Privacy Policy
Portal Mate
Effective date: July 15, 2026 Last updated: July 15, 2026
This Privacy Policy explains how Union Mate Pty Ltd ("Portal Mate," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the Portal Mate service available at portalmate.app and its tenant subdomains (*.portalmate.app) (collectively, the "Service").
Portal Mate is a multi-tenant SaaS platform that lets our business customers ("Customers") build branded portals that render content the Customer connects from Google Docs, Google Sheets, and Google Slides. People who sign in to and browse a Customer's portal are "End Users." As an Australian company, we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), in addition to the GDPR (for EEA/UK individuals) and the CCPA/CPRA (for California residents) where those laws apply.
This policy applies to both Customers and End Users, but our role differs depending on the data — see Our Role: Controller vs. Processor below.
1. Summary
- End Users sign in with a passwordless email "magic link." We store the email address you use to sign in so we can authenticate you and let the portal owner control access.
- Customers connect content from Google Docs, Sheets, and Slides. We read that content (read-only) to render it in the portal and to generate content overviews.
- We use a small set of trusted subprocessors: Google Cloud / Firebase (authentication, database, hosting), SendGrid (email delivery), and Google Vertex AI (automated content overviews).
- Portal owners (Customers) decide who may access their portal. We host and secure the data; the Customer controls it.
- We do not sell personal information and we do not use End User content to train our own or third parties' foundation models.
- If you are in the EEA/UK or California, you have specific rights described in Sections 10 and 11.
2. Our Role: Controller vs. Processor
Portal Mate plays two different roles depending on the data:
| Data | Our role | Controller |
|---|---|---|
| Customer account data (billing contact, portal owner/admin accounts, configuration) | Controller | Portal Mate |
| Content a Customer connects from Google Docs/Sheets/Slides, and End User personal data processed inside a Customer's portal (including End User sign-in emails and access logs for that portal) | Processor (on the Customer's behalf) | The Customer |
Website visitors, marketing, and support interactions with portalmate.app | Controller | Portal Mate |
Where we act as a processor, we process personal data only on the documented instructions of the Customer, under the Data Processing Addendum. If you are an End User and want to exercise privacy rights over data inside a specific portal, you may need to contact the portal owner (the Customer), who is the controller of that data. We will assist our Customers in responding to such requests.
3. Information We Collect
3.1 Information from End Users (portal sign-in and use)
- Email address. When you sign in to a portal, you request a magic link sent to your email. We store your email address to authenticate you, to create your session, and to let the portal owner manage who may access the portal. Authentication is handled by Firebase Authentication.
- Authentication and session data. A secure, HTTP-only session cookie is set in your browser after sign-in so you stay logged in. We also process authentication tokens and tenant/portal access claims associated with your account.
- Access and security logs. To operate the Service securely and prevent abuse, we log request metadata such as IP address, timestamp, and the endpoint accessed. For example, our magic-link endpoint records a truncated IP address for rate-limiting and abuse forensics because all tenants share one email-sending reputation.
- Portal content you view or interact with. Records of which portal areas you are authorized to access, and search queries you run inside the portal.
3.2 Information from Customers (account and configuration)
- Account and identity data. The email address of the portal owner and any admin or member accounts, and the organization/customer identifier.
- Portal configuration. Portal settings, branding, access policies, access groups, and the list of email addresses or domains a Customer authorizes to access its portal.
- Billing information. If applicable, billing contact details and subscription records. Payments are processed by Stripe; we do not store full payment-card numbers.
3.3 Connected Google Workspace content
When a Customer connects a Google Doc, Sheet, or Slides file, we access that file using Google APIs with read-only scope (drive.readonly and the Sheets/Docs/Slides read APIs). We synchronize and store a rendered copy of that content so the portal can display it quickly. This content may contain personal data that the Customer chose to include; the Customer is the controller of that content and is responsible for having a lawful basis to process it and to expose it to their End Users.
3.4 Automatically generated content (AI overviews)
At content-sync time, we use Google Vertex AI (Gemini models) to generate section and content overviews and search embeddings from the Customer's connected content. These overviews are pre-generated and stored; the portal serves them without making live AI calls per visitor. See Section 7 (Automated Processing and AI).
