Effective date: 15 May 2026
Applies to: pushbutton.cloud, related product pages, and the Pushbutton service operated by Refined Holdings Pty Ltd
1. Who we are
Refined Holdings Pty Ltd ('Refined', 'we', 'us', 'our') operates Pushbutton.
Pushbutton uses a hybrid deployment model. Customer business data stays in the customer's own environment. We process a narrower set of data to run authentication, governance records, support, billing, and service operations.
2. What this policy covers
This policy explains:
- what personal information we collect
- why we collect it
- how we use, store, and disclose it
- how you can ask for access or correction
- how our hybrid data boundary affects privacy
This policy covers:
- visitors to
pushbutton.cloud - people who contact us
- account users of Pushbutton
- customer representatives who buy, manage, or support a Pushbutton deployment
This policy does not replace any signed contract. If your organisation has a separate order form, MSA, or DPA with us, those documents govern that commercial relationship as well.
3. Our privacy position
We designed Pushbutton so customer business data stays with the customer wherever possible.
In the ordinary course, we do not host or process the customer's business records, documents, messages, vault content, or agent outputs. Those stay in the customer's own tenant or infrastructure.
We do process limited service data so Pushbutton works. That usually includes:
- account and login details
- authentication and session metadata
- governance metadata such as approval records, policy decisions, and audit-chain entries
- support records
- billing and account management records
- anonymised or aggregated telemetry, where enabled
4. What personal information we collect
The types of personal information we collect depend on how you interact with us.
A. Website and enquiry data
We may collect:
- your name
- work email address
- company name
- phone number, if you provide it
- enquiry details
- marketing preference data
- device, browser, IP address, and usage data from the website
B. Account and service data
We may collect:
- name
- work email address
- username or account identifier
- role, permissions, and organisation details
- sign-in history
- SSO and identity-provider metadata
- support communications
C. Governance and operational metadata
We may collect:
- workflow and approval metadata
- audit timestamps
- policy and classifier outcomes
- event identifiers and cryptographic hashes
- service logs needed for security, troubleshooting, and reliability
D. Billing and commercial data
We may collect:
- billing contact details
- invoice and payment records
- contract and order details
5. What we generally do not collect
In the ordinary course, we do not collect or host the customer's core business content inside Refined infrastructure. That includes:
- customer records
- business documents
- internal messages
- vault entries
- task content
- agent memory
- generated business outputs
If a customer asks us to help with a support issue that requires temporary access to business content, we treat that as a limited support event. We restrict access, log it, and remove any working copy when the support work ends.
6. How we collect personal information
We collect personal information when:
- you use our website
- you submit a form or contact us
- your organisation creates or manages a Pushbutton account
- you sign in through SSO or another identity service
- you use service features that create governance or audit metadata
- you contact support
- your organisation enters a contract with us
We may also receive personal information from:
- your employer or organisation
- your identity provider
- service providers that support authentication, hosting, billing, or support
7. Why we collect and use personal information
We collect and use personal information to:
- provide and secure Pushbutton
- authenticate users
- operate governance, approval, and audit features
- respond to enquiries and support requests
- manage accounts, contracts, and billing
- improve reliability, performance, and security
- meet legal, regulatory, and record-keeping obligations
- investigate misuse, incidents, or fraud
Where we use anonymised or aggregated data for product improvement, we do not use it to identify you.
8. Our legal basis and Australian privacy compliance
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
Depending on the context, we process personal information because:
- it is necessary to provide the service
- we need it to manage a contract or pre-contract steps
- we have a legitimate operational or security reason
- the law requires it
- you or your organisation asked us to do it
If your organisation uses Pushbutton for decisions about individuals, that organisation remains responsible for its own privacy notices, lawful basis, and automated decision-making obligations.
9. Hybrid deployment and data sovereignty
Pushbutton does not follow a standard shared-data SaaS model.
The boundary works like this:
- customer business data stays in the customer's own environment
- Refined operates a service layer for authentication, governance metadata, audit integrity, support, and account operations
- telemetry is opt-in where the product or contract says it is optional
This structure reduces the amount of personal information we process directly. It does not remove the customer's own privacy obligations for the data they control in their environment.
10. Disclosure of personal information
We may disclose personal information to:
- our related corporate entities
- service providers that help us run Pushbutton
- professional advisers such as lawyers, accountants, and insurers
- payment and billing providers
- identity, authentication, hosting, logging, and support providers
- regulators, courts, law enforcement, or government agencies where the law requires it
We do not sell personal information.
We do not disclose customer business data as part of a general commercial data-sharing model because that data does not sit with us in the ordinary course.
11. Cross-border disclosure
We aim to keep Refined-hosted data for Australian customers in Australian infrastructure where practical, including our default Sydney-region posture.
Some service providers may process limited personal information outside Australia. This can happen, for example, in identity, support, or AI inference workflows if a customer enables those features or chooses a provider with offshore processing.
Where cross-border disclosure occurs, we use contractual and operational controls that fit the service. Enterprise customers can review the details in their contract documents, including the DPA where one applies.
12. Cookies and similar technologies
We use cookies and similar tools to:
- keep the website and service working
- maintain sessions
- remember preferences
- understand performance and usage trends
- improve security
You can control cookies through your browser settings. If you block essential cookies, parts of the website or service may not work properly.
13. Security
We use technical and organisational controls to protect personal information we hold. Those controls include access control, encryption in transit, monitoring, audit logging, and incident response processes.
No system is perfect. If we detect an eligible data breach, we will respond under our incident procedures and any legal obligations that apply.
14. Retention
We keep personal information only for as long as we need it for the reasons in this policy, including legal, accounting, security, dispute, and record-keeping purposes.
Retention periods vary by data type:
- account and contract records stay for as long as the customer relationship requires and for a reasonable period after it ends
- support records stay as long as we need them for operational and legal reasons
- governance and audit records stay as long as the service, contract, or compliance posture requires
If we no longer need personal information, we delete it or de-identify it where reasonable.
15. Access, correction, and complaints
You can ask us to:
- confirm whether we hold your personal information
- give you access to it
- correct inaccurate or out-of-date information
- explain how we handle it
- consider a privacy complaint
Email support@refinedautonomy.ai and mark the subject line 'Privacy'. We may need to verify your identity before we act.
If you are an end user of a customer deployment, contact your organisation first for requests about customer business data held in that deployment. Your organisation controls that data environment.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
16. Direct marketing
We may send product, event, or company updates to people who asked for them or whose business role makes the contact reasonably expected.
You can opt out at any time by using the unsubscribe option in the message or by contacting us.
17. Children's privacy
Pushbutton is for business use. We do not design it for children.
18. Changes to this policy
We may update this policy from time to time. We will post the current version at pushbutton.cloud. If a change is material, we will use a reasonable notice method for the context.
19. Contact
For privacy questions, requests, or complaints:
Refined Holdings Pty Ltd
Email: support@refinedautonomy.ai
Subject line: 'Privacy'
