Socii Platform Privacy Policy
Contents
- Introduction
- About the Platform
- Anonymity and Pseudonymity
- Information We Collect
- How We Collect Information
- Purposes of Collection and Use
- Direct Marketing
- Unsolicited Personal Information
- Disclosure of Information
- Cross-Border Disclosure
- Data Collected From and About Non-Users
- Sensitive Information
- Data Retention
- Access and Correction
- Cookies and Tracking Technologies
- Security
- Data Breaches
- Third-Party Links and Children's Privacy
- Changes to This Privacy Policy
- Complaints
- Contact
1. Introduction
1.1 Socii Book Pty Ltd (ACN 695 597 141) (trading as Socii) (we, us or our) operates a software platform accessible at sociibook.com and via the Socii application (together, the Platform).
1.2 We are committed to managing personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) (Privacy Act).
1.3 This document sets out our policies for managing your personal information and is referred to as our Privacy Policy.
1.4 In this Privacy Policy, you and your refers to any individual about whom we collect personal information. This includes registered users, visitors to the Platform, and third parties whose personal information is submitted to or collected by the Platform.
1.5 If you have any queries about this Privacy Policy or the way we handle your personal information, please contact us using the details set out in section 21.
2. About the Platform
2.1 The Platform provides infrastructure for storing, tracking and managing referral relationships and related agreements. The Platform enables users to create business profiles, connect with other users, record and track introductions, manage events, communicate through a community board, access AI-assisted tools, and store referral agreements.
2.2 We are not a party to any referral agreement or arrangement between users of the Platform.
2.3 The Platform incorporates automated systems including algorithmic reputation scoring, adaptive interface personalisation, behavioural tracking, and AI-assisted features. These are described in this Privacy Policy.
3. Anonymity and Pseudonymity
3.1 The Platform requires users to register an account and provide accurate business and contact details in order to access and use the Platform.
3.2 It is not practicable for us to allow you to deal with us anonymously or using a pseudonym. This is because the Platform is designed to facilitate business-to-business referral relationships, which require users to identify themselves and their businesses to other users.
3.3 If you do not wish to provide personal information to us, you will be unable to use the Platform.
4. Information We Collect
4.1 The types of personal information we collect will depend on the circumstances of collection and your interaction with the Platform. The categories of information we may collect are set out below.
Account Registration
4.2 When you register for an account on the Platform, we collect:
- your full name;
- your email address;
- your phone number (if provided); and
- your password (stored securely using industry-standard encryption).
Business Profile
4.3 When you create and maintain a business profile, we may collect:
- your business name;
- your Australian Business Number (ABN);
- your Australian Company Number (ACN);
- your business address;
- your industry;
- your role and title;
- your professional headline;
- services offered and areas of specialty;
- industry verticals;
- geographic coverage areas;
- ideal client description;
- client types and client size preferences;
- applicable legislation and professional conduct rules;
- restraint of trade dates;
- your profile photo and company logo;
- your pitch description;
- social media profile links; and
- other professional information you choose to provide.
Referral Kit Data
4.4 Where you complete your referral kit on the Platform, we collect:
- your ideal client description;
- exclusions (clients you do not wish to receive);
- talking points for referrers;
- fit checklists;
- key links and resources;
- one-pager or capability statement uploads; and
- deal criteria and preferences.
4.5 Referral kit data is made available to your connections on the Platform to assist them in making referrals on your behalf.
Personal and Social Data
4.6 You may optionally provide personal and social information including:
- biography;
- personal interests;
- approach style;
- birthday;
- preferred drink order; and
- dietary preferences.
4.7 Dietary preferences may constitute sensitive information. See section 12 for how we handle sensitive information.
Connection and Relationship Data
4.8 When you use the Platform to connect with other users, we collect information about:
- connections made with other users;
- connection tier and status;
- how and where you met;
- preferred contact cadence;
- interaction history;
- private insights and notes about connections; and
- contact information for non-users added as connections (see section 11).
4.9 Private insights and notes you record about connections are visible only to you and are not shared with the connection or other users.
Lead and Introduction Data
4.10 When you record introductions or leads on the Platform, we collect:
- lead title and description;
- estimated value;
- contact name, email and phone number of the introduced party;
- lead status, conversion data and outcome;
- attestation data, including mutual confirmation flags and client attestation tokens and responses; and
- contextual notes about the introduction.
