Diveboard · Poolwerx South Australia
Diveboard is the business-management platform operated by Bruins Trading Pty Ltd ATF the Bruins Trust (trading as Diveboard).
This policy is given by Bruins Group Pty Ltd, trading as Poolwerx South Australia, across six franchise locations (Kings Park, North Brighton, Morphett Vale, Salisbury, West Lakes, Service Outlet) ("we", "us"), the business that uses Diveboard and is responsible for the personal information of its customers. Diveboard is our internal business-management platform. It is not a public-facing product, but it holds personal information about our customers, so this policy explains what we hold and why.
ABN: 83606001174
We hold, on customers who have used or enquired about our pool services:
To run pool service and retail operations: scheduling and carrying out jobs, quoting work, processing sales, following up with customers, sending service reminders, and responding to enquiries and complaints. We also use aggregated, de-identified data internally to measure how our stores and technicians are performing.
We use a number of third-party services to run the business. Each is given only the information it needs to do its job:
| Anthropic | Powers the Diveboard AI assistant staff use, and checks inbound emails for complaints (the email text, sender address and subject are sent for that check) |
| DigitalOcean (Sydney) | Hosts the Diveboard application and database (customer data resides in Australia) |
| Lightspeed | Point-of-sale: retail and service transactions |
| Xero | Accounting and invoicing |
| Deputy | Staff rostering and timesheets (staff data, not customer data) |
| Google / Gmail | Store email accounts used to correspond with customers |
| Pooltrackr | Job and quote management |
| MaxoTel | Phone calls and SMS with customers |
| Birdeye | Customer review requests and collection |
| Verizon Connect & Geotab | Vehicle/fleet tracking for our service vans (not customer data) |
| ElevenLabs | Voice for the phone-based Diveboard assistant (what a caller says is processed to hold the conversation) |
We do not sell personal information, and we do not share it beyond the processors above except where required by law.
Most of Diveboard runs in Australia: the application and its database are hosted by DigitalOcean in Sydney. A few of the services above are run by companies that process information outside Australia. Under Australian Privacy Principle 8 we are telling you which, and what they receive:
| Anthropic (United States) | Questions staff type into the Diveboard AI assistant, plus the first names, quote amounts and job types the assistant needs to answer them; and the text, subject and sender address of inbound emails that are checked for complaints. We do not send phone numbers or email addresses of customers to the assistant. |
| ElevenLabs (United States and other countries) | The voice conversation with the phone-based Diveboard assistant, including what the caller says. |
| Birdeye (United States) | A customer's name and contact details when we ask them for a review, and the review they leave. |
| Google (United States and other countries) | Store email accounts (the emails we send and receive, including customers' email addresses and the contents), and business-listing information such as store opening hours, which is not customer information. |
| Lightspeed, Xero and Pooltrackr | Sales, invoices and job records. These providers may store or back up data outside Australia; their own privacy policies apply to what they hold. |
| Stripe (United States) | Subscription billing between Diveboard and the franchise business. It does not receive our customers' personal information. |
If a staff member chooses to connect an outside AI assistant (such as Claude, ChatGPT or Grok) to Diveboard, the answers they ask it for are sent to that provider, which processes them overseas.
We take reasonable steps to make sure these providers handle personal information in line with the Australian Privacy Principles, including choosing providers that commit to protecting the information they process and giving them only what they need for the task. Because they are overseas, we cannot control how they handle it, and if one of them mishandled it we may not be able to hold it to the Australian Privacy Principles directly. By giving us your information you accept that.
Customer and job records are kept for as long as the customer relationship is active and for a reasonable period afterwards, to meet our record-keeping and legal obligations. Cached call, SMS and email history is kept for 12 months from the date of the communication and then automatically removed on a nightly basis; the underlying job, quote and financial records are retained separately per the above. Retention periods are reviewed periodically and may change.
Data synced from Lightspeed (point-of-sale) or Xero (accounting) is retained for as long as that integration stays connected. If we disconnect an integration (for example, to re-authenticate after an expired token), the previously synced data is kept so we don't have to re-sync from scratch. If we deliberately uninstall an integration, its locally cached data for our franchise is permanently deleted at that point.
Access to Diveboard is restricted to authorised staff by individual login, with permissions scoped to each person's role, and sensitive access is logged. Credentials and tokens for the third-party services above are encrypted at rest; traffic to and from Diveboard is encrypted in transit (HTTPS). We apply rate limits and monitoring to guard against bulk extraction of customer data, whether by an outside party or a compromised staff account.
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it, by contacting us. See our support page for how, or contact your local Poolwerx store directly. You can also email gad.admin@poolwerx.com.au.
What deleting actually does. We de-identify your record rather than erase it outright. We remove your name, email address, phone numbers and address, and we delete the staff notes, call, SMS and email history held against you. We keep the underlying job, quote, repair and sales records (the dates, amounts and what work was done) because we are required to retain those; once de-identified they are no longer linked to your name or contact details. Free-text comments a technician typed on an individual job are not searched or edited, so one may still mention a name; tell us if that matters to you and we will look.
What we keep after you ask us to delete. To make sure your details are not brought back in by the next automatic update from our other systems, we keep a short list of protected references: scrambled (hashed) forms of your email address and phone numbers, plus internal ID numbers. These cannot be read as your name or contact details. Scrambled references recorded before October 2026 used a simpler method that someone with direct access to our database could, with effort, test against a guessed number or address; newer ones use a secret key that is stored separately from the database. We also keep, for the seven-year accounting period, the internal reference that ties your past payments to Xero. It contains no name, address, email or phone number and is removed automatically after the seven years. Photos a technician took on a job are kept with the job record as evidence of the work, and they may show a customer's property. Tell us if you want a photo removed and we will look at it.
Backups. We keep disaster-recovery copies of our database (nightly backups held for about two weeks, and short-term copies taken before a software update). A backup made before your deletion still contains your details until that copy is itself deleted. We do not restore deleted people from a backup.
Other systems hold their own copies. Deleting your information in Diveboard does not by itself delete it from the third-party services listed above. Pooltrackr, Lightspeed, Xero, Gmail and our phone provider each keep their own records. We action those separately when you ask us to, and we will tell you what was done and where.
If you fill in the Register interest form on the Diveboard website, your details (name, business, role, email, mobile, number of stores, the systems you use and any message) are held by Bruins Trading Pty Ltd ATF the Bruins Trust (trading as Diveboard), not by any franchise. Only the Diveboard platform owners can see them, and we use them only to contact you about Diveboard, as you agreed when you sent the form. We do not keep your IP address or browser details with them.
If you tell us now is not the right time, we delete your details 12 months later; any registration we have not followed up for 24 months is deleted too. You can ask us to delete them sooner at any time by replying to our confirmation email or writing to support@diveboard.com.au, and we delete every registration under your email address.
If we become aware of a data breach that is likely to result in serious harm, we will assess and respond in line with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth), including notifying the Office of the Australian Information Commissioner (OAIC) and any individuals affected, where required.
Last updated: 2026-10-02 (draft).