Privacy Policy
Last updated: 12 September 2026
This Privacy Policy explains how HODforce collects, uses, stores, and discloses information when you register, run a workspace, add Knowledge Center material, or use Website Reception, connected email, SMS, or phone. It should be read with our Terms of Service.
1. Who HODforce is
HODforce is an Australian-operated AI workforce platform. We provide the HODforce website and the HODforce Service described in our Terms of Service.
These documents use the name “HODforce”. We have not included a registered company name, ABN, ACN, or postal address here because those details have not been confirmed for publication. When they are confirmed, we will update this Policy.
If you have a privacy question, contact support@hodforce.com or use the contact options on our website.
2. Information we collect
We collect information needed to create accounts, run workspaces, operate the AI Executive Team, send and receive customer communications you enable, take payment for subscriptions, and keep the Service secure.
The categories below explain the main types of information. What we actually hold for you depends on the features you use. We do not collect every category for every visitor.
3. Account and business information
When you register or manage a workspace we may collect your name, email address, phone number, password or sign-in details, business name, workspace settings, role, and similar account information.
We also keep records of the package or trial associated with your workspace and the features you have enabled.
4. Customer, lead, member, and contact information
If you use HODforce to talk with your customers or leads, we may store names, email addresses, phone numbers, enquiry details, conversation history, and other contact information that you, your team, or those people provide.
That information belongs to your business relationship with those people. You are responsible for collecting it lawfully and for telling them, where required, that your business uses HODforce to help manage communications.
5. Communications information
We process the content and metadata of conversations that take place through HODforce. That can include website chat messages, email subject lines and bodies, SMS text, call-related information where phone is enabled, timestamps, channel type, and which AI executive or human handled the conversation.
We use this information to maintain thread continuity, generate replies, show your team what happened, and improve reliability of the Service for your workspace.
6. Connected email information
If you connect a mailbox, HODforce may process emails that are relevant to customer conversations. That typically includes the sender and recipient addresses, subject, message body, timestamps, and thread identifiers needed to keep a conversation together.
We use that information to detect inbound customer email, understand context, generate an AI reply, and send the reply through the same connected mailbox. We do not ask you to share mailbox passwords with us. Connection uses the mailbox provider’s sign-in and permission flow.
We do not claim to need every message in your mailbox. We process what is reasonably required to operate inbound detection, conversation continuity, and outbound replies for the Service.
7. Website Reception and chat
If you install Website Reception or use HODforce website chat, we collect messages visitors send, technical information needed to run the widget, and any name, email, or phone number a visitor chooses to provide.
The widget is bound to the workspace identified in the install configuration. We do not use one customer’s Website Reception install to access another customer’s conversations or Knowledge Center.
8. SMS and phone where enabled
Where SMS or phone is enabled for your workspace, we may process phone numbers, message content, call metadata, and, if a feature records or transcribes a call, that recording or transcript.
Telephony is typically provided by a third-party communications provider. Delivery, caller ID, and carrier handling are outside HODforce’s full control.
9. Knowledge Center and business information
You may add services, hours, pricing you choose to publish, FAQs, policies, and other business knowledge. We store that material so HODforce can ground answers in what you have taught the workspace.
Do not put secrets, card numbers, or other people’s sensitive information into the Knowledge Center unless you have a lawful reason and it is necessary.
10. Integration information
When you connect a third-party service, we receive the identifiers and data that connection needs to work — for example a mailbox address, a provider account identifier, or a status showing the connection is healthy.
We do not publish connection secrets such as access tokens in this Policy or in product pages, and you should not send those secrets to support email.
11. Billing and payment information
If you subscribe, we keep records of your plan, billing email, invoices, and payment status. Payments are processed by a third-party payment provider.
HODforce does not store complete card numbers. Card details are entered with the payment provider. We may receive a limited token or last-four digits and expiry metadata from that provider so we can show billing status and retry a failed charge.
12. Technical, log, and device information
We collect technical information such as IP address, browser or app type, device signals, approximate location derived from IP, cookies or similar identifiers, and logs of requests, errors, and security events.
We use this information to operate, secure, and diagnose the Service — not to read the content of your customer conversations for advertising.
13. How information is collected
We collect information in these main ways:
- directly from you when you register, configure a workspace, or contact us;
- from your customers or website visitors when they message you through HODforce;
- automatically when you or they use the website, widget, or connected channels;
- from integrations you authorise, including Google and Microsoft mailboxes; and
- from payment and communications providers that process transactions or message delivery for the Service.
