Skip to main content
Varial Energy Varial Energy
  • Home
  • Products
    • VAR
    • Positions
    • Spot
    • Revert
  • Support
  • Docs
  • Contact
Explore
AU NEM
Pricing
Log in Register

Varial Energy Pty Ltd – Privacy Policy

Last updated: 23 June 2026

Varial Energy Pty Ltd (ABN 19 699 848 470) (we, us or our) is committed to protecting your privacy. This policy explains how we collect, use and protect your personal information. It applies to all personal information we handle, whether we collect it through our website, in person, or through other means.

Quick overview

  • We collect information you provide to us and information we gather when we interact with you.
  • We use this information to provide our services and improve your experience.
  • We protect your information using secure systems and processes.
  • You have rights regarding your personal information, including access and correction rights.

1. Information we collect

Identity and contact details

  • Name, address, email address and phone number
  • Professional details

Service-related information

  • Payment and transaction details for products and services you've purchased from us or enquiries about our products and services
  • Your preferences for our services and your marketing preferences
  • Feedback and survey responses

Digital information

  • IP address and general location information derived from your IP address
  • Search and browsing behaviour
  • Website usage patterns
  • Cookie preferences

Recordings

  • Call recordings
  • Records of meetings and decisions

Professional information (for job applicants and workers)

  • Employment history
  • Professional experience
  • Required authorisations and licences
  • Professional registrations
  • Information about your right to work in the relevant jurisdiction

2. How we collect personal information

  • Directly from you when you: interact with us, contact us, fill out forms.
  • Automatically when you: visit our website, use our technologies, interact with our online services.
  • From third parties: service providers, business partners, public sources, government organisations and organisations or people authorised by you.
  • From publicly available sources: such as ASIC and other regulatory bodies and professional networking sites such as LinkedIn.

3. Why we collect, hold, use and disclose personal information

We collect and use your personal information to run our business and provide our services as set out below.

Business operations

  • To manage our relationship with you as a customer or supplier
  • To process and deliver our products and services
  • To handle your inquiries, support requests, and communications
  • To maintain accurate records for billing and administration

Client onboarding and verification

  • To assess whether to take you on as a new client or provide services to you, including performing anti-money laundering, anti-terrorism, sanction screening, fraud and other background checks when required or permitted by law
  • To retain records of verification checks as required by law

Communication and support

  • To respond to your questions and support requests
  • To communicate important updates about our services
  • To handle inquiries made through our website or platforms
  • To manage your participation in surveys, feedback sessions, or events

Service improvement

  • To conduct analytics and market research
  • To improve our business operations and services
  • To develop and enhance our applications and platforms
  • To understand how our services are used

Marketing and promotions

  • To send you promotional information about our services and events
  • To inform you about products or services that may interest you
  • To manage your marketing preferences
  • To run competitions, promotions, and special offers
  • To provide additional benefits to our customers

Employment purposes

  • To assess employment applications
  • To evaluate candidate qualifications
  • To manage professional certifications and licences
  • To maintain employment records

Legal and compliance

  • To comply with our legal obligations
  • To respond to court orders or legal processes
  • To maintain required business records
  • To fulfill regulatory requirements or reporting obligations
  • To protect our legal rights and interests or as authorised by law

4. Our disclosures of personal information to third parties

We do not sell your personal information. We keep the number of parties who receive it small, share only what each one genuinely needs to do its job, and disclose it beyond that only where the law requires it. In practice, that means:

Service providers

  • Microsoft Azure (Australia East) – hosts our application, database, file storage, cache, and observability. All Customer Data sits in Australia.
  • Databricks – modelling compute for our market-forecasting pipeline. No personal information flows to Databricks; it only ever receives de-identified market data and run metadata.
  • PostHog (European Union – Frankfurt) – our only analytics provider. Receives de-identified usage events keyed to a random pseudonymous identifier, not your name. IP addresses are discarded at ingestion, we do not enable session recording, and we do not use Google Analytics, Meta Pixel, or any other advertising or tracking pixel. You can opt out at any time via your browser's Do-Not-Track or Global Privacy Control signal.
  • HubSpot (United States) – our CRM, used to manage sales and customer relationships. Receives your name, email, and account/usage signals (such as lifecycle stage and credit balance) so our team can support you. We do not sync payment details, or the scenario, position, or forecast data you put into the platform, to HubSpot.
  • Stripe – payment processing. We do not currently process payments through Stripe. If we introduce self-serve paid plans, Stripe (Ireland/United States) will process your payment-card details directly and we will not store card data ourselves.