4.10A Where you opt in to share a past introduction with the Socii member who was a party to it, a copy of the introduction record (including your name and the introduction details) is made available to that member, who may confirm or dispute the recorded outcome. Confirmed and disputed outcomes are reflected in trust score calculations (see section 6.2).
Agreement Data
4.11 When you create or manage agreements on the Platform, we collect:
- commission type and fee structure;
- billing company details;
- agreement status and history; and
- an audit trail of agreement actions (creation, acceptance, amendment, expiry).
Behavioural and Usage Data
4.12 When you use the Platform, we automatically collect:
- pages viewed and features accessed;
- clicks and interactions;
- time spent on features;
- feature affinity scores (computed from usage patterns); and
- login history and timestamps.
4.13 Behavioural data is retained for 90 days on a rolling basis and is used for adaptive interface personalisation (see section 6.7).
Visitor Tracking Data
4.14 When you visit the Platform without logging in, we may collect:
- HMAC-signed visitor tokens (included in email links so that we can recognise you when you return from one of our emails);
- UTM parameters and referral source data; and
- IP-derived information (approximate country and region; the IP address itself is not stored in the visitor profile).
4.14A We do not set a visitor identification cookie and we do not create a browser fingerprint.
4.15 Visitor tracking cookies expire after 12 months. Email visitor tokens expire after 30 days. If you later register an account or sign in, your visitor profile may be linked to your account so that we can attribute your sign-up source and personalise your experience.
A/B Testing Data
4.16 We conduct A/B tests on marketing and interface copy. When you are exposed to an A/B test, we collect:
- the variant shown to you;
- your visitor identification cookie;
- the timestamp of the impression; and
- whether you completed a conversion action.
4.17 A/B test data is associated with your visitor identification cookie, not with your user account, unless you subsequently register an account.
Events Data
4.18 When you interact with events on the Platform, we collect:
- event details (title, description, date, location, type);
- RSVP status and responses;
- dietary notes provided for events;
- invitee information (including email addresses of non-users invited to events);
- where you reply to a save the date invitation: the name, email address and phone number you give us, your postal address, and your company and role if you choose to provide them. We collect your postal address so that we can send you correspondence about the event by post, and your phone number so that we can contact you about the event. Neither is shown to other guests; and
- for events with paid seats, whether your seat payment has been received. Seat payments are processed by Stripe through a payment link; we do not receive or store your card details.
Financial and Billing Data
4.19 When you subscribe to a paid plan, we collect:
- your Stripe customer identifier;
- your billing plan and subscription status;
- billing company name and details; and
- payment failure information.
4.20 We do not store your credit card number or full payment details. Payment processing is handled by Stripe, Inc. and is subject to Stripe's privacy policy.
Communications
4.21 We collect information contained in support requests, feedback, community board posts and other communications you send to us or post on the Platform.
Session and Device Data
4.22 When you access the Platform, we automatically collect:
- IP address;
- user agent (browser and device information);
- session token and authentication timestamps; and
- administrative audit log entries, including records of any administrator access to an account for support or investigation purposes (such access is flagged in the session and auditable).
Direct Messaging Data
4.23 When you send or receive direct messages on the Platform, we collect:
- the content of your messages;
- thread metadata, including participants, timestamps, last-read indicators and mute or archive flags;
- delivery and read status; and
- contextual references to any lead or agreement linked to the thread.
4.24 Direct messaging is trust-gated. You can only message another User if you share an active connection with that User or if you and the recipient are both approved Black Book members.
Push Notification Subscriptions
4.25 If you opt in to receive web or mobile push notifications from the Platform, your browser or device sends us a push subscription endpoint together with cryptographic keys (the p256dh and auth keys defined by the Web Push Protocol). We store these against your account and use them solely to deliver Platform notifications via your browser or device vendor's push service (such as Apple, Google or Microsoft).
4.26 We track the delivery success or failure of push messages so that we can remove subscriptions that are no longer valid. You may revoke push notifications at any time through your browser or device settings, or through your Platform notification preferences.
Two-Factor Authentication Data
4.27 If you enable two-factor authentication on your account, we store:
- a TOTP secret used to verify codes generated by your authenticator application; and
- a set of single-use backup codes, stored in hashed form for use in account recovery.
