Privacy Policy
Your privacy is a top priority at Smartmates. Our Privacy Policy details how we collect, use, and safeguard your personal information to ensure your data is protected in compliance with relevant privacy laws. We’re committed to maintaining your trust by keeping your data secure and confidential every step of the way.

Protecting your personal information is fundamental to how we operate. This Privacy Policy outlines the measures we take to collect, use, and safeguard your data while ensuring compliance with privacy regulations. By maintaining transparency and security in our data practices, we strive to build a trusted relationship with every client. Below, we detail how your information is handled and protected throughout your interactions with us.

1. Introduction
At Smartmates, we take the security and privacy of our clients’ data seriously. This policy describes how we access, handle, and protect client data in the course of delivering our services. It has been written to accurately reflect our actual day-to-day practices.
Smartmates operates as a Zoho implementation and consulting partner. Our engineering team is based in Bali, Indonesia (PT Smartmates Software Engineering), delivering services to clients primarily in Australia and New Zealand.
2. Scope
This policy applies to all Smartmates staff, contractors, and subcontractors who access client systems or handle client data in the course of providing our services. It covers activities including consulting, implementation, support, and maintenance.
3. Platforms We Use
Smartmates does not operate proprietary data infrastructure. All work is always conducted through industry-leading, enterprise-grade platforms. The security of client data is primarily governed by the security frameworks of these platforms.
3.1 Google Workspace
All internal communications, file storage, and video conferencing are conducted through Google Workspace, covering:
- Email (Gmail)
- File storage and document sharing (Google Drive)
- Video meetings (Google Meet)
Google Workspace provides enterprise-grade security including end-to-end encryption (TLS and AES-256), advanced threat protection, and compliance with SOC 2, ISO 27001, ISO 27018, and GDPR.
Full details:
https://workspace.google.com/security/
3.2 Zoho
All client-facing project work is delivered through Zoho’s platform. Zoho provides robust security including SSL encryptions, role-based access control, geographically redundant data backups, and compliance with international data protection standards.
Full details:
https://www.zoho.com/security.html
3.3 Zoho Vault (Password Management)
All Smartmates staff use Zoho Vault as our company-wide password manager. Client credentials are stored securely in Zoho Vault and are never shared via email, chat, or any unsecured channel. Access to credentials is limited to staff assigned to the relevant project.
4. How We Access Client Systems
Smartmates staff access client Zoho environments by logging in directly to the client’s account using credentials arranged with the client.
4.1 Dedicated Chrome Profiles
Every Smartmates staff member is required to use a dedicated Google Chrome browser profile for each client they work with. This is an enforced, company-wide practice. Dedicated profiles ensure that:
- Client sessions are fully isolated from one another
- No cross-contamination of cookies, cached credentials, or browsing data can occur between clients
- Client data is not inadvertently accessible outside the relevant profile
4.2 Need-to-Know Access
Access to client systems is limited to staff members directly assigned to that client’s project. These credentials are shared only with the relevant team members.
4.3 Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) is used across all core systems where applicable to provide an additional layer of account security. OTP (one-time password) requests may be required during the course of accessing client systems.
5. Data Handling Practices
5.1 Data Access
Our team accesses client data strictly to deliver the services agreed in the project scope. We do not access, copy, or retain client data beyond what is necessary for project delivery.
5.2 No Proprietary Data Storage
Smartmates does not store client business data on its own servers or proprietary infrastructure. Smartmates primarily accesses client systems remotely, and client business data remains hosted within the client’s own system environment and the applicable third-party platforms authorised by the client or used by Smartmates in connection with the services. Such platforms are subject to their respective data hosting, privacy and security frameworks.
Where reasonably required for the delivery of the services, limited client information may be processed or temporarily transmitted through authorised third-party business, productivity, collaboration, automation or AI services, subject to Smartmates’ applicable security and privacy requirements and the relevant client agreement. Smartmates does not use such services as proprietary storage infrastructure for client business data.
Files or information shared directly with Smartmates for project purposes are used solely for the relevant project purpose and handled in accordance with the applicable confidentiality, privacy and security requirements.
5.3 No Third-Party Data Sharing
We do not share or disclose client data to third parties except where required to deliver agreed services or comply with legal obligations.
5.4 Communication Security
All client communication is conducted through Google Workspace (Gmail and Google Meet), which provides enterprise-grade encryption in transit and at rest.
