-free Service Data and exclude Customer content and customer-specific outputs. Browser controls can limit cookies, although some features may then not work correctly.
14. Changes and contact
We may update this policy as our service, providers or legal obligations change. We will publish the revised policy with a new date and provide additional notice where a change is material or consent is required.
Privacy enquiries: nick@proe.ai
Security enquiries: alex@proe.ai
Book demo