14. How information is used
We use information to provide HODforce, including creating workspaces, routing conversations to the relevant AI executive or human, generating replies, sending messages on the channels you enable, billing subscriptions, providing support, preventing abuse, and meeting legal obligations.
We may also use aggregated or de-identified information to understand how the product is used. We do not sell personal information.
15. AI processing
To generate a response, HODforce may send relevant conversation text, Knowledge Center excerpts, and workspace instructions to AI service providers. Those providers process that information so the model can produce a reply for your workspace.
We use this processing to operate HODforce for you. We do not claim that your customer emails, chats, or Knowledge Center content are used to train general-purpose foundation models that we do not control. If that practice changes, we will update this Policy.
AI processing can be imperfect. You should supervise outputs that matter to your customers.
16. Service providers
We use service providers to host the product, send email or SMS, process payments, provide AI generation, and monitor reliability. They are allowed to process information only to provide their service to us, subject to their terms and applicable law.
We choose providers we consider reputable, but we do not claim that any provider is free of incidents or that we can control every server they operate.
17. Google-connected mailbox data
You may connect a Google mailbox, including personal Gmail and Google Workspace mailboxes, where HODforce supports that connection.
If you do, HODforce may read inbound messages that are relevant to customer conversations and may send replies from that mailbox. We do this so the AI Executive Team can detect a customer email, keep the same conversation together, draft a response, and send it from your connected Google address rather than from an unrelated HODforce mailbox.
We process the message content and thread information needed for that workflow. We do not use your Google connection to advertise to your contacts or to access a different customer’s workspace.
18. Microsoft-connected mailbox data
You may connect a Microsoft mailbox, including Outlook, Hotmail, Live, and Microsoft 365 mailboxes, where HODforce supports that connection.
If you do, HODforce may process inbound Inbox messages that are part of a customer conversation and may send replies through that mailbox so the reply appears in your Sent Items. We use conversation identifiers supplied by Microsoft to keep a follow-up in the same thread.
We process the sender, recipients, subject, body, and thread information needed to ingest the message, generate a reply, and send it. We do not use a Microsoft connection from Workspace A to read Workspace B’s mail.
19. Overseas and cloud processing
HODforce is operated from Australia and uses cloud infrastructure and AI providers. Some of those providers may process information on servers outside Australia, including in the United States and other countries where they operate.
When information is processed overseas, it may be subject to the laws of that country, which can differ from Australian law. We take reasonable steps to use established providers. We do not claim that overseas processing has identical legal protection in every location, and we do not list every data-centre country because those locations can change as providers operate their networks.
20. Data security
We take reasonable technical and organisational steps to protect information, including access controls, encrypted connections in transit where the product uses HTTPS, and restricted handling of mailbox credentials.
No internet service is completely secure. We do not claim absolute security, and we do not claim security certifications in this Policy. You should use strong passwords, limit workspace invites, and disconnect integrations you no longer need.
21. Data retention
We keep account, conversation, and Knowledge Center information for as long as your workspace is active and for a reasonable period afterwards so you can return, we can complete billing, or we can meet a legal obligation.
If you cancel and ask us to delete a workspace, we will take reasonable steps to delete or de-identify personal information that we no longer need, except where we must keep a record (for example a tax invoice or a record of a complaint).
We do not publish a single fixed retention period for every data type because needs differ by channel, billing, and legal requirement.
22. Access and correction
You can often access or correct account and workspace information by signing in. If you cannot, email support@hodforce.com and tell us what you want to access or correct.
If you are an individual whose information was stored because you contacted a HODforce customer (for example you emailed a studio that uses HODforce), you may also contact that business. We can help where we are able to identify your information and the request is lawful.
23. Privacy enquiries and complaints
If you have a privacy enquiry or complaint, contact support@hodforce.com. Please include enough detail for us to investigate. We will try to respond within a reasonable time.
If you are not satisfied, you may be able to contact the Office of the Australian Information Commissioner (OAIC). This Policy does not guarantee a particular outcome and is not legal advice about whether the Privacy Act 1988 (Cth) or the Australian Privacy Principles apply to a specific activity.
24. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of the page will change when we do. For material changes, we will take reasonable steps to notify account holders.
The current Policy is the version published on this page.
25. Contact
Privacy questions can be sent to support@hodforce.com or submitted through the HODforce contact page.
Do not email mailbox passwords, access tokens, or full payment-card numbers. We have not published a registered office address in this Policy because it has not been confirmed.
Privacy enquiries
Email support@hodforce.com or use our contact page.