4.28 We do not store the time-based codes themselves. We verify codes only at the moment of sign-in.
Delegate and Managed Account Data
4.28A You may authorise another person (a delegate) to access and act on your account. If you do, we record the delegation (including the delegate's identity and the date of authorisation) and we log every action the delegate takes while acting as you, including the identity of the acting delegate, so that account activity can always be attributed to the person who performed it.
4.28B A delegate can see the account data reasonably necessary to act on your behalf. You may revoke a delegation at any time through your account settings; audit records of past delegate actions are retained.
Affiliate and Partner Commission Program Data
4.29 When you apply to or participate in the public affiliate program or the Black Book partner commission program, we collect:
- application data you provide, including why you wish to join, a size bucket for your network, social media URLs you choose to share and the channels you propose to use to share Socii;
- the application status (pending, approved, rejected or revoked), the source of the application (public application or Black Book partner invitation), the date you applied, the identity of the administrator who reviewed your application and any reason recorded for a rejection or revocation;
- commission ledger entries generated automatically when an end-user you referred pays an invoice, including the amount, currency, invoice period, status (clawback pending, eligible, voided or paid), the source Stripe invoice identifier and the date the entry becomes payable;
- payout batch records showing when commissions were aggregated and paid; and
- milestone bonus records where you have earned an additional bonus under the Black Book partner program.
4.30 Commission ledger entries are generated by Stripe webhooks when a referred user pays an invoice. Refunds, chargebacks or subscription cancellations within 90 days of the original payment will void the corresponding ledger entry. Eligible entries are aggregated into a quarterly payout batch issued on the first day of January, April, July and October.
Newsletter Consent Records
4.31 If you opt in to receive Socii newsletters or other marketing communications, we record:
- the boolean recording your consent;
- the exact text of the consent statement that was displayed to you at the time; and
- the timestamp of the consent.
4.32 We retain this audit record so that we can demonstrate the basis on which we sent you marketing communications, in accordance with the Spam Act 2003 (Cth).
Sensitive Information
4.33 We collect the following categories of information that may constitute sensitive information under the Privacy Act:
- dietary preferences (which may reveal information about religious beliefs or health conditions); and
- professional conduct rules and applicable legislation (which may identify membership of a professional association).
4.34 We do not intentionally collect other categories of sensitive information. If you voluntarily include sensitive information in free-text fields (such as notes, descriptions, direct messages or community posts), you consent to our collection and handling of that information in accordance with this Privacy Policy.
5. How We Collect Information
5.1 We collect personal information:
- directly from you, when you register for an account, create or update your business profile, complete your referral kit, record introductions, create or manage agreements, RSVP to events, post on the community board, or communicate with us;
- from other users of the Platform, when they record an introduction involving you or a third party, add you as a connection, or invite you to an event;
- from third parties whose information is submitted to the Platform (for example, a client who provides an attestation in respect of a lead);
- automatically, through cookies, visitor tracking technologies, behavioural tracking, analytics tools and server logs when you access the Platform; and
- from third-party services we integrate with, including Stripe (payment processing and commission webhooks that record referred-user invoice events for the affiliate and partner commission program), Google (authentication), LinkedIn (authentication and, where you sign in with LinkedIn, basic profile information such as your name, photo, headline and profile URL), HubSpot (CRM mirror, when you choose to connect a HubSpot portal) and the push messaging services operated by your browser or device vendor (Apple, Google or Microsoft); and
- from visitors to our public marketing pages (including the referral fee, network ROI and commission split calculators under sociibook.com/tools) where the visitor provides their contact details to receive a follow-up.
6. Purposes of Collection and Use
6.1 We collect and use personal information for the following purposes:
- to provide and operate the Platform;
- to create and manage user accounts;
- to authenticate sign-in attempts, including verification of two-factor authentication codes and backup codes;
- to enable connections between users;
- to record and track introductions and leads;
- to store and manage referral agreements;
- to facilitate counter-proposals, agreement template reuse and bulk agreement invitations between users;
- to facilitate referral kit sharing between connections;
- to enable trust-gated direct messaging between users and to deliver in-product, email and push notifications about new messages and other Platform activity;
- to organise and manage events and RSVPs;
- to operate the community board;
- to process subscriptions and billing;
- to administer the public affiliate program and the Black Book partner commission program, including reviewing applications, attributing referred sign-ups to a partner, recording commissions earned from invoices paid by referred users, applying the 90-day clawback window for refunds and cancellations, and issuing quarterly payouts (see section 6.15);
- to capture, store and follow up on submissions made through our public calculator tools and lead capture forms (see section 11.7);
- to compute trust scores and assign trust tiers (see section 6.2);
- to determine eligibility for Verified Dealmaker badges (see section 6.5);
- to personalise the interface based on usage patterns (see section 6.7);
- to provide AI-assisted features (see section 6.8);
- to conduct A/B testing on marketing and interface copy (see section 6.11);
- to recognise returning visitors and personalise marketing content;
- to send automated communications (see section 6.12);
- to communicate with you about your account, the Platform and our services;
- to send you marketing communications in accordance with section 7;
- to improve the Platform and develop new features;
- to comply with our legal obligations;
- to enforce our terms of use; and
- for security purposes and to prevent fraud.
