← All legal documents · Privacy Policy · Children's Privacy Notice

Balance — Australia Country Annex

Effective date: 28 June 2026 Last updated: 28 June 2026

Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Australian resident covered by this Annex; the individual responsible for compliance under Australian Privacy Principle ("APP") 1.2 read with s 13 of the Privacy Act 1988 (Cth) ("Privacy Act"); the designated contact point for the Office of the Australian Information Commissioner ("OAIC") and the Australian Communications and Media Authority ("ACMA") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Privacy Act 1988 (Cth) or to the Australian Privacy Principles (Schedule 1 to the Privacy Act) including the bringing into force of any provision of the Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA Act") that is not yet in force at the Effective date (in particular Schedule 1 Part 9 — the Children's Online Privacy Code — the OAIC has been directed to develop and register the Code within 24 months of Royal Assent on 10 December 2024, i.e., by 10 December 2026; and Schedule 2 — the statutory tort for serious invasions of privacy — in force from 10 June 2025); (b) any amendment to the Privacy Regulation 2013 (Cth); (c) the OAIC's registration of the Children's Online Privacy Code under Privacy Act s 26GC (in force from registration); (d) any amendment to the Online Safety Act 2021 (Cth) ("OSA") or to the Online Safety (Basic Online Safety Expectations) Determination 2022 (Cth) ("BOSE Determination"); (e) the bringing into force of any provision of the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) — the social-media-minimum-age framework that takes effect from 10 December 2025 (12 months after Royal Assent on 10 December 2024); (f) any amendment to the Criminal Code Act 1995 (Cth), in particular Division 273 (offences involving child abuse material outside Australia), Division 273A (possession of child-like sex dolls), Division 471 (postal services offences), Division 474 (telecommunications offences — including ss 474.19–474.27A, child abuse material, child-procurement, and grooming offences) and Part 10.6 (telecommunications offences); (g) any amendment to the Crimes Act 1900 (NSW), Crimes Act 1900 (ACT), Crimes Act 1958 (Vic), Criminal Code Act 1899 (Qld), Criminal Code Act 1913 (WA), Criminal Law Consolidation Act 1935 (SA), Criminal Code Act 1924 (Tas), Criminal Code Act 1983 (NT); (h) any amendment to the Spam Act 2003 (Cth); (i) any amendment to the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) ("ACL") or to any fair-trading statute of any State or Territory; (j) any determination of the OAIC made under Privacy Act s 52 (including a determination on a representative complaint under s 38), any Direction of the OAIC, any Information Commissioner Decision, any Privacy Guideline, any registered APP Code under Privacy Act Part IIIB, or any binding determination by the Federal Court of Australia or the Federal Circuit and Family Court of Australia under Privacy Act Division 5; (k) any decision of the High Court of Australia that materially affects the constitutional implied freedom of political communication or the Australian Human Rights Commission Act 1986 (Cth) reading of Article 17 of the International Covenant on Civil and Political Rights ("ICCPR") as applied to privacy; (l) any determination of the eSafety Commissioner under the Online Safety Act 2021 (Cth), and any amendment to a registered industry code under OSA Part 9 (industry codes and standards) or industry standard under OSA Part 10; (m) any amendment to a sub-processor's Australian data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Commonwealth or State or Territory regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.

This Annex discharges the country-annex obligations referenced in:

This Annex is the canonical Australia-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Australian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Australian resident a right that this Annex does not, the global Policy governs. The two are read together.

This Annex is drafted in English (the de facto national language of Australia; no constitutional or statutory official-language designation exists at the Commonwealth level — see Sue v Hill [1999] HCA 30 and the Constitution of Australia generally). No translation is required at the Effective date.


1. Scope and applicability

This Annex applies to every Balance user (parent or kid) whose State or Territory of residence is one of the six States or two internal Territories of the Commonwealth of Australia: New South Wales (NSW), Victoria (VIC), Queensland (QLD), Western Australia (WA), South Australia (SA), Tasmania (TAS), Australian Capital Territory (ACT), and Northern Territory (NT) — or the Jervis Bay Territory. The external Territories (Norfolk Island, Christmas Island, Cocos (Keeling) Islands, Heard Island and McDonald Islands, Coral Sea Islands, Ashmore and Cartier Islands, Australian Antarctic Territory) are classified as Cat-3 (excluded markets) per the full country classification table § 2 carve-out (e) — small or unpopulated; the Privacy Act nonetheless applies to any resident of those territories who has the Commonwealth as their administering authority, and this Annex's protections extend to them on a most-protective reading.

We determine country and State/Territory of residence at install/sign-up time by (a) the country and State/Territory the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.

Where any of the three signals identifies Australia as the country of residence, this Annex applies, even if the other signals are non-Australian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.

The Privacy Act has extraterritorial effect under s 5B: it applies to "an act done, or practice engaged in, outside Australia and the external Territories by an organisation" where the organisation "has an Australian link" — defined to include carrying on business in Australia and collecting or holding personal information in Australia. The Federal Court of Australia in Optus v ACMA (No 2) [2018] FCAFC 36 and the OAIC's published Australian Privacy Principles guidelines Chapter B confirm that targeting Australian-resident consumers from outside Australia satisfies the "carrying on business in Australia" limb. Balance squarely targets Australian residents through Google Play Australia, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Australian-resident parents and kids; the Privacy Act applies in full.

The Privacy Act applies to Balance as a "private sector organisation" (Privacy Act s 6C) regardless of whether Balance's annual turnover would meet the AU$3 million threshold under the small business operator carve-out at Privacy Act s 6D, because Balance's core activity is the processing of personal information of children, which engages the carve-out exception at Privacy Act s 6D(4)(b) (an organisation that provides a service that involves the collection or disclosure of personal information about a child to another person other than the child for a benefit, service, or advantage). Balance also provides a health service in the secondary sense of supporting a parent's care of a child but does not collect health information of any kind from any Australian resident, so the health service provider carve-out exception at s 6D(4)(a) is engaged only in the alternative.

