Privacy Policy

Goldmine Labs Pty Ltd trading as Reclaim Revenue

ABN 37 699 967 621

Effective: 6 July 2026

Last updated: 9 July 2026

Section 1. About this policy

Reclaim Revenue ("we", "us", "our") provides done-for-you database reactivation services. We operate an AI SMS agent that re-engages dormant enquiries held in our clients' customer databases and books qualified appointments on their behalf.

This policy explains how we handle personal information. It is written to align with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

A note on our obligations. Businesses with an annual turnover of $3 million or less may be exempt from the Privacy Act under the small business exemption. Regardless of whether that exemption applies to us at any given time, we have chosen to comply with the Australian Privacy Principles as a matter of policy. Handling other people's customer databases is the core of what we do, and we do not think an exemption is a sensible basis on which to do it.

Section 2. Two kinds of information, two different roles

This is the most important section of this policy. We handle personal information in two distinct capacities, and your rights differ depending on which applies to you.

(a) Information we collect for our own purposes.

This is information about our prospects, clients, website visitors and enquirers. We decide what to collect and why. We are directly accountable to you for it.

(b) Information we handle on behalf of a client.

When a business engages us, they provide us with records from their CRM — people who previously enquired with that business. We process this information solely to deliver the service our client has instructed. We do not own it, we do not sell it, we do not use it to market our own services, and we do not merge it with any other database.

If you received an SMS from us and you are wondering why: you enquired with a business at some point, and that business has engaged us to follow up with you. The business you originally contacted is the entity that holds your information and controls what happens to it. We identify that business by name in every message we send. Requests to access, correct or delete your information are usually best directed to them, though we will always act on a request made directly to us and will notify our client accordingly.

Section 3. What we collect

From clients and prospects: name, business name, position, email address, phone number, business address, billing details, and records of our communications with you.

From client databases (on their instruction): name, mobile phone number, the nature and date of the original enquiry, and any information you volunteer during an SMS conversation with our agent.

From our website: IP address, browser and device information, pages visited, and any details you submit through an enquiry form or booking calendar.

We do not collect sensitive information as defined by the Privacy Act, and we ask that you do not send it to us. If you disclose sensitive information during an SMS conversation, we will pass it to the relevant client and will not retain it separately.

Section 4. How we use information

Client and prospect information is used to provide our services, communicate with you, issue invoices, meet our legal obligations, and market our services to businesses. You can opt out of marketing at any time.

Client database information is used for one purpose only: to conduct the reactivation campaign our client has instructed, and to report the results to that client. We may use de-identified, aggregated performance data (for example, reply rates across campaigns) to improve our service and in marketing materials. Such data cannot be used to identify any individual.

Section 5. SMS messages and consent

Our messages are sent under the Spam Act 2003 (Cth) on the basis of inferred consent — you provided your contact details to a business in the context of a genuine enquiry about its goods or services, and it is reasonable to expect that business to contact you about that enquiry.

Every message we send:

- identifies the business on whose behalf it is sent;

- comes from a number that is registered and traceable to that business relationship;

- contains a functional, no-cost means of opting out.

Reply STOP at any time. Opt-outs are actioned immediately and are honoured permanently. We suppress opted-out numbers across our systems and notify our client.

Where a message is sent under Australia's SMS Sender ID Register requirements, the sender ID we use is registered in accordance with the applicable ACMA industry code.

Section 6. Who we share information with

We disclose personal information to:

- the client on whose behalf we are conducting a campaign (their own data, returned to them with conversation records and booking outcomes);

- our service providers, listed below, who host, transmit or process information on our instruction;

- anyone you ask us to, or where we are required or authorised by law.

We do not sell personal information. We do not disclose personal information to overseas recipients for direct marketing purposes.


Our principal service providers:

| Provider | Function | Data location |

| HighLevel Inc. (GoHighLevel) | CRM, SMS delivery, campaign automation | United States |

| Microsoft Corporation | Business email and document storage | Australia / United States |

| Cloudflare, Inc. | Website hosting and delivery | Global edge network |

Section 7. Overseas disclosure

Some of the providers above store or process information outside Australia, principally in the United States. Under APP 8, we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, including through contractual data protection terms.

By engaging our services or interacting with our agent, you acknowledge that your information may be stored or processed overseas.

Section 8. Security

We hold information in access-controlled cloud systems with multi-factor authentication enabled on all administrator accounts. Access to a client's database is restricted to personnel who need it to deliver that client's campaign.

No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm, we will assess and respond in accordance with the Notifiable Data Breaches scheme, and will notify affected individuals and the Office of the Australian Information Commissioner as required.

Section 9. How long we keep information

Client database information is retained only for the duration of the engagement and for 30 days after it ends, to allow for reporting and handover. It is then permanently deleted from our systems. Clients may request deletion sooner.

Opt-out records are retained indefinitely. This is deliberate: we cannot honour a permanent opt-out if we delete the record of it.

Client and prospect information is retained for the duration of our relationship and for seven years afterwards, where required for tax and record-keeping purposes.

Section 10. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Contact us using the details below. We will respond within 30 days.

There is no charge for making a request. We may charge a reasonable fee for the cost of providing access. In limited circumstances set out in the Privacy Act we may refuse a request, in which case we will tell you why in writing.

If your request concerns information we hold on behalf of a client, see section 2(b).

Section 11. Cookies and website analytics

Our website uses cookies to operate correctly and to understand how visitors use it. You can disable cookies in your browser settings, though parts of the site may not function as intended. We do not use cookies to build advertising profiles of individuals.

Section 12. Complaints

If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact us first. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to:

Office of the Australian Information Commissioner (OAIC)

Website: oaic.gov.au

Phone: 1300 363 992

Post: GPO Box 5218, Sydney NSW 2001

Section 13. Changes to this policy

We may update this policy from time to time. The current version is always available at www.reclaim-revenue.com and takes effect from the date it is published. Material changes affecting how we handle client database information will be notified to affected clients directly.

Section 14. Contact us

Privacy Officer

Goldmine Labs Pty Ltd t/as Reclaim Revenue

Email: [email protected]