Automated Decision-Making (Trust Score, Trust Tier and Verified Dealmaker)
6.2 The Platform computes a trust score for each user based on the following dimensions:
- profile completeness;
- connection depth and reciprocity;
- lead volume and conversion rates;
- agreement compliance and renewal history;
- vouches received from other users;
- client attestation outcomes;
- community engagement; and
- platform tenure and login consistency.
6.3 Trust scores are used to assign users to trust tiers (Proven, Rising or New). Trust tiers affect:
- default sort order in search and discovery features (higher trust users appear first);
- priority for automatic event invitations; and
- visibility indicators shown to other users (trust tier badges).
6.4 Trust scores are computed algorithmically without human review. You may contact us to request an explanation of your trust tier or to raise a concern about its accuracy, and we will review it and correct any error (see clause 6.8 of our Terms of Use).
6.4A Decisions we make using computer programs
We use computer programs to make, and to do things substantially and directly related to making, decisions about members. Some of those decisions could reasonably be expected to significantly affect your rights or interests, because they affect how visible you are to other members and what parts of the Platform you can reach. This section sets out what those programs use and what they decide.
The categories of personal information used. The programs described below use: your profile information and how complete it is; your connection records, including how many connections you hold, their tier and whether the relationship is reciprocal; your lead and introduction records, including volume, status, recorded outcomes and conversion; your agreement records, including compliance and renewal history; vouches other members have given you and the dimensions they were given on; client attestation responses; your community board and Lounge activity; your account tenure; your login history; your billing plan; and your nomination records.
Decisions made solely by a computer program, with no human involvement. These are: the calculation of your trust score; your assignment to a trust tier (Proven, Rising or New); the award, retention or removal of the Verified Dealmaker badge, which is reassessed daily; your default position in search and discovery results, where higher trust users appear first; the prominence of your posts in the Lounge; whether you are automatically prioritised for an event invitation; which trust tier badge other members see on your profile; whether you have met the nomination threshold for Trusted Partners; and which interface layout and content ordering you are shown.
Decisions a computer program substantially and directly contributes to, where a person also has a role. These are: whether your application for the Trusted Partners directory is approved, where meeting the automated nomination threshold produces a pending status that we then review; whether your application to the affiliate or Black Book partner programme is approved or revoked; whether your account is flagged for review for suspected breach of our Terms; and the curation of Deal Flow Briefings, where content is selected automatically from engagement metrics.
6.4B If a decision described above affects you and you disagree with it, you may contact us using the details in section 21. We will tell you the general basis on which the decision was made, review it, and correct it if we find an error. We will not charge you for this. Nothing in this section limits your right to complain to us or to the Office of the Australian Information Commissioner under section 20.
Verified Dealmaker Badge
6.5 The Platform awards a Verified Dealmaker badge to users who meet the following criteria:
- 10 or more converted leads;
- 5 or more vouches received across at least 3 distinct vouch dimensions; and
- at least 1 year of active Platform membership.
6.6 Verified Dealmaker status is computed daily by an automated process. It confers additional visibility and priority within the Platform.
Adaptive Interface Personalisation
6.7 The Platform uses behavioural data (see section 4.12) to personalise the user interface, including reordering navigation items and dashboard widgets based on your usage patterns. This personalisation is computed from your own activity data and does not involve profiling against other users. You may contact us if you wish to reset your personalisation data.
AI-Assisted Features
6.8 The Platform provides AI-assisted features including:
- referral matching suggestions (identifying which connections may be suitable for a given referral);
- draft introduction messages;
- network health alerts (identifying dormant connections or underutilised relationships);
- deal flow briefings (curated summaries of relevant community activity); and
- network value analysis.
