Privacy policy

Last updated 8 September 2026

This policy explains how Acacia Data Pty Ltd handles personal information in connection with Wattle Branch. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Wattle Branch reports information published by government about government spending. That published material is not covered by this policy. This policy is about the people who hold an account with us.

What we collect, and why

  • Your email address. It is how you sign in and how an invitation reaches you.
  • Your name, if you give us one. Optional. It is shown to your organisation's administrators so an account is identifiable.
  • Your organisation and your role in it, where you belong to one, so seats can be counted and managed.
  • Your password, stored only as a cryptographic hash by our authentication provider. We never see it and cannot read it.
  • Your two step sign in secret, generated and stored by our authentication provider. It is shown to you once, in your browser, when you set it up. We do not store or transmit it.
  • Sign in times and last activity, so an administrator can tell an unaccepted invitation from a dormant account, and so we can enforce one session per account.
  • Security events, being the fact that you signed in, set up or reset two step sign in, or were issued a sign in link. These are kept as an append only record.
  • That you asked the assistant a question, the time, what it cost, and the shape of the answer. We do not record the question itself or the answer.
  • Views you save, entities you watch, and the news matched to them, so the product can take you back to a search and tell you when something changes.
  • Support requests you send us, along with the page you were on and its filters, so we can reproduce what you saw. Where you report a problem with an answer from the assistant, that exchange is included, and the form says so before you send it.

What we deliberately do not collect

We do not collect your IP address, your device or browser details, your location, or a record of the pages you visit. We do not use analytics, advertising, session recording or any third party tracker. Nothing in the product loads one.

We never see or store your payment details. When paid subscriptions start, card details will be handled entirely by Stripe and our systems will hold nothing but an opaque customer reference.

Cookies and what is stored on your device

We store as little on your device as the product can work with, and all of it is strictly necessary. There is no analytics cookie, no advertising cookie and no third party tracker anywhere in the product.

  • Your sign in session. Set when you sign in and cleared when you sign out. It ends after two hours without any activity, so a session you walk away from does not stay open. Without it you cannot stay signed in at all.
  • A record of the cookie notice. One cookie that says you have seen it, so it is not shown again. It expires after twelve months, and it holds nothing but a version number.
  • Your own settings, in your browser rather than in a cookie. Whether you chose light or dark, which guided tours you have seen, and anything you were part way through. These stay on that device, are never sent to us, and are cleared when you clear your browser data.

Because none of this is optional, there is nothing here to switch off: refusing the session cookie would only mean you could not sign in. If we ever add anything that is not strictly necessary, we will ask you first and you will be able to say no. You can delete all of it at any time through your browser, and signing out clears the session.

The one external request the product makes is for the background map tiles on the world view, which are fetched by your browser from a map provider. They set no cookie of ours, and that provider sees only what any web request reveals.

Who else can see it

If you belong to an organisation, its administrators can see your name, email, role and whether your seat is active. They cannot see the views you save, the things you watch, or anything you ask the assistant. That is enforced by the database rather than by a setting.

We use service providers to run the product: hosting and databases in Australia, an authentication provider, an email delivery provider, and a provider for the assistant feature. We do not sell personal information to anyone, and we do not disclose it for marketing.

Where it is held

Our database and application are hosted in Australia, in the Sydney region. Some service providers may process limited information overseas in the course of delivering their service, for example when an email is sent.

How long we keep it

We keep account information for as long as the account exists. Where access is withdrawn we keep the record rather than deleting it, because an organisation needs to be able to answer when somebody left. Security events are kept as a permanent record and cannot be edited.

Getting at it, correcting it, or complaining

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account. Write to support@wattlebranch.au and we will respond within a reasonable time.

If you are not satisfied with how we have handled a privacy matter, you can complain to us at the same address. If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes

Wattle Branch is under active development. When we change what we collect we change this page, and the date at the top of it, at the same time.