Privacy Policy
Effective date: 21 August 2026
This Privacy Policy explains how Bentendo Pty Ltd ACN 646 790 865, ABN 95 739 056 828, trading as CXO Advisory and operating the CXOdoo brand collects, holds, uses and discloses personal information.
In this Privacy Policy, we, us and our mean Bentendo Pty Ltd.
This Privacy Policy applies to personal information handled in connection with:
a. CXO Advisory;
b. CXOdoo;
c. our websites;
d. our software and applications;
e. enquiries and sales;
f. consultancy engagements;
g. Software support;
h. customer accounts;
i. events and meetings;
j. recruitment and contractor relationships; and
k. other business activities conducted by Bentendo Pty Ltd.
1. Our approach to privacy
1.1 We respect the privacy of individuals whose information we handle.
1.2 We seek to collect only information reasonably necessary for our functions and activities.
1.3 Where the Privacy Act 1988 (Cth) and Australian Privacy Principles apply to us, we handle personal information in accordance with those requirements.
1.4 Certain information may also be subject to:
a. contractual confidentiality obligations;
b. professional obligations;
c. customer-specific privacy or security requirements; or
d. other applicable laws.
1.5 This Privacy Policy does not reduce any privacy right that cannot lawfully be excluded.
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or not and whether recorded in material form or not.
Depending on the circumstances, information handled by us may include personal information, sensitive information, commercially confidential information, or information that does not identify an individual.
3. Information we may collect
The information we collect depends on the nature of your relationship with us.
It may include the following categories.
3.1 Contact information
We may collect:
a. name;
b. business or organisation;
c. job title;
d. email address;
e. telephone or mobile number;
f. business address; and
g. other contact details you provide.
3.2 Account information
If you create or use an account with us, we may collect:
a. account identifiers;
b. username;
c. organisation details;
d. account preferences;
e. licence information;
f. subscription information; and
g. account activity reasonably required to operate the service.
We should not ordinarily need to know your password in plaintext.
3.3 Transaction and billing information
Where you purchase Software or Services, we may collect:
a. products or services ordered;
b. billing details;
c. invoicing information;
d. transaction references;
e. payment status;
f. tax information where required;
g. purchase history; and
h. information necessary to deal with refunds, disputes or accounting obligations.
Payment card transactions may be processed by a third-party payment provider.
We do not need to retain complete payment card details where payment processing can appropriately be performed by that provider.
3.4 Enquiry and communications information
We may collect information you provide through:
a. website forms;
b. email;
c. telephone calls;
d. video conferences;
e. support requests;
f. meetings;
g. correspondence;
h. demonstrations;
i. discovery sessions; and
j. other communications with us.
3.5 Consultancy information
When providing Consultancy Services, we may receive personal information contained within Customer systems or documents.
Depending on the Engagement, this could include information about:
a. employees and contractors;
b. customers;
c. suppliers;
d. business stakeholders;
e. system users;
f. directors and officers;
g. project participants; and
h. other persons whose information is relevant to the Engagement.
The types of information involved depend on the work we have been engaged to perform.
3.6 Technical and support information
When you use Software or request technical support, we may collect information reasonably necessary to provide the Software or investigate the issue, including:
a. Software version;
b. Odoo version and edition;
c. deployment environment;
d. device or browser information;
e. IP address;
f. diagnostic information;
g. logs;
h. error messages;
i. installed dependencies;
j. relevant third-party modules;
k. database or installation identifiers;
l. licence status; and
m. steps required to reproduce an issue.
We do not seek unrelated Customer business data merely because technical support is being provided.
3.7 Website information
When you use one of our websites, technical information may be generated automatically, including:
a. IP address;
b. browser type;
c. device type;
d. referring page;
e. pages accessed;
f. timestamps;
g. session information; and
h. cookie or similar technical identifiers.
The exact information collected depends on the website technology and services being used at the time.
3.8 App and software information
Our applications or Software may collect information reasonably necessary for:
a. authentication;
b. licensing;
c. synchronisation;
d. security;
e. diagnostics;
f. support;
g. service operation; or
h. functionality specifically requested by the user.
Where an application requires access to device capabilities or data, such as a camera, photographs, files, notifications or location, applicable platform permissions will be used where required.
3.9 Recruitment and contractor information
If you apply to work with us or provide services to us, we may collect information such as:
a. employment history;
b. qualifications;
c. professional memberships;
d. contact information;
e. references;
f. identification information where reasonably required; and
g. other information relevant to the proposed relationship.
4. Sensitive information
4.1 We do not ordinarily seek sensitive information unless it is reasonably necessary for a legitimate business function or an Engagement.