6.9 AI-assisted features are powered by language models provided by Anthropic, PBC. When you use AI-assisted features, relevant data from your profile, connections, leads and agreements may be sent to Anthropic's API for processing. Anthropic's data handling practices are described in Anthropic's privacy policy.
6.9.1 Specifically, the following profile fields may be sent to Anthropic when you use Quick-Fill enrichment: your LinkedIn URL, full name, current company, current role, the additional context you type into the Quick-Fill prompt, and any existing values for your headline, bio, expertise, location, approach style, referral philosophy, and connect-with statement. For company enrichment, we additionally send the company name, website, and your role at that company. We do not send connection lists, lead notes, vouch text, or message contents to Anthropic.
6.9.2 Separately from the built-in AI-assisted features, you may choose to connect a third-party AI assistant (such as Anthropic's Claude) to your account through an authorisation (OAuth consent) screen. Once connected, that assistant can read and act on your account data - including your profile, connections, leads, agreements, messages and settings - when you instruct it to, through our tool interface. Data the assistant retrieves is processed by the assistant's provider under that provider's own terms and privacy policy, not ours. Actions taken by a connected assistant are logged against your account. You can revoke a connected assistant's access at any time through your account settings.
6.10 AI-generated outputs (such as draft messages or suggestions) are not sent, shared or acted upon without your review and approval.
A/B Testing
6.11 We conduct A/B tests using a statistical method (Thompson Sampling) to optimise marketing and interface copy. A/B test participation is based on your visitor identification cookie and does not use personal information from your user account to determine variant assignment.
Automated Communications
6.12 The Platform sends automated communications including:
- agreement renewal reminders;
- follow-up reminders for leads and introductions;
- event RSVP reminders;
- post-event follow-up nudges;
- referral qualification notifications;
- network health alerts;
- deal flow briefings;
- weekly activity digests;
- client attestation requests;
- nomination notifications; and
- subscription and billing notifications.
6.13 Automated communications relating to your account and Platform activity are transactional and cannot be unsubscribed from while your account is active.
6.14 Marketing communications can be unsubscribed from at any time (see section 7).
Affiliate and Partner Commission Program
6.15 The Platform operates two referral commission programs: a public affiliate program (15% of paid invoices for 12 paid months) and a private Black Book partner commission program (25% of paid invoices for 12 paid months, plus milestone bonuses). Both programs are gated by an apply-to-join application that an administrator reviews before approval.
6.16 Commission ledger entries are generated automatically when a Stripe webhook tells us that a user you referred has paid an invoice. Each entry remains in a 90-day clawback-pending state before becoming eligible for payout, so that we can void it if the underlying payment is refunded, charged back or the subscription is cancelled inside the clawback window. Eligible entries are aggregated into quarterly payout batches issued on the first day of January, April, July and October.
6.17 We use your contact details and bank or payout details (if you provide them) solely to administer the program, calculate your earnings, send program-related notifications and remit payouts. Payout transfers are processed by Stripe, Inc.
6.18 Where your referral code is shared with a prospective User, we record an attribution link between that referral code and the resulting account so we can credit you with future commissions.
7. Direct Marketing
7.1 We may use your personal information to send you marketing communications about our products, services, events and promotions that may be of interest to you.
7.2 You may opt out of receiving marketing communications from us at any time by:
- clicking the unsubscribe link in any marketing email you receive from us;
- updating your communication preferences in your account settings; or
- contacting us using the details set out in section 21.
7.3 If you opt out of receiving marketing communications, we may still contact you in relation to your account, transactions, and other non-marketing matters relating to the Platform.
7.4 We do not sell your personal information to third parties for their marketing purposes.
8. Unsolicited Personal Information
8.1 From time to time, we may receive personal information that we have not requested or solicited. This may occur, for example, when a user records an introduction that contains personal information about a third party, or when a user adds a non-user as a connection.
8.2 Where we receive unsolicited personal information, we will determine whether we could have collected the information under the APPs. If so, we will handle that information in accordance with this Privacy Policy. If not, we will destroy or de-identify the information (provided it is lawful and reasonable to do so).