3.5 Optional integrations
A Customer may enable optional integrations, such as a ThoughtSpot analytics embed on its portal. If enabled, the embedded third-party component is governed by that provider's terms and privacy practices. For portals that enable ThoughtSpot analytics, the signed-in user's email and analytics query context are shared with ThoughtSpot to render embedded dashboards.
3.6 Website and marketing data
If you visit our marketing site or contact us, we may collect the information you submit (name, email, message) and standard analytics. We do not currently use a third-party web-analytics tool on portals.
4. How We Use Information
We use personal information to:
- Provide the Service — authenticate End Users, render connected content, generate overviews, and operate portals.
- Enforce access control — apply the access policies and allowlists configured by each Customer so only authorized End Users see a portal's content.
- Send transactional email — deliver magic-link sign-in emails and service notifications via SendGrid.
- Secure and maintain the Service — rate-limit abuse, detect fraud, debug, and protect the shared email-sending reputation across tenants.
- Support Customers — respond to requests and troubleshoot.
- Comply with law — meet legal, tax, and regulatory obligations.
- Improve the Service — analyze aggregated, de-identified usage to improve reliability and features.
We do not use End User content or a Customer's connected Google Workspace content to train our own or third parties' generative-AI foundation models.
5. Legal Bases for Processing (EEA/UK)
Where we act as a controller and the GDPR or UK GDPR applies, we rely on:
- Contract (Art. 6(1)(b)) — to provide the Service you or your organization requested (e.g., authenticating your sign-in, sending magic links).
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse, and improve reliability, balanced against your rights.
- Consent (Art. 6(1)(a)) — where required, e.g., certain cookies or marketing.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law.
Where we act as a processor, the Customer (controller) is responsible for establishing the lawful basis for the processing carried out through the Service.
6. How We Share Information (Subprocessors and Disclosures)
We do not sell personal information and we do not share it except as described here.
6.1 Subprocessors
We use the following subprocessors to run the Service:
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud Platform / Firebase (Google LLC / Google Ireland Ltd.) | Authentication (Firebase Auth), database (Firestore), and hosting (App Hosting / Cloud Run) | Account data, End User emails, connected content, generated overviews, logs | United States (us-east4 / us-central1) |
| Twilio SendGrid | Delivery of magic-link and notification emails | Recipient email address, email metadata | United States |
| Google Vertex AI (Google Cloud) | Automated generation of content overviews and search embeddings at sync time | Connected content text | United States (us-central1) |
| ThoughtSpot (analytics embedding, for portals that enable it) | Optional Customer-enabled analytics embed | connected content text | United States |
Our current subprocessors are listed in the table above (Google Cloud / Firebase, Twilio SendGrid, Stripe, Google Vertex AI). We give Customers advance notice before adding or replacing a subprocessor, as described in the DPA.
6.2 Between Customers and their End Users
Each portal is controlled by its Customer. A Customer's admins can see the email addresses of End Users who access their portal and can manage access. Portal Mate does not expose one Customer's data to another Customer.
6.3 Legal and safety disclosures
We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Portal Mate, our Customers, or the public. Where legally permitted, we will notify the affected Customer.
6.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
7. Automated Processing and AI
We use Google Vertex AI (Gemini) to generate content overviews, summaries, and search embeddings from Customer-connected content at sync time. These are informational summaries displayed in the portal; they do not produce legal or similarly significant decisions about any individual, and there is no automated decision-making that produces legal effects on End Users within the meaning of GDPR Art. 22.
We do not use this content to train foundation models. Per Google Cloud's terms, prompts and content submitted to Vertex AI are not used by Google to train its models. We rely on Google Cloud's data-processing and AI/ML data-governance terms; content processed by Vertex AI is not used to train Google's foundation models.
8. Cookies and Similar Technologies
Portal Mate uses a small number of cookies:
- Essential / authentication cookies — a secure, HTTP-only session cookie that keeps you signed in to a portal. The Service does not function without this cookie.
- None currently; portals use only essential cookies (authentication session and App Check). — none other than those listed above. Where required by law, we request consent before setting non-essential cookies.
You can control cookies through your browser settings; disabling essential cookies will prevent sign-in. Because portals currently use only essential cookies, no consent banner is required; if non-essential cookies are introduced we will display a consent banner and honor Global Privacy Control signals.