4.2 Consultancy work may occasionally involve access to sensitive information held by a Customer.
4.3 Where sensitive information is collected by us, we will seek any consent required by applicable law unless another lawful basis permits or requires its collection.
4.4 Customers should avoid sending sensitive personal information through ordinary email or support channels unless it is genuinely necessary.
5. How we collect personal information
We may collect personal information:
a. directly from you;
b. from your employer or organisation;
c. from an authorised representative;
d. from another party to a project or Engagement;
e. through our websites;
f. through Software and applications;
g. through customer support;
h. through meetings and communications;
i. through payment and commerce providers;
j. through Odoo or other business platforms;
k. from publicly available sources;
l. from professional or business networks;
m. from a customer where we are performing Consultancy Services; or
n. from another person where collection is lawful and reasonably necessary.
6. Information provided by our Customers
6.1 A Customer may provide us with personal information relating to other individuals as part of a Consultancy Engagement or Software-support request.
6.2 In those circumstances, the Customer is responsible for ensuring that it has an appropriate basis to provide that information to us.
6.3 We will use such information only for purposes reasonably connected with:
a. the Engagement;
b. Software support;
c. our contractual obligations;
d. legal obligations; or
e. another purpose authorised by the Customer or law.
6.4 Where appropriate, we may act as a service provider handling information on behalf of the Customer rather than determining the principal purposes for which that information is used.
7. Why we collect and use personal information
We may collect, hold, use or disclose personal information for purposes including:
a. responding to enquiries;
b. providing quotations and proposals;
c. establishing a customer relationship;
d. processing Orders;
e. supplying Software;
f. administering Software Licences;
g. providing Software support;
h. providing Consultancy Services;
i. providing training;
j. managing projects;
k. communicating with Customers;
l. processing invoices and payments;
m. managing accounts and records;
n. operating and improving our websites and systems;
o. maintaining security;
p. detecting or preventing fraud and misuse;
q. investigating technical issues;
r. meeting legal, regulatory, tax and accounting obligations;
s. managing disputes;
t. enforcing contractual rights;
u. managing suppliers and contractors;
v. maintaining insurance and professional obligations; and
w. conducting our business generally.
8. Data minimisation
8.1 We seek to limit personal information collection to what is reasonably necessary for the relevant function or activity.
8.2 Where practical, we will use information that does not identify an individual where identifiable information is unnecessary.
8.3 Customers should not provide unrelated information merely because a system or support channel allows it to be uploaded.
8.4 When providing support, Customers should ordinarily provide only the logs, screenshots, examples or data reasonably needed to investigate the issue.
9. Anonymous or pseudonymous dealings
9.1 Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym.
9.2 This will often not be practicable where we need to:
a. enter into a contract;
b. issue an invoice;
c. provide licensed Software;
d. provide Consultancy Services;
e. verify an account;
f. meet legal requirements; or
g. provide ongoing support.
10. Use and disclosure
10.1 We ordinarily use personal information for the purpose for which it was collected or for a related purpose that would reasonably be expected.
10.2 We may also use or disclose information:
a. with consent;
b. where required or authorised by law;
c. where reasonably necessary to protect legal rights;
d. to address fraud, cybersecurity or safety concerns; or
e. in another circumstance permitted by applicable privacy law.
11. Service providers
11.1 We may use third-party providers to support our business.
Depending on the services in use, these providers may include:
a. cloud hosting providers;
b. Odoo and related service providers;
c. Microsoft and other productivity providers;
d. Apple and mobile-platform providers;
e. payment processors;
f. accounting providers;
g. telecommunications providers;
h. domain and website providers;
i. email providers;
j. security providers;
k. backup providers;
l. analytics providers;
m. professional advisers;
n. consultants and subcontractors; and
o. other technology providers.
11.2 A service provider may process personal information where reasonably necessary to provide its service to us.
11.3 We seek to use reputable providers and to limit their access to information to what is reasonably necessary for their role.
12. Odoo
12.1 Our business and Software products may interact with Odoo systems.
12.2 Personal information stored in a Customer's Odoo database remains subject to:
a. the Customer's own privacy obligations;
b. the hosting arrangements applicable to that database; and
c. Odoo's applicable terms and privacy arrangements where Odoo provides the relevant service.
12.3 Supplying CXOdoo Software does not mean that we automatically receive or control all information stored in the Customer's Odoo environment.
12.4 Where we require access to a Customer's Odoo environment for implementation or support, access should be limited to what is reasonably required for the work.