State and Territory privacy laws (e.g., Privacy and Personal Information Protection Act 1998 (NSW), Privacy and Data Protection Act 2014 (Vic), Information Privacy Act 2009 (Qld), Personal Information Protection Act 2004 (Tas), Information Privacy Act 2014 (ACT), Information Act 2002 (NT)) apply principally to the public sector of the respective State or Territory and to State / Territory Government contracted service providers; they do not apply to Balance as a private-sector organisation. The Commonwealth Privacy Act is the controlling framework for Balance's Australian-resident processing in every State and Territory.


2. Statutory framework — what applies

The Australian personal-information-protection regime is a Commonwealth-dominant framework with overlay statutes for online-safety, spam, criminal-content, consumer-protection, and human-rights. The Privacy Act 1988 (Cth), incorporating the 13 Australian Privacy Principles at Schedule 1 (in force from 12 March 2014, the consolidating amendment delivered by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth)), is the principal statute. The Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA Act"), which received Royal Assent on 10 December 2024, is the most significant amendment to the Privacy Act in over a decade and is phased into force as set out in § 2.1 below. The Online Safety Act 2021 (Cth) is the principal online-safety statute and is administered by the eSafety Commissioner. The Criminal Code Act 1995 (Cth) Division 474 contains the federal CSAM and online-luring offences; State and Territory Crimes Acts / Criminal Codes contain parallel offences. The Spam Act 2003 (Cth) governs commercial electronic messages. The Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) governs the subscription flow.

2.1 POLA Act 2024 — phased commencement

The POLA Act amends the Privacy Act in three substantive tranches. The Effective date is in the middle of the commencement schedule. The provisions in force at the Effective date are:

