1. About this policy
IndustryCue is operated by Red Yellow Blue Pty Ltd ACN 695 759 525 (“we”, “us”, “our”), trading as IndustryCue, a company incorporated in New South Wales, Australia.
This Privacy Policy explains how we collect, use, store, and disclose personal information when you use IndustryCue at industrycue.com and app.industrycue.com (“the Service”). It covers two distinct categories of data we handle:
Customer data — information about you as a subscriber to IndustryCue (your name, email, billing details, account activity).
Contact data — information about your contacts imported from your HubSpot CRM and enriched by IndustryCue on your behalf. You, as our customer, are the controller of this data. We process it only under your instruction.
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where our customers’ contact data includes individuals located in the European Economic Area or United Kingdom, we also comply with the General Data Protection Regulation (GDPR) as a data processor.
2. Customer data we collect
2.1 Account information
When you create an IndustryCue account, we collect your name, business email address, company name, and password (stored as a bcrypt hash — we never store plaintext passwords).
2.2 HubSpot connection
When you connect your HubSpot portal, we store an encrypted access token that allows IndustryCue to read and write to your HubSpot portal on your behalf. This token is encrypted using AWS Key Management Service (KMS) and never stored in plaintext. We do not store your HubSpot account password.
2.3 Billing information
We use Stripe to process payments. We do not store your credit card number, CVV, or full card details on our systems. Stripe stores and processes payment information in accordance with PCI DSS Level 1. We store your Stripe customer ID, subscription status, and billing history for account management and support purposes.
2.4 Usage data
We collect logs of actions performed on the Service — enrichment jobs run, tokens consumed, signals detected, moments generated, and pages visited within the application. This data is used to operate the Service, generate your usage reports, and improve IndustryCue.
2.5 Communications
If you contact us by email or through the Service, we retain the content of those communications to respond to your request and improve our support.
3. Contact data — your HubSpot contacts
3.1 Your role as controller
When you import contacts from your HubSpot CRM into IndustryCue, you remain the data controller for those contacts. IndustryCue processes this data solely on your instruction as your data processor. You represent and warrant that you have a lawful basis to share this contact data with IndustryCue for the purpose of enrichment and signal monitoring.
3.2 What contact data we process
We import and process the following fields from your HubSpot contacts: first name, last name, email address, current job title, current company, LinkedIn URL, location, and HubSpot owner ID. We may also process deal history, email reply counts, and call activity associated with a contact where this data is available in your HubSpot portal and relevant to relationship scoring.
3.3 How we enrich contact data
IndustryCue uses the following methods to enrich contact data on your behalf:
- Web search via Brave Search API: We submit anonymised search queries (first name, last name, company) to Brave Search to locate publicly available professional information. Contact email addresses are never transmitted to Brave Search.
- Email validation via Hunter.io: We submit contact email addresses to Hunter.io to validate deliverability.
- AI analysis via Anthropic Claude API: We transmit contact profile information to Anthropic’s Claude API to extract structured data from search results and generate enrichment outputs. Anthropic does not use API inputs for model training. Data submitted via the API is not retained by Anthropic beyond the duration of the API request in accordance with Anthropic’s API data processing terms.
3.4 What we write back to HubSpot
IndustryCue writes enriched data back to your HubSpot contact records using custom properties prefixed with ic_. Only fields with a confidence score at or above your configured write-back threshold (default 60%) are written to HubSpot. Lower-confidence data is stored within IndustryCue only, accessible to you in the IndustryCue dashboard.
3.5 Contact data storage
Contact data is stored in AWS DynamoDB in the ap-southeast-2 (Sydney, Australia) region. Contact snapshot data (used to detect career changes) is stored in AWS S3 in the same region with a 365-day retention period, after which it is automatically deleted.
3.6 Your obligations regarding contact data
You must not import contacts into IndustryCue unless you have a lawful basis to do so under applicable privacy law. You are responsible for maintaining suppression lists and honouring any opt-out or erasure requests received from your contacts. If a contact requests deletion of their data and you notify us, we will delete that contact’s data from IndustryCue within 30 days.
