§1About Us
Hawthorn Technologies Pty Ltd (ABN 35 694 551 098) (“we”, “us”, “our”) operates SwiftRebate — a SaaS platform for the Australian residential energy upgrade industry. The platform supports the full lifecycle of energy upgrade installations under the Victorian Energy Upgrades (VEU) program, Solar Victoria Solar Homes Program, and the federal Small-scale Technology Certificate (STC) scheme.
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information. It applies to all users of the SwiftRebate platform and website, including retailers, installers, tradespeople, contractors, accredited persons, and distributors. It also explains how we handle the personal information of residential customers whose details are entered into the platform by retailers.
We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
§2Personal Information We Collect
2.1 Platform Users (Retailers, Installers, Tradespeople, Contractors, Distributors)
When you register on the platform or are added by a retailer, we collect:
- Identity information: full name.
- Contact details: business address, email address, phone number.
- Business information: ABN/ACN, business name, trading name.
- Professional credentials: trade licence numbers (electrical, plumbing), solar accreditation numbers, registration numbers with relevant regulatory bodies (BPC, ESV, SAA).
- Financial details: bank account details for RCTI (Recipient Created Tax Invoice) payments.
- Vehicle and driver information (delivery contractors only): driver licence number, vehicle registration number.
- Login credentials: username and hashed password managed via our identity provider.
- Usage data: records of actions taken on the platform, including jobs created, documents signed, and communications sent.
2.2 Residential Customers
Residential customers do not register on or directly access the SwiftRebate platform. Their personal information is entered by the retailer they are dealing with. We collect and hold the following customer information on the retailer’s behalf:
- Full name, property address, email address, phone number.
- National Metering Identifier (NMI) for the property.
- Electricity and gas consumption data — either extracted from a bill uploaded by the retailer or, where the customer separately consents, retrieved via the Consumer Data Right (CDR) framework.
- E-signature and acceptance records for proposals, and completion sign-off records.
- Property details relevant to the installation (roof type, existing equipment, installation address).
2.3 Automatic Collection
When you use the platform, we automatically collect device identifiers, IP address, browser or app type, pages accessed, timestamps, and error logs. This information is used for security monitoring, platform improvement, and troubleshooting.
2.4 Information We Do Not Collect
- We do not collect raw payment card numbers. Payment processing is handled entirely by our PCI DSS-compliant payment provider via redirect-based integration; cardholder data does not enter our systems.
- We do not collect health or medical records.
§3How We Collect Personal Information
We collect personal information in the following ways:
- Directly from you when you register, onboard, or use the platform.
- From the retailer you work with, when they enter your details on your behalf (applies to installers, tradespeople, delivery contractors, and residential customers).
- From third-party verification services — we verify trade licence numbers and accreditations against the relevant regulatory bodies (BPC, ESV, SAA, ARC) using publicly available registers or approved API connections.
- Via CDR data retrieval — where a residential customer separately consents, their electricity account data is retrieved from their energy retailer through our accredited CDR intermediary. This consent is obtained directly from the customer and is managed in accordance with the CDR Rules.
- From uploaded documents — where a bill, certificate, or identity document is uploaded to the platform, we may extract information from it using optical character recognition (OCR).
§4Why We Collect Personal Information and How We Use It
| Purpose | Information Used |
|---|---|
| Onboarding and account management — creating and maintaining your account on the platform. | Identity, contact, business, and credential information. |
| Credential verification — verifying that trade licences, accreditations, and registrations are current and valid before any job is assigned. | Licence numbers, accreditation numbers, registration details. |
| Proposal generation — generating solar system designs and energy upgrade proposals for residential customers. | Customer property address, NMI, consumption data, existing equipment. |
| Job scheduling and execution — scheduling installations, assigning installers, and coordinating delivery. | Installer credentials, availability, contact details, customer appointment information. |
| Compliance and certificate generation — generating compliance certificates (CoES, BPC certificates) and submitting to the VEU Registry, Solar Victoria, and the REC Registry. | All job-related details including customer, installer, equipment, and accreditation information. |
| Invoicing and payment — generating RCTIs and processing payments to installers and contractors. | Bank account details, job completion records. |
| Communications — sending job notifications, appointment confirmations, and compliance updates to the relevant parties. | Contact details, job status. |
| Regulatory submission — lodging VEECs, STCs, and Solar Homes rebate claims with government agencies. | Customer address, NMI, equipment serial numbers, installer accreditation details. |
| Platform security and monitoring — detecting fraud, unauthorised access, and system anomalies. | Usage data, IP addresses, access logs. |
| Legal and compliance obligations — meeting our obligations under the Privacy Act 1988, CDR Rules, VEU Specifications, and other applicable laws. | All categories as required. |
We do not use personal information for direct marketing to residential customers. We do not sell personal information to any third party.
§5Consumer Data Right (CDR) Energy Data
Where a residential customer separately consents, we retrieve their electricity account data from their energy retailer through the Consumer Data Right (CDR) framework. This data may include meter type, current tariff, consumption history, billing history, and solar feed-in information.
CDR data is used solely to generate an accurate solar system design and financial model for the customer’s proposal. It is not used for any other purpose.
