Legal

Privacy Policy

Last updated: August 2026

1. About this Privacy Policy

QUCHR is an Australian safety and compliance intelligence platform for businesses.

This Privacy Policy explains how QUCHR Pty Ltd as trustee for The Radatti Family Trust, trading as QUCHR, ABN 93 709 631 226, collects, holds, uses, discloses and protects personal information when you use QUCHR, visit our website or contact us.

QUCHR is currently offered to Australian businesses.

This policy is intended to provide transparent information about our privacy practices and to address applicable Australian privacy requirements, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

2. Personal information we collect

The information we collect depends on how you use QUCHR and may include:

  • your name, email address, organisation details and account information
  • authentication, session and security information associated with your account
  • documents and information you choose to upload to QUCHR
  • text extracted from uploaded documents so that QUCHR can analyse and retrieve relevant information
  • questions, conversations and prompts you submit through QUCHR
  • citations, responses and other information generated while using the service
  • technical information reasonably required to operate, secure and troubleshoot the service
  • information you provide when contacting us for support or making a privacy request

Documents uploaded by organisations may sometimes contain personal information about other people. Depending on the document, this could also include sensitive information such as workplace injury or health information.

Organisations using QUCHR are responsible for ensuring they have the appropriate authority to upload and use information relating to other individuals.

3. How we collect information

We generally collect personal information directly from you when you create an account, use QUCHR, upload documents, ask questions, communicate with us or otherwise interact with the service.

We may also receive information through authentication providers or from an organisation using QUCHR where that organisation is authorised to provide the information.

4. Why we use personal information

We may use personal information to:

  • create and manage QUCHR accounts
  • authenticate users and protect accounts against unauthorised access
  • process, analyse and retrieve information from customer documents
  • generate answers and source citations
  • maintain conversation history
  • provide support
  • operate, secure, maintain and improve QUCHR
  • investigate technical or security issues
  • comply with legal obligations
  • manage privacy, access, correction or deletion requests

We do not use customer documents for unrelated advertising purposes.

5. How QUCHR uses artificial intelligence

QUCHR uses artificial intelligence services as part of document analysis, retrieval and answer generation.

When a document is uploaded, QUCHR may extract text from that document. Extracted text and relevant document sections may then be processed by OpenAI for functions including document analysis, embeddings and answer generation.

When you use QUCHR chat, information sent for processing may include your question, relevant conversation context and relevant evidence retrieved from organisation documents or governed sources.

Under QUCHR's current document analysis and retrieval architecture, the original uploaded document file itself is not sent to OpenAI. Extracted text and relevant content are processed instead.

AI-generated answers may be incomplete or incorrect. QUCHR provides citations and source references where supported so users can review the underlying information.

6. Storage and overseas processing

New customer-uploaded original document files are stored using Amazon Web Services in the Sydney region, Australia.

This does not mean that all QUCHR information remains in Australia.

Other parts of the QUCHR service may involve infrastructure and service providers operating outside Australia. Personal information or document content may therefore be disclosed to or processed by overseas service providers where required to provide the service.

Current service arrangements may involve processing in locations including the United States and India, depending on the service being used.

QUCHR also uses OpenAI to process extracted document text and information required for AI functionality.

We will review this section as our infrastructure and service-provider arrangements change.

7. Security

QUCHR uses technical and organisational measures designed to protect information against unauthorised access, misuse, loss and disclosure.

Current controls include:

  • encrypted transmission using HTTPS/TLS
  • encryption of new customer document originals at rest in AWS S3
  • password hashing
  • secure authentication cookies
  • customer account isolation controls
  • protection against repeated failed password login attempts

No internet-based service can guarantee absolute security.

More information about our current technical controls is available on the QUCHR Security page.

8. Document deletion

Users may delete customer documents through QUCHR.

For documents stored using QUCHR's current AWS S3 storage architecture, deleting a document removes the original S3 object and removes associated retrieval material, including indexed document sections, knowledge records and vectors.

Customer-derived extracted text and AI-generated document profile information retained by QUCHR are also purged as part of the deletion process.

We do not describe this as deletion of every possible copy everywhere because limited technical, security or provider records may be subject to different handling.

Some documents created under an earlier QUCHR storage configuration used a legacy storage provider that does not provide QUCHR with per-object physical deletion capability.

Where this applies, QUCHR removes the customer content and retrieval information it can control but cannot independently erase the legacy provider's original stored object.

9. Conversations

QUCHR conversations are retained until you delete the conversation or delete your QUCHR account.

Users can delete individual conversations from their account.

Conversation information may be processed by AI service providers where required to respond to your questions.

10. Account deletion

You may delete your QUCHR account through the account controls available within QUCHR.

Account deletion requires explicit confirmation.

When account deletion succeeds, QUCHR removes customer content that it can technically delete, deletes conversations, removes active sessions and removes the user account after document cleanup has completed.

For current S3-backed customer documents, QUCHR attempts physical deletion of the original document before completing account deletion.

If physical deletion fails, QUCHR does not falsely report the account deletion as completed.

The legacy storage limitation described above may continue to apply to documents originally stored using QUCHR's previous storage provider.

11. Retention

We retain personal information only for as long as it is reasonably required for the purposes for which it is held, the operation and security of QUCHR, and applicable legal requirements. In particular:

  • Customer documents remain until deleted by the user or through account deletion, subject to the legacy storage limitation described above.
  • Conversations remain until individually deleted or the account is deleted.
  • Account information remains while the account is active and is removed through the account deletion process.
  • Limited non-content security or deletion records may be retained where reasonably necessary for security, legal, fraud-prevention or operational purposes.

12. Access and correction

You may request access to personal information QUCHR holds about you or ask us to correct information that is inaccurate, out of date, incomplete or misleading.

To make an access or correction request, contact:

Privacy Contact
QUCHR
support@quchr.com
Melbourne, Victoria, Australia

We may need to verify your identity before providing access to or changing personal information.

13. Privacy complaints

If you believe QUCHR has not handled your personal information appropriately, contact support@quchr.com with details of your concern.

We will review the matter and aim to respond within a reasonable period.

If you are not satisfied with our response and you are entitled to do so under Australian privacy law, you may contact the Office of the Australian Information Commissioner.

14. Third-party service providers

QUCHR relies on third-party technology providers to operate the service, including providers of cloud infrastructure, AI processing, authentication and hosting.

These providers may process information on our behalf where necessary to provide their services.

We assess what information is required to be provided to these services and aim to limit processing to what is reasonably necessary for QUCHR to operate.

15. Children

QUCHR is a business service and is not intended for use by children.

16. Changes to this policy

We may update this Privacy Policy when QUCHR's products, infrastructure, service providers or legal obligations change.

The current version and its last updated date will be published on the QUCHR website.

17. Contact us

For privacy questions, access or correction requests, complaints or other privacy enquiries:

QUCHR Pty Ltd as trustee for The Radatti Family Trust
Trading as QUCHR
ABN 93 709 631 226
Melbourne, Victoria, Australia
support@quchr.com