13. Payment providers
13.1 Online payments may be processed using a third-party payment service.
13.2 The payment provider may collect payment information directly from you.
13.3 Payment information processed directly by that provider is subject to its own privacy and security arrangements.
13.4 We may receive transaction information such as:
a. payment status;
b. amount;
c. transaction identifier;
d. card type or partial card information;
e. billing contact information; and
f. fraud or verification status.
14. Apple and other app marketplaces
14.1 If you acquire or use an application through the Apple App Store or another marketplace, the marketplace provider may independently collect information about:
a. your account;
b. purchase;
c. device;
d. downloads;
e. subscriptions; and
f. application usage.
14.2 Information collected independently by the marketplace provider is governed by that provider's privacy arrangements.
14.3 We may receive information made available to application developers through the applicable marketplace.
15. Cookies and similar technologies
15.1 Our websites may use cookies or similar technologies where required for:
a. core website functionality;
b. session management;
c. authentication;
d. shopping-cart operation;
e. security;
f. preferences;
g. analytics; or
h. other legitimate website functions.
15.2 The cookies actually used may change as our website technology changes.
15.3 Browser settings may allow you to block or delete cookies, although doing so may prevent some website functions from operating correctly.
15.4 Where applicable law requires additional consent for a particular cookie or tracking technology, we will seek that consent.
16. Analytics and measurement
16.1 We may use analytics tools to understand matters such as:
a. website traffic;
b. page performance;
c. application stability;
d. product usage;
e. errors; and
f. general usage patterns.
16.2 Where analytics involves personal information, we will handle that information in accordance with this Privacy Policy and applicable law.
16.3 We do not sell personal information to advertisers.
17. Direct marketing
17.1 We may use contact details for direct marketing where permitted by law.
17.2 You may opt out of receiving marketing communications at any time.
17.3 A request to stop marketing does not prevent us from sending necessary operational communications concerning:
a. an Order;
b. an account;
c. Software;
d. a security issue;
e. an Engagement;
f. an invoice; or
g. another existing business relationship.
17.4 We do not presently need to operate a newsletter merely because this Privacy Policy permits lawful marketing activity.
18. Automated decisions
18.1 We may use software automation to support ordinary business processes.
18.2 Where the Privacy Act requires disclosure about the use of personal information in automated decisions that could reasonably be expected to significantly affect an individual's rights or interests, we will provide the information required by applicable law.
18.3 As at the effective date of this Privacy Policy, this clause is not intended to represent that Bentendo Pty Ltd uses automated systems to make significant decisions about individuals where it does not in fact do so.
18.4 We will update this Privacy Policy if our use of automated decision-making technology materially changes and applicable law requires additional disclosure.
19. Artificial intelligence
19.1 We may use artificial intelligence or machine-assisted tools as part of our business or Consultancy Services where appropriate.
19.2 Where personal or confidential Customer information is proposed to be processed using an external AI service, we will consider:
a. the purpose of the processing;
b. the information involved;
c. confidentiality;
d. security;
e. the applicable service terms;
f. contractual requirements; and
g. applicable privacy law.
19.3 We do not treat the availability of an AI tool as permission to disclose Customer Confidential Information to it.
19.4 Customers should not submit sensitive information to AI functionality within our Software unless that functionality is specifically intended and configured to process that information.
20. Overseas disclosure and processing
20.1 Technology providers used by us may operate infrastructure outside Australia.
20.2 As a result, personal information may in some circumstances be stored or processed outside Australia.
20.3 The countries involved depend on:
a. the provider;
b. the service configuration;
c. the Customer's own systems;
d. hosting selections; and
e. the relevant Engagement.
20.4 Where the Australian Privacy Principles impose obligations concerning overseas disclosure, we will take the steps required of us.
20.5 We will not state that information remains exclusively in Australia unless that is actually guaranteed by the applicable service arrangement.
21. Security
21.1 We take reasonable steps appropriate to our circumstances to protect personal information from:
a. misuse;
b. interference;
c. loss;
d. unauthorised access;
e. unauthorised modification; and
f. unauthorised disclosure.
21.2 Measures may include, as appropriate:
a. access controls;
b. multifactor authentication;
c. encryption;
d. security updates;
e. backups;
f. device-security controls;
g. role-based access;
h. contractual confidentiality;
i. security monitoring; and
j. staff or contractor controls.
21.3 No electronic system can be guaranteed to be completely secure.
21.4 You should notify us promptly if you believe an account, credential or information supplied to us has been compromised.
22. Credentials and secrets
22.1 You should not send passwords, private keys, access tokens, API secrets or other highly sensitive credentials through ordinary email or support forms unless specifically requested.
22.2 Where access to a system is reasonably necessary for an Engagement, an appropriately secure mechanism should be used where available.