2.2 Instrument table

Instrument Short cite What it does Balance's posture
Constitution of Australia Commonwealth of Australia Constitution Act 1900 (Imp) — s 51(v) (postal, telegraphic, telephonic, and other like services) + s 51(xx) (foreign, trading, financial corporations) + s 51(xxix) (external affairs) + implied freedom of political communication as recognised in Lange v Australian Broadcasting Corporation (1997) 189 CLR 520 + Comcare v Banerji [2019] HCA 23 The constitutional anchor for the Commonwealth's legislative competence over privacy (via s 51(v), s 51(xx) and s 51(xxix) — external affairs power activated by Australia's ratification of the ICCPR on 13 August 1980). The Constitution does not contain an explicit privacy right; the privacy right is statutory (Privacy Act) supplemented by the common-law and equitable causes of action and (from 10 June 2025) the statutory tort for serious invasions of privacy. Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below.
Australian Human Rights Commission Act 1986 (Cth) AHRC Act Establishes the Australian Human Rights Commission (AHRC) and gives effect to Australia's obligations under the ICCPR and other treaties. Schedule 2 to the AHRC Act incorporates the ICCPR, including Art 17 (no one shall be subjected to arbitrary or unlawful interference with their privacy, family, home, or correspondence). The AHRC has a complaints jurisdiction in respect of human-rights matters where the Commonwealth is involved (s 11(1)(f) AHRC Act). The OAIC remains the principal forum for Privacy-Act-grounded complaints.
Privacy Act 1988 (Cth) Privacy Act — including the 13 Australian Privacy Principles ("APPs") at Schedule 1, in force from 12 March 2014: APP 1 (open and transparent management of personal information — privacy policy + APP 1.4(b) cross-border-disclosure transparency); APP 2 (anonymity and pseudonymity); APP 3 (collection of solicited personal information); APP 4 (dealing with unsolicited personal information); APP 5 (notification of the collection of personal information — collection notice); APP 6 (use or disclosure of personal information — primary and secondary purpose); APP 7 (direct marketing — opt-out mechanism); APP 8 (cross-border disclosure of personal information — accountability + 5 carve-outs); APP 9 (adoption, use, or disclosure of government related identifiers); APP 10 (quality of personal information); APP 11 (security of personal information — reasonable steps to protect from misuse, interference, loss, unauthorised access, modification, disclosure); APP 12 (access to personal information — 30 calendar days); APP 13 (correction of personal information — reasonable steps within 30 calendar days). Substantive sections: s 5B (extraterritorial application — Australian link); s 6 (definitions — personal information, sensitive information, health information); s 6C (private-sector organisation); s 6D (small business operator carve-out + s 6D(4)(b) collection-or-disclosure-of-children's-information exception that applies to Balance); s 13G (serious or repeated interference — civil penalty); s 13H (minor interference — civil penalty); s 16A (permitted general situations); s 16B (permitted health situations); Part IIIC — Notifiable Data Breaches scheme (ss 26WE through 26WT, in force since 22 February 2018); s 26WK (eligible data breach assessment — 30 days); s 26WL (notification to OAIC); s 26WM (notification to affected individuals); Part IV — Privacy Codes (ss 26B through 26F + Part IIIB ss 26C through 26R); Part V — Functions of the Commissioner; Part VI — Investigations (s 36 complaints, s 40 own-motion investigations, s 41 declined investigations, s 52 determinations); s 80W (Federal Court applications); POLA Act amendments (in force as set out in § 2.1 above). The principal Commonwealth statute. Applies in full to Balance as a private-sector organisation engaged in the collection or disclosure of personal information of children (Privacy Act s 6D(4)(b) exception to the small business operator carve-out). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below.
Privacy Regulation 2013 (Cth) The principal regulation under the Privacy Act. Operationalises specified Privacy Act sections, including the prescribed circumstances under APP 6.2(c)/(d), the prescribed amount under s 6D(1) (turnover threshold — currently AU$3 million), and the prescribed circumstances for Part IIIC notification. Applies in full as the operational layer.
Privacy (Notifiable Data Breaches) Determination 2018 (Cth) Privacy Act Part IIIC determination Operationalises Part IIIC. Applies in full.
OAIC Guidelines and Determinations The OAIC's Australian Privacy Principles guidelines (most recent consolidated edition published progressively from 2014 through 2024) — Chapter B (extraterritorial application), Chapter 1 (APP 1), Chapter 5 (APP 5 collection notice), Chapter 6 (APP 6 use/disclosure), Chapter 7 (APP 7 direct marketing), Chapter 8 (APP 8 cross-border disclosure), Chapter 11 (APP 11 security), Chapter 12 (APP 12 access), Chapter 13 (APP 13 correction); the Notifiable Data Breaches scheme — Guide to the NDB scheme (most recent edition); the OAIC Privacy Impact Assessment Guide; the OAIC Privacy management framework — enabling compliance and encouraging good practice; the OAIC Guide to securing personal information; the OAIC's Guide to the privacy of children and young people; the body of OAIC determinations and own-motion findings published at https://www.oaic.gov.au/privacy/privacy-decisions/. Sets the OAIC's binding interpretive layer on the Privacy Act + APPs. Applies. Balance's posture is operationalised consistently with the OAIC's published guidance — in particular the Guide to the privacy of children and young people.
Online Safety Act 2021 (Cth) OSA — in force 23 January 2022, replacing the Enhancing Online Safety Act 2015 (Cth). Establishes the eSafety Commissioner (s 26) with functions over: Part 5 (adult cyber-abuse); Part 6 (cyber-bullying material targeted at an Australian child); Part 7 (non-consensual intimate images); Part 8 (material that depicts abhorrent violent conduct); Part 9 (industry codes and standards); Part 10 (industry standards); Part 11 (Online Content Scheme — class 1 and class 2 material); the Basic Online Safety Expectations (BOSE) made by determination under s 45 (in force per the Online Safety (Basic Online Safety Expectations) Determination 2022 (Cth) since 23 January 2022). The principal online-safety statute. Applies to "social media services", "relevant electronic services", "designated internet services", "internet carriage services", and "hosting services" as defined in OSA Part 2. Balance is not a "social media service" (OSA s 13 — Balance has no functionality of enabling end-users to publish material on the service for distribution to other end-users), not a "relevant electronic service" (OSA s 13A — Balance is not an email, messaging, or VoIP service), not a "designated internet service" (OSA s 14 — Balance is not an Internet service that allows end-users to access material using a carriage service) in the sense engaged by Parts 5–8 and the BOSE Determination's broad-content-moderation expectations, and not a "hosting service" (OSA s 17 — Balance does not host third-party content for the public); Balance is best characterised as a private parental-control client that does not provide a content-distribution surface to the public. The OSA's content-removal-notice regime (Parts 5–8) does not engage Balance's architecture (which contains no public-distribution surface). Applies to the extent of Balance's voluntary best-effort honor of the substantive child-safety obligations of the BOSE Determination — in particular the expectation that "the provider of the service will take reasonable steps to ensure that the service is safe to use" (BOSE s 6) and the expectation that the provider of a service "will take reasonable steps to minimise the extent to which the material on the service is unlawful or harmful" (BOSE s 14). Cross-reference: Child Safety Standards § 5 + § 6.
Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) The 2024 amendment to the OSA, introducing a minimum age of 16 for use of "age-restricted social media platforms" (defined narrowly to mean a social media service of which the sole or significant purpose is to enable online social interaction between two or more end-users, where the service allows end-users to link to or interact with another end-user, post material, generate a profile, and where the service is not exempted), in force from 10 December 2025. Imposes "reasonable steps" obligations on providers of age-restricted social media platforms. Civil penalties up to AU$49.5 million per contravention. Balance is not an "age-restricted social media platform" within the meaning of the 2024 amendment: Balance does not enable online social interaction between two or more end-users in the public sense, does not allow end-users to link to or interact with another end-user outside the parent-kid pairing of a single household, does not allow end-users to post material to the public, and is not a service of which the sole or significant purpose is to enable online social interaction. The 2024 amendment therefore does not impose a direct statutory obligation on Balance. Applies as a context-setting fact (the 2024 amendment confirms the Commonwealth's most-protective-of-children online-safety policy direction).
Criminal Code Act 1995 (Cth) Criminal Code — Division 273 (offences involving child abuse material outside Australia); Division 273A (possession of child-like sex dolls); Division 471 (postal-services offences); Division 474 (telecommunications offences — including ss 474.19 (using a carriage service for child abuse material — production, possession, controlling access to, soliciting, transmitting), 474.20 (possession of child abuse material in Australia obtained or accessed using a carriage service), 474.22 (using a carriage service for child abuse material outside Australia), 474.23 (possession etc of child-like sex doll obtained or accessed using a carriage service), 474.25A (using a carriage service for sexual activity with a person under 16), 474.25B (using a carriage service to procure a person under 16), 474.25C (using a carriage service to "groom" a person under 16), 474.27 (using a carriage service to procure persons under 16 years of age), 474.27A (using a carriage service to transmit indecent communication to a person under 16)) The principal Commonwealth criminal statute for CSAE, online-luring, and grooming offences. Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below.
State and Territory Crimes Acts / Criminal Codes Crimes Act 1900 (NSW); Crimes Act 1958 (Vic); Criminal Code Act 1899 (Qld); Criminal Code Act 1913 (WA); Criminal Law Consolidation Act 1935 (SA); Criminal Code Act 1924 (Tas); Crimes Act 1900 (ACT); Criminal Code Act 1983 (NT). Each contains State / Territory-specific CSAE, grooming, and indecent-image offences. The State / Territory criminal regimes layer parallel to the Commonwealth Criminal Code. Applies. State / Territory police forces enforce within their jurisdiction; the AFP enforces the Commonwealth offences.
Spam Act 2003 (Cth) Spam Act — regulates the sending of commercial electronic messages ("CEMs") to or from a telecommunications-related computer in Australia. Requires consent (express or inferred) at s 16, identification of the sender at s 17, and an unsubscribe facility at s 18. Enforced by the Australian Communications and Media Authority ("ACMA"). Regulates commercial electronic messages sent to or from Australia. Includes civil penalties under Part 4 administered by ACMA (up to AU$2.22 million per day for repeated breach by a body corporate). Applies. Balance does not send commercial electronic messages to Australian residents; the only email Balance sends is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). Treatment in § 12.3 below.
Do Not Call Register Act 2006 (Cth) Establishes the Australian Do Not Call Register. Applies to telemarketing calls and faxes — not to email or push notifications. Not engaged. Balance does not place telemarketing calls.
Telecommunications (Interception and Access) Act 1979 (Cth) TIA Act — governs lawful interception of telecommunications by Commonwealth and State / Territory law-enforcement and security agencies. The lawful-access framework for telecommunications. Applies to the lawful-access response posture in § 13 below.
Telecommunications Act 1997 (Cth) Telecommunications Act — Part 14 + Part 15 industry assistance regime + s 313 industry-assistance obligations. The lawful-access framework for telecommunications service providers. Balance is not a "carrier" or "carriage service provider" within the meaning of the Telecommunications Act, so Part 14 / Part 15 / s 313 obligations do not engage Balance directly. Applies as a context-setting fact.
Australian Consumer Law (ACL) Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth) — s 18 (misleading or deceptive conduct); s 23 (unfair contract terms — standard form consumer contracts and small business contracts); s 29 (false or misleading representations about goods or services); s 36 (misleading representations about future matters); s 49 (referral selling — prohibition); ss 60–62 (consumer guarantees as to services — due care and skill, fit for any disclosed purpose, reasonable time for supply); ss 64–64A (limits on liability for failure to comply with consumer guarantees); ss 69–95 (unsolicited consumer agreements — 10-business-day cooling-off period for in-person solicitations); s 232 (injunctions); s 236 (compensatory damages); s 237 (compensatory orders for non-party consumers); s 246 (non-punitive orders); s 247 (adverse publicity orders); civil penalties up to the greater of AU$50 million / 3x benefit / 30% of adjusted turnover (consistent with the 2022 Treasury Laws Amendment (More Competition, Better Prices) Act 2022 (Cth)). Enforced by the Australian Competition and Consumer Commission ("ACCC") + State / Territory Fair Trading agencies. The principal consumer-protection statute. Applies in full. Treatment in § 16 below.
State / Territory Fair Trading Acts NSW Fair Trading Act 1987; Vic Fair Trading Act 1999 + Australian Consumer Law and Fair Trading Act 2012; Qld Fair Trading Act 1989; WA Fair Trading Act 2010; SA Fair Trading Act 1987; Tas Australian Consumer Law (Tasmania) Act 2010; ACT Fair Trading (Australian Consumer Law) Act 1992; NT Consumer Affairs and Fair Trading Act 1990. Each applies the ACL within the State / Territory. Each State / Territory Fair Trading agency enforces the ACL within the State / Territory + a small additional layer of State / Territory consumer-protection rules. Applies. Treatment in § 16 below.
EU adequacy None. Australia does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. Australia is not listed in the European Commission's Adequacy decisions register. EU/EEA → Australia transfers are governed by EU SCCs + a Transfer Impact Assessment. Applies as a context-setting fact. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to Australia only under EU SCCs + supplementary measures. The absence of EU adequacy does not affect Balance's posture because Balance has no Australian data residency (the backend is in the US — see § 9 below).
Convention 108 Not applicable. Australia is not a party to the Council of Europe Convention 108 or Convention 108+. Applies as a context-setting fact. The Council-of-Europe layer is not engaged for the Australian-resident flows.

