Security Policy
At Smartmates, we prioritise the security, privacy, and integrity of our clients’ data. Our Security Policy outlines how we access, manage, and safeguard information across every stage of our engagement. It is designed to provide full transparency into our day-to-day practices, ensuring alignment on how data is handled while delivering Zoho solutions. Review this policy to understand the measures we take to protect your information and maintain a secure working environment throughout our collaboration.

1. Introduction
At Smartmates, we take the security and privacy of our clients’ data seriously. This policy describes how we access, handle, and protect client data in the course of delivering our services. It has been written to accurately reflect our actual day-to-day practices.
Smartmates operates as a Zoho implementation and consulting partner. Our engineering team is based in Bali, Indonesia (PT Smartmates Software Engineering), delivering services to clients primarily in Australia and New Zealand.
2. Scope
This policy applies to all Smartmates staff, contractors, and subcontractors who access client systems or handle client data in the course of providing our services. It covers activities including consulting, implementation, support, and maintenance.
3. Platforms We Use
Smartmates does not operate proprietary data infrastructure. All work is always conducted through industry-leading, enterprise-grade platforms. The security of client data is primarily governed by the security frameworks of these platforms.
3.1 Google Workspace
All internal communications, file storage, and video conferencing are conducted through Google Workspace, covering:
- Email (Gmail)
- File storage and document sharing (Google Drive)
- Video meetings (Google Meet)
Google Workspace provides enterprise-grade security controls, including encryption of data in transit and at rest, advanced threat-protection capabilities, identity and access controls, and internationally recognised security and privacy frameworks.
Full details:
https://workspace.google.com/security/
3.2 Zoho
All client-facing project work is delivered through Zoho’s platform. Zoho provides robust security including SSL encryptions, role-based access control, geographically redundant data backups, and compliance with international data protection standards.
Full details:
https://www.zoho.com/security.html
3.3 Zoho Vault (Password Management)
All Smartmates staff use Zoho Vault as our company-wide password manager. Client credentials are stored securely in Zoho Vault and are never shared via email, chat, or any unsecured channel. Access to credentials is limited to staff assigned to the relevant project.
4. How We Access Client Systems
Smartmates staff access client Zoho environments by logging in directly to the client’s account using credentials arranged with the client. For HubSpot, Client must invite Smartmates to their environment using the available Partner Seat. The following practices govern this access.
4.1 Dedicated Chrome Profiles
Every Smartmates staff member is required to use a dedicated Google Chrome browser profile for each client they work with. This is an enforced, company-wide practice. Dedicated profiles ensure that:
- Client sessions are fully isolated from one another
- No cross-contamination of cookies, cached credentials, or browsing data can occur between clients
- Client data is not inadvertently accessible outside the relevant profile
4.2 Need-to-Know Access
Access to client systems is limited to staff members directly assigned to that client’s project. These credentials are shared only with the relevant team members.
4.3 Multi-Factor Authentication (MFA)
Multi-Factor Authentication (MFA) is required for Smartmates-controlled access to core business systems where MFA is supported by the relevant platform. OTP (one-time password) requests may also be required when accessing client environments, depending on the client’s own security configuration.
5. Data Handling Practices
5.1 Data Access
Our team accesses client data strictly to deliver the services agreed in the project scope. We do not access, copy, or retain client data beyond what is necessary for project delivery.
5.2 No Proprietary Data Storage
Smartmates does not store client business data on its own servers or proprietary infrastructure. Smartmates primarily accesses client systems remotely, and client business data remains hosted within the client’s own system environment and the applicable third-party platforms authorised by the client or used by Smartmates in connection with the services. Such platforms are subject to their respective data hosting, privacy and security frameworks.
Where reasonably required for the delivery of the services, limited client information may be processed or temporarily transmitted through authorised third-party business, productivity, collaboration, automation or AI services, subject to Smartmates’ applicable security and privacy requirements and the relevant client agreement. Smartmates does not use such services as proprietary storage infrastructure for client business data.
Files or information shared directly with Smartmates for project purposes are used solely for the relevant project purpose and handled in accordance with the applicable confidentiality, privacy and security requirements.
5.3 No Third-Party Data Sharing
We do not share or disclose client data to third parties except where required to deliver agreed services or comply with legal obligations.
5.4 Communication Security
All client communication is conducted through Google Workspace (Gmail and Google Meet), which provides enterprise-grade encryption in transit and at rest.