Professional advisers – bankers, auditors, insurers and insurance brokers, and legal advisers, where needed to run the business.

Corporate transactions – if we merge with or are acquired by another company, or sell our business assets, your information may be disclosed to our advisers and the potential purchaser's advisers, and may be included in the transferred assets.

Legal and regulatory bodies – courts and tribunals, regulatory authorities (including as required for reporting obligations), and law enforcement officers, where required or permitted by law.

Other parties – third parties you have authorised, emergency services when necessary, and any other parties as required or permitted by law.

5. Overseas disclosure

Storage and access. We store your personal information in Australia. Our hosting provider, Microsoft Azure, keeps Customer Data in its Australia East region. Two of our service providers are based overseas and process a limited slice of information as described in section 4 above: PostHog (European Union) for de-identified analytics events, and HubSpot (United States) for CRM contact and account records. If we introduce Stripe for payment processing, it will process payment details in Ireland/the United States. We do not otherwise transfer your personal information overseas.

Our approach to overseas disclosure. Before disclosing your personal information overseas, we take reasonable steps to ensure that the recipient treats your information in accordance with applicable law by only sending what is necessary, requiring recipients to protect your information through contractual agreements which require the recipient to comply with the privacy standards in applicable law or through other mechanisms that provide comparable safeguards and by monitoring how recipients handle your information.

6. Your privacy rights and choices

Providing information. You can choose whether to provide personal information to us, however, if you don't provide certain information, we may not be able to provide some services. Let us know if you don't want to provide information and we will let you know when information is required versus optional.

Access to your information. You can request access to the personal information we hold about you and we will respond to your request within a reasonable time. We may charge a reasonable administrative fee for providing access and if we cannot provide access, we will explain why and explore alternative ways to share relevant information.

Correction rights. You can ask us to correct any information that is inaccurate, out of date, incomplete, irrelevant or misleading and we will take reasonable steps to correct your information promptly. If we cannot make the correction, we will explain why and discuss alternatives. You can ask us to add a statement to your information noting your requested correction.

Marketing communications. You can opt-out of receiving marketing communications at any time. Each marketing communication will include an unsubscribe option. You can change your marketing preferences by contacting us. We will process your request as soon as practicable.

7. How to contact us about your rights or to make a complaint and what happens next

Step 1: Contact our privacy officer

  • Email: [email protected]
  • Phone: 0422 212 642
  • Post: PO Box 133, Mona Vale, NSW 1660, Australia

What to include: your full name, contact details, clear details about your request or complaint, and any relevant dates or reference numbers.

Step 2: Our response. We will:

  • Verify your identity before processing your request
  • Investigate thoroughly (for complaints) or process your request (for rights)
  • Respond to you in writing within reasonable timeframes and as required by law
  • Explain what actions we will take and keep you updated on progress
  • Not charge you for making a request (except for reasonable access fees if applicable)
  • Help you understand and exercise your rights

Step 3: If you're not satisfied (complaints only). If you're not satisfied with our response to your complaint, you can:

  • Ask for a review by our senior management, or
  • Contact external bodies: Australian residents can contact the Office of the Australian Information Commissioner (Phone: 1300 363 992, Website: www.oaic.gov.au)

This is the same process whether you want to access your information, correct mistakes, change marketing preferences, or make a complaint about our privacy practices.

8. Protecting your information

We use multiple layers of security to protect your information.

Technical safeguards

  • Enterprise-grade encryption for data storage and transmission
  • Regular security testing and monitoring
  • Automated threat detection systems

Operational security

  • Staff training on security and privacy
  • Strict access controls based on job requirements
  • Regular security audits and incident response procedures testing

Physical security

  • Secure premises with controlled access
  • Secure disposal of physical documents
  • Equipment security protocols

9. Public information

Please note that any information you choose to share publicly on online platforms (such as comments or reviews) can be accessed and used by others. We cannot control or protect information that you make publicly available.