(Any prospective Commonwealth or State or Territory regulation governing automated processing, algorithmic decisions, or related techniques — including the proposed automated decision-making transparency requirements that may be developed by the OAIC under the POLA Act 2024 framework, any future Australian AI Safety Standard (the Department of Industry, Science and Resources' voluntary AI Safety Standard published 5 September 2024 is voluntary and does not impose a binding statutory obligation), any future AI Act before the Commonwealth Parliament, and any State or Territory automated-decision regulation, and any OAIC or ACMA guidance in that area — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Australian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)


3. Supervisory authorities

3.1 OAIC — Office of the Australian Information Commissioner

The principal supervisory authority is the Office of the Australian Information Commissioner ("OAIC"), established under the Australian Information Commissioner Act 2010 (Cth). The OAIC is led by the Australian Information Commissioner + the Privacy Commissioner + (from December 2024) the Freedom of Information Commissioner — three separate statutory officers within the OAIC.

Field Value
Name Office of the Australian Information Commissioner (OAIC)
Headquarters GPO Box 5288, Sydney NSW 2001 + Level 3, 175 Pitt Street, Sydney NSW 2000
Website https://www.oaic.gov.au/
Complaint channel OAIC online complaint form at https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us, by mail to GPO Box 5288, Sydney NSW 2001, or by phone at 1300 363 992 (cost of a local call within Australia)
Breach-notification channel OAIC online Notifiable Data Breach form per Privacy Act Part IIIC at https://www.oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach
Australian Information Commissioner At the Effective date — Elizabeth Tydd (or successor as published at the OAIC website)
Privacy Commissioner At the Effective date — Carly Kind (or successor as published at the OAIC website)

The OAIC is the first-line forum for any Privacy-Act-grounded complaint from any Australian resident. An Australian resident may petition the OAIC without first raising the matter with Balance, provided the resident has first attempted to resolve the matter directly with the respondent organisation (Privacy Act s 40(1A)). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the individual responsible for compliance under APP 1.2 + s 13 of the Privacy Act) and we respond within the APP timelines (see § 6 below).

