Privacy Policy
Effective 20 September 2026 · Last updated 20 September 2026
This Privacy Policy explains how Vicinia Pty Ltd (ABN 70 653 966 637), trading as Hamlet ("Hamlet", "we", "us", "our"), collects, uses, discloses, stores and otherwise handles personal information.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where they apply, the Privacy Act 2020 (NZ), the UK GDPR and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR), and applicable US state privacy laws.
1. About this policy
1.1 Who we are
Hamlet provides a cloud platform for running coworking spaces, serviced and flexible offices, landlord-operated flex and other shared facilities. Our customers are the businesses that operate those spaces. Our head office is in Sydney, Australia.
1.2 The two roles in which we handle personal information
(a) Where Hamlet is the controller (APP entity). We collect personal information directly from prospective customers, customer staff and administrators, website visitors, job applicants, suppliers and event attendees for our own business purposes. This policy mainly covers that information.
(b) Where Hamlet is a processor (service provider) for a customer. When an operator uses the Hamlet platform, it uploads and processes personal information about its own members, guests, employees, contractors and other end users. The operator is the controller of that information and its privacy policy governs how it is handled. Hamlet processes it on the operator's behalf under our Services Agreement and Data Processing Addendum.
If you are a member, guest or end user of a Hamlet customer, contact that customer first about your personal information. Section 17 explains how we handle information processed on customers' behalf.
1.3 Scope
This policy applies to our website at hamletco.space and associated domains we operate (including resources.hamletco.space), the Hamlet platform and mobile and web applications, our marketing, sales, support and business activities, and any other interaction you have with us.
2. What is personal information?
Personal information (or personal data) is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and however recorded. It includes your name, contact details, identifiers, device information and information about how you use our services.
Sensitive information (or special category data) includes information about health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and biometrics. We do not generally collect sensitive information, and where we do we only do so with your consent or as otherwise permitted by law.
3. Personal information we collect
3.1 Information you provide
When you register for an account or demo, request a quote or proposal, subscribe to our communications, attend an event or training session, contact our support or sales teams, apply for a role, or take part in surveys or research, we may collect your name, business name, role, email address, phone number, postal address, social media profile information and anything else you choose to provide.
3.2 Information collected automatically
When you use our website or platform we may collect log data (IP address, browser, pages visited, time and date, referrer), device data (device type, operating system, identifiers, screen size), usage data (features used, click paths, session information), approximate location derived from your IP address (or more precise location from your device only with your consent), and error data.
3.3 Information from third parties
We may receive personal information from our customers (in the context of section 1.2(b)), referrers, partners or resellers, public sources such as LinkedIn or business directories for sales prospecting where lawful, service providers who help us deliver our services, and recruiters or referees in connection with employment applications.
3.4 Sensitive information
We do not seek to collect sensitive information through the platform. Customers must not use the platform to process sensitive information without our prior written agreement (Services Agreement, clause 4). In limited cases we may collect sensitive information directly, such as dietary or accessibility requirements for an event, and only with your consent.
4. How we collect personal information
We collect personal information directly from you, automatically through our website and platform (including cookies, see section 7), from third parties (section 3.3), and from publicly accessible sources where lawful. Where lawful and practicable you may deal with us anonymously or under a pseudonym, though this is not possible for most of our services.
5. Why we collect personal information
We collect, use and disclose personal information only for purposes reasonably necessary to our functions and activities: to provide access to our website, applications and platform; to provide and operate the Services; to communicate with you about your account, services and support; to send service announcements, billing notices and security alerts; to conduct sales and marketing (subject to section 6); to understand and improve how our website and platform are used; to develop new features and services (subject to section 12); to detect and investigate security incidents, fraud and abuse; to comply with legal, regulatory, accounting and reporting obligations; to exercise or defend legal rights; to recruit; and to manage corporate transactions (section 19).
Where the UK GDPR or EU GDPR applies, our lawful bases are performance of a contract, our legitimate interests (operating, securing and improving our services, and business-to-business marketing), compliance with legal obligations, and your consent where we ask for it (which you can withdraw at any time).
Collection notice
When you contact us, request a walkthrough, subscribe, or submit a form on our sites, we collect the details you provide (typically your name, business, email, phone and message) in order to respond to you, provide the information or services you've asked for, and, if you've agreed, tell you about Hamlet products and services. We collect it directly from you. We may share it with the service providers listed in section 8 and, where required, by law. If you don't provide it, we may not be able to respond. This policy explains how to access or correct your information, how to opt out of marketing, and how to complain.
