Privacy & Cookie Policy Statement
Privacy Policy — Larrg. Last updated: 31 March 2026
1. Introduction
Larrg Pty Ltd (ABN 31 678 805 000) ("Larrg", "we", "us", "our") is committed to protecting your personal information and complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, store, and otherwise handle personal information in connection with our website, products, and services.
2. What Personal Information We Collect
We collect only the personal information necessary to provide and operate the Larrg platform. The categories of data we collect are:
2.1 Account Information
- Full name, email address, and password (stored as a salted hash — we never see or store your plaintext password)
- Organization name and job title
- Phone number (used solely for SMS notification delivery, where you opt in)
2.2 Authentication Data
- Login timestamps and session tokens
- IP addresses (retained for security monitoring and abuse prevention)
2.3 Subscription Data
- Plan tier (Starter, Professional, or Enterprise)
- Billing information and payment history (payment card details are processed by our PCI-compliant payment provider, Stripe — we do not store full card numbers on our servers)
2.4 Monitoring Configuration & Preferences
- Tracked entities: Which of the 892 government entities you are monitoring (departments, courts, councils)
- Topic selections: Which of the 346 legal topics across 23 categories you follow
- Content type filters: Which of the 7 content types you wish to receive (legislation, media releases, speeches, consultations, decisions, policy & guidance, subordinate legislation)
- Geographic scope: Federal, State, and/or Local jurisdiction preferences
- Priority settings: High, medium, and low priority configurations for different topics
2.5 Notification Preferences
- Channel settings: Email, Slack, WhatsApp, and SMS preferences
- Frequency settings: Timely alerts versus daily digest
- Integration tokens: Slack webhook URLs and WhatsApp API credentials (encrypted at rest)
- Notification history: When notifications were sent to you and their delivery status
2.6 Usage & Engagement Data
- Activity logs: Search queries, items viewed, and exports requested
- Interaction data: Which legislative updates were opened, marked relevant, or bookmarked
- Dashboard configurations: Saved searches, custom views, and filters
- User notes: Any comments or annotations you add to legislative items
2.7 What We Do Not Store
Larrg does not store full-text legislative content. Our platform detects changes to government sources and delivers notifications containing summaries, links, and contextual metadata — the underlying legislation, bills, and parliamentary documents remain on the official government websites. This minimises our data footprint and ensures we never become a secondary repository for source material. Similarly, documents uploaded for analysis are scanned and instantly deleted — no document content is retained (see section 2.8).
We do not collect sensitive information (as defined under the APPs) unless required and with your explicit consent.
2.8 Document Uploads — No Retention
When you upload a document for analysis (e.g. to identify relevant jurisdictions and topics), the document is processed solely for the purpose of extracting metadata. The file is scanned in temporary memory and instantly deleted after analysis — no document content, file URL, or original file is retained in our database. Only the extracted topics, jurisdictions, government entities, and a brief AI-generated summary are stored, and only if you choose to save them. You can delete any stored analysis at any time.
3. How We Collect Personal Information
We collect personal information:
- Directly from you when you use our website, register for an account, contact us, or complete a survey or form
- Automatically through cookies and analytics tools when you visit our website (see our Cookie Policy for details)
- From third parties, where permitted by law
We will only collect personal information by lawful and fair means.
4. Why We Collect Personal Information
We collect and use personal information for the following purposes:
- Providing and improving our products and services
- Communicating with you about your account or enquiries
- Conducting research and analytics (including aggregated, anonymised survey analysis)
- Complying with our legal obligations
- Marketing and promotional communications (where you have consented)
We will not use or disclose your personal information for any other purpose without your consent, unless required or authorised by law.
5. Survey Data
Where you participate in a Larrg survey, your responses are used for research and product development purposes only. Survey responses are aggregated and reported anonymously — no individual response will be attributed to you or shared with any third party in an identifiable form.
6. Disclosure of Personal Information
We may disclose your personal information to:
- Service providers and technology partners who assist us in operating our business
- Professional advisors (lawyers, accountants) where necessary
- Regulatory bodies or law enforcement agencies where required by law
6.1 Overseas Disclosure — Data Storage Location
Your account data, monitoring preferences, notification history, and platform information are stored on secure cloud servers located in the United States, hosted by our cloud infrastructure provider (Base44). This means your personal information is disclosed to and held by overseas recipients in the United States.
Under Australian Privacy Principle 8 (APP 8 — Cross-border disclosure of personal information), we are required to take reasonable steps to ensure that overseas recipients do not breach the APPs in relation to your information. We disclose this overseas storage arrangement so you can make an informed decision about providing your personal information to Larrg. By using our services, you acknowledge and consent to your personal information being stored and processed in the United States.
We do not sell your personal information to third parties. Other service providers (e.g. our PCI-compliant payment provider, Stripe) may also be located outside Australia. Where we disclose personal information to any overseas recipient, we take reasonable steps to ensure those recipients handle your information in a manner consistent with the APPs.
7. Storage and Security
We store personal information on secure cloud servers located in the United States, hosted by our cloud infrastructure provider (Base44). We take reasonable technical and organisational measures to protect it from loss, theft, unauthorised access, disclosure, copying, use, or modification. See section 6.1 above for details on overseas disclosure and APP 8 compliance.