An Australian resident may also pursue private remedies against Balance via the statutory tort for serious invasions of privacy (in force from 10 June 2025 — see § 2.1 above); via the direct right of action to the Federal Court of Australia or the Federal Circuit and Family Court of Australia (in force from 10 December 2025); via the Federal Court of Australia under Privacy Act s 80W after an OAIC determination; via the ordinary State / Territory courts; or via the criminal route under the Commonwealth Criminal Code Act 1995 or the State / Territory Crimes Acts where criminal offences are engaged.

3.2 eSafety Commissioner

The eSafety Commissioner is established under Online Safety Act 2021 s 26 (succeeding the Children's eSafety Commissioner of 2015). The eSafety Commissioner administers the OSA Parts 5–8 (adult cyber-abuse, child cyber-bullying, non-consensual intimate images, abhorrent violent material), the BOSE Determination, the Online Content Scheme (Part 11), and the registered industry codes and standards (Parts 9–10).

Field Value
Name eSafety Commissioner
Headquarters PO Box Q500, Queen Victoria Building NSW 1230 + Level 16, 207 Kent Street, Sydney NSW 2000
Website https://www.esafety.gov.au/
Complaint channel eSafety online reporting forms at https://www.esafety.gov.au/report — separate forms for adult cyber-abuse, child cyber-bullying, non-consensual intimate images, illegal and restricted content
Phone (02) 9219 5000
eSafety Commissioner At the Effective date — Julie Inman Grant (or successor as published at the eSafety website)

3.3 ACMA — Australian Communications and Media Authority

The Australian Communications and Media Authority ("ACMA") administers the Spam Act 2003 (Cth), the Telecommunications Act 1997 (Cth), and certain provisions of the OSA in cooperation with the eSafety Commissioner.

Field Value
Name Australian Communications and Media Authority (ACMA)
Headquarters PO Box Q500, Queen Victoria Building NSW 1230 + Level 16, 207 Kent Street, Sydney NSW 2000
Website https://www.acma.gov.au/
Spam complaint channel ACMA online Spam complaint at https://www.acma.gov.au/forms/lodge-spam-complaint; phone 1800 226 003

3.4 ACCC — Australian Competition and Consumer Commission

The Australian Competition and Consumer Commission ("ACCC") administers the ACL.

Field Value
Name Australian Competition and Consumer Commission (ACCC)
Headquarters 23 Marcus Clarke Street, Canberra ACT 2600 + GPO Box 3131, Canberra ACT 2601
Website https://www.accc.gov.au/
Complaint channel ACCC online complaint at https://www.accc.gov.au/consumers/complaints-and-problems/make-a-consumer-complaint; phone 1300 302 502
State / Territory Fair Trading agencies NSW Fair Trading (https://www.fairtrading.nsw.gov.au/); Consumer Affairs Victoria (https://www.consumer.vic.gov.au/); Queensland Office of Fair Trading (https://www.qld.gov.au/law/fair-trading/); Consumer Protection WA (https://www.commerce.wa.gov.au/consumer-protection); Consumer and Business Services SA (https://www.cbs.sa.gov.au/); Consumer Affairs Tasmania (https://www.cbos.tas.gov.au/); ACT Office of Regulatory Services (https://www.accesscanberra.act.gov.au/); NT Consumer Affairs (https://consumeraffairs.nt.gov.au/)

3.5 The Privacy Officer / individual responsible for compliance

APP 1.2 + Privacy Act s 13 read with the OAIC's APP Guidelines Chapter 1 require an organisation to take reasonable steps to implement practices, procedures, and systems that will ensure compliance with the APPs — including the designation of a contact point for the organisation's privacy obligations.

The Balance Privacy Officer is:

The Privacy Officer's contact details are published in this Annex and in the global Privacy Policy (Privacy Policy § 1). The Privacy Officer is the contact point for the OAIC, the eSafety Commissioner, the ACMA, and the ACCC on any regulatory matter; and for data subjects on rights-exercise matters.


4. Lawful bases — APP 3 + APP 6

The Privacy Act does not use the GDPR "lawful bases" taxonomy. Instead:

Balance processes personal information of Australian residents under the following primary-purpose mapping:

Processing purpose APP basis Cross-reference
Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) APP 3.1 (reasonably necessary for the entity's function of providing the parental-control service) + APP 3.6 (collection from the individual — the parent — to whom the information relates) + APP 3.5 (lawful and fair means) + APP 6.1 (use for the primary purpose) H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex
Process the kid's personal information APP 3.1 + APP 3.6 (collection from the kid + collection from the parent, both with the parent's consent on behalf of the kid + OAIC Guide to the privacy of children and young people on capacity test) + s 16A permitted general situation (collection necessary to lessen or prevent a serious threat to the life, health, or safety of any individual — applies only in safeguarding edge cases) § 7 of this Annex; our Data Protection Impact Assessment § 6
Deliver operational alerts APP 6.1 (primary purpose) H1 § 4; H7 PA-09; M3
Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access APP 11 (security duty) + APP 6.2(b) (use or disclosure for a secondary purpose reasonably necessary for one or more enforcement-related activities) + s 16A (permitted general situation) H7 PA-15; § 13 below
Comply with legal, regulatory, and supervisory obligations APP 6.2(b) (required or authorised by or under an Australian law or a court / tribunal order) § 13 below; M1; § 14 below
Process Verifiable Parental Consent for the kid's data APP 3.1 + APP 3.6 — collection of the parent's information for the primary purpose of obtaining VPC § 7 of this Annex; A-US § 5
Process the parent's billing / subscription data APP 3.1 — necessary for the entity's function of providing the subscription service; ACL overlay in § 16 below H4; § 16 below

Balance does not collect sensitive information (Privacy Act s 6) from any Australian resident: no health information, no biometric information, no information about racial or ethnic origin, no political opinions, no religious beliefs, no sexual orientation or practices, no criminal record, no membership of a professional or trade association, no membership of a trade union, no philosophical beliefs. The APP 3.3 sensitive-information consent regime is therefore not engaged.

Balance also does not collect government related identifiers (Privacy Act s 6) from any Australian resident: no Tax File Number, no Medicare number, no driver's licence number, no passport number, no Centrelink customer reference number, no Department of Veterans' Affairs file number, no individual healthcare identifier. The APP 9 government-related-identifiers regime is therefore not engaged.


5. Children's rights overlay

Australia does not have a federal children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The POLA Act 2024 directs the OAIC to develop and register the Children's Online Privacy Code under Privacy Act s 26GC within 24 months of Royal Assent (by 10 December 2026). At the Effective date, the Code has not yet been registered; the § 18 versioning protocol provides for an immediate off-cycle update of this section on the Code's registration.

The children's regime at the Effective date is built up from (i) Privacy Act + APPs read with the OAIC's Guide to the privacy of children and young people; (ii) the capacity test at common law (whether a child has sufficient understanding and intelligence to enable them to understand fully what is proposed — the Gillick competence test as adopted in Australia in Secretary, Department of Health and Community Services v JWB and SMB (Marion's Case) (1992) 175 CLR 218); (iii) State and Territory child-welfare statutes setting cooperation and mandatory-reporting obligations (e.g., Children and Young Persons (Care and Protection) Act 1998 (NSW), Children, Youth and Families Act 2005 (Vic), Child Protection Act 1999 (Qld), Children and Community Services Act 2004 (WA), Children and Young People (Safety) Act 2017 (SA), Children, Young Persons and Their Families Act 1997 (Tas), Children and Young People Act 2008 (ACT), Care and Protection of Children Act 2007 (NT)); (iv) the UN Convention on the Rights of the Child (Australia ratified 17 December 1990).

5.1 Definitions

For the purposes of this Annex:

Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Australian kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Australian residents itemises the categories of personal information being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the Privacy Act.

Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of APP 3 + APP 5 + APP 6 + the OAIC Guide + Marion's Case.

5.4 No advertising directed at children

Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the OAIC's interpretive position that Privacy Act APP 7 direct-marketing restrictions apply with particular force where the recipient is a child; (ii) the Australian Association of National Advertisers Code for Advertising and Marketing Communications to Children (the AANA Children's Code); (iii) the BOSE Determination s 8 expectations regarding the impact of services on the safety of children. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.

5.5 Cooperation routes

The principal Australian child-protection bodies are: (i) the Australian Federal Police — Australian Centre to Counter Child Exploitation ("ACCCE") — the federal law-enforcement node for online CSAE; (ii) the eSafety Commissioner — for cyber-bullying, image-based abuse, and online safety; (iii) the State and Territory police forces — NSW Police, Victoria Police, Queensland Police, Western Australia Police, South Australia Police, Tasmania Police, Northern Territory Police, ACT Policing; (iv) the State and Territory child-protection agencies — Department of Communities and Justice (NSW), Department of Families, Fairness and Housing (Vic), Department of Child Safety, Seniors and Disability Services (Qld), Department of Communities (WA), Department for Child Protection (SA), Department for Education, Children and Young People (Tas), Community Services Directorate (ACT), Department of Territory Families, Housing and Communities (NT); (v) Kids Helpline — Australia's national 24-hour confidential helpline for young people aged 5–25; (vi) National Office of Child Safety within the Attorney-General's Department. Balance cooperates with each on incidents involving Australian kids — see § 14 below.


6. Privacy Act + APP rights catalogue

6.1 The rights catalogue

An Australian resident has the following rights under the Privacy Act + APPs as in force at the Effective date. The article-list mirrors the APPs as in force at the Effective date (incorporating the POLA Act 2024 amendments in force).

6.2 Timeline

Where the request is manifestly unfounded or excessive, Balance may charge a reasonable fee based on administrative cost (APP 12.8 — Balance does not charge for the application itself; only for access, and only at reasonable cost) or refuse to act on the request, telling the data subject the reason and informing them of the right to complain to the OAIC.

6.3 Identity verification

Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (APP 12.6). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.

6.4 No cost

The exercise of the APP 12 access right is free of charge for the application (APP 12.7); Balance may charge for actually giving access only if the charge is not excessive (APP 12.8). Balance does not charge for access in practice.

6.5 Language

A request may be submitted in English. The OAIC accepts complaints in English.


7. Children's data — APP 3 + APP 5 + APP 6 + OAIC Guide to the privacy of children and young people

Balance processes personal information of Australian kids under the following layered framework:

For Balance:

A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.


8. International data transfers from Australia — APP 8

The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Australian resident's personal information leaves Australia at the point of being uploaded to the Balance backend.

8.1 The Australia-to-US transfer mechanism — APP 8

APP 8 governs the disclosure of personal information by an APP entity to an overseas recipient. The general rule (APP 8.1): before an APP entity discloses personal information about an individual to a person (the overseas recipient) who is not in Australia or an external Territory and who is not the entity, the entity must take reasonable steps to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information. The five carve-outs to APP 8.1 are at APP 8.2 (the entity reasonably believes the recipient is subject to a law / binding scheme that has the effect of protecting the information in a way that, overall, is at least substantially similar to the APPs, and the individual is able to access mechanisms to enforce it; or the individual consents to the disclosure after being expressly informed that APP 8.1 will not apply; or the disclosure is required or authorised by an Australian law; or the disclosure is required by a court / tribunal order; or one of the permitted general situations (s 16A) applies).

In addition, Privacy Act s 16C sets the "accountability" rule: where an APP entity has discloses personal information about an individual to an overseas recipient and the recipient handles the information in a way that would breach the APPs (had APP 8 applied), the entity is taken to have done the act or engaged in the practice that breached the APPs — i.e., the disclosing entity remains liable for the recipient's mishandling.

Balance relies on the following stack to satisfy APP 8 + s 16C for the Australia → US transfer:

8.2 APP 8 transparency overlay — APP 1.4(b) and APP 5

The POLA Act 2024 amendment to APP 1.4 (in force from 10 December 2024) strengthened the transparency obligations on cross-border disclosures: the privacy policy must now state the countries in which overseas recipients are likely to be located. The Balance global Privacy Policy and this Annex satisfy that obligation by naming the United States as the destination country (§ 9 below); the in-app collection notice under APP 5 names the United States and the categories of recipients.

8.3 The Australia-to-KZ axis (controller administrative access)

The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on any Australian "substantially similar" list (because Australia does not maintain such a list under APP 8.2(a) at the Effective date), the Australia-KZ axis is covered by the parent's express consent (APP 8.2(b)) + written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.


9. Data residency for Australian residents

Question Answer
Where is the backend hosted? United States. Emergent Labs Inc. (Delaware) on US infrastructure.
Where is the MongoDB database located? United States.
Where is the proof-media storage located? United States — Google Cloud Storage us multi-region.
Where are push notifications dispatched from? United States — Firebase Cloud Messaging.
Is any Australian resident's personal information held in Australia? No. Every Australian resident's personal information is held in the United States. The APP 8 transfer mechanism in § 8 above is the legal basis for the transfer.
Where is the controller? Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements.
Is there an Australian establishment? No. Balance has no permanent establishment in Australia. The Privacy Act's extraterritorial reach (s 5B + the Australian link test) is the basis for Balance's Australian-Privacy-Act compliance.
Where is the supervisory authority? Australia — OAIC + eSafety Commissioner + ACMA + ACCC.

The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Australia does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the My Health Records Act 2012 (Cth) s 77 — health-information data-localisation; not applicable to Balance because Balance does not collect health information) and certain national-security regimes (Security of Critical Infrastructure Act 2018 (Cth); not applicable to Balance because Balance is not a critical infrastructure asset).


10. Sub-processors touching Australian-resident data

Sub-processor Role Location of processing Australian transfer paperwork
Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer Hosts the FastAPI backend + MongoDB cluster United States Parent's express consent (APP 8.2(b)) + written processor agreement with APP-aligned safeguards (APP 8.1 reasonable steps) on file per our international-transfer pack § 6; E2EE supplementary measure for proof media.
Google LLC — Google Cloud Storage (USA) Stores end-to-end-encrypted proof-media ciphertext United States (us multi-region) Parent's express consent + written processor agreement (Google Cloud Data Processing Addendum) with APP-aligned safeguards; ciphertext-only handling.
Google LLC via Google Cloud (USA) Periodic (daily) backups of our operational database United States (us multi-region) Parent's express consent + written processor agreement (Google Cloud Data Processing Addendum) with APP-aligned safeguards; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted.
Google LLC — Firebase Cloud Messaging Delivers push notifications to Australian kid + parent devices United States Parent's express consent + written processor agreement as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures).
Google LLC — Google Sign-In Authenticates parent Google identity (when used) United States Parent's express consent + written processor agreement as above.
Google LLC — Google Play Billing Processes subscription purchases United States Parent's express consent + Google Play Developer Distribution Agreement.
Resend, Inc. (San Francisco, CA, USA) Delivers transactional email to Australian parent users United States Parent's express consent + written processor agreement on file.

Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + APP 11 (security duty). The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.


11. Breach notification — Privacy Act Part IIIC (NDB scheme)

Privacy Act Part IIIC (the Notifiable Data Breaches scheme, in force since 22 February 2018) sets the breach-notification regime:

Audience Trigger Deadline Channel
OAIC An eligible data breach has occurred — defined at Privacy Act s 26WE as (i) unauthorised access to, or unauthorised disclosure of, personal information held by the entity, or (ii) loss of personal information in circumstances where unauthorised access or disclosure is likely to occur, and (iii) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to one or more of the individuals to whom the information relates (the "serious harm" test). As soon as practicable after the entity becomes aware that the breach has occurred (Privacy Act s 26WL). The entity has 30 calendar days to conduct an assessment to determine whether the breach is an eligible data breach (s 26WK). Balance internal anchor: 72 hours (consistent with the GDPR Art 33 benchmark; faster than the Privacy Act "as soon as practicable" floor). OAIC online Notifiable Data Breach form per Privacy Act Part IIIC + the Privacy (Notifiable Data Breaches) Determination 2018 (Cth)
Affected individuals Same trigger as the OAIC notification. As soon as practicable after the entity is satisfied that the breach is an eligible data breach (Privacy Act s 26WL). Balance internal anchor: 72 hours. Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English.
CSAE-specific An incident with a CSAE component. Per § 14 below + the internal runbook (M1). AFP ACCCE + eSafety Commissioner + State / Territory police.

The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, OAIC notification within the 72-hour Balance internal anchor, affected-individual notification at the same point unless a court / tribunal order requires deferral.

11.1 Minimum content of the OAIC NDB notification (Privacy Act s 26WK + s 26WL + Determination)

The OAIC notification states: - the identity and contact details of the entity; - a description of the eligible data breach; - the kind or kinds of information concerned; - the recommendations about the steps that individuals should take in response to the eligible data breach; - the DPO / Privacy Officer contact point (, named individual: ).

The English-language template lives in our breach-notification runbook § 8.1.

11.2 No notification carve-out (s 26WM)

Where Balance takes remedial action that prevents the access or disclosure from resulting in serious harm to the individual (s 26WF), Balance is not required to notify; Balance records the action taken in the breach register at our breach-notification runbook § 11.