6. Direct marketing
We may send you direct marketing about our products, services and events. You can opt out at any time using the unsubscribe link in any marketing email, by contacting privacy@hamletco.space, or by updating your preferences in your account. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law.
7. Cookies and similar technologies
We use cookies and similar technologies on our website and platform to keep you signed in, remember your preferences (including your chosen currency and theme), understand and analyse usage, and support marketing. Where required by law, including for visitors from the UK and EU, we ask for your consent to non-essential cookies through a banner before setting them. You can control cookies through your browser and through the banner. Our Cookie Policy at hamletco.space/cookie-policy lists the cookies we use.
8. Disclosure of personal information
8.1 Service providers and sub-processors
We disclose personal information to service providers who help us operate our business and deliver the Services, including cloud hosting, analytics and product telemetry, email and communications, payment and billing, customer relationship management and support tooling, security and monitoring, error logging, guides and training content hosting, professional advisers, and debt collection where applicable. They may only use personal information to perform services for us, under contractual confidentiality and security obligations.
Providers we currently use include:
- Google Cloud, cloud infrastructure for the platform, in Australian and UK regions
- Google Analytics, website analytics, only with consent for UK and EEA visitors
- Stripe and Worldpay (formerly Payrix in Australia), payment gateways
- SendGrid (Twilio), transactional email
- Xero, accounting integration and our own accounting
- Slack, team communications and shared support channels with customers
- Attio, our customer relationship management system for prospects and customers
- Supademo, hosting of our interactive guides at resources.hamletco.space
- PostHog, error and performance monitoring
- Atlassian (Jira), support tickets
- Lovable Cloud, hosting of this website and storage of website form submissions
The maintained list of sub-processors that handle Customer Data within the platform is at hamletco.space/sub-processors, and we give customers at least 30 days' notice of additions.
8.2 Other disclosures
We may also disclose personal information to our related entities, employees, contractors and authorised representatives; to prospective business partners or acquirers; to credit reporting bodies and debt collectors where you fail to pay amounts owed; to courts, regulators and law enforcement as required by law; and to any other party with your consent.
9. Where personal information is held and cross-border disclosure
Platform data. Customer Data in the Hamlet platform is hosted in the region associated with the customer's billing region: Australia for customers in Australia and New Zealand, and the United Kingdom for customers in the United Kingdom. [State the hosting region for EU and US customers before those regions go live.]
Other data. Some of our service providers process personal information in other countries, including the United States, the United Kingdom, the European Union and Singapore.
Where we transfer personal data out of the UK or the EEA, we rely on adequacy regulations where available and otherwise on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. Where we disclose personal information overseas from Australia or New Zealand, we take reasonable steps, including contractual arrangements, to ensure the recipient handles it consistently with the Australian Privacy Principles or the New Zealand Information Privacy Principles.
10. Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including encryption in transit and at rest, role-based access controls and multi-factor authentication, network and infrastructure security, staff confidentiality obligations and training, and vendor due diligence. A summary of our security practices is at hamletco.space/security. No method of transmission or storage is completely secure, and you are responsible for keeping your credentials secure and telling us promptly of any suspected compromise.
11. Data breaches
If we become aware of a data breach involving personal information we will assess it without delay and, where required, notify the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, the New Zealand Privacy Commissioner, the UK Information Commissioner's Office or the relevant EU supervisory authority (within 72 hours where the UK GDPR or EU GDPR requires it), and affected individuals. Where the breach involves Customer Data we process for a customer, we will notify that customer within 72 hours of becoming aware so it can meet its own obligations. If you believe a breach involving your information has occurred, contact privacy@hamletco.space.
12. Automated and AI-assisted features
The platform includes automated features and may include AI-assisted features (such as summaries, drafting and workflow automation). Where they process personal information: they are designed to assist people, and material decisions affecting individuals (membership, billing disputes, access) should be reviewed and made by a person; we do not use personal information processed for customers to train general-purpose AI models; where we use data for product improvement it is aggregated and irreversibly de-identified; and where a feature relies on a third-party AI provider, personal information sent to it is subject to contractual protections and is not used by that provider to train its models. If a decision that significantly affects you appears to have been made by automated processing, you can ask us for human review.
13. Retention
We keep personal information only as long as we need it for the purposes in this policy or as required by law. In general: account information for the life of the account plus a period for record-keeping and legal compliance (typically up to 7 years); Customer Data in accordance with the Services Agreement, including a 30-day export window and deletion from production within 90 days of termination; marketing data until you opt out, plus a short period for suppression; website analytics for the period configured in our analytics provider; financial and tax records for at least 7 years; and support and security logs for a reasonable period. When no longer needed, we delete or irreversibly de-identify it.