9. Disclosure of Information
9.1 We may disclose your personal information to:
- other users of the Platform, to the extent that your profile information, referral kit, trust tier and badges are visible to your connections, and lead details are visible to relevant partners, in accordance with the Platform functionality;
- a delegate you have authorised to access and act on your account, to the extent needed to act on your behalf (see section 4.28A);
- a third-party AI assistant you have connected to your account, when you instruct it to access your data (see section 6.9.2);
- our service providers, including hosting providers, payment processors, AI service providers and email delivery services, under appropriate contractual arrangements;
- our professional advisers, including lawyers and accountants, who are bound by confidentiality obligations;
- regulatory authorities or law enforcement agencies, where required or authorised by law or in response to a court order or lawful government request;
- a third party in connection with a business transfer, if we sell, merge or transfer any part of our business;
- third parties who provide attestations in respect of leads, to the extent necessary to facilitate the attestation process; and
- any other party where you have consented to such disclosure.
9.2 Lead contact details are not shared beyond the relevant partner relationship on the Platform, except where you opt in to share a past introduction with the Socii member who was a party to it (see section 4.10A).
9.3 Private notes and insights you record about connections are not disclosed to those connections or to other users.
9.4 Community board posts are visible to all registered users of the Platform in accordance with the applicable visibility settings.
9.6 Your participation mode - the reward setting you declare for your personal profile and for each company you act for (for example, open exchange, pays for introductions, or favours only) - is shown as a short label to other members on your profile and in the introduction and agreement screens where they choose you, so they know whether introduction fees can apply before they deal with you. The label shows the mode only; it does not reveal your fee amounts or the reasons behind your choice.
10. Cross-Border Disclosure
10.1 We use service providers that are located in, or store data in, countries outside Australia. As at the date of this Privacy Policy, these include:
- Stripe, Inc. (membership subscription payment processing) - United States;
- Resend, Inc. (email delivery) - United States;
- Google LLC (authentication) - United States;
- LinkedIn Corporation (authentication) - United States;
- Sentry (error monitoring) - United States;
- Inngest, Inc. (workflow automation) - United States;
- Replit, Inc. (application hosting and file storage for profile photos, agreement attachments, referral kits and other user-uploaded documents) - United States;
- Anthropic, PBC (AI language model services) - United States; and
- HubSpot, Inc. (CRM mirror, only for users who connect a HubSpot portal) - United States. When you connect HubSpot, we send: deal name, deal status, deal close date, deal amount, a short context summary (truncated to 280 characters), referrer name and trust score, contact first/last name, contact email, contact phone, contact headline, the dimension on which a vouch was given, and the count of vouches received. We do not send: the full body of introduction emails you write, your private memos beyond the truncated context summary, or any data about connections you have not explicitly synced; and
- browser and device push messaging services operated by Apple Inc. (Apple Push Notification service), Google LLC (Firebase Cloud Messaging) and Microsoft Corporation (Windows Push Notification Services), only for users who opt in to push notifications - United States. We send to these services only the encrypted notification payload and the push subscription endpoint your browser or device gave us; we do not send your account information.
10.2 Where we disclose your personal information to overseas recipients, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to your personal information, or that an exception under the APPs applies.
10.3 By using the Platform, you acknowledge that your personal information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.
11. Data Collected From and About Non-Users
11.1 The Platform allows registered users to submit personal information about individuals who are not registered users of the Platform (non-users). This section describes the circumstances in which non-user data is collected and how it is handled.
Client Attestation
11.2 A registered user may request that a client (who may be a non-user) provide an attestation confirming the outcome of a referral. When this occurs, the client receives an email containing a unique attestation link. The client's response (confirmation or decline) is recorded on the Platform.
11.3 The attestation email identifies the referring user and the nature of the referral. The client's email address and response are stored for the purpose of verifying the referral outcome.
Event Invitations
11.4 A registered user may invite non-users to events by providing their email address. Non-users who are invited to events will receive an invitation email. Their email address and RSVP response (if any) are stored on the Platform.
Lead and Introduction Contact Details
11.5 When a registered user records a lead or introduction, they may provide the contact name, email address and phone number of the introduced party, who may be a non-user. This information is stored on the Platform and is visible only to the parties to the relevant referral relationship.
Partner Applications
11.6 Individuals who apply to become a Partner submit their name, email address, company name, industry, and a description of their network. This information is stored and reviewed by our team.
