Legal

Privacy policy

Last updated 28 September 2026

This policy explains how Matthew Xanthopoulos trading as MGX Systems (ABN 87 531 778 267), referred to here as “MGX”, “we” or “us”, handles personal information. It covers this website, the MGX client portal, and the pages we send you links to for quotes, agreements, payments and system access. We follow the Australian Privacy Principles in the Privacy Act 1988 (Cth).

What we collect

  • When you contact us through this website: your name, business name, email address, phone number (if you give one) and your message.
  • When you become a client: your contact details and those of the people you ask us to copy in, your business details, quotes, agreements, invoices, payment history, hours worked, support requests and the files you share with us.
  • When you sign an agreement online:the name you type or the signature you draw, the date and time, your IP address and your browser's description of itself (its user agent). We keep these as the record of your signature.
  • When you use the client portal: your email address, a securely hashed version of your password (never the password itself), when you last signed in, your notification choices, and a log of changes made in your account.
  • When you pay online or save a card:your card or bank details are entered into a form provided by Stripe and go straight to Stripe. We never see or store your full card number. We keep Stripe's reference for the payment method, the card brand, its last four digits and its expiry month and year, so we can show you which card is saved and remind you before it expires.
  • When you give us access to your systems: any logins you choose to share with us are encrypted before they are stored.
  • Technical information:your IP address is used briefly to limit repeated attempts at signing in, submitting forms and making payments. We also count page views on this website (see “Cookies and analytics” below).

How we use it

We use personal information to:

  • reply to your enquiry and arrange a chat;
  • prepare quotes and agreements, do the work, and send invoices and receipts;
  • take payments you make or have authorised, including automatic payments you turn on;
  • send you the emails that go with that work, such as invoices, payment reminders, receipts and portal notifications;
  • run the client portal and keep it secure; and
  • meet our legal, tax and record-keeping obligations.

We do not sell personal information, and we do not use it for advertising.

Who we share it with

We use a small number of service providers to run our systems. They handle personal information only to provide their service to us.

  • Supabase hosts our databases and stored files, in its Sydney region.
  • Vercelhosts this website, the client portal and our business systems, and provides the website's page-view counts.
  • Stripe processes card and bank payments and stores saved payment methods.
  • Resend sends our emails.
  • Upstash holds the short-lived counters we use to limit repeated attempts, which include IP addresses.

We may also disclose information where the law requires it, or to our professional advisers such as an accountant, who are bound by confidentiality.

Information sent overseas

Our database and stored files are kept in Australia. Vercel, Stripe, Resend and Upstash are based in the United States and may process information there or in other countries where they operate, under their own privacy and security commitments.

Cookies and analytics

This website does not set cookies. We count page views with Vercel Web Analytics, which does not use cookies and does not identify you personally. The client portal uses a cookie to keep you signed in, which is needed for it to work. Stripe's payment form sets its own cookies to prevent fraud.

How we keep it secure

Our systems are reached only over encrypted connections. Portal passwords are hashed, system logins you share with us are encrypted at rest, and access to client records is limited to MGX. No system is perfectly secure, and if a breach is likely to cause you serious harm we will tell you and act as the Notifiable Data Breaches scheme requires.

How long we keep it

We keep client and financial records for as long as we need them for the work and for as long as Australian tax law requires, which is generally five years. Enquiries that do not lead to work are kept so we can follow up, and we will delete one on request.

Accessing and correcting your information

You can ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing matt@mgxsystems.com.au. We will respond within 30 days. Much of it can also be viewed in the client portal.

Questions and complaints

If you have a question or a complaint about how we have handled your personal information, email matt@mgxsystems.com.au and we will reply within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We will update this page when our practices change. The date at the top shows when it last changed.