9. Data Retention
- End User account / email: retained while the End User has access to a portal and for the account's lifetime, then deleted or de-identified within 90 days of account deletion or loss of access.
- Connected content and generated overviews: retained while the Customer keeps the content connected; refreshed on sync and deleted when the Customer disconnects the content or terminates the account, within 90 days.
- Security and access logs: retained for 90 days for abuse prevention and forensics.
- Backups: may persist for up to 35 days before being overwritten.
When a Customer's account is terminated, we delete or return Customer data as described in the DPA, subject to legal retention requirements.
10. Your GDPR Rights (EEA/UK)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the right to:
- Access your personal data and obtain a copy.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten").
- Restriction of processing.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your supervisory authority.
To exercise these rights, contact us at legal@portalmate.app. Where Portal Mate acts as a processor, we will refer your request to the relevant Customer (controller) or act on their instructions.
- Data Protection Officer / Privacy contact: We have not appointed a statutory Data Protection Officer; direct privacy inquiries to legal@portalmate.app.
- EU Representative (Art. 27): Not currently appointed (to be designated if required under GDPR Article 27).
- UK Representative: Not applicable.
International data transfers
We are based in Australia, and our subprocessors may process data in the United States. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum), and, where applicable, the EU-U.S. / UK / Swiss Data Privacy Framework. We rely on the Standard Contractual Clauses together with Google Cloud's data-transfer terms for any transfer of personal data outside your region.
11. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the rights below. Note that much of the personal information we process on behalf of Customers is subject to the CCPA's business-to-business and service-provider provisions; for that data we act as a service provider to the Customer.
11.1 Categories of personal information
In the past 12 months we have collected the following categories (as defined in Cal. Civ. Code § 1798.140):
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email address, IP address, account/user IDs | Yes |
| Customer records | Billing contact details | Yes |
| Internet/network activity | Access logs, portal usage, search queries | Yes |
| Geolocation | Coarse location inferred from IP | Yes (coarse only) |
| Professional/employment info | If included in connected content | Possibly (Customer-controlled) |
| Other content | Data within connected Google Workspace files | Possibly (Customer-controlled) |
We collect this information from the sources described in Section 3 and use it for the purposes in Section 4.
11.2 Your rights
- Right to know what personal information we collect, use, and disclose.
- Right to delete personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt out of sale/sharing of personal information.
- Right to limit use of sensitive personal information.
- Right to non-discrimination for exercising your rights.
11.3 We do not sell or share personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CPRA. We honor opt-out preference signals such as Global Privacy Control where applicable.
11.4 Sensitive personal information
We do not use or disclose sensitive personal information for purposes other than those permitted under CPRA § 1798.121 (i.e., to provide the Service).
11.5 How to exercise your rights
Submit a request to legal@portalmate.app or by emailing legal@portalmate.app. We will verify your request using the email associated with your account. You may use an authorized agent. We will respond within the timeframes required by law. For data we process on a Customer's behalf, we will direct your request to that Customer.
12. Security
We implement technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest (Google Cloud managed encryption).
- Passwordless, magic-link authentication and secure, HTTP-only session cookies.
- Tenant isolation enforced by Firestore security rules and per-tenant access claims.
- Read-only access to connected Google Workspace content.
- Rate limiting and abuse detection on public endpoints.
- Access controls and least-privilege service accounts.
No system is perfectly secure. If we become aware of a personal-data breach, we will notify affected Customers and, where required, regulators and individuals, without undue delay.
13. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us at legal@portalmate.app and we will delete it.
14. Data Processing Addendum (DPA)
For personal data we process on a Customer's behalf, our Data Processing Addendum (DPA) governs and is incorporated by reference into the Customer's agreement. It sets out the subject matter, duration, nature and purpose of processing, categories of data subjects and personal data, subprocessor terms, security measures, and international transfer mechanisms. Customers may request a signed DPA at legal@portalmate.app.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (e.g., email or in-product notice). Your continued use of the Service after the effective date constitutes acceptance.
16. Contact Us
Union Mate Pty Ltd Australia Privacy / DPO contact: legal@portalmate.app General contact: legal@portalmate.app
If you are in the EEA/UK and have concerns we have not resolved, you may contact our not currently appointed; we will designate one if and when required under GDPR Article 27 / UK GDPR or lodge a complaint with your local supervisory authority.