Last updated: 27 July 2026
MySecureSend is a product of Dotline Infotech Pty Ltd (ABN 82 129 575 088), Sydney, Australia. Dotline Infotech Pty Ltd (“we”, “our”, “us”) is the APP entity responsible for the handling of personal information described in this policy, and is committed to protecting the privacy of individuals whose personal information we handle. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using MySecureSend, you agree to the practices described in this policy. If you do not agree, please discontinue use of the service.
Account information: When you register, we collect your name, email address, and organisation name.
OAuth2 connection: When you connect Gmail or Outlook 365, we store OAuth2 access and refresh tokens (AES-256 encrypted) to send email on your behalf. We do not access any email content beyond sending.
Send metadata (audit log): For each send, we log: recipient email address, last 3 digits of recipient phone, email subject, file names and count, sender IP address, SMS delivery status, and a 2-character password hint. We do not log full passwords or full phone numbers.
Files: We do not retain files. Files pass through our Australian infrastructure only long enough to be encrypted with AES-256 and sent. They are deleted immediately after sending, typically within seconds, and no file content is kept once a send completes.
Enquiry form: If you contact us through the enquiry form, your name, email address, organisation and message are delivered to us by email via Resend. Enquiry submissions are not stored in our systems.
We do not use your information for advertising, profiling, or sale to third parties.
We disclose personal information only to the following service providers, strictly for the purpose of delivering the service:
The current list of subprocessors, including the purpose and location of each, is maintained on our Security & Compliance page.
We do not sell, rent, or share personal information with any other third party.
Cross-border disclosure (APP 8):Twilio and Resend are headquartered in the United States. For SMS password delivery, Twilio receives the recipient's mobile number and the decryption password. For transactional email and email password delivery, Resend receives recipient email addresses and, when email password delivery is selected, the decryption password. These are the only cross-border disclosures of personal information we make. No file content is disclosed to either provider: file contents never leave Australian infrastructure.
Location: File contents and audit data are stored and processed exclusively in Australia (Supabase Sydney, AWS ap-southeast-2; encryption processing in Google Cloud Sydney, australia-southeast1). The only personal information disclosed overseas is the recipient contact details and decryption passwords described in section 4.
Encryption at rest: OAuth2 tokens are encrypted with AES-256 before storage. All database connections use TLS.
Zero file retention: Files are deleted immediately after sending and are never retained. Once a send completes, we have no ability to access, retrieve, or disclose any file content.
Under the Privacy Act 1988 (Cth), you have the right to:
To exercise any of these rights, contact us at support@mysecuresend.com.au. We will respond within 30 days.
MySecureSend provides a PII subject redaction feature. When the sender ticks the “Subject contains PII” checkbox, the subject line is replaced with a reference number before sending, so a patient or client name, date of birth, Medicare number or other identifier is not exposed in mail server logs, lock screen notification previews, or mailbox search indexes. The original subject is stored in the sender's audit log, visible only to the sender - not to recipients. This supports the secure handling of personal information and sensitive information as defined in section 6 of the Privacy Act 1988 (Cth), where sensitive information expressly includes health information, and the security obligations in APP 11.
We assess suspected data breaches promptly. Where an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
We use session cookies for authentication only. We do not use tracking cookies, analytics scripts, or advertising pixels. We do not track users across third-party websites.
We may update this policy from time to time. Material changes will be notified by email to the account holder at least 14 days before taking effect. Continued use of the service after that date constitutes acceptance of the updated policy.
For privacy enquiries contact us at support@mysecuresend.com.au.