Privacy Policy
Last updated: 6 July 2026
Kontrak Social Pty Ltd (ABN 38 677 831 097 ), trading in respect of the Kontrak Social application (“Kontrak Social”, “we”, “us”, “our”), is
committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, store and protect your personal data when you use the Kontrak Social application and website at www.kontrak.social.
We are committed to handling your personal data in accordance with:
the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth); and the EU General Data Protection Regulation (GDPR) and the UK GDPR, where they apply to you.
A copy of the Australian Privacy Principles is available from the Office of the Australian Information Commissioner at https://www.oaic.gov.au/.
1. Who we are (Data Controller)
For the purposes of the GDPR, the data controller responsible for your personal data is:
Kontrak Social Pty Ltd
22/44 Deering St, Ulladulla, NSW 2539, Australia
Email: contact@kontrak.social
Because we offer services to individuals located in the European Union / United Kingdom, we are considering appointing an EU/UK representative under Article 27 of the GDPR.
2. Scope of this policy
This policy applies to personal data we collect through the Kontrak Social app, our website, our email communications, and any related services. It does not cover third-party websites or services that we link to but do not control.
3. What personal data we collect
We collect the following categories of personal data:
Account and contact information — such as your name, email address, phone number, and postal address, and information about the
informal agreements (“kontraks”) you create, track, and share with your contacts.
One-time password (OTP) data — phone numbers, the dates and times of OTP requests, and the type of communication used (e.g. SMS or
voice call). We use this solely to verify your identity and secure access to your account.
Facial / biometric data — still images of your face, where you choose to use identity-verification features. Under the GDPR this is
special category (biometric) data and receives the additional protections described in Section 5.
Usage and technical data — device information, log data, app-performance and crash data, and cookie/identifier data collected
when you use the app or website.
Information from third parties — where reasonable and practicable, we collect personal data directly from you. In some cases
we may receive information about you from third parties or publicly available sources, in which case we take reasonable steps to make you
aware of it.
We do not guarantee the content or privacy practices of third-party websites or services that we link to.
4. Our lawful bases for processing (GDPR Article 6)
Where the GDPR applies, we only process your personal data where we have a lawful basis to do so. The basis depends on the purpose:
| Purpose | Lawful basis |
|---|---|
| Creating your account and providing the Kontrak Social service (including creating and tracking kontraks) | Performance of a contract with you (Art. 6(1)(b)) |
| Verifying your identity and delivering OTP codes | Performance of a contract and our legitimate interest in account security (Art. 6(1)(b), 6(1)(f)) |
| Facial / biometric identity verification | Your explicit consent (Art. 9(2)(a)) — see Section 5 |
| Sending marketing or newsletter emails | Your consent (Art. 6(1)(a)), which you may withdraw at any time |
| Keeping the service secure and preventing fraud or abuse | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal, tax and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may ask us
for more information about this assessment.
5. Facial and biometric data (special category data)
For the purposes of this policy, “face data” means still images of an individual’s face. This is biometric data used to identify you and is a
special category of personal data under Article 9 of the GDPR and “sensitive information” under the Australian Privacy Act.
We collect face data only where you have given your explicit consent, and only to verify your identity and confirm your transactions.
We will never use your face data for any other purpose, except where required or authorised by law.
We don’t sell or rent your face data.
We will not disclose your face data to third parties unless: you have given express consent; disclosure is required or authorised by law; it
is reasonably necessary to enable one of our service providers to deliver the verification service; or the third party is subject to laws
substantially similar to the Australian Privacy Principles.
You can withdraw your consent and delete your face data at any time, either within the app or by contacting our Privacy Officer (Section 15).
Withdrawing consent does not affect the lawfulness of processing before withdrawal.
We retain face data only for as long as necessary to fulfil the purpose for which it was collected, and we delete it promptly once it is
no longer required or once you withdraw consent, unless we are legally required to keep it for longer.
6. Other sensitive information
“Sensitive information” under the Australian Privacy Act includes information about racial or ethnic origin, political opinions, religious
or philosophical beliefs, trade-union membership, criminal record, or health. Under the GDPR these overlap with “special category data.” We
use sensitive information only:
- for the primary purpose for which it was collected;
- for a directly related secondary purpose;
- with your consent; or
- where required or authorised by law.
7. Who we share your data with (recipients)
We do not sell your personal data. We share it only with:
Service providers (data processors) who help us run Kontrak Social under contract and on our instructions. These currently include:
- Providers of hosting and database services: Supabase;
- Push-notification services: OneSignal;
- Error/crash monitoring: Sentry;
- SMS/OTP delivery: Twilio.
Other users, but only to the extent you choose to share a kontrak with a contact.
Authorities or third parties where you consent, or where disclosure is required or authorised by law.
