Revenue North
Privacy Policy
Effective 3 August 2026 | Version 1.0
Partner AI Index Privacy Policy. Return to the homepage.
Operator: Murray Jess, a sole trader carrying on business under the registered business name Revenue North (ABN 59 414 885 869).
Privacy contact: privacy@partneraiindex.com
1. About this policy
This Privacy Policy explains how Revenue North collects, holds, uses, discloses and protects personal information in connection with the Partner AI Index and related Revenue North services.
The policy applies to the Partner AI Index website, early-access and priority-access forms, the diagnostic, diagnostic reports and report links, evidence-review features when enabled, transactional emails, support enquiries and related service interactions.
Revenue North is directed primarily to business users in Australia and New Zealand. The service may also be accessed from other countries. Additional privacy rights may apply depending on where a user is located.
This policy is intended to explain our practices under applicable privacy laws, including the Privacy Act 1988 (Cth), the Australian Privacy Principles and the New Zealand Privacy Act 2020 where they apply.
2. Who we are
The Partner AI Index is operated by Murray Jess, a sole trader carrying on business under the registered business name Revenue North.
| Legal operator | Murray Jess |
|---|---|
| Business name | Revenue North |
| ABN | 59 414 885 869 |
| Product | Partner AI Index |
| Business address | Suite 6, 11 Oaks Avenue, Dee Why NSW 2099, Australia |
| Postal address | PO Box 1485, Dee Why NSW 2099, Australia |
Privacy contact: privacy@partneraiindex.com
3. How the Partner AI Index works
When you complete the Partner AI Index diagnostic, Revenue North uses the information you provide for two connected purposes:
- to analyse your organisation’s responses and provide you with a personalised diagnostic report; and
- to contribute to the broader Partner AI Index, improve the diagnostic methodology, and develop industry benchmarks and market insights.
Your contact details, individual responses, organisation-specific results and personalised report will not be published or shared with Microsoft without your permission.
Information used in external benchmarks, research or published insights will be aggregated or de-identified so that individual respondents and participating organisations are not reasonably identifiable. We may combine results into sufficiently broad groups and withhold or combine small cohort results where publication could make an organisation identifiable.
We will not identify your organisation in a benchmark, case study, public report or marketing material without express permission.
You may request deletion of identifiable diagnostic information we hold about you. Once information has been appropriately aggregated or de-identified so that it can no longer reasonably be connected with you or your organisation, it may not be possible to isolate and remove your individual contribution.
4. Information we collect
Early-access and priority-access information
When you request early access, priority access or a notification that the diagnostic has been released, we may collect:
- your work email address;
- your name, if requested or supplied;
- your organisation name;
- the date and source of the request; and
- records of service-related communications sent to you.
Joining the early-access list does not contribute diagnostic information to the Partner AI Index. Index participation begins when diagnostic responses are submitted.
Diagnostic registration and profile information
When you start or complete the diagnostic, we may collect:
- your first name, work email address and organisation name;
- your role or relationship to the organisation;
- partner type, employee band, revenue band, customer focus, geography and Microsoft AI focus; and
- other business profile information used to interpret the diagnostic or create relevant benchmark groups.
Diagnostic responses and commercial information
We collect the answers you submit about your organisation, including information relating to:
- strategy and leadership alignment;
- AI offer architecture;
- go-to-market and sales enablement;
- customer progression and value realisation;
- business and delivery readiness;
- AI pipeline, revenue, pilots, deployments and recurring revenue;
- commercial measurement and performance; and
- organisational priorities, constraints and perceived barriers.
Some information may be commercially confidential even where it is not personal information under privacy law. We apply the handling practices described in this policy to organisation-specific diagnostic information as well as personal information.
Evidence information, if enabled
Evidence submission is not a general public feature at launch. If an evidence-review feature is introduced, users may be able to provide documents, PDFs, screenshots, sales decks, offer materials, website links, LinkedIn or other public-profile links and supporting comments.
Users should provide only information reasonably necessary for the review and must be authorised to submit it. Users must not upload passwords, authentication credentials, payment or financial-account details, health information, government identifiers, customer or employee records, or other sensitive or third-party information that is not required for the diagnostic.
Reports, support and service interactions
We may collect and retain diagnostic scores, maturity results, category and barrier results, constraints, revenue-leakage findings, recommendations, generated reports, report-access records, support correspondence, debrief notes and related service enquiries.