12. Cookies, spam, and electronic direct marketing

Australia does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) APP 3 + APP 5 + APP 6 for any cookie that processes personal information; (ii) the OAIC's APP Guidelines Chapter 5 (Collection Notice) and Chapter 7 (Direct Marketing); (iii) the Spam Act 2003 (Cth) for commercial electronic messages; (iv) the Do Not Call Register Act 2006 (Cth) for telemarketing; (v) the Privacy Act s 7C (allows direct marketing for related primary purpose with opt-out); (vi) State / Territory consumer-protection statutes.

12.1 In-app — strictly-necessary storage only

The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.

The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.

12.3 Electronic direct marketing — not sent

Balance does not send commercial electronic messages within the meaning of Spam Act 2003 s 6 to Australian residents. The only email Balance sends to Australian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The Spam Act s 6(4) carve-out for factual information and the s 6(5) carve-out for transactional messages (where the message is about a transaction the recipient has agreed to enter into) cover the Balance transactional posture. If Balance ever introduces a marketing channel, we will comply with Spam Act s 16 (consent — express or inferred), s 17 (identification), and s 18 (unsubscribe).

12.4 No telemarketing

Balance does not place telemarketing calls. The Do Not Call Register Act 2006 is not engaged.


13. Lawful-access requests and the encryption posture

Australian authorities may serve a lawful-access request on Balance via:

The Balance architectural posture interacts with these mechanisms as follows:

The full encryption posture is in our encryption-posture record.


14. CSAE reporting routes — Australia

An Australian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:

The full CSAE Country Routing Table is in Child Safety Standards § 8.6.


15. Complaint routes (summary)

An Australian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:

Authority Subject matter Address / URL
Office of the Australian Information Commissioner (OAIC) Privacy Act + APPs GPO Box 5288, Sydney NSW 2001; https://www.oaic.gov.au/; phone 1300 363 992
eSafety Commissioner Online Safety Act 2021 + BOSE Determination + cyber-bullying / image-based abuse / illegal content PO Box Q500, Queen Victoria Building NSW 1230; https://www.esafety.gov.au/; phone (02) 9219 5000
Australian Communications and Media Authority (ACMA) Spam Act 2003 + Telecommunications Act 1997 PO Box Q500, Queen Victoria Building NSW 1230; https://www.acma.gov.au/; phone 1800 226 003
Australian Competition and Consumer Commission (ACCC) Australian Consumer Law 23 Marcus Clarke Street, Canberra ACT 2600; https://www.accc.gov.au/; phone 1300 302 502
Australian Human Rights Commission (AHRC) Human-rights complaints under the ICCPR + AHRC Act GPO Box 5218, Sydney NSW 2001; https://humanrights.gov.au/; phone 1300 369 711
State / Territory Fair Trading agencies State / Territory ACL enforcement + State / Territory consumer-protection Per State / Territory — see § 3.4 above
Federal Court of Australia Privacy Act s 80W application + statutory tort + direct right of action (from 10 December 2025) https://www.fedcourt.gov.au/
Federal Circuit and Family Court of Australia Direct right of action (from 10 December 2025) + statutory tort https://www.fcfcoa.gov.au/
Supreme Court of NSW / Vic / Qld / WA / SA / Tas / ACT / NT Statutory tort + State / Territory civil action Per State / Territory

An Australian resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the Privacy Officer). We will respond within the APP timelines. Raising the matter with us first is a precondition to the OAIC complaint (Privacy Act s 40(1A) — the OAIC may decide not to investigate if the complainant has not first complained to the respondent), unless the OAIC determines that requiring prior complaint would not be appropriate.


16. Consumer rights — the ACL overlay

The Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) applies to Balance's subscription flow as a consumer contract within the meaning of ACL s 23(3) (the supply is to a "consumer" under s 3 — a person who acquires services where the amount paid does not exceed the prescribed amount (currently AU$100,000) or where the services are of a kind ordinarily acquired for personal, domestic, or household use). Treatment is implemented in Subscription Terms § 20.

16.1 Consumer guarantees as to services (ACL ss 60–62)

The ACL implies into every consumer-services contract three non-excludable consumer guarantees:

Failure to comply with a consumer guarantee triggers a major / non-major failure analysis (ACL ss 267–269) and a consumer's right to remedy (refund or compensation for reduction in value, or supply the services again).

16.2 Unfair contract terms (ACL ss 23–28A)

A term of a standard form consumer contract is unfair if it (i) would cause a significant imbalance in the parties' rights and obligations arising under the contract, (ii) is not reasonably necessary in order to protect the legitimate interests of the party advantaged by the term, and (iii) would cause detriment to a party if relied on. Unfair terms are void under s 23 + s 24. The 2022 amendments (in force from 9 November 2023) introduced civil penalties for proposing unfair terms (up to AU$50 million per term per individual / 3x benefit / 30% adjusted turnover for a body corporate). The Balance Terms of Service (Terms of Service) are drafted to avoid each ACL unfair-term risk.

16.3 Misleading or deceptive conduct (ACL s 18)

A person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. The Balance marketing copy at balance.babayagaprogram.com and on the Google Play Store listing is drafted to avoid each ACL s 18 risk.

16.4 Unsolicited consumer agreements (ACL ss 69–95)

Where the contract is an unsolicited consumer agreement (made in-person or by telephone away from the supplier's business premises), the consumer has a 10-business-day cooling-off period during which the consumer may terminate the agreement without penalty (ACL s 82). Balance's subscription is concluded in-app (i.e., it is a "distance" contract but not an "unsolicited" contract within the ACL meaning — the consumer initiated the subscription by downloading the app and proceeding through the subscription flow); the s 82 cooling-off does not directly apply. Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the s 82 standard.

16.5 Forum and choice of law

The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the ACL to the prejudice of the Australian consumer are unenforceable under ACL s 67 (where the proper law of the contract would be the law of a place outside the Commonwealth or a State or Territory, but for the term, the ACL applies to the contract).


17. Cross-references


18. Versioning and review

This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:


End of Australia Country Annex.

← Back to Privacy Policy · Children's Privacy Notice