7.1 Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Sensitive data — including integration tokens (Slack webhook URLs, WhatsApp API credentials) — is encrypted at rest
- Passwords are never stored in plaintext; they are salted and hashed using industry-standard algorithms
- Payment card data is handled exclusively by our PCI-DSS compliant payment provider (Stripe) and never touches our infrastructure
7.2 Data Retention
- Account and subscription data is retained for the life of your account and deleted within 30 days of account closure
- Activity logs and engagement data are retained for up to 24 months for analytics and product improvement
- Authentication and security logs (IP addresses, login timestamps) are retained for up to 12 months for security monitoring
- Notification history is retained for up to 12 months
- When data is no longer required, it is securely destroyed or de-identified in accordance with our retention schedule
7.3 Anonymisation
Where data is used for analytics, product improvement, or research purposes, it is aggregated and de-identified so that it cannot reasonably be linked back to an individual user.
7.4 SOC 2 Compliance
Larrg is working towards SOC 2 Type II readiness. We have engaged Vanta to support our compliance programme and are in the process of implementing the controls necessary to meet the SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy). We do not yet hold a SOC 2 attestation; this is a forward-looking programme and further updates on our compliance status will be published as it progresses.
7.5 Data Minimisation
We apply the principle of data minimisation: we collect only what is necessary for the platform to function and deliver value. We do not store full-text legislative content, which significantly reduces the volume and sensitivity of data we hold.
7.6 Notifiable Data Breaches (NDB) Scheme
Under Part IIIC of the Privacy Act 1988 (Cth), Larrg is subject to the Notifiable Data Breaches scheme. If we experience a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Conduct an expedited assessment of the breach within 30 days of becoming aware of it
- Notify affected individuals as soon as practicable after concluding the breach is an "eligible data breach"
- Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- Include in our notification: the identity and contact details of Larrg, a description of the breach, the kinds of information involved, and recommended steps for affected individuals to protect themselves
We maintain internal incident response procedures to ensure rapid detection, containment, and notification of eligible data breaches in accordance with our obligations under the NDB scheme.
7.7 Australian Privacy Principles (APP) Compliance
Larrg's data handling practices are mapped to the Australian Privacy Principles as follows:
- APP 1 — This Privacy Policy is publicly available and kept up to date
- APP 2 — Users may browse legislative updates anonymously without an account
- APP 3 — We collect only personal information reasonably necessary for the platform's function
- APP 5 — This policy notifies individuals of the collection of their personal information at or before collection
- APP 6 — Personal information is used only for the purposes stated in this policy
- APP 7 — Direct marketing communications are sent only with consent and include a functional unsubscribe facility (Spam Act 2003 compliant)
- APP 8 — Overseas disclosure to the United States is disclosed in section 6.1
- APP 11 — Security measures include row-level access controls, TLS encryption, and security headers (see section 7.1)
- APP 12 — Individuals may request access to their personal information (see section 8)
- APP 13 — Individuals may request correction of their personal information (see section 8)
8. Access, Correction, Export, and Deletion
You have the right to request access to the personal information we hold about you, and to request corrections if it is inaccurate, incomplete, or out of date.
You also have the right to export your data — including your account information, monitoring preferences, notification history, and dashboard configurations — in a machine-readable format. To request a data export, contact us at contact@larrg.com.
You may request deletion of your account and associated personal data at any time. Upon such a request, we will securely delete your data in accordance with our retention schedule, except where we are required to retain certain records for legal, accounting, or security purposes.
9. Spam Act 2003 Compliance
All commercial electronic messages sent by Larrg — including daily legislative digests and tracked update alerts — comply with the Spam Act 2003 (Cth). Specifically:
- Consent: We send electronic messages only to users who have registered an account and configured notification preferences
- Sender identification: Every message clearly identifies Larrg Pty Ltd as the sender, including our ABN and physical address
- Functional unsubscribe: Every message includes a prominent, functional unsubscribe link that directs recipients to their notification preference settings, where they may disable or modify email alerts at any time
- No concealed sender information: We do not use misleading subject lines or disguised sender identities
10. Complaints
If you believe we have handled your personal information in a way that does not comply with the APPs, you may lodge a complaint with us. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC).
11. Contact Us
For privacy enquiries, access requests, corrections, or complaints, please contact contact@larrg.com, 81-83 Campbell St, Surry Hills, NSW 2010, Australia.
12. Changes to This Policy
Larrg may update this Privacy Policy from time to time. The current version will always be available on our website. We encourage you to review this policy periodically. Material changes will be notified to you where practicable.
Cookie Policy
Last updated: March 2026
1.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently, improve user experience, and provide information to website operators.
1.2 How Larrg Uses Cookies
- Essential Cookies — necessary for the website to function.
- Analytics and Performance Cookies — help us understand how visitors interact with our website.
- Functional Cookies — remember choices you make for enhanced features.
- Marketing and Targeting Cookies — deliver content and advertisements relevant to your interests.
1.3 Third-Party Cookies
Some cookies on our website are set by third-party service providers, including analytics and advertising partners. We do not control these cookies.
1.4 Your Cookie Choices
- Browser settings: Most browsers allow you to refuse or delete cookies.
- Opt-out tools: For analytics cookies, you can opt out of Google Analytics.
- Cookie consent banner: Where required, we will ask for your consent before placing non-essential cookies.
Please note that disabling certain cookies may affect the functionality of the website.