Technical and usage information
When you use the website or diagnostic, we and our service providers may automatically collect technical and usage information such as:
- IP address and approximate location;
- browser, device and operating-system information;
- dates and times of access;
- pages, features and report links accessed;
- referral source, pageviews, session duration and bounce information;
- error, performance, security and diagnostic logs; and
- session, resume-link and report-access activity.
5. How we collect information
We generally collect information directly from you when you submit an early-access form, start or complete the diagnostic, access a report, provide evidence, request a debrief, contact us or engage Revenue North for related services.
Where an evidence review is requested or authorised, we may also collect relevant information from publicly available business sources, such as an organisation’s website, published offers, public LinkedIn presence and other public market materials.
If you provide personal information about another person, you must be authorised to do so and should ensure the person is aware of this policy where appropriate.
6. Why we use information
We may use personal and organisation-specific information to:
- provide, save, resume and administer the Partner AI Index;
- calculate scores, maturity bands, constraints, customer-barrier results, revenue-leakage findings and recommendations;
- generate, deliver and support access to personalised reports;
- conduct an evidence review where requested and enabled;
- confirm early-access requests and notify registrants when the diagnostic is released;
- send assessment, report, evidence, security, support and other service-related communications;
- respond to enquiries and arrange debriefs or related Revenue North services;
- protect the service against misuse, fraud, unauthorised access and security threats;
- diagnose technical problems and improve service performance and usability;
- improve the diagnostic methodology and recommendation logic;
- create aggregated or de-identified benchmarks, research and market insights;
- maintain business, legal, security and audit records; and
- comply with applicable legal and regulatory requirements.
We do not currently use the early-access or diagnostic mailing lists for general marketing newsletters or promotional campaigns. If we introduce marketing communications later, we will provide an appropriate choice and a working unsubscribe mechanism.
7. Automated scoring and report generation
The Partner AI Index uses defined scoring and interpretation rules to analyse submitted responses and generate diagnostic outputs. Depending on the diagnostic version and the information supplied, outputs may include category and overall scores, maturity bands, maturity constraints, customer-barrier indicators, revenue-leakage findings and priority actions.
The diagnostic is advisory. Its outputs are business insights and are not used by Revenue North to make decisions about an individual’s employment, credit, insurance, legal rights or access to essential services.
Where an evidence-reviewed report is offered, automated calculations may be combined with review by authorised Revenue North personnel.
You may contact us if you believe a result was produced using incorrect information or would like an explanation of the information used to produce it.
8. Microsoft and third-party sharing
Revenue North and the Partner AI Index operate independently from Microsoft unless expressly stated otherwise for a specific program or engagement.
Revenue North does not share individual diagnostic results, reports or organisation-identifiable information with Microsoft unless you expressly request or authorise us to do so, or disclosure is required by law.
You may choose to download, forward or otherwise provide your report to Microsoft or another third party. Any sharing you initiate is at your discretion. Once information is provided to a third party, that third party’s privacy practices will apply to its handling of the information.
Before sharing a report, you should ensure that you are authorised to disclose any organisational, personal or confidential information it contains.
We may share aggregated or appropriately de-identified benchmark information and market insights, provided individual participants and organisations are not reasonably identifiable.
9. Emails and communications
Revenue North uses Resend to send transactional and service-related emails. These may include:
- early-access confirmations;
- notification that the Partner AI Index has been released;
- assessment access or resume messages;
- diagnostic completion notices and report links;
- evidence-submission confirmations, if that feature is enabled; and
- security, support and service notices.
These emails are used to provide or support a service you requested. We do not currently send marketing newsletters or promotional email campaigns through the Partner AI Index mailing list.
Resend processes information needed to deliver and manage emails, which may include recipient and sender addresses, subject lines, message content, delivery events, bounces, complaints, logs and related email metadata.
10. Analytics and storage technologies
We use Lovable’s built-in project analytics to understand how the Partner AI Index is used and to monitor service performance. This may include visitor and pageview counts, visit duration, bounce rate, pages viewed, general traffic sources, device type and country-level location.
We do not currently use Google Analytics, Microsoft Clarity, advertising pixels or cross-site behavioural advertising on the Partner AI Index.
The website may use cookies, local browser storage and similar technologies where needed to operate and secure the service, maintain or resume an assessment, protect report access, remember essential preferences and provide platform analytics. Browser settings may allow you to control some of these technologies, but disabling essential storage may prevent parts of the service from working correctly.
