Last updated 4 September 2026
Privacy Policy
In short
We collect only what verification and the marketplace need. We never sell your data or your introductions. Your business identity is not disclosed to anyone until you approve it. You can access, correct, export or delete your information.
Draft for review
This policy has not yet been settled by a qualified privacy practitioner. It must be reviewed before the platform accepts real users.
Our two commitments
These are published principles we hold ourselves to, and that you can hold us to:
- We never sell data. Not to advertisers, not to data brokers, not to anyone.
- We never sell introductions. No one pays us to reach you.
What we collect
- Account: name, email, password (stored only as a hash), and your role.
- Business: legal name, national business identifier, region, industry, year founded, website, and a description you provide.
- Capital provider: entity name, investor classification, mandate, and the evidence you supply to verify it.
- Documents: anything you upload to a data room or a verification case.
- Activity: sign-ins, listings, access requests, NDA signatures, messages, document views and downloads.
- Technical: IP address, browser, and session information — used for security and abuse prevention.
Most of this you give us directly. Some we collect about you from others: our identity, business and investor verification providers return the results of the checks we ask them to run, and the national business register returns the details attached to a business identifier you enter. We collect technical information automatically when you use the platform.
Why we collect it
To verify that members are who they say they are; to operate the marketplace; to enforce confidentiality and our terms; to prevent fraud and abuse; and to meet our legal obligations. We do not use your information for advertising or profiling.
Who sees it
Your business identity is not disclosed to another member until you approve their NDA-backed access request. Before you approve an access request, providers see the anonymous listing information you choose to publish, including banded figures and a coded handle. Your business identity is revealed only after you approve their access request.
We share information with:
- identity and business verification providers, to verify you;
- our payment processor, to take subscription payments (we never see your card);
- our hosting, storage and email providers, who process data on our instructions;
- an automated screening provider that checks the listing text you choose to publish for identity leaks — it never sees your documents;
- law enforcement or regulators, where we are legally required to.
We disclose personal information to recipients overseas. The country involved is the United States: payment processing, error monitoring, inbound mail forwarding and the optional screening of listing text you choose to publish are handled there. Every email we send you — address verification, password reset, access-request and NDA notices, and data-room alerts — is processed through Amazon SES in Sydney; those messages carry your name and the reference of the listing concerned. Your account database and every document you upload are held in Australia.
Before 2 August 2026 the application itself also ran on servers in the United States while its data was stored in Australia, so personal information was processed there. It now runs in Sydney.
Our service providers (sub-processors)
We use the following providers to run the platform. Each processes only what its role requires, on our instructions:
- Vercel — application hosting (Australia — Sydney; United States before 2 August 2026).
- Neon — database hosting (Australia).
- Amazon Web Services (S3, Sydney) — encrypted document storage (Australia).
- Amazon Web Services (SES,
ap-southeast-2) — outbound email (Australia — Sydney). - Fly.io — transient malware scanning of uploaded documents (Australia — Sydney). Files are scanned in memory as they pass through and are not stored by the scanner.
- Upstash — rate limiting and abuse prevention. It holds short-lived request counters keyed by IP address or account identifier, and no document or message content (Australia — Sydney).
- ImprovMX — inbound email forwarding for our domain (United States / EU).
- Stripe — subscription payment processing (United States; we never see your card number).
- Sentry — error monitoring; we redact identifiers before sending (United States).
- Anthropic — optional automated screening of listing text you choose to publish, and reading public web pages to record the transaction figures those pages state; it never sees your documents (United States).
- Identity, business and investor verification providers, to verify you.
- Public-source search providers, to search publicly reported transactions on the factual criteria you choose. None is engaged today; nothing about your business is sent.
This list may change as our providers do; the current version always appears here.
How we protect it
- Passwords are hashed with scrypt, a modern memory-hard algorithm — we cannot read them.
- Data-room documents are encrypted at rest. PDFs and images (PNG, JPEG) a provider downloads are watermarked with their identity; spreadsheets, Word documents and CSV files cannot carry a watermark, and are logged rather than marked.
- Every document view and download is logged, and the business can see the log.
- Two-factor authentication is required for all staff, and available to every member.
- Every sensitive action is written to an append-only audit trail.
Your rights
You can, at any time, from Settings:
- Access the information we hold about you;
- Export your data in a machine-readable format;
- Delete your account.
You can ask us to correct personal information that is wrong. Some verification-related changes require review before they take effect.
Some records survive deletion because the law or the integrity of the marketplace requires it: the audit trail, NDA signatures, moderation history, and financial records. We keep the minimum, for the minimum time.
How long we keep it, and how deletion works
When you ask to close your account, we schedule it for permanent deletion after a 30-day grace period, and revoke your other sessions straight away. You can cancel your account closure while you can still sign in. If your account has already been deactivated following identifier release, contact us to request any further account action. After the grace period, we erase or anonymise your personal information — the documents you uploaded, your profile, your identity-verification records, and the content of messages you sent. If you are the last member of the organisation, closing your account also anonymises the business record and withdraws its listings, as part of that anonymisation.
A small set of records is retained and then disposed of on its own clock: audit and NDA records are kept for seven years. After seven years, identifying details associated with NDA signatures are de-identified. The underlying audit record is retained to preserve the integrity of the transaction history. In practice that means we remove the name typed at signing, the signer’s IP address and their browser details, and we keep a cryptographic fingerprint of the document that was signed, which access request it related to, and when it was signed — enough to show that a party was bound, without identifying them as a person. The audit trail is de-identified on the same clock: personal details removed, the action record kept. Documents you uploaded are not held on this clock at all — they are erased with your account, as described above. Sessions expire in hours and are purged after thirty days. If your account is subject to an open investigation or legal hold, deletion is paused until the hold lifts.
If something goes wrong
If a data breach occurs that is likely to cause you serious harm, we will notify you and the relevant regulator as required by law, and tell you plainly what happened and what to do.
Contact
The Big Help is operated by The Big Help Capital Pty Ltd (ACN 700 573 646), which is responsible for the personal information described in this policy.
Privacy questions, requests, or complaints: privacy@thebighelp.com.au. We will respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) atoaic.gov.au or on 1300 363 992.
Questions? Contact support.