Privacy Policy
Address: Level 7, 222 Exhibition Street, Melbourne VIC 3000, Australia
1. About this policy
1.1 This policy explains how 121 Group Pty Ltd (we, us) handles personal information in Reachable, our lifecycle email and SMS platform at getreachable.com.au and associated or successor domains (the Service).
1.2 We seek to comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles. Our Data Processing Agreement applies by default when we process Customer Data for a customer.
2. Information we handle
2.1 Account information. We collect user names, business and contact details, billing identifiers, login and session information, plan selection, legal acceptance records, support correspondence and records of Service use. We determine how this information is processed to operate the customer relationship.
2.2 Customer Data. Customers may upload or connect names, email addresses, phone numbers, identifiers, consent records, transaction and engagement history, custom attributes and message content concerning their subscribers and contacts. The customer controls this information; we process it on the customer's documented instructions to provide the Service.
2.3 Technical information. We collect limited device, browser, IP, security, event and diagnostic information. Our public website uses first-party, privacy-preserving funnel events and does not use third-party advertising cookies.
3. Collection and use
3.1 We collect account information directly from users, Customer Data from customer uploads and enabled integrations, and interaction data when a recipient receives or interacts with a message, such as delivery, bounce, complaint, open, click, reply, unsubscribe and STOP events.
3.2 We use account information to provide accounts, security, billing, support, legal and service notices and to operate and improve Reachable. We use Customer Data only to host, segment, transmit and report the messaging configured by the customer, maintain consent and suppression records, provide support and security, and comply with law.
3.3 We do not sell or rent personal information or use one customer's contact list to market for us or another customer. We may use aggregated or de-identified information that cannot reasonably identify a customer, user or recipient to operate, secure and improve the Service.
4. Internal access
4.1 Internal access is role-based and limited to personnel who need it to operate the Service, provide customer-requested support, investigate abuse or security incidents, or comply with law. Authorised staff administration, exports and material changes are audited.
4.2 Some support and operational roles can access individual records when necessary. We train authorised personnel and require them to protect confidentiality. We do not claim that all internal tools are counts-only.
5. Disclosure and service providers
5.1 We disclose information to service providers needed to operate Reachable, professional advisers under confidentiality, a successor in a business transaction subject to appropriate safeguards, and regulators or other parties where required or permitted by law.
5.2 Key providers include Google Cloud for Australian application and database hosting; Amazon Web Services SES in Sydney for campaign delivery; Resend for platform and, where configured, email delivery; MobileMessage and carrier networks for SMS; Stripe for billing; Cloudflare for network security and delivery; Google for sign-in and support email; and optional customer-selected integrations such as Shopify. The current list and purpose are at Subprocessors.
5.3 We do not disclose one customer's Customer Data to another customer.
6. Hosting and overseas disclosures
6.1 Reachable's application, primary database and backups are configured in Australian cloud regions. Campaign email is sent through Amazon SES in ap-southeast-2 (Sydney).
6.2 Some necessary processing or disclosure may occur outside Australia through message transit, card billing, network security, account email, sign-in, recipient networks or an integration enabled by the customer. Likely locations include Australia, the United States and countries in which the recipient's email or telecommunications provider, the customer's connected service, or the relevant global provider operates. Provider locations can change; current details are described on our Subprocessors page.
6.3 We take reasonable steps to use providers with appropriate privacy and security commitments and to address applicable cross-border disclosure obligations.
7. Security and data breaches
7.1 Controls include encryption in transit, secret management, tenant separation using PostgreSQL row-level security, role-based access, hashed passwords, optional authenticator-app 2FA, session revocation, audit records and Australian backups. More detail is on our Security page.
7.2 No system is absolutely secure. We assess suspected breaches under the Notifiable Data Breaches scheme and notify affected customers and authorities when required by law and our DPA.
8. Unsubscribe and preferences
8.1 Marketing email includes a one-step unsubscribe link and marketing SMS supports STOP and common variants. A valid request immediately changes the relevant consent state and suppresses further marketing on that channel; no login, survey or confirmation is required.
8.2 We retain a minimal suppression record so that an opt-out continues to be honoured. A customer must not override it without fresh, verifiable consent.
9. Retention and deletion
9.1 We retain account and billing records while needed for the customer relationship and legal, accounting, fraud-prevention and tax obligations.
9.2 Customer Data is retained during the subscription. When a customer closes a workspace, sending is disabled and deletion is scheduled after the 30-day export window, subject to backups cycling out, legal retention and minimal suppression records.
9.3 Requests to access, correct or delete account information may be sent to privacy@121group.io. An end recipient should normally contact the customer that sent the message; we will assist that customer and may act directly where appropriate or required.
10. Complaints and contact
10.1 Send privacy questions or complaints to privacy@121group.io. We will acknowledge a complaint promptly and aim to respond within 30 days.
10.2 If you are not satisfied, you may complain to the Office of the Australian Information Commissioner.
10.3 We may update this policy on at least 30 days' notice for a material change. If an adverse material change affects a paid customer, the termination and refund rights in the Terms apply.