Retailers and the residential customer see the design output and financial modelling generated from the CDR data, including modelling for whole-of-home electrification and replacing of internal combustion engine vehicles with electric vehicles. Retailers do not have access to the underlying raw CDR data fields.
CDR data is deleted promptly upon consent withdrawal, consent expiry, or completion of the purpose for which consent was given — whichever occurs first. We do not retain CDR data beyond what is required under the CDR Rules.
§6Disclosure of Personal Information
6.1 Within the Platform
The SwiftRebate platform enforces strict information boundaries. Retailers can only see data for jobs they manage. Installers can only see data for jobs assigned to them.
6.2 Third-Party Service Providers
We disclose personal information to third-party providers where necessary to deliver the platform. These providers are contractually required to protect the information and use it only for the purpose for which it was disclosed. Key categories include:
- Cloud infrastructure provider — stores all platform data within Australia.
- Identity and authentication provider — manages login credentials and MFA.
- Payment processing provider — processes payments. Does not receive raw card data from our systems.
- Electronic signature provider — manages document signing workflows.
- Communications provider — delivers SMS, email, and WhatsApp messages on behalf of retailers.
- Accounting software integration — financial data is synced with the retailer’s nominated accounting software with the retailer’s authorisation.
- AI and machine learning services — used for compliance photo review, OCR extraction, and certificate generation. Deployed within Australian infrastructure where possible.
6.3 Regulatory Bodies
We disclose personal information to government agencies and regulatory bodies as required to deliver the platform’s compliance functions, including the Essential Services Commission (ESC), the REC Registry, Solar Victoria, the Building and Plumbing Commission (BPC), and Energy Safe Victoria (ESV). This is a core function of the platform and does not require separate consent beyond acceptance of these terms.
6.4 Other Disclosures
We may disclose personal information where required by law, court order, or to protect the rights, property, or safety of Hawthorn Technologies, platform users, or the public.
We do not disclose personal information to overseas recipients except where a third-party provider processes data outside Australia as part of their service. In such cases, we take reasonable steps to ensure the information is handled in accordance with the APPs.
§7Data Storage and Security
All data controlled by Hawthorn Technologies is stored in Australia. We implement the following controls to protect personal information:
- Encryption at rest (AES-256) for all stored data.
- Encryption in transit (TLS 1.2 or higher) for all data transmissions.
- Role-based access controls — each user can only access data relevant to their role.
- Multi-factor authentication for all accounts with access to sensitive data.
- Continuous security monitoring on cloud infrastructure.
- 7-year immutable retention of compliance records as required under applicable government program rules.
Despite these measures, no data transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme if a breach occurs.
§8Retention and Deletion
We retain personal information for as long as necessary to deliver the platform services, meet regulatory obligations, and resolve disputes. The retention periods set out below apply only to records associated with completed jobs. Records associated with incomplete, cancelled, or abandoned jobs are deleted in accordance with our standard data minimisation practices once it is determined the job will not proceed.
| Data Category | Retention Period |
|---|---|
| Compliance records (job photos, certificates, audit trails) — completed jobs only | 7 years from job completion — mandatory under VEU, STC, and Solar Homes program rules. |
| Financial records (RCTIs, invoices, payment records) — completed jobs only | 7 years from transaction — required under ATO record-keeping obligations. |
| CDR energy data | Deleted promptly upon consent withdrawal, consent expiry, or completion of the consented purpose — whichever occurs first. |
| Platform user account data | For the duration of the account and for 7 years following account closure, or as required by law. |
| Communication logs (SMS, email, WhatsApp audit trails) — completed jobs only | 7 years from the date of communication. |
| Security and access logs | Minimum 12 months. Retained longer where relevant to an investigation. |
When data is no longer required, it is deleted securely using cryptographic erasure or equivalent methods.
§9Accessing and Correcting Your Personal Information
You have the right to request access to the personal information we hold about you, and to request that inaccurate, out-of-date, or incomplete information be corrected.
To make a request, contact us at privacy@swiftrebate.com.au. We will respond within 30 days. We may need to verify your identity before processing the request.
In some circumstances we may decline to provide access — for example, where doing so would reveal another person’s personal information, or where we are required by law to retain the information. If we decline, we will explain why.
Residential customers whose information is held on behalf of a retailer should direct their access or correction requests to the retailer in the first instance. We will cooperate with the retailer to facilitate access.
§10Complaints
If you have a complaint about how we handle your personal information, please email us at privacy@swiftrebate.com.au.
We will acknowledge your complaint within 5 business days and respond substantively within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
§11Cookies and Tracking
The SwiftRebate web platform uses session cookies for authentication and security. We do not use third-party advertising or tracking cookies on the platform application.
The swiftrebate.com.au marketing website may use analytics tools to measure traffic and usage. These tools may use cookies. You can control cookie settings through your browser preferences.
§12Changes to This Policy
We may update this Privacy Policy from time to time. The current version and effective date are always shown on this page. Material changes will be communicated to registered platform users by email or in-platform notification at least 14 days before taking effect.
§13Contact Us
- Organisation
- Hawthorn Technologies Pty Ltd
- ABN
- 35 694 551 098
- Address
- Delahey VIC 3037, Australia
- Platform
- swiftrebate.app
For complaints to the OAIC: oaic.gov.au · 1300 363 992