5.5 Client Responsibility and Access Control
Clients retain full control and responsibility over user access within their own systems. This includes managing user permissions, access rights, and password policies within their Zoho environment or other platforms where required. Smartmates does not manage or administer client-side user access controls.
5.6 Use of Artificial Intelligence-Assisted Tools
Smartmates may use approved business, enterprise, private or embedded AI service, automation, and machine-assisted productivity tools to support the administration and delivery of its services. These may include business or enterprise AI services and AI functionality embedded within authorised software platforms, including Zoho.
AI-assisted tools may be used for activities such as drafting and refining communications, organising or summarising information, identifying action items, supporting research and analysis, assisting with preliminary technical work, and improving internal productivity.
AI is used as a supporting tool and does not replace professional judgement. AI-generated material is treated as preliminary or supporting content, and material technical recommendations, configurations, development decisions and client-facing deliverables remain subject to appropriate review by Smartmates personnel before being relied upon or implemented.
Smartmates personnel are required not to enter Client Confidential Information, sensitive personal information, client datasets, system exports, source code, architecture diagrams, flowcharts, confidential documents or other proprietary client material into publicly accessible consumer AI services. Publicly accessible AI services may be used for general research, drafting or productivity purposes where the information used is non-confidential, publicly available, appropriately de-identified, or otherwise does not disclose protected client information. Passwords, API keys, access tokens, authentication credentials, MFA codes or other security credentials must not be entered into any AI service.
Where reasonably required in connection with the services, Smartmates may use approved business, enterprise, private or embedded AI services to process information relevant to a client engagement. Smartmates will assess, to the extent reasonably practicable, the relevant provider, service configuration and available contractual, privacy and security protections, including how information may be accessed, retained, disclosed or used for model training. Where Client Confidential Information or personal information relating to the Client is involved for the intended use and consistent with applicable law, the relevant client agreement and Smartmates’ internal security requirements. Smartmates will take reasonable steps to minimise the amount of Client Confidential Information or personal information provided to an AI service and will use de-identification, redaction or other data-minimisation measures where reasonably practicable. Approval of an AI platform or feature may depend on the particular service, account type, configuration and underlying AI provider. The fact that an AI feature is embedded within an otherwise approved business platform does not, by itself, mean that every AI feature or external AI integration within that platform is approved for use with Client Confidential Information.
AI services and underlying models are provided and operated by third-party technology providers. Smartmates does not control and does not warrant the continued availability, functionality, accuracy, security practices or future operation of those third-party services. Smartmates may review, restrict, replace or discontinue the use of an AI service where its security, privacy, contractual arrangements, functionality or suitability changes. Any client-specific restrictions on the use of AI should be documented and agreed in writing as part of the applicable engagement. This section is intended to provide transparency regarding Smartmates’ use of AI-assisted tools. It does not create any additional warranty, representation, service level, indemnity or liability beyond those expressly contained in the applicable written agreement or required by law. The use of AI-assisted tools does not alter the agreed scope of services, Smartmates’ time-based consulting model, or the exclusions, limitations and allocation of risk contained in the applicable Service Agreement.
6. Staff Practices & Responsibilities
All Smartmates staff are required to:
- Use a dedicated Chrome profile per client — mandatory and enforced company-wide
- Store and access all client credentials through Zoho Vault
- Never share client credentials via unsecured channel
- Never download or copy client data to personal devices or unsanctioned storage
- Report any suspected security incident to management immediately
7. Incident Response
In the event of a suspected or confirmed security incident affecting client data, Smartmates will:
- Notify the affected client as soon as reasonably practicable after becoming aware of a confirmed data security incident
- Take immediate steps to contain and assess the impact
- Cooperate with the client and relevant authorities as required
- Document the incident and take corrective action to prevent recurrence
Smartmates will comply with applicable Australian data protection notification obligations under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme.
8. Data Retention
Smartmates does not operate proprietary storage for client business data. Any files temporarily shared with Smartmates for project purposes will be deleted upon project completion or earlier request by the client. Google Meet recordings of client sessions are retained for a maximum of 90 days, in line with our Terms of Service, after which they are permanently deleted.
9. Client Rights
Clients may at any time:
- Request information about what data Smartmates has access to on their behalf
- Request deletion of any files shared with Smartmates
- Update credentials or permissions within their own Zoho or HubSpot environment
- Raise a data privacy concern by contacting us at the details below
10. Policy Review
This policy is maintained and reviewed by the Smartmates Management Team to ensure it remains accurate and aligned with current operational practices. It will be updated as our practices evolve. The current version is always available on request.