Calculator Tools and Lead Capture
11.7 Visitors who use any of our public calculator tools at sociibook.com/tools (including the referral fee calculator, the network ROI calculator and the commission split calculator) or submit a referral audit or affiliate ROI estimate may provide:
- their name and email address;
- their LinkedIn URL, company name, profession and country (each optional);
- the inputs they entered into the calculator and the result that was displayed back to them; and
- an explicit, opt-in (not pre-ticked) consent to receive the Socii newsletter, together with the exact wording of the consent statement they were shown.
11.7A This information is stored for the purpose of responding to the enquiry, sending the requested follow-up content, reviewing the lead for membership eligibility and (where the visitor has opted in) sending marketing communications subject to section 7.
Affiliate Referral Attribution
11.7B Where a non-user signs up to the Platform via an affiliate referral link, we record the referral code, the timestamp of the click, basic browser metadata and the resulting user identifier once the visitor registers, so that we can attribute future paid invoices to the referring partner.
Connection Records About Non-Users
11.8 A registered user may add a non-user as a connection, providing their name, email, phone number and notes. This information is visible only to the user who added it. If the non-user subsequently registers on the Platform, the connection record may be linked to their account.
12. Sensitive Information
12.1 We collect the following categories of information that may constitute sensitive information under the Privacy Act:
- dietary preferences (which may reveal information about religious beliefs or health conditions); and
- professional conduct rules and applicable legislation (which may identify membership of a professional association).
12.2 We collect dietary preferences for the purpose of catering at events and collect professional conduct information for the purpose of agreement compliance. We do not use this information for any other purpose.
12.3 By providing sensitive information to us, you consent to our collection, use and disclosure of that information in accordance with this Privacy Policy.
12.4 If you do not wish to provide sensitive information, you may leave the relevant fields blank. This may limit certain functionality (for example, dietary preferences will not be communicated to event organisers).
13. Data Retention
13.1 We retain your personal information for as long as your account is active or as needed to provide you with the Platform and our services.
13.2 When you request closure of your account, a 30-day grace period applies during which you can cancel the request. After the grace period, your identifying details (such as your name, email address, phone number and profile content) are anonymised. Business records connected to the anonymised account - including agreement, lead and financial records - are retained in anonymised or original form for up to 7 years for the purposes of complying with our legal obligations, resolving disputes and enforcing our agreements, and are then permanently deleted.
13.3 The exception is records we are required by law to keep in identified form, such as financial and tax records. These are retained for the periods the law requires, even after account closure.
13.4 Specific data types are subject to the following retention periods:
- behavioural and usage data: 90 days on a rolling basis;
- visitor tracking cookies: 12 months;
- email visitor tokens: 30 days;
- A/B test impression data: retained for the duration of the experiment plus 90 days;
- session tokens: duration of the active session;
- administrative audit logs: 7 years;
- agreement documents and audit trails: 7 years following account closure;
- lead and introduction records: 7 years following account closure;
- direct messages and thread metadata: retained while either participant maintains an active account, and thereafter for the period set out in section 13.2;
- push notification subscription endpoints: until the subscription is revoked by you or invalidated by the browser or device vendor;
- two-factor authentication secrets and backup codes: until you disable two-factor authentication or close your account;
- affiliate and partner commission ledger entries, payout batch records and milestone bonus records: 7 years (financial records);
- calculator and lead capture submissions: until you ask us to delete them, or 24 months from the date of submission if you have not converted to a registered account; and
- signed GDPR data export tokens: 24 hours from issue or until first use, whichever is sooner.
13.5 Non-user data (see section 11) is retained for as long as the registered user who submitted it maintains an active account, and thereafter in accordance with the retention periods above.
13.6 You may request deletion of your data by contacting us using the details set out in section 21. Deletion requests are subject to our legal retention obligations.
14. Access and Correction
14.1 You may access and update certain personal information we hold about you through your account settings on the Platform.
14.2 You may request access to any personal information we hold about you by contacting us using the details set out in section 21.
14.3 We will respond to your request within 30 days. We may require verification of your identity before providing access to your personal information.
14.4 You will not be charged for making an access request, but we may charge a reasonable fee for the time and expense of providing access if your request requires substantial effort.
14.4A Where we provide a copy of your personal information by email, we will send a single-use signed download link rather than attaching the full data export. The link expires 24 hours after issue or on first use, whichever is sooner. The token is stored on our servers as a SHA-256 hash so that the original link cannot be reconstructed from our database.