We require all our processors to protect your data and to use it only for the purposes we specify.
8. International data transfers
Kontrak Social is operated from Australia, and some of our service providers store or process data outside the European Economic Area (EEA) and the United Kingdom, including in Australia, Singapore and the United States.
Where we transfer personal data outside the EEA/UK, we ensure an appropriate safeguard is in place, such as:
- transfer to a country covered by an adequacy decision; or
- Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Agreement / Addendum where relevant); or
- the provider’s certification under the EU–US Data Privacy Framework, where applicable.
You may contact us to request a copy of the relevant safeguards.
9. How long we keep your data (retention)
We keep personal data only for as long as necessary for the purposes for which it was collected, or as required by law.
| Purpose | Lawful basis |
|---|---|
| Creating your account and providing the Kontrak Social service (including creating and tracking kontraks) | Performance of a contract with you (Art. 6(1)(b)) |
| Verifying your identity and delivering OTP codes | Performance of a contract and our legitimate interest in account security (Art. 6(1)(b), 6(1)(f)) |
| Facial / biometric identity verification | Your explicit consent (Art. 9(2)(a)) — see Section 5 |
| Sending marketing or newsletter emails | Your consent (Art. 6(1)(a)), which you may withdraw at any time |
| Keeping the service secure and preventing fraud or abuse | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal, tax and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
When personal data is no longer needed, we take reasonable steps to securely destroy or permanently de-identify it.
10. Your rights
Depending on where you are located, you have the following rights over your personal data. Where the GDPR applies, these include the right to:
Access — request a copy of the personal data we hold about you.
Rectification — request that we correct inaccurate or incomplete data.
Erasure (“right to be forgotten”) — request deletion of your data in certain circumstances.
Restriction — request that we limit how we use your data in certain circumstances.
Data portability — receive certain data in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
Object — object to processing based on our legitimate interests, and to direct marketing at any time.
Withdraw consent — where we rely on your consent, withdraw it at any time (this does not affect processing already carried out).
Rights in relation to automated decision-making — see Section 13.
Lodge a complaint — see Section 11.
To exercise any of these rights, contact us using the details in Section 15. We will respond within the time required by law (generally one month under the GDPR). We do not charge a fee to access your data, though we may charge a reasonable administrative fee for providing a copy in limited circumstances permitted by law. To protect your data, we may ask you to verify your identity before we act on a request.
11. Complaints and supervisory authorities
If you have concerns about how we handle your data, please contact us first (Section 15) so we can try to resolve the issue.
You also have the right to lodge a complaint with a supervisory authority:
- In Australia: the Office of the Australian Information Commissioner (OAIC) — https://www.oaic.gov.au/.
- In the EU: your local Data Protection Authority.
- In the UK: the Information Commissioner’s Office (ICO) — https://ico.org.uk/.
12. Cookies and similar technologies
We use cookies and similar technologies on our website and app to operate the service, remember your preferences, and understand usage.
Where required by law, we ask for your consent before setting non-essential cookies, and you can withdraw that consent or manage your
preferences at any time through insert: your browser settings / in-app settings.
13. Automated decision-making
We do not currently make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling.
14. Children’s privacy
Kontrak Social is not directed at children under 16, and we do not knowingly collect personal data from children under that age. Where the
GDPR applies and we rely on consent to offer services to a child, we obtain verifiable parental or guardian consent. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Data security and breaches
We store your personal data in a manner that reasonably protects it from misuse, interference, loss, and unauthorised access, modification or disclosure. We use technical and organisational measures appropriate to the risk.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to them, in accordance with the GDPR and the Australian Notifiable Data Breaches scheme.
16. Business transfers and insolvency
If Kontrak Pty Ltd is involved in a merger, acquisition, reorganisation, sale of assets, or insolvency proceeding, your personal data may be transferred or shared as part of that transaction. We will take reasonable steps to ensure your data continues to be treated in accordance with this policy, and any successor entity will be bound by equivalent obligations, unless you are notified otherwise and given choices as required by law.
17. Changes to this policy
We may update this policy from time to time. The current version is always available on our website, and we will indicate the “Last updated” date at the top. Where changes are significant, we will take reasonable steps to notify you.
18. Contact us
For any questions, requests, or complaints about this Privacy Policy or your personal data, please contact our Privacy Officer:
Kontrak Pty Ltd — Privacy Officer
22/44 Deering St, Ulladulla, NSW 2539, Australia
Email: contact@kontrak.social
| Data | Retention |
|---|---|
| Account and kontrak data | For as long as your account is active, then 5 years after closure |
| OTP data | Only as long as necessary to provide the verification service, then securely deleted |
| Face / biometric data | Until no longer needed or you withdraw consent, then promptly and securely deleted |
| Records we must keep by law (e.g. tax) | For the minimum period required by applicable law |