5.5 Client Responsibility and Access Control
Clients retain ultimate ownership and control of user access within their own systems, including responsibility for approving users, permissions, access rights and password policies. Where access-control configuration forms part of the agreed project scope, Smartmates may configure roles, permissions or other access settings on the Client’s behalf and in accordance with the Client’s instructions. Smartmates does not independently grant or maintain access beyond what is authorised by the Client.
5.6 Use of Artificial Intelligence-Assisted Tools
Smartmates may use approved business, enterprise, private or embedded AI service, automation, and machine-assisted productivity tools to support the administration and delivery of its services. These may include business or enterprise AI services and AI functionality embedded within authorised software platforms, including Zoho.
AI-assisted tools may be used for activities such as drafting and refining communications, organising or summarising information, identifying action items, supporting research and analysis, assisting with preliminary technical work, and improving internal productivity.
AI is used as a supporting tool and does not replace professional judgement. AI-generated material is treated as preliminary or supporting content, and material technical recommendations, configurations, development decisions and client-facing deliverables remain subject to appropriate review by Smartmates personnel before being relied upon or implemented.
Smartmates personnel are required not to enter Client Confidential Information, sensitive personal information, client datasets, system exports, source code, architecture diagrams, flowcharts, confidential documents or other proprietary client material into publicly accessible consumer AI services. Publicly accessible AI services may be used for general research, drafting or productivity purposes where the information used is non-confidential, publicly available, appropriately de-identified, or otherwise does not disclose protected client information. Passwords, API keys, access tokens, authentication credentials, MFA codes or other security credentials must not be entered into any AI service.
Where reasonably required in connection with the services, Smartmates may use approved business, enterprise, private or embedded AI services to process information relevant to a client engagement. Smartmates will assess, to the extent reasonably practicable, the relevant provider, service configuration and available contractual, privacy and security protections, including how information may be accessed, retained, disclosed or used for model training. Where Client Confidential Information or personal information relating to the Client is involved, any such use must be reasonably necessary for the intended business purpose and consistent with applicable law, the relevant client agreement and Smartmates’ internal security requirements. Approval of an AI platform or feature may depend on the particular service, account type, configuration and underlying AI provider. The fact that an AI feature is embedded within an otherwise approved business platform does not, by itself, mean that every AI feature or external AI integration within that platform is approved for use with Client Confidential Information.
AI services and underlying models are provided and operated by third-party technology providers. Smartmates does not control and does not warrant the continued availability, functionality, accuracy, security practices or future operation of those third-party services. Smartmates may review, restrict, replace or discontinue the use of an AI service where its security, privacy, contractual arrangements, functionality or suitability changes. Any client-specific restrictions on the use of AI should be documented and agreed in writing as part of the applicable engagement. This section is intended to provide transparency regarding Smartmates’ use of AI-assisted tools. It does not create any additional warranty, representation, service level, indemnity or liability beyond those expressly contained in the applicable written agreement or required by law. The use of AI-assisted tools does not alter the agreed scope of services, Smartmates’ time-based consulting model, or the exclusions, limitations and allocation of risk contained in the applicable Service Agreement.
6. Staff Practices & Responsibilities
All Smartmates staff are required to:
- Use a dedicated Chrome profile per client — mandatory and enforced company-wide
- Store and access all client credentials through Zoho Vault
- Never share client credentials via unsecured channel
- Never download or copy client data to personal devices or unsanctioned storage
- Report any suspected security incident to management immediately
7. Incident Response
In the event of a suspected or confirmed security incident affecting client data, Smartmates will:
- Notify the affected client as soon as reasonably practicable after becoming aware of a confirmed data security incident
- Take immediate steps to contain and assess the impact
- Cooperate with the client and relevant authorities as required
- Document the incident and take corrective action to prevent recurrence
Smartmates will comply with applicable Australian data protection notification obligations under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme. Smartmates will also comply with any other applicable privacy, data-protection or breach-notification requirements relevant to the Client or the engagement.
8. Data Retention
Smartmates does not operate proprietary storage for client business data. Any files temporarily shared with Smartmates for project purposes will be deleted upon project completion or earlier request by the client. Google Meet recordings of client sessions are retained for a maximum of 90 days, in line with our Terms of Service, after which they are permanently deleted.
9. Client Rights
Clients may at any time:
- Request information about what data Smartmates has access to on their behalf
- Request deletion of any files shared with Smartmates
- Update credentials or permissions within their own Zoho or HubSpot environment
- Raise a data privacy concern by contacting us at the details below
10. Policy Review
This policy is maintained by the Smartmates Management Team and reviewed periodically, and whenever there is a material change to Smartmates’ security, data-handling or technology practices. It will be updated as our practices evolve. The current version is available to clients on request.

