Privacy
P6M Privacy Policy
Last updated: 25 May 2026
This policy explains how Platform Team handles personal information and customer data when providing hosted P6M services through p6m.xyz. It is intended to align with the Australian Privacy Principles where they apply.
1. Information we collect
We may collect account information such as names, email addresses, organisation names, billing details, payment provider identifiers, support messages, authentication events, audit events, usage records, IP addresses, device and browser metadata, API request metadata, and customer payload data submitted to enabled P6M domains.
2. How we use information
We use information to create and operate accounts, provide hosted domains, authenticate users and API keys, enforce quotas and billing limits, process payments, calculate usage, provide support, maintain security, investigate abuse, improve the platform, and comply with legal obligations.
3. Customer data and ownership
Customer data remains owned by the customer. P6M processes customer data only to provide, secure, support, meter, back up, and operate the hosted platform, unless the customer directs otherwise or the law requires a different use.
4. Payment processing and GST
Payment details may be collected and processed by Stripe or another payment provider. We may store payment provider customer IDs, checkout session IDs, subscription or billing status, tax-relevant billing details, and invoice metadata. We use this information to charge fees, apply free credits, calculate GST or other taxes where applicable, and reconcile billing records.
5. Support access
Platform support personnel may access account, audit, billing, support, and operational metadata to help resolve issues. Access to customer payload data is limited to what is needed to provide support. Where customer-held encryption keys are used, support cannot decrypt encrypted payloads unless the customer explicitly authorises access and provides the required key material or decrypted data.
6. Disclosure to service providers
We may disclose information to service providers that help us host, secure, monitor, bill, email, support, or operate P6M. Examples include cloud infrastructure, payment processing, logging, monitoring, and support tooling providers. We require service providers to handle information consistently with their role in delivering the service.
7. International disclosure
Some service providers may process or store information outside Australia. Where the Australian Privacy Principles apply, we will take reasonable steps to handle cross-border disclosures consistently with those principles.
8. Security
We use technical and organisational controls intended to protect information, including authentication, access controls, audit logging, encryption support, gateway controls, and operational monitoring. No hosted service can guarantee absolute security. Customers must protect their own credentials, API keys, and customer-held keys.
9. Retention and deletion
We retain information for as long as needed to provide the service, comply with law, resolve disputes, maintain security, recover from incidents, and keep billing and audit records. Customers may request export or deletion subject to plan capabilities, technical feasibility, legal requirements, backup cycles, and legitimate operational needs.
10. Access, correction, and complaints
You may request access to or correction of personal information we hold about you. You may also complain about how we handle personal information. Contact Platform Team through the hosted portal support channel or the contact details published by Platform Team. We will respond within a reasonable period.
11. Changes
We may update this Privacy Policy as the hosted service changes. Material updates will be published on this page or notified through the product.
12. Governing law
This policy is governed by the laws of Queensland, Australia and the laws of the Commonwealth of Australia in force in Queensland.