10. How long we keep your information

We keep your personal information only as long as we need it for the purposes we collected it, or as required by law. When we no longer need it, we securely destroy or de-identify it.

11. Cookies and Analytics

What we use. We keep this deliberately minimal. We do not use Google Analytics, Meta Pixel, or any other third-party advertising or tracking pixel, and we do not run advertising campaigns that track you across sites. We use:

  • Essential cookies – remember your login status, maintain your session security, and enable core website features. These are required for the platform to work and can't be switched off.
  • PostHog product analytics – understand how the platform is used (page views, navigation patterns, feature adoption) so we can improve it. Events are keyed to a random pseudonymous identifier rather than your name, IP addresses are discarded at ingestion, and we do not enable session recording.

Your control. You can manage these technologies by:

  • Adjusting your browser settings to block or delete cookies
  • Using privacy-focused browser extensions
  • Sending a Do-Not-Track or Global Privacy Control signal, which PostHog respects

Note: blocking essential cookies will affect your ability to stay signed in.

12. Artificial Intelligence (AI) Technologies

We use artificial intelligence and machine learning technologies in our business operations and services, including AI tools provided by third parties. We only use these technologies when legally permitted and necessary for our business.

How we use AI. We may use AI technologies to:

  • Conduct analysis and data processing
  • Generate and modify content and coding
  • Improve and optimise our services and operations
  • Automate routine tasks and communications
  • Personalise your experience with our services
  • Support quality assurance processes
  • Assist with customer support and queries

Data protection and security. When we work with third-party AI providers, we ensure they handle your personal information in accordance with privacy laws through contractual requirements and appropriate safeguards.

Your rights and our commitments. Any information generated or inferred about you by AI technologies is treated as personal information, and you maintain all the rights outlined in this privacy policy. When using AI with your personal information, we commit to:

Transparency and control

  • We'll inform you when AI is used to make decisions that may significantly affect you
  • We maintain human oversight and review of significant AI-generated decisions
  • Our staff are trained to understand AI limitations and verify outputs before relying on them
  • We implement processes to verify the accuracy of AI-generated outputs

Security

  • We use appropriate technical and organisational measures to maintain the security and integrity of your personal information
  • We regularly test and monitor AI outputs for accuracy and reliability

Risk mitigation

  • We regularly assess and document risks associated with using AI to process personal information
  • We implement appropriate measures to address these risks
  • We continuously monitor AI performance and regularly review their impact

13. AI Chatbot Privacy Collection Notice

This notice describes how Varial Energy Pty Ltd (ABN 19 699 848 470) (we, us or our) collects and handles your personal information when you use or otherwise interact with the AI chatbot provided on our website (Varial Bot).

We collect personal information from you and may process it through Varial Bot to provide our services, to assist with customer support and queries, to analyse and improve our customer service interactions, to personalise your experience with our services, and for related purposes set out elsewhere in this Privacy Policy. The personal information you input to Varial Bot is not used to train the underlying AI model.

We may disclose this personal information to our IT service providers (including Anthropic, which powers Varial Bot), our personnel, related entities, and as otherwise set out elsewhere in this Privacy Policy. Varial Bot may generate or infer information about you, which we treat as personal information.

We store personal information in Australia. Where we disclose your personal information to third parties, those third parties may store, transfer or access personal information outside of Australia (see section 5, Overseas disclosure).

Please avoid entering personal or commercially sensitive information (such as PPA pricing or position data) into Varial Bot. See the rest of this Privacy Policy for more information about how we collect, store, use and disclose your personal information, including your rights of access and correction and how to make a complaint. If you have questions about our privacy practices, please contact us by email at [email protected]. By using Varial Bot, you agree to the collection, use, storage and disclosure of your personal information as described in this notice.

14. Visitors from the European Union or United Kingdom

Varial does not currently offer the platform to data subjects in the European Union or the United Kingdom, and we do not deliberately target or monitor visitors from those jurisdictions. If you nevertheless contact us from the EU or UK and have a request under the GDPR or UK GDPR, please reach out using the contact details in section 7 and we will treat your request on equivalent terms.

15. Amendments

We may update this policy at any time by posting the revised version on our website. We recommend that you review our website regularly to stay current with any policy changes.

© 2026 Varial Energy
Privacy Terms Security
Docs Contact