Privacy Policy

Portal Mate

Effective date: July 15, 2026 Last updated: July 15, 2026

This Privacy Policy explains how Union Mate Pty Ltd ("Portal Mate," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with the Portal Mate service available at portalmate.app and its tenant subdomains (*.portalmate.app) (collectively, the "Service").

Portal Mate is a multi-tenant SaaS platform that lets our business customers ("Customers") build branded portals that render content the Customer connects from Google Docs, Google Sheets, and Google Slides. People who sign in to and browse a Customer's portal are "End Users." As an Australian company, we handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), in addition to the GDPR (for EEA/UK individuals) and the CCPA/CPRA (for California residents) where those laws apply.

This policy applies to both Customers and End Users, but our role differs depending on the data — see Our Role: Controller vs. Processor below.


1. Summary


2. Our Role: Controller vs. Processor

Portal Mate plays two different roles depending on the data:

DataOur roleController
Customer account data (billing contact, portal owner/admin accounts, configuration)ControllerPortal Mate
Content a Customer connects from Google Docs/Sheets/Slides, and End User personal data processed inside a Customer's portal (including End User sign-in emails and access logs for that portal)Processor (on the Customer's behalf)The Customer
Website visitors, marketing, and support interactions with portalmate.appControllerPortal Mate

Where we act as a processor, we process personal data only on the documented instructions of the Customer, under the Data Processing Addendum. If you are an End User and want to exercise privacy rights over data inside a specific portal, you may need to contact the portal owner (the Customer), who is the controller of that data. We will assist our Customers in responding to such requests.


3. Information We Collect

3.1 Information from End Users (portal sign-in and use)

3.2 Information from Customers (account and configuration)

3.3 Connected Google Workspace content

When a Customer connects a Google Doc, Sheet, or Slides file, we access that file using Google APIs with read-only scope (drive.readonly and the Sheets/Docs/Slides read APIs). We synchronize and store a rendered copy of that content so the portal can display it quickly. This content may contain personal data that the Customer chose to include; the Customer is the controller of that content and is responsible for having a lawful basis to process it and to expose it to their End Users.

3.4 Automatically generated content (AI overviews)

At content-sync time, we use Google Vertex AI (Gemini models) to generate section and content overviews and search embeddings from the Customer's connected content. These overviews are pre-generated and stored; the portal serves them without making live AI calls per visitor. See Section 7 (Automated Processing and AI).

3.5 Optional integrations

A Customer may enable optional integrations, such as a ThoughtSpot analytics embed on its portal. If enabled, the embedded third-party component is governed by that provider's terms and privacy practices. For portals that enable ThoughtSpot analytics, the signed-in user's email and analytics query context are shared with ThoughtSpot to render embedded dashboards.

3.6 Website and marketing data

If you visit our marketing site or contact us, we may collect the information you submit (name, email, message) and standard analytics. We do not currently use a third-party web-analytics tool on portals.


4. How We Use Information

We use personal information to:

We do not use End User content or a Customer's connected Google Workspace content to train our own or third parties' generative-AI foundation models.


5. Legal Bases for Processing (EEA/UK)

Where we act as a controller and the GDPR or UK GDPR applies, we rely on:

Where we act as a processor, the Customer (controller) is responsible for establishing the lawful basis for the processing carried out through the Service.


6. How We Share Information (Subprocessors and Disclosures)

We do not sell personal information and we do not share it except as described here.

6.1 Subprocessors

We use the following subprocessors to run the Service:

SubprocessorPurposeData involvedLocation
Google Cloud Platform / Firebase (Google LLC / Google Ireland Ltd.)Authentication (Firebase Auth), database (Firestore), and hosting (App Hosting / Cloud Run)Account data, End User emails, connected content, generated overviews, logsUnited States (us-east4 / us-central1)
Twilio SendGridDelivery of magic-link and notification emailsRecipient email address, email metadataUnited States
Google Vertex AI (Google Cloud)Automated generation of content overviews and search embeddings at sync timeConnected content textUnited States (us-central1)
ThoughtSpot (analytics embedding, for portals that enable it)Optional Customer-enabled analytics embedconnected content textUnited States

Our current subprocessors are listed in the table above (Google Cloud / Firebase, Twilio SendGrid, Stripe, Google Vertex AI). We give Customers advance notice before adding or replacing a subprocessor, as described in the DPA.

