← Legal & compliance

Privacy Policy

Last updated 7 July 2026 · HAMANI Marketing

This policy explains how HAMANI PTY LTD (“HAMANI”, “we”) handles personal information in HAMANI Marketing, consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Our role

For your account data we are the controller. For the contact lists and campaigns you create, we act as a processoron your behalf — you are the controller of your audience’s personal information and remain responsible for having a lawful basis and consent to contact them.

Your account

By default you sign in with an email and password managed by HAMANI. For your account we store only your email address, a one-way password hash (PBKDF2-SHA256; we never store your password), and an essential, signed session cookie that keeps you logged in. We use no analytics or advertising cookies.

When you create a workspace we send a verification email to confirm the address is yours — the account cannot be signed in to until the emailed link is used. If you forget your password you can request a password reset link. For both we store only a one-way hash of the token (SHA-256; the link itself exists only in the email we send you), which account it belongs to and when it expires. Each link is single-use and time-limited (verification 24 hours, reset 1 hour), requesting a new link replaces the old one, and the token records are erased with your account. These are account service emails, not marketing.

Enterprise customers may federate their own identity provider for single sign-on (SAML 2.0 or OIDC). In that case we receive from your provider only what is needed to sign you in — your email address and a stable identifier — and HAMANI remains the system of record for your account and workspace. We do not receive your password from your provider, and there is no shared identity provider across HAMANI products.

You can also sign in with Google or Microsoft(no password). Either provider’s sign-in also shares your name (and, with Google, a profile photo) as a standard part of signing in — we receive but do not store your name or photo; we keep only your email address and a stable identifier, the same as any other account.

You can add a passkey (Face ID, Touch ID, Windows Hello or an Android biometric) to sign in without a password. Your biometric never leaves your device— we store the passkey’s public key, a usage counter, the name you give it and when it was added; none of this can reconstruct your fingerprint or face. Passkeys are erased with your account when you delete your workspace. A passkey is an additional way in; your password still works.

Setting up your business profile

To help you set up quickly, we can learn a starting profile of your own business. If you provide a website address or Google Business Profile, we fetch only the address you give us— your own public web presence — read its public text, and use it (together with your business name and ABN) to infer your likely industry, what you offer, your price positioning and who your customers are. We do not crawl beyond the address you provide and we do not fetch other people’s private data.

The fetched public content is sent to our AI sub-processor (Anthropic) to draft the profile; a deterministic classifier does this when the AI is off. The result is stored in your workspace as an editable draft that you review and confirm — nothing is applied until you do. Your ABN is checked for a valid format locally. The saved profile is your workspace data, covered by the export and deletion rights below.

Billing information

When you top up, we store your prepaid balance, a credit/debit ledger, and the GST tax invoiceswe issue (amount, GST, date). Card payments are handled by our payment provider (Stripe) — we do not store your card details. We keep invoices as long as tax law requires.

Data residency

Primary application data is provisioned in Sydney, Australia (Google Cloud australia-southeast1), verified at go-live. Edge cache and static assets may be distributed globally via our CDN.

Sub-processors

We share personal information only with vetted sub-processors: Google (Firebase/Firestore), our CDN, Stripe (billing), Amazon Web Services (SES, email delivery, via HAMANI's own Email engine), and Anthropic (HAMANI CONCIERGE AI). The current sub-processor list is published on the Trust Centre.

Marketing messages & tracking

When you send through HAMANI, recipient email addresses, delivery status and opt-out status are processed to run your campaign. Every marketing message carries one-click unsubscribe and clear sender identification consistent with the Spam Act 2003 (Cth) (ACMA). We do not use covert open or click tracking.

API & webhooks

If you use the API, requests are authenticated with your API keys (we store only a one-way hash of each key, plus its label, permissions and last-used time). API actions are recorded in your workspace’s audit history the same way in-app actions are. If you register webhook endpoints, we deliver event data (for example campaign ids, contact ids, delivery status, wallet balance thresholds) to those endpoints you control — signed so you can verify each delivery came from us, with per-delivery logs kept in your workspace. The security of a webhook endpoint and anything stored behind it is your responsibility; we stop delivering to an endpoint that keeps failing.

Agencies & client sub-accounts

Some businesses use HAMANI through a marketing agency. In that case the agency runs a separate sub-account for each client business: the agency decides which campaigns are sent and to whom, and we act on the agency’s instructions, handling the audience information in each sub-account under this policy and the APPs. Each client’s contacts and campaigns are stored separately from every other client’s.

Access is limited: the agency’s owner, and only the staff the owner assigns to your sub-account, can see its data — and every action an agency takes in a sub-account is recorded in both audit histories(the sub-account’s and the agency’s), so there is always a record of who did what. Messages sent for an agency client may show the agency’s brand, but sender identification and one-click unsubscribe appear on every message regardless of branding. If you have a privacy question about a campaign an agency sent for a business, you can contact us or the sender identified in the message.

Commands, voice & notifications

Typed commands you run are recorded in your workspace’s audit history (the command text and what it did), so you can always see what changed and when. If you use the voice option, speech-to-text and text-to-speech happen in your browser’s own speech servicesno voice recording reaches HAMANI’s servers; only the resulting text command does, exactly as if you had typed it. Spend suggestions and their approve/decline decisions are stored with your account so the record of what you authorised is always available to you.

Your rights & retention

You may request access to, correction of, or deletion of your personal information. From Settings → Data & governance you can export a machine-readable copy of your whole workspace and your audit log, and from Settings → Account you can delete your workspace. Deletion is verified (we re-check that no personal records remain) and a deletion record is retained as proof. We retain records only as long as needed for the service or as required by law; the full retention schedule and sub-processor list are on the Trust Centre.

Unresolved privacy complaints may be referred to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

HAMANI PTY LTD · ACN 696 864 981 · ABN 48 696 864 981