Quick summary
GELLIBN PTY LTD collects personal information to provide and secure the platform, facilitate workplace communication, process subscriptions, operate optional AI features, improve the service, and meet legal obligations.
We do not sell your data. You're always in control – you can access, correct, or delete your information.
EU-based users should review Section 16 for GDPR-specific rights.
1. Policy scope
This policy applies to:
- www.gellibn.com website
- Mobile and web applications
- Direct services provided
- Data collected through interactions (marketing, sales, support)
We process information to perform our contract with customers, pursue legitimate interests such as security and service improvement, comply with legal obligations, and, where required, based on consent. We may update the policy, with significant changes communicated via account notification or email.
2. Personal information collected
General user information
Name, email, phone, business name, login credentials, subscription and transaction details, and contact form submissions are collected to establish accounts, deliver services, administer payments, and respond to inquiries.
Marketing data
Email addresses and engagement metrics are gathered to distribute updates, newsletters, and promotional materials, with opt-out available anytime.
Employee information
Names, roles, shift data, performance records, and contact details are collected to enable customer organizations to manage teams through gellibn.
HR information
Contact details, CVs, tax records, payroll information, and background checks are obtained for hiring, employment, and onboarding purposes.
User content and technical information
Workplace messages, feedback, tasks, files, images, Knowledge Base documents, search terms, support requests, and AI prompts or voice interactions are collected when users submit or use them. We also collect account and company identifiers, subscription status, device and push-notification identifiers, product interactions, IP addresses, and crash, performance, and diagnostic information.
3. Collection methods
Information is obtained through:
- Direct submission via forms, phone, email, or face-to-face interaction
- Platform and website usage (including cookies and IP addresses)
- Authorized third-party integrations
- Public sources or references when applicable
We attempt to notify users when information originates from external sources.
4. Information usage
Personal data supports:
- gellibn service provision
- Support request and inquiry responses
- Payment processing and account administration
- Platform improvement and development
- Opt-in updates and communications
- Product analytics, diagnostics, and benchmarking
- Optional AI assistance and document processing
We do not sell personal information, serve third-party advertising, or use personal information for cross-app or cross-site advertising tracking.
5. Information disclosure
We disclose information to service providers only as needed for the functions described below:
- Supabase provides authentication, databases, file storage, and server-side application functions.
- OpenAI processes information for Ask Gellibn, voice and transcription features, web-assisted answers, search, embeddings, and indexing.
- Anthropic provides the Claude Document Specialist used for optional Knowledge Base document imports and exports.
- OpenRouter routes limited prompts used for feedback sentiment classification and assistant conversation titles to the configured AI model provider.
- PostHog provides identified product analytics. Gellibn does not enable PostHog session replay or use it to record screen text or images.
- Sentry processes user-linked crash, performance, and diagnostic information so we can investigate reliability problems.
- Firebase Cloud Messaging processes device and push-notification identifiers and delivery diagnostics to send notifications.
- Chargebee provides hosted checkout, billing, and subscription management. Payment credentials are entered with Chargebee; Gellibn receives the customer, subscription, and transaction information needed to administer the account.
- Authorized advisors or integrations
- Regulators, law enforcement, or government bodies (when legally required)
- Potential business buyers
We disclose information to these providers for the stated service, legal compliance, security, and abuse prevention. Gellibn does not use these disclosures for third-party advertising or advertising tracking.
AI services
Before any AI request is processed, Gellibn explains the processing in the app and asks the user for permission. If the user selects “Not now,” no request content is sent to an AI service provider. Permission can be turned off at any time under AI Features & Privacy in Settings, which stops future AI processing.
When permission is enabled and a user invokes an AI feature, Gellibn securely sends only the content needed for that request to OpenAI, Anthropic, OpenRouter, or an AI model provider used through OpenRouter. Depending on the feature, this can include a prompt and recent conversation, voice audio or transcript, relevant company information, a document the user chooses to process, or feedback text used to suggest an internal rating.
These providers act as service providers processing content on Gellibn’s behalf solely to return the requested result. Under the commercial API data controls used by Gellibn, request content is not used to train AI models, for advertising, or for sale. Providers may retain limited records for security, abuse prevention, or legal compliance as described in their applicable commercial terms.
Customer organizations are responsible for ensuring that users are authorized to submit company and personal information to these features.
6. Sensitive information
Sensitive data, such as health or ethnicity information, is collected only when:
- Explicit user or employee consent is provided
- Necessity for service delivery or legal compliance exists
Sensitive information is excluded from marketing activities. Users and customer organizations should not submit sensitive information to an AI feature unless they are authorized to do so and the information is necessary for the requested service.
7. Direct marketing
Recipients may opt in or out of promotional communications anytime. Opted-in users receive an "unsubscribe" link in each email for easy withdrawal.
8. Credit information
Credit-related information may be collected for customers receiving extended payment terms. Details are available in the Credit Reporting Policy upon request.
9. Anonymity and pseudonymity
Where feasible, users can interact anonymously or under pseudonyms. However, most services require verified identity.
10. Cross-border transfers
Gellibn is based in Australia. Our service providers, including the cloud, analytics, diagnostic, payment, messaging, and AI providers named above, and their subprocessors may process information in the United States, European Union, United Kingdom, Australia, or other countries where they operate. Privacy laws in those locations may differ from those in a user's country.
We use contractual and organizational safeguards for international processing where required by applicable law. AI-provider processing occurs as described in Section 5 when a user uses an AI feature.
11. Data accuracy
Users are encouraged to notify us of changes to keep records current. Contact: support@gellibn.com.
12. Data protection measures
Reasonable protective steps include:
- Encryption and secure storage
- Access controls and internal protocols
- Regular data backups and reviews
Users are reminded that no system achieves complete security and should protect login credentials.
13. Access and correction rights
Users may:
- Request a personal data copy
- Request correction of inaccurate or outdated information
- Request deletion or de-identification of personal information
Requests should be directed to support@gellibn.com. We may verify identity and authority before acting. If a customer organization controls the information, we may refer the request to that organization. Limited fees may apply where permitted by law.
14. Data retention
Account, company, and user content is retained while the relevant account is active and for as long as reasonably needed to provide the service, resolve disputes, maintain security, or meet legal obligations. Billing, tax, transaction, and audit records may be retained for up to seven years where required. Other information is deleted or de-identified when it is no longer needed for its stated purpose.
We aim to delete or de-identify information from active systems within seven days of an in-app deletion request. Information may remain longer where retention is legally required, needed for security or legal claims, controlled by a customer organization, or held in restricted backups until their normal rotation. Where required, we also instruct relevant service providers to delete the information they process for us.
15. Complaint resolution
Users with concerns should:
- Contact support@gellibn.com
- Await prompt acknowledgment and resolution
- Lodge complaints with the OAIC (Australia) or relevant privacy authority if needed
16. GDPR rights (EU users)
EU-based individuals possess GDPR rights including:
- Access, correction, or deletion of personal data
- Processing restriction or objection
- Data portability
- Supervisory authority complaint lodging
gellibn operates as a processor for customers and controller for its own employees. EU users should contact us or their employer to exercise these rights.
17. Policy changes
The Privacy Policy may be modified, with the latest version maintained on the website. Significant changes trigger email or account notification.
Where required, we will request new consent before applying a change to previously collected information or optional AI processing.
Contact information
GELLIBN PTY LTD
39 Furlong Street, Broadbeach Waters QLD 4218, Australia
Email:
support@gellibn.com