4. How we use your data
We use customer and contact data for the following purposes:
- Providing and operating the Service — processing enrichment jobs, generating signals and revenue moments, delivering alerts
- Billing and account management — processing payments, managing subscriptions, communicating about your account
- Product improvement — analysing aggregate, anonymised usage patterns to improve IndustryCue’s enrichment accuracy and signal quality
- Customer support — responding to inquiries, diagnosing technical issues
- Security and fraud prevention — detecting and preventing abuse of the Service
- Legal compliance — meeting our obligations under applicable law
We do not sell your customer data or contact data to any third party. We do not use your contact data to train AI models or improve enrichment for other customers.
5. Who we share data with
We share data only with the following third-party service providers, under data processing agreements, to the extent necessary to provide the Service:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| AWS (Amazon Web Services) | Infrastructure — Lambda, DynamoDB, S3, SES, SQS, Cognito | All data | Sydney, AU (ap-southeast-2) |
| Stripe | Payment processing | Billing data, email | US (Stripe handles PCI compliance) |
| Brave Search | Contact enrichment (web search) | First name, last name, company name | US |
| Hunter.io | Email validation | Email addresses | US |
| Anthropic | AI analysis (Claude API) | Contact profile data for enrichment | US |
We do not share your data with advertising networks, data brokers, or analytics platforms beyond what is necessary to operate the Service.
6. Data retention
| Data type | Retention period |
|---|---|
| Customer account data | Duration of subscription + 12 months after cancellation |
| Contact enrichment data | Duration of subscription + 30 days after cancellation |
| Contact snapshots (S3) | 365 days, then auto-deleted |
| Token ledger / usage records | 3 years (for billing dispute resolution) |
| CloudWatch logs | 90 days |
| Stripe billing records | 7 years (for tax and financial record keeping) |
When you cancel your subscription, all contact data and enrichment data is deleted within 30 days. Customer account data is retained for 12 months to allow reactivation. You may request earlier deletion by contacting privacy@industrycue.com.
7. Security
We implement the following security measures:
- Encryption at rest: All data in DynamoDB and S3 is encrypted using AWS KMS. HubSpot access tokens are encrypted with a dedicated KMS key.
- Encryption in transit: All data transmissions use TLS 1.2 or higher.
- Access control: Production AWS resources are accessible only to authorised personnel via IAM roles with least-privilege policies. No direct database access from application code without the Lambda authorizer.
- Authentication: User authentication via AWS Cognito with password hashing. Passwords are never stored in plaintext.
- Audit logging: All admin actions are logged with the admin’s identity and a timestamp in DynamoDB.
- No PII in application logs: CloudWatch logs are configured to mask email addresses and contact names.
Despite these measures, no method of transmission or storage is 100% secure. We will notify affected customers and relevant authorities of any data breach in accordance with the Notifiable Data Breaches scheme under the Australian Privacy Act.
8. Your rights
Australian customers have the right under the Australian Privacy Principles to:
- Request access to personal information we hold about you
- Request correction of inaccurate, incomplete, or out-of-date personal information
- Make a complaint about how we have handled your personal information
EU/UK customers have additional rights under GDPR including:
- The right to erasure (“right to be forgotten”)
- The right to data portability
- The right to restrict processing
- The right to object to processing
To exercise any of these rights, contact us at privacy@industrycue.com. We will respond within 30 days.
To make a complaint about our handling of your personal information, you may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
9. Cookies and tracking
The IndustryCue marketing website (industrycue.com) uses:
- Strictly necessary cookies — authentication session cookies required to use the Service
- Analytics — Vercel Analytics and Google Analytics 4 to understand website usage (anonymised IP addresses, no cross-site tracking)
The IndustryCue application (app.industrycue.com) uses strictly necessary cookies only. We do not use advertising cookies or third-party tracking in the application.
You may opt out of Google Analytics tracking at tools.google.com/dlpage/gaoptout.
10. Children’s privacy
IndustryCue is a B2B service intended for business professionals aged 18 and over. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@industrycue.com.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify customers of material changes by email and by displaying a notice in the IndustryCue application. The updated policy will be effective from the date it is published. Your continued use of the Service after that date constitutes acceptance of the updated policy.
12. Contact us
For privacy-related inquiries:
Email: privacy@industrycue.com
Mail: Red Yellow Blue Pty Ltd, 22 Lidiard St, Hawthorn, Melbourne VIC 3101, Australia