6.2 Between Customers and their End Users

Each portal is controlled by its Customer. A Customer's admins can see the email addresses of End Users who access their portal and can manage access. Portal Mate does not expose one Customer's data to another Customer.

6.3 Legal and safety disclosures

We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Portal Mate, our Customers, or the public. Where legally permitted, we will notify the affected Customer.

6.4 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.


7. Automated Processing and AI

We use Google Vertex AI (Gemini) to generate content overviews, summaries, and search embeddings from Customer-connected content at sync time. These are informational summaries displayed in the portal; they do not produce legal or similarly significant decisions about any individual, and there is no automated decision-making that produces legal effects on End Users within the meaning of GDPR Art. 22.

We do not use this content to train foundation models. Per Google Cloud's terms, prompts and content submitted to Vertex AI are not used by Google to train its models. We rely on Google Cloud's data-processing and AI/ML data-governance terms; content processed by Vertex AI is not used to train Google's foundation models.


8. Cookies and Similar Technologies

Portal Mate uses a small number of cookies:

You can control cookies through your browser settings; disabling essential cookies will prevent sign-in. Because portals currently use only essential cookies, no consent banner is required; if non-essential cookies are introduced we will display a consent banner and honor Global Privacy Control signals.


9. Data Retention

When a Customer's account is terminated, we delete or return Customer data as described in the DPA, subject to legal retention requirements.


10. Your GDPR Rights (EEA/UK)

If you are in the European Economic Area, United Kingdom, or Switzerland, you have the right to:

To exercise these rights, contact us at legal@portalmate.app. Where Portal Mate acts as a processor, we will refer your request to the relevant Customer (controller) or act on their instructions.

International data transfers

We are based in Australia, and our subprocessors may process data in the United States. Where we transfer personal data out of the EEA/UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum), and, where applicable, the EU-U.S. / UK / Swiss Data Privacy Framework. We rely on the Standard Contractual Clauses together with Google Cloud's data-transfer terms for any transfer of personal data outside your region.


11. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the rights below. Note that much of the personal information we process on behalf of Customers is subject to the CCPA's business-to-business and service-provider provisions; for that data we act as a service provider to the Customer.

11.1 Categories of personal information

In the past 12 months we have collected the following categories (as defined in Cal. Civ. Code § 1798.140):

CategoryExamplesCollected?
IdentifiersEmail address, IP address, account/user IDsYes
Customer recordsBilling contact detailsYes
Internet/network activityAccess logs, portal usage, search queriesYes
GeolocationCoarse location inferred from IPYes (coarse only)
Professional/employment infoIf included in connected contentPossibly (Customer-controlled)
Other contentData within connected Google Workspace filesPossibly (Customer-controlled)

We collect this information from the sources described in Section 3 and use it for the purposes in Section 4.

11.2 Your rights

11.3 We do not sell or share personal information

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CPRA. We honor opt-out preference signals such as Global Privacy Control where applicable.

11.4 Sensitive personal information

We do not use or disclose sensitive personal information for purposes other than those permitted under CPRA § 1798.121 (i.e., to provide the Service).

11.5 How to exercise your rights

Submit a request to legal@portalmate.app or by emailing legal@portalmate.app. We will verify your request using the email associated with your account. You may use an authorized agent. We will respond within the timeframes required by law. For data we process on a Customer's behalf, we will direct your request to that Customer.


12. Security

We implement technical and organizational measures appropriate to the risk, including:

No system is perfectly secure. If we become aware of a personal-data breach, we will notify affected Customers and, where required, regulators and individuals, without undue delay.


13. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us at legal@portalmate.app and we will delete it.


14. Data Processing Addendum (DPA)

For personal data we process on a Customer's behalf, our Data Processing Addendum (DPA) governs and is incorporated by reference into the Customer's agreement. It sets out the subject matter, duration, nature and purpose of processing, categories of data subjects and personal data, subprocessor terms, security measures, and international transfer mechanisms. Customers may request a signed DPA at legal@portalmate.app.


15. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice (e.g., email or in-product notice). Your continued use of the Service after the effective date constitutes acceptance.


16. Contact Us

Union Mate Pty Ltd Australia Privacy / DPO contact: legal@portalmate.app General contact: legal@portalmate.app

If you are in the EEA/UK and have concerns we have not resolved, you may contact our not currently appointed; we will designate one if and when required under GDPR Article 27 / UK GDPR or lodge a complaint with your local supervisory authority.