CXF, a product of CXpert

Privacy Policy

Last updated 24 September 2026

This Privacy Policy explains how CXpert (“CXpert”, “we”, “us”, or “our”) collects, holds, uses, and discloses personal information in connection with the CXF platform (the “Service”), and how you can access or correct your information or make a complaint. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Policy should be read together with our Terms of Service.

This Policy uses the same defined terms as our Terms of Service (“Customer”, “Authorised User”, “Respondent”, “Service”) where relevant.

1. Who This Policy Covers

CXF is used by two distinct groups of people, and we collect different information from each:

  • Customers and their Authorised Users - the organisations and individuals who sign up for CXF to create and manage surveys.
  • Respondents - the customers or employees of a Customer who complete a survey distributed through CXF.

Survey responses collected through CXF are anonymous by design. We explain exactly what this means, and the one situation in which it doesn’t apply, in Section 4.

2. Information We Collect From Customers and Authorised Users

2.1 Account information

When you create an account, we collect your name, email address, and password (stored in encrypted, hashed form - we never store your actual password).

2.2 Organisation information

When you set up an organisation, we collect its name, ABN, and basic business details (such as state and city). You may optionally provide a logo, site/location details, and staff department names.

2.3 Billing information

If you subscribe to a paid plan, our payment processor, Stripe, collects your payment details directly. We do not receive or store your full card number. We hold a reference to your Stripe customer and subscription records so we can manage your subscription.

2.4 Communications

If you contact us for support, request a demo, or express interest in consulting help, we collect the information you provide in that message (such as your name, email, and the content of your enquiry).

3. Information We Collect From Respondents

If you are answering a survey sent to you by an organisation using CXF, this section applies to you.

3.1 Survey responses

We collect the answers you provide to survey questions. Surveys distributed through CXF are configured to collect responses anonymously: we do not ask for your name, and we do not record any identifier - such as an email address, IP address, or account - that could be used to connect your specific answers back to you.

3.2 If you choose to request a follow-up

Some surveys give you the option, at the end, to ask the organisation to follow up with you directly. If you choose this option, the name, email address, phone number, or reason you provide is collected and shared with that organisation so they can contact you. This is entirely optional, and choosing not to provide it does not affect your survey response.

4. How We Protect Respondent Anonymity

Anonymity is a deliberate design feature of CXF, not an afterthought. Beyond simply not collecting identifying information, CXF applies a minimum sample-size threshold before showing any aggregated result to a Customer: a result is only displayed once enough responses have been collected that no individual respondent’s answer could reasonably be inferred from it. Until that threshold is met, results are withheld.

Because responses are not linked to any identifier, we are not able to locate, retrieve, or delete an individual survey response on request - there is no way to identify which response, among many anonymous ones, belongs to a particular person. This does not apply to information you volunteer through a follow-up request (Section 3.2), which we can locate and act on.

5. How We Use Personal Information

We collect, hold, use, and disclose personal information for the following purposes:

  • to provide, operate, and maintain the Service, including creating and managing your account and organisation;
  • to process payments and manage subscriptions;
  • to communicate with you, including sending account verification, password reset, and service-related emails;
  • to respond to support requests, demo requests, and other enquiries;
  • to pass on a Respondent’s follow-up request to the relevant Customer, where the Respondent has chosen to make one;
  • to detect, investigate, and prevent fraud, misuse, or security incidents;
  • to comply with our legal obligations.

We do not sell personal information, and we do not use it for advertising or marketing to third parties.

6. Who We Share Information With

We share personal information with the following service providers, each of whom processes it only on our behalf and only for the purposes described in this Policy:

  • Stripe - to process payments and manage subscriptions.
  • Microsoft Azure (Communication Services) - to send account, verification, and notification emails.
  • Supabase - to host our database.
  • Vercel - to host the Service and store uploaded files such as organisation logos.

We do not disclose personal information to any other third party except as described in this Policy, with your consent, or as required by law.

A Respondent’s follow-up request details (Section 3.2) are disclosed to the Customer whose survey the Respondent answered - this is the whole purpose of that feature.

7. Overseas Disclosure

Our core infrastructure - our database and application hosting - is located in Australia. Some of our service providers (including our payment processor and email provider) are global businesses that may store or process information outside Australia as part of their own operations. Where this occurs, we take reasonable steps to ensure those providers handle personal information in a manner consistent with the Australian Privacy Principles.

8. How We Protect Personal Information

We take the security of personal information seriously and use a range of technical and organisational measures to protect it, including:

  • encrypting data in transit using HTTPS/TLS;
  • restricting our own systems’ database access to the minimum level needed to operate the Service, using a hardened, non-administrative database role for all ordinary operations;
  • enforcing organisation-level data separation at the application layer, so one Customer’s data cannot be accessed through another Customer’s account;
  • logging and auditing administrative access to Customer data;
  • storing passwords only in encrypted, hashed form.

No method of transmission or storage is completely secure. While we work hard to protect personal information, we cannot guarantee its absolute security.

9. How Long We Keep Personal Information

We keep personal information for as long as your account remains active, and for 30 days after your subscription ends, to give you the opportunity to export your data. After this period, we securely delete or de-identify personal information, except where we are required to retain it for legal, accounting, or dispute-resolution purposes.

10. Accessing and Correcting Your Information

If you are a Customer or Authorised User, you can access and update most of your account and organisation information directly within CXF. If you would like a copy of your personal information, or believe any information we hold about you is incorrect, contact us using the details in Section 14.

As explained in Section 4, we are generally not able to identify or retrieve an individual anonymous survey response. If you have volunteered contact details through a follow-up request, contact us and we will do our best to locate and act on that specific record.

11. Cookies

We use cookies that are necessary for the Service to function, such as keeping you signed in. We do not use cookies for advertising or cross-site tracking.

12. Children’s Privacy

CXF is intended for business use and is not directed at children. We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Policy from time to time. If a change is material, we will provide at least 30 days’ notice before the change takes effect, by email or a notice within the Service. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

14. Complaints and Contact

If you have a concern about how we have handled personal information, please contact us first using the details below. We will investigate and respond to your complaint within a reasonable time.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

support@cxpert.com.au, CXpert, ABN: 54 274 900 848

Kent Town, South Australia