22.3 Access should be restricted to the level reasonably necessary for the work.
22.4 Credentials should be revoked or changed when they are no longer required where appropriate.
23. Data breaches
23.1 We maintain processes for assessing suspected data breaches.
23.2 Where the Notifiable Data Breaches scheme under the Privacy Act applies, we will assess whether a breach is likely to result in serious harm and comply with applicable notification requirements.
23.3 We may contact affected Customers or individuals where reasonably necessary to investigate, contain or respond to an incident.
23.4 Where we are handling information on behalf of a Customer, we may also be required to notify that Customer under the applicable contract.
24. Retention
24.1 We retain personal information for as long as reasonably necessary for:
a. the purpose for which it was collected;
b. a continuing business relationship;
c. contractual obligations;
d. Software licensing;
e. support;
f. legal obligations;
g. tax and accounting obligations;
h. professional obligations;
i. insurance requirements;
j. dispute management; or
k. legitimate recordkeeping.
24.2 Retention periods vary according to the type of information.
24.3 When personal information is no longer required and applicable law does not require its retention, we will take reasonable steps to destroy or de-identify it where required.
24.4 Information may persist for a limited period in secure backups after deletion from active systems.
25. Access to personal information
25.1 You may request access to personal information that we hold about you.
25.2 We may need to verify your identity before providing access.
25.3 Access may be refused or limited where permitted or required by law.
25.4 If we refuse access where the Privacy Act applies, we will provide any notice or reasons required by law.
25.5 We will not provide another person's personal information merely because it appears in a record concerning you.
26. Correction
26.1 You may ask us to correct personal information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.
26.2 We may take reasonable steps to verify the requested correction.
26.3 Where applicable law requires us to take further action concerning a correction request, we will do so.
27. Information held on behalf of a Customer
27.1 If your personal information is contained in a system or dataset that we handle solely on behalf of one of our Customers, the Customer may be the appropriate organisation to deal with your access or correction request.
27.2 If appropriate, we may refer you to that Customer or assist the Customer to respond.
27.3 We will not override a Customer's lawful authority over its own business records merely because we provide technology or consultancy services.
28. Privacy complaints
28.1 If you believe we have mishandled your personal information, please contact us and provide enough information for us to investigate the matter.
28.2 We will take reasonable steps to investigate a privacy complaint and respond within a reasonable period.
28.3 We may ask for additional information where required to understand or investigate the complaint.
28.4 If the Privacy Act applies and you are dissatisfied with our response, you may have a right to complain to the Office of the Australian Information Commissioner.
29. Third-party websites and services
29.1 Our websites and Software may contain links to third-party websites or integrate with third-party services.
29.2 We are not responsible for the privacy practices of an independent third party merely because we provide a link or integration.
29.3 You should review the privacy terms of third-party services you choose to use.
30. Children's information
30.1 Our Software, websites and Consultancy Services are principally directed to businesses and organisations rather than children.
30.2 We do not knowingly seek to collect personal information directly from children for general CXO Advisory or CXOdoo marketing purposes.
30.3 A Customer's business system may nevertheless contain information about children, particularly where the Customer operates in sectors such as education or early childhood services.
30.4 Where we encounter such information while providing Services, it will be handled only as reasonably necessary for the relevant Engagement and subject to applicable confidentiality, contractual and privacy obligations.
30.5 Customers remain responsible for determining whether they have a lawful basis for collecting and providing information held in their systems.
31. Business sale or restructure
31.1 Personal information may form part of a genuine corporate transaction involving:
a. a merger;
b. acquisition;
c. business sale;
d. restructure; or
e. transfer of relevant business assets.
31.2 Information will only be disclosed for such a purpose where reasonably necessary and subject to applicable confidentiality and privacy requirements.
32. Changes to this Privacy Policy
32.1 We may update this Privacy Policy to reflect:
a. changes to law;
b. changes to our business;
c. new Software or Services;
d. changes to technology;
e. changes to service providers; or
f. changes to our information-handling practices.
32.2 The current version will be published on our Website with its effective date.
32.3 Where a change materially affects how we handle personal information and additional notice or consent is legally required, we will take appropriate steps.
33. Contacting us
Privacy questions, requests and complaints may be submitted using the contact details published on the CXO Advisory or CXOdoo websites.
You may also contact CXO Advisory by telephone on 07 3472 7442.
Where your enquiry concerns a particular Customer Engagement or Software support matter, please identify the relevant Customer or Order so that we can locate the appropriate records.
Bentendo Pty Ltd
ACN 646 790 865
ABN 95 739 056 828
Trading as CXO Advisory
CXOdoo is a software and applications brand operated by Bentendo Pty Ltd
Liability limited by a scheme approved under Professional Standards Legislation.