Privacy Policy
Last updated: April 2026
Hypercube Ventures Pty Ltd (ABN 69 691 185 690), trading as AskBev, (“AskBev”, “we”, “us”, “our”) operates an AI-powered business administration platform for trade professionals. This policy explains how we collect, use, and protect personal information.
AskBev is an Australian company. We serve customers in Australia and the United Kingdom. This policy complies with the Australian Privacy Act 1988 (including the Australian Privacy Principles) and the UK General Data Protection Regulation (UK GDPR).
1. Who This Policy Applies To
Important: when a tradie uses AskBev to manage their customers’ data, the tradie is the data controller and AskBev is the data processor. The tradie is responsible for obtaining appropriate consent from their customers to collect and process their personal information. See our Terms of Service and Data Processing Agreement for details.
- Tradies (our direct customers): sole traders and small business owners who use AskBev to manage their business.
- Tradie’s customers (end users): people whose personal information tradies store and process through AskBev.
2. Information We Collect
2.1 Tradie Account Information
- Full name, business name, trading name
- Phone number, email address, postal address
- Australian Business Number (ABN) or UK Unique Taxpayer Reference (UTR) / VAT registration number
- Trade type and licence numbers
- Bank details (BSB/account or sort code/account) for invoice generation
- Authentication data (via Clerk)
2.2 Customer Information (Processed on Behalf of Tradies)
- Customer names, phone numbers, email addresses, postal addresses
- Job records, quotes, invoices, payment history
- Communication history (WhatsApp messages, SMS, email, voice call transcripts)
- Receipt photos and expense records
2.3 Automatically Collected Information
- Usage data (features used, frequency, timestamps)
- Device and browser information (for the dashboard)
- Error logs and performance data
2.4 Voice Call Data
- Voice calls handled by our AI assistant may be recorded and transcribed
- Transcripts are stored as part of conversation history
- Voice recordings are retained for 90 days, then deleted
3. How We Use Information
We use personal information to:
- Provide the AskBev service (quoting, invoicing, scheduling, bookkeeping, compliance reminders, customer communications)
- Process AI-assisted conversations and tool actions
- Generate and deliver quotes, invoices, and other business documents
- Send communications on behalf of the tradie (SMS, email, WhatsApp messages)
- Sync data with connected accounting systems (Xero, QuickBooks)
- Monitor and improve service reliability and performance
- Comply with legal obligations
We do not:
- Sell personal information to third parties
- Use customer data for marketing purposes
- Use tradie data to train AI models (Anthropic’s API terms prohibit this)
4. Third-Party Services and Data Transfers
AskBev uses the following third-party services to operate. Personal information may be transferred to these services, some of which are based outside Australia/UK:
- Anthropic (Claude API) — AI conversation processing — United States — Standard Contractual Clauses, data not used for training
- Meta (WhatsApp Cloud API) — WhatsApp message delivery — United States — Meta Data Processing Terms
- Twilio — SMS delivery — United States — Twilio DPA, SCCs
- Google (Gemini API) — voice/image transcription — United States — Google Cloud DPA
- Vapi — voice call handling — United States — Vapi DPA
- Amazon Web Services — hosting, database, email (SES) — Australia (ap-southeast-2) — AWS DPA, data at rest in Sydney
- Clerk — authentication — United States — Clerk DPA
- Xero / QuickBooks — accounting sync (when connected by tradie) — Australia / United States — connected at tradie’s direction
- Sentry — error monitoring — United States — Sentry DPA
- Langfuse — AI observability — European Union — Langfuse DPA
Cross-border transfer safeguards: where data is transferred outside Australia or the UK, we rely on Standard Contractual Clauses (SCCs), the UK-US Data Bridge, and/or the service provider’s certified data processing agreements. These ensure an equivalent level of data protection.
5. Data Security
We implement the following security measures:
- Tenant isolation: Row-Level Security (RLS) ensures each tradie can only access their own data
- Encryption in transit: all data transmitted via TLS/HTTPS
- Encryption at rest: AWS RDS encrypted storage
- Access controls: role-based access, Clerk authentication for the dashboard
- Structured logging: access and action logging for audit purposes
- Regular security reviews: dependency scanning, vulnerability checks
6. Data Retention
When a tradie deletes their account, we delete all associated data within 30 days, except where retention is required by law (e.g., tax records).
- Tradie account data — duration of account + 30 days after deletion
- Customer records — duration of tradie’s account (tradie controls deletion)
- Conversation history — duration of tradie’s account
- Voice recordings — 90 days
- Invoices and quotes — 7 years (tax compliance requirement)
- Error logs — 90 days
7. Your Rights
7.1 Australian Privacy Principles (APPs)
Under the Privacy Act 1988, you have the right to:
- Access your personal information (APP 12)
- Correct inaccurate information (APP 13)
- Complain about a breach of the APPs
7.2 UK GDPR Rights
If you are in the UK, you additionally have the right to:
- Erasure (“right to be forgotten”) — request deletion of your data
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Withdraw consent at any time (where processing is based on consent)
We will respond to rights requests within 30 days (AU) or one calendar month (UK).
7.3 For Tradie’s Customers
If you are a customer of a tradie who uses AskBev, your primary contact for data rights is the tradie (who is the data controller). If the tradie is unable to help, you may contact us directly.
8. Data Breach Notification
In the event of a data breach that is likely to result in serious harm:
- Australia: we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals within 30 days, as required by the Notifiable Data Breaches scheme.
- United Kingdom: we will notify the Information Commissioner’s Office (ICO) within 72 hours and affected individuals without undue delay, as required by UK GDPR.
9. Children’s Data
AskBev is a business tool for trade professionals. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. We will notify tradies of material changes via email or in-app notification at least 30 days before the changes take effect. The “Last updated” date at the top of this policy indicates when it was last revised.
11. Contact Us
Post: Hypercube Ventures Pty Ltd (trading as AskBev), Sydney, NSW, Australia
Australian Privacy Commissioner: Office of the Australian Information Commissioner (OAIC) — phone 1300 363 992 — www.oaic.gov.au
UK Information Commissioner (for UK residents): Information Commissioner’s Office (ICO) — phone 0303 123 1113 — ico.org.uk
For privacy inquiries, data access requests, or complaints, email privacy@askbev.io.