Who We Are
Setlrs.com is a global migration coordination platform operated in Australia under ABN 49 535 527 646, registered business name Setlrs.com (ASIC registered), based in Queensland, Australia.
For all privacy matters: shuklas@setlrs.com
We respond to all privacy enquiries within 30 days.
Our Global Privacy Stance
Global Compliance: Setlrs operates as a privacy-first application. We voluntarily adhere to GDPR-level standards for all users globally, regardless of their location, ensuring uniform protection of your personal information.
At Setlrs, we believe privacy is a fundamental human right. Your data helps you relocate. Nothing more. We respect the sanctity of your personal journey.
What We Collect
We collect only the data necessary to provide our service:
| Category | What specifically | How collected |
|---|---|---|
| Account | Name, email address, encrypted password | You provide at registration |
| Profile Data | Relocation preferences, family status, budget, origin country, destination country, visa type, migration timeline | You provide in onboarding |
| Task Progress | Migration checklist items and completed milestones | Generated through use |
| AI Interactions | Contextual data provided to agents to generate strategies | Collected through use |
| Device | Device type, operating system, browser type | Collected automatically |
| Communications | Emails you send us, support requests, community story submissions | You provide directly |
We do NOT collect: passport or government ID numbers · financial account details · health information · biometric data · precise geolocation without consent.
Why We Collect It
- Create and manage your Setlrs account
- Build and maintain your personalised migration roadmap
- Operate Setlrs intelligence agents to surface relevant information
- Improve the platform based on aggregate, anonymised usage patterns
- Respond to your support requests
- Send you updates relevant to your migration progress
- Comply with legal obligations where applicable
We do not use your information for any purpose not listed above without your explicit consent.
Lawful Basis for Processing
We process your data under the following legal bases (GDPR Article 6):
- Contract performance: Account management, roadmap generation, and core coordination features
- Legitimate interests: Platform improvement using anonymised data; security monitoring; fraud prevention
- Explicit consent: Automated decision-making via agents; cross-border data transfer to Firebase/Google servers. You provide consent during onboarding and may withdraw at any time by contacting shuklas@setlrs.com
- Legal obligation: Data retention required by law; breach reporting; response to lawful government requests
AI & Your Data
AI commitment: Your conversations with our AI agents are used only to generate your relocation plan. They are never used to train AI models or shared with third parties for marketing purposes.
AI-generated content within Setlrs is produced solely to assist you with your migration coordination. Your personal data and AI interactions are treated as confidential to your account.
Automated Processing — Intelligence Agents
Transparency disclosure: Required under GDPR Article 22 and the Australian Privacy Act (APP 1.7, effective December 2026).
Setlrs uses automated intelligence agents to process your profile data and generate personalised migration coordination outputs. The agents use your origin/destination countries, visa type, family structure, timeline, and task history to determine your migration task sequence, relevant pathways, and recommended connections.
These outputs are coordination information — not binding decisions. You retain full control and decide what to do with the information. No automated Setlrs output has legal force.
Your rights regarding automated processing
- Human review: Request human review of any agent output — email shuklas@setlrs.com
- Correction: Update your profile at any time, which updates all agent outputs
- Objection: Object to automated processing by closing your account
- Withdrawal: Withdraw consent for automated processing at any time (note: this prevents roadmap generation)
Affiliate Partner Data
When Setlrs recommends an affiliated service, only the following limited anonymous data may be shared:
- That a referral came from Setlrs (referral source identifier)
- Your destination country (to show relevant services)
- An anonymous referral identifier — not your name, email, or profile
We do NOT share your name, email address, or personal profile with any affiliate partner without your explicit consent. Affiliate partners operate their own privacy policies.
No Selling of Data
We never sell, rent, or trade your personal data to third parties. Your data is your property. We act only as a secure vault to help you manage your relocation journey.
We do not use personal information for advertising profiling. We do not share personal information with third parties except as described in this policy.
Your Rights — All Users
You have the right to export or permanently delete your account and all associated data at any time through the dashboard settings. Once deleted, data cannot be recovered.
All users globally also have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your account and all personal data
- Human review: Request human review of any automated agent output
Contact: shuklas@setlrs.com · We respond within 30 days.
Encryption & Security
Setlrs uses industry-standard encryption provided by Firebase and Google Cloud Infrastructure:
- All data in transit is encrypted via HTTPS / end-to-end TLS
- All data at rest is encrypted on Firebase / Google Cloud servers
- Passwords are stored encrypted — we cannot read your password
- Token-based authentication: secure, short-lived tokens manage session state, reducing the risk of unauthorised access
- Firebase security rules restrict access to your data to your account only
Found a security vulnerability? Please report it to shuklas@setlrs.com
Data Storage
Your data is stored on Google Firebase servers, operated by Google LLC, powered by Firebase and Google Cloud — world-class data centres with physical and digital security audits. Data may be stored in servers located outside Australia, including the United States and Singapore.
By using Setlrs and providing consent during onboarding, you consent to your personal information being transferred to and stored in these locations. We have entered into Google's Data Processing Agreement to ensure appropriate safeguards. For EU/UK users, transfers are covered by Google's Standard Contractual Clauses.
Retention & Deletion
We retain your personal information for as long as your account is active. When you delete your account:
- Your profile and migration roadmap data is deleted within 30 days
- Your account credentials are deleted immediately
- Anonymised usage data may be retained in aggregate form
- Once deleted, data cannot be recovered
Request deletion: shuklas@setlrs.com or via dashboard settings.
Cookie Policy
Simple, transparent, and respectful of your digital footprint. Setlrs uses essential cookies only:
setlrs_auth
Essential authentication token used to verify your identity across session requests. Does not contain personal data. Required for login to function.
We do NOT use: advertising cookies · analytics cookies that share your data · third-party tracking cookies · social media pixels · fingerprinting or cross-site tracking of any kind.
We do not share your browsing behaviour with any external marketing agencies. Your relocation journey is your business alone.
Children
Setlrs is not directed at children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child under 18 has created a Setlrs account, contact shuklas@setlrs.com and we will delete the account and associated data promptly.
Australian Users — Privacy Act 1988
This privacy policy complies with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
Your rights (APPs)
- Access your personal information
- Correct inaccurate information
- Complain about our handling of your data
- Opt out of direct marketing
Lodge a complaint
If unsatisfied with our response:
OAIC
oaic.gov.au
1300 363 992
EU and UK Users — GDPR / UK GDPR
GDPR and UK GDPR apply in full. Additional rights beyond Section 10:
Additional GDPR rights
- Data portability (Article 20) — export your data as JSON
- Restriction of processing (Article 18)
- Object to processing (Article 21)
- Rights re automated decisions (Article 22)
- Withdraw consent at any time
Lodge a complaint
EU: Your national supervisory authority (edpb.europa.eu)
UK: Information Commissioner's Office — ico.org.uk
To request a data export in machine-readable JSON format, email shuklas@setlrs.com. We respond within 30 days.
US Users — CCPA
California residents have the right to know what personal information is collected, request deletion, and opt out of sale of personal information. Setlrs does not sell personal information. Contact: shuklas@setlrs.com
Canadian and Indian Users
Canada (PIPEDA): You have the right to access and correct your personal information and withdraw consent. Contact: shuklas@setlrs.com
India (DPDPA 2023): You have the right to access, correct, and erase your personal data. Contact: shuklas@setlrs.com
Data Breaches
In the event of a data breach likely to result in serious harm, we will notify affected users as soon as practicable and the OAIC within 30 days (Notifiable Data Breaches scheme). For EU/UK users, we will notify relevant supervisory authorities within 72 hours where required by GDPR.
If you believe your account has been compromised, contact shuklas@setlrs.com immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before significant changes take effect. The current version is always at setlrs.com/privacy.
Contact
Privacy concerns? Reach out at shuklas@setlrs.com
Last updated 3 June 2026 · Complies with: Australian Privacy Act 1988 · GDPR (EU) · UK GDPR · CCPA · PIPEDA · DPDPA 2023