14. Your rights and choices
You can choose not to provide personal information, though that may limit the services we can offer. You can ask us to access or correct your personal information, opt out of marketing, withdraw consent where we rely on it, and complain (section 18). We will not discriminate against you for exercising your rights. To exercise any right, contact privacy@hamletco.space. We may need to verify your identity, and we will respond within the time required by the law that applies to you (30 days in most cases).
15. Children
Our services are for businesses and adults, and we do not knowingly collect personal information directly from children under 16. Some of our customers run spaces where children are present, such as coworking with childcare. In those cases the customer is the controller of any information about children collected through the platform and is responsible for obtaining the consents and meeting the obligations that apply. If you believe a child has provided personal information to us directly, contact privacy@hamletco.space and we will delete it.
16. Additional rights by region
New Zealand. If you are in New Zealand you have the right under the Privacy Act 2020 to access and correct your personal information and to complain to the Office of the Privacy Commissioner.
United Kingdom and European Union. Where the UK GDPR or EU GDPR applies you also have the right to erasure in certain circumstances, to restrict processing, to data portability, to object to processing (including for direct marketing), and not to be subject to solely automated decisions with legal or similarly significant effects except in limited cases. You can lodge a complaint with the Information Commissioner's Office (UK) or your local supervisory authority (EU). Where we process personal data on behalf of a customer, that customer is the controller and you should contact them first.
United States. If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and how we use and disclose it, to access it, to correct it, to delete it, to opt out of the sale or sharing of personal information (we do neither), and not to be discriminated against for exercising those rights. You may use an authorised agent to make a request. We do not use or disclose sensitive personal information for purposes other than those permitted by law.
17. Personal information we process for our customers
When customers use the Hamlet platform they upload and process personal information about their own members, guests, employees, contractors and end users. Our customer is the controller of that information; Hamlet is the processor and acts on the customer's instructions under the Services Agreement and Data Processing Addendum. We do not use that information for our own marketing or commercial purposes. If you are a member, guest or end user of a Hamlet customer and want to access, correct or delete your information, contact that customer first; we assist customers with such requests as our agreement and the law require. If you cannot resolve the matter with the customer, contact privacy@hamletco.space and we will help where appropriate.
18. Complaints
If you believe we have mishandled your personal information, contact privacy@hamletco.space with full details. We will acknowledge your complaint, investigate it and respond in writing with the outcome and any steps we will take. If you are not satisfied, you can complain to:
- Australia: Office of the Australian Information Commissioner, oaic.gov.au, 1300 363 992
- New Zealand: Office of the Privacy Commissioner, privacy.org.nz
- United Kingdom: Information Commissioner's Office, ico.org.uk
- European Union: your local data protection supervisory authority
- United States: your state attorney general or privacy agency, where applicable
19. Business transfers
If Hamlet or substantially all of its assets are acquired, merged, restructured or sold, personal information may be transferred to the acquiring party subject to this policy or a substantively similar one, and we will notify you where required by law.
20. Third-party sites
Our website and platform may link to third-party websites and services we do not operate. We are not responsible for their privacy practices; review their policies before providing personal information.
21. Changes to this policy
We may update this policy to reflect changes in our practices, services or legal obligations. For material changes we will update the date at the top, notify registered users by email or in the platform where appropriate, and seek consent for new uses where required.
22. Contact
Vicinia Pty Ltd trading as Hamlet, ABN 70 653 966 637, Sydney, Australia. Privacy: privacy@hamletco.space. General: hello@hamletco.space. Website: hamletco.space.
Plain-English summary (non-binding)
This summary is for convenience and does not replace the policy above.
- We're Vicinia Pty Ltd, trading as Hamlet, an Australian business software company with customers in Australia, New Zealand and the UK.
- We handle personal information two ways: what we collect about you directly (as a prospect, customer contact or visitor), and what our customers process about their members and guests through our platform. For the second kind, the customer is in charge and you should go to them first.
- We use personal information to run our business, operate and improve the platform, and talk to you. We don't sell it.
- Platform data lives in Australia for Australian and New Zealand customers and in the UK for UK customers. Some of our tools process data elsewhere, under contracts that protect it.
- We use cookies, and if you're in the UK or EU we ask before setting the non-essential ones.
- If there's a breach that matters, we tell the regulator, our customer and you, as the law requires.
- Automated features assist; people make the decisions that matter. We don't train general AI models on customer data.
- You can access, correct, opt out and complain. UK, EU, NZ and US residents have extra rights, listed in section 16.