ChannelX Privacy Notice - Connected Accounts

ChannelX Privacy Notice - Connected Accounts

Last updated: 19 June 2026

This Privacy Notice explains how ChannelX, operated by LocalCom Pty Ltd (ABN 77 139 093 306) ("LocalCom", "we", "us"), accesses, uses, stores, shares, and retains data from the third-party platforms you connect to ChannelX -- Google (Gmail), Microsoft (Outlook / Exchange Online), Meta (Facebook Messenger and Instagram), and WhatsApp Business. It supplements, and should be read together with, the LocalCom Privacy Policy.

1. About ChannelX and how it is hosted

ChannelX is a multi-channel contact-centre and helpdesk platform. It can be deployed in two ways, and this affects where your message content is stored:

  • LocalCom-hosted: we host your ChannelX instance on LocalCom-operated infrastructure located at the NEXTDC B2 data centre in Brisbane, Australia.
  • Self-hosted: you deploy ChannelX on infrastructure you control. In this case your message content is stored on your own systems and LocalCom does not have access to it.

In both deployment models, the authorisation that permits access to a connected platform (for example, an OAuth refresh token or a platform access token) is brokered and held only by LocalCom's central authentication gateway, which runs on LocalCom-operated infrastructure at the NEXTDC B2 data centre in Brisbane, Australia. These credentials are never stored on a customer ChannelX instance.

2. The platforms we connect to and the data we access

We request only the access required to operate the connected-inbox feature, and only after you explicitly initiate a connection. The specific data accessed depends on the platform you connect:

Platform Data we access Purpose
Google (Gmail) Your basic Google profile and email address; and access to your Gmail mailbox via the https://mail.google.com/ scope (IMAP/SMTP). Identify the connected mailbox; read incoming email and send replies on your behalf.
Microsoft (Outlook / Exchange Online) Your basic Microsoft profile and email address; and access to your Microsoft mailbox via IMAP and SMTP permissions (with offline access). Identify the connected mailbox; read incoming email and send replies on your behalf.
Meta - Facebook Messenger The connected Facebook Page's identifier and access token; the content of messages sent to your Page; and the page-scoped identifiers and public profile names of people who message your Page. Show Page conversations in ChannelX and let your agents reply.
Meta - Instagram The connected Instagram professional account's identifier and access token; the content of messages sent to that account; and the identifiers/usernames of people who message you. Show Instagram conversations in ChannelX and let your agents reply.
WhatsApp Business (subject to Meta approval) The connected WhatsApp Business phone number and its identifier; the content of messages exchanged with your customers; and the phone numbers and profile names of people who message your business number. Show WhatsApp conversations in ChannelX and let your agents reply.

3. How we use this data

We use the data described above solely to operate the connected-inbox feature, specifically to:

  • retrieve incoming messages and present them to your authorised agents as conversations and helpdesk tickets within ChannelX;
  • send the outbound replies your agents compose;
  • display message details (sender, subject where applicable, timestamps, body, and attachments) to your authorised agents.

We do not use connected-platform data for advertising, and we do not use it to develop, improve, or train generalised or non-personalised artificial-intelligence or machine-learning models.

4. How we store and secure this data

  • Authorisation tokens. Long-lived authorisation tokens (OAuth refresh tokens and platform access tokens) are stored, encrypted, only on LocalCom's central authentication gateway at the NEXTDC B2 data centre in Brisbane, Australia. They are never stored on a customer ChannelX instance. Short-lived access tokens are issued only as needed and are time-limited.
  • Message content. Messages retrieved from a connected platform are stored as part of your conversation and ticket history within your ChannelX instance -- in our Brisbane cluster at NEXTDC B2 where LocalCom hosts your instance, or on infrastructure you control where you self-host.
  • Security. All connected-platform data is encrypted in transit and at rest. Access is restricted to authorised systems and personnel, and we take reasonable and appropriate measures to protect it against unauthorised access, use, loss, alteration, or disclosure.

5. How we share this data

We do not sell connected-platform data, and we do not share or transfer it except as necessary to provide ChannelX:

  • with the originating platform (Google, Microsoft, or Meta) to operate the connection;
  • with the LocalCom-operated hosting infrastructure used to run the service (our own cluster at NEXTDC B2, Brisbane); we do not transfer message content to external third-party cloud providers;
  • where required to comply with applicable law, regulation, legal process, or an enforceable governmental request; and
  • in connection with a merger, acquisition, or sale of assets, with prior notice and continued protection of your data.

6. Data retention and deletion

  • Message content. When your ChannelX service is cancelled, your message and conversation content is deleted as part of decommissioning, because the hosted server is destroyed or the tenancy is removed. For self-hosted deployments, deletion of message content is performed by you on your own infrastructure.
  • Authorisation tokens and account identifiers. When you disconnect a connected account, or when your service is cancelled, we revoke the authorisation and delete the stored token and associated account identifier from our gateway promptly -- within 7 days, and typically within 24 hours.
  • Operational metadata. We retain limited operational records that do not contain message content or live credentials (for example, an internal tenant identifier and connection/disconnection timestamps) for up to 24 months for security and audit purposes. Billing records are retained for the period required by Australian law.

7. Requesting deletion of your data

You can request deletion of data we hold from any connected platform at any time:

  • Self-service: disconnect the relevant account from within ChannelX. This stops further access and triggers revocation and deletion of the stored authorisation token.
  • By request: email support@localcom.com.au with the subject "Data Deletion Request" and tell us which connected account (and, for messaging platforms, which Page, Instagram account, or WhatsApp number) you want deleted. We will action the request within 30 days and confirm once complete, except where retention is required by law.

8. Your choices and platform controls

You can also remove ChannelX's access directly from each platform:

9. Platform compliance statements

  • Google. ChannelX's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • Meta. Our access to and use of data from Facebook, Instagram, and WhatsApp complies with the Meta Platform Terms and Developer Policies. We use this data only to provide the messaging features you connect, and not for any unauthorised purpose.
  • Microsoft. Our access to and use of Microsoft account and mailbox data complies with the Microsoft APIs Terms of Use and the Microsoft Services Agreement.

10. Changes to this Notice

If we change how ChannelX uses data from a connected platform, we will update this Notice and, where required, prompt affected users to consent before the new use takes effect.

11. Contact us

LocalCom Pty Ltd
220 Varsity Parade, Varsity Lakes QLD 4227, Australia
Email: support@localcom.com.au
Phone: 1300 978 979