11. Service providers and disclosures
We disclose information only where reasonably necessary to operate the service, fulfil a request, protect our rights or comply with law. The main service providers used at launch are:
Supabase
Supabase provides database, authentication, storage and related backend services. The primary Supabase project used for the Partner AI Index is hosted in the Oceania (Sydney) region, technically identified as ap-southeast-2. Diagnostic records, reports and evidence files, if enabled, may be stored through Supabase.
Lovable
Lovable provides application development, deployment, hosting-related services, operational analytics and technical infrastructure used to make the Partner AI Index available. Lovable and its subprocessors may process application, service, log and technical information for hosting, security, support, analytics and service operation.
Resend
Resend provides transactional email delivery. Account data, email metadata, logs and API records may be stored in the United States, regardless of the region from which an email is dispatched.
Other disclosures
We may also disclose information to professional advisers, insurers, accountants, lawyers, contractors supporting an authorised engagement, regulators, courts or law-enforcement bodies where required or authorised by law, and parties involved in a genuine business sale or restructure subject to appropriate confidentiality protections.
We do not sell personal information or disclose personal information for cross-context behavioural advertising.
12. International processing
Although the primary Supabase project is hosted in Sydney, some technical, operational, support, analytics and email-delivery information may be processed by service providers or their subprocessors outside Australia, including in the United States and other countries in which those providers operate.
We take reasonable steps to select reputable service providers and use contractual, security and access controls appropriate to the nature of the information. Privacy protections in another country may differ from those available in Australia or New Zealand.
Users outside Australia and New Zealand may have additional rights under local privacy law. Where those laws apply to Revenue North’s handling of personal information, we will respond in accordance with the applicable requirements.
13. Security
Revenue North uses reasonable technical and organisational measures designed to protect personal and organisation-specific information from unauthorised access, loss, misuse, interference, alteration and disclosure.
These measures may include encrypted network connections, restricted administrative access, role-based controls, row-level database security, secure session and report-access credentials, logging, monitoring, controlled file access and software updates.
No internet service or storage system can be guaranteed to be completely secure. You should protect assessment, resume and report links and should not forward them to people who are not authorised to view the information.
If we become aware of a suspected data breach, we will investigate, take appropriate steps to contain and remediate it, and notify affected individuals and relevant regulators where required.
14. Retention and deletion
We retain information only for as long as reasonably needed for the purposes described in this policy, subject to legal, security, backup and operational requirements.
| Information | General retention period |
|---|---|
| Early-access record where no diagnostic is started | Up to 24 months after the last interaction |
| Started but incomplete diagnostic | Up to 12 months after the last activity |
| Completed diagnostic responses and instant report | Up to 36 months after completion or the last related interaction |
| Evidence uploads, if enabled | Generally up to 12 months after the evidence review is completed |
| Evidence-reviewed report | Up to 36 months after completion or the last related interaction |
| Support enquiries and correspondence | Up to 36 months after resolution |
| Transactional email and delivery records | Generally up to 24 months, subject to provider and security requirements |
| Suppression or opt-out records | As long as reasonably necessary to ensure the request continues to be honoured |
| Legal, tax, insurance or contractual records | For the period required by applicable law or reasonably needed to protect legal interests |
At the end of the relevant period, information will be deleted, securely destroyed or de-identified where it is no longer reasonably required. Deleted information may remain for a limited period in restricted backups before being overwritten through the ordinary backup cycle.
Aggregated or de-identified benchmark information that no longer reasonably identifies an individual or organisation may be retained for methodology, benchmarking, research and historical analysis. It may not be possible to isolate and remove a person’s earlier contribution once it has been incorporated into such information.
15. Access, correction and deletion requests
You may contact Revenue North to request:
- access to personal information we hold about you;
- correction of inaccurate or incomplete personal information;
- deletion of identifiable personal and diagnostic information;
- withdrawal of any optional consent;
- information about how a diagnostic result was produced; or
- other privacy rights available under applicable law.
Send requests to: privacy@partneraiindex.com
We may need to verify your identity and authority before acting on a request. We aim to respond within 30 days, although additional time may be required for a complex request or where permitted by law.
We may be unable to delete some information immediately where it must be retained by law, is needed for security or legal claims, remains temporarily in restricted backups, or is required to honour an opt-out or suppression request. Deleting diagnostic information may make an assessment, resume link or report unavailable.
16. Privacy complaints
If you have a question or complaint about how Revