Ralfi (Beta)

Effective date: 17 July 2026

Ralfi Privacy Policy

Ralfi is operated by HEY WHAT’S NEXT PTY LTD, trading as Ralfi (“Ralfi”, “we”, “us” or “our”).

This Privacy Policy explains how we collect, use, store and protect personal information when you visit our website, communicate with us or use the Ralfi platform.

1. What Ralfi does

Ralfi provides workflow software for insurance brokers.

Ralfi may connect with email accounts, communication tools and broking systems authorised by a customer. It helps users organise renewals, identify open tasks, manage follow-ups and maintain records of activity.

2. Information we collect

The information we collect depends on how you interact with Ralfi and how your organisation configures the platform.

It may include:

  • Your name, business contact details, organisation and job title.
  • Account details, login information and user permissions.
  • Billing and subscription information.
  • Information provided during enquiries, demonstrations, onboarding and support.
  • Technical information such as your browser, device, IP address, login activity and platform usage.
  • Information contained in accounts and systems connected to Ralfi.
  • Emails, messages, attachments, client information, insurer information, policy information, renewal information and workflow records processed through the platform.

Information processed through connected systems may include personal or sensitive information where it is contained in a customer’s emails, documents or broking records.

3. How we collect information

We may collect information:

  • Directly from you.
  • From your organisation or account administrator.
  • Through systems your organisation authorises Ralfi to access.
  • Automatically when you use our website or platform.
  • From service providers that help us operate, secure and support Ralfi.

Customers are responsible for ensuring they have the appropriate authority, notices and permissions to connect systems and provide information to Ralfi.

4. How we use information

We may use information to:

  • Provide, operate and secure the Ralfi platform.
  • Identify and organise renewals, tasks and follow-up activity.
  • Prepare, schedule or send communications authorised by users.
  • Maintain workflow and activity records.
  • Administer accounts and user permissions.
  • Provide demonstrations, onboarding and customer support.
  • Process payments and manage subscriptions.
  • Detect misuse, security incidents and technical problems.
  • Improve the reliability and performance of Ralfi.
  • Comply with legal and regulatory obligations.
  • Develop and improve Ralfi using aggregated or de-identified information.

We do not sell personal information.

We do not use Customer Data, including client records, emails or documents, to train general-purpose AI models.

5. Customer Data

“Customer Data” means information submitted to Ralfi by a customer or accessed through systems connected by that customer.

Customers retain ownership and control of their Customer Data.

Ralfi processes Customer Data only to:

  • Provide and support the service.
  • Carry out actions authorised by the customer.
  • Maintain the security and reliability of the platform.
  • Meet applicable legal obligations.

Customers determine which systems are connected, which users have access and which actions Ralfi is permitted to perform.

Where we process personal information on behalf of a customer, the customer remains responsible for its relationship with its clients, staff and other individuals.

6. AI processing

Ralfi may use AI to organise information, identify possible tasks, summarise correspondence and prepare suggested content or workflow actions.

Customer Data is not provided to third-party AI providers for their independent use, advertising or model training.

AI-generated information may occasionally be incomplete or inaccurate. Important outputs should be reviewed by an authorised user before being relied upon or communicated.

7. Data hosting and location

Production Customer Data is hosted in either Australia or New Zealand, depending on the hosting region selected or agreed for the customer.

  • Australian-region Customer Data is hosted in Australia.
  • New Zealand-region Customer Data is hosted in New Zealand.

We will not move production Customer Data outside the agreed hosting region unless:

  • The customer authorises or directs us to do so.
  • It is reasonably necessary to provide a service requested by the customer.
  • It is required by law.

Some limited business information, such as website enquiries, billing records and support communications, may be handled separately from production Customer Data.

Where personal information is handled across borders, we take reasonable steps to ensure appropriate privacy and security protections are in place.