14.5 If you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may request that we correct that information. We will take reasonable steps to correct the information upon receiving such a request.
14.6 We may refuse a request for access or correction in circumstances permitted by the APPs. If we refuse a request, we will provide you with written reasons for the refusal.
15. Cookies and Tracking Technologies
15.1 The Platform uses cookies and similar technologies. A cookie is a small file stored on your device that assists in managing customised settings and delivering content.
15.2 We use the following types of cookies:
- Essential cookies, which are necessary for the Platform to function (including session authentication cookies). These are set regardless of your choice, because the Platform cannot work without them;
- Functional cookies, which enable enhanced functionality and personalisation (including visitor recognition cookies and the hashed browser fingerprint described in section 4.14). These are non-essential and are set only if you accept them;
- A/B testing cookies, which assign you to test variants for copy optimisation experiments. These are non-essential and are set only if you accept them.
15.2A If you reject non-essential cookies, we do not record your activity against a copy-testing variant and we do not enrol you in A/B measurement. If you have not answered the banner yet, we treat that the same way as a rejection. You can change your choice at any time from the Cookie preferences link in the footer.
15.3 We do not use advertising cookies or third-party analytics or tracking cookies. Usage measurement is performed first-party by the Platform itself (see sections 4.12 and 4.14) and is not shared with advertising or analytics networks.
15.4 You can manage your cookie preferences through your browser settings. However, disabling cookies may affect the functionality of the Platform, including the ability to log in.
15.5 The Platform displays a cookie consent notice to first-time visitors with the option to accept all cookies or reject non-essential cookies. Essential cookies are set regardless of consent as they are necessary for the Platform to function.
15.6 For information about specific cookies used by the Platform and their retention periods, please contact us using the details in section 21.
16. Security
16.1 We take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
16.2 Our security measures include:
- encryption of data in transit and at rest;
- access controls to limit access to personal information to authorised personnel; and
- regular security reviews.
16.3 However, no data transmission over the internet or data storage system can be guaranteed to be completely secure. We cannot guarantee the absolute security of your personal information.
16.4 You are responsible for maintaining the confidentiality of your account credentials and for any activity that occurs under your account.
17. Data Breaches
17.1 We have procedures in place to respond to suspected or actual data breaches.
17.2 If we experience a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- take reasonable steps to contain the breach and mitigate any resulting harm;
- assess the breach to determine whether it is an eligible data breach under the Privacy Act;
- if the breach is an eligible data breach, notify the Office of the Australian Information Commissioner and affected individuals as required under Part IIIC of the Privacy Act; and
- take steps to prevent future breaches.
18. Third-Party Links and Children's Privacy
Third-Party Links
18.1 The Platform may contain links to third-party websites, applications or services.
18.2 We are not responsible for the privacy practices of any third party. We encourage you to review the privacy policies of any third-party websites you visit.
Children's Privacy
18.3 The Platform is not intended for persons under the age of 18.
18.4 We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information.
19. Changes to This Privacy Policy
19.1 We may update this Privacy Policy from time to time.
19.2 We will notify you of any material changes by email or through a notice on the Platform.
19.3 Your continued use of the Platform following notification of changes constitutes your acceptance of the updated Privacy Policy.
19.4 The date of the most recent update is displayed at the top of this Privacy Policy.
20. Complaints
20.1 If you have any concerns about this Privacy Policy or the way we have handled your personal information, you may lodge a complaint with us.
20.2 Complaints should be directed to our Privacy Officer using the contact details set out in section 21.
20.3 We will acknowledge receipt of your complaint within 5 business days.
20.4 We will investigate your complaint and will use reasonable efforts to respond within 30 days. If we require additional time to investigate your complaint, we will notify you.
20.5 If you are not satisfied with our response to your complaint, or you consider that we may have breached the APPs or the Privacy Act, you may make a complaint to the Office of the Australian Information Commissioner (OAIC). The OAIC can be contacted:
- by telephone on 1300 363 992; or
- via the OAIC website at www.oaic.gov.au.
21. Contact
21.1 If you have any questions about this Privacy Policy or wish to make an access or correction request, please contact our Privacy Officer:
Socii Book Pty Ltd
Socii Privacy Officer
Email: hello@sociibook.com
Website: sociibook.com
See also our Terms of Use.