8. When we share information

We may share information with:

  • Authorised users within the customer’s organisation.
  • Service providers that help us host, secure, operate or support Ralfi.
  • Payment and billing providers.
  • Professional advisers such as lawyers, accountants, auditors and insurers.
  • Regulators, courts or law-enforcement bodies where required by law.
  • Parties involved in a proposed investment, sale, merger or restructuring.
  • Other parties where the customer directs us or gives permission.

Service providers may only use information for the services they provide to Ralfi and must protect it appropriately.

We do not provide Customer Data to advertisers or data brokers.

9. Security

We use reasonable technical and organisational safeguards designed to protect information from loss, misuse, interference and unauthorised access, modification or disclosure.

These safeguards may include:

  • Encryption in transit and at rest.
  • Authentication and access controls.
  • Restricted internal access.
  • Security logging and monitoring.
  • Backup and recovery processes.
  • Incident-response procedures.
  • Regular review of security practices.

Our security practices are informed by recognised industry security frameworks.

No online system can be guaranteed to be completely secure. Customers are also responsible for protecting their accounts, credentials, devices and connected systems.

10. Data retention and deletion

We retain information only for as long as reasonably necessary to:

  • Provide and support Ralfi.
  • Maintain security and business records.
  • Meet legal and regulatory obligations.
  • Resolve disputes.
  • Enforce our agreements.

Customers may request an export or deletion of their Customer Data.

When a customer’s service ends, Customer Data will be deleted in accordance with the applicable agreement and our standard deletion processes, unless retention is required by law.

Deleted information may remain temporarily in secure backups before being removed through our normal backup-retention process.

11. Access and correction

You may request access to, or correction of, personal information we hold about you by contacting hey@ralfi.io.

We may need to verify your identity before completing a request.

Where the information is controlled by one of our customers, such as an insurance brokerage, we may refer your request to that customer.

We may decline or limit access where permitted by applicable law and will provide an explanation where required.

12. Direct marketing

We may use business contact information to send relevant information about Ralfi, including product updates, events and invitations.

You may opt out at any time by using the unsubscribe option or contacting hey@ralfi.io.

We do not use personal information taken from connected customer systems for Ralfi’s own marketing.

13. Cookies and similar technologies

Ralfi may use cookies and similar technologies when you visit our website or use the platform.

Cookies are small files stored on your browser or device. We may use them to:

  • Operate and secure our website and platform.
  • Keep authorised users signed in.
  • Remember preferences and settings.
  • Understand general website usage.
  • Diagnose technical issues.
  • Improve website and platform performance.
  • Measure the effectiveness of our communications, where applicable.

Some cookies are necessary for Ralfi to function. Other cookies, such as analytics or marketing cookies, may be optional.

Where required, we will ask for permission before using non-essential cookies.

You can manage cookies through your browser settings or any cookie controls available on our website. Disabling certain cookies may affect how parts of Ralfi function.

Third-party services used on our website may also place cookies or collect technical information in accordance with their own privacy policies.

14. Data incidents

We maintain processes for assessing and responding to suspected privacy and security incidents.

Where required by applicable law, we will notify affected customers, individuals and relevant regulators of an eligible or notifiable data breach.

15. Children

Ralfi is a business service and is not intended for use by children.

Customers should not knowingly provide children’s personal information to Ralfi unless it is lawful, necessary for their insurance activities and appropriately protected.

16. Privacy complaints

Questions or complaints about how we handle personal information may be sent to:

Privacy Officer
Ralfi
hey@ralfi.io

We will review the matter and respond within a reasonable period.

You may also have the right to contact the Office of the Australian Information Commissioner or the Office of the Privacy Commissioner in New Zealand.

17. Changes to this policy

We may update this Privacy Policy as Ralfi develops or legal requirements change.

The latest version will be published on our website with its effective date. We will provide additional notice where a change materially affects how we handle Customer Data.

18. Contact

HEY WHAT’S NEXT PTY LTD trading as Ralfi
ABN 34 693 275 786 · ACN 693 275 786
Level 1, 63-73 Ann Street, Surry Hills NSW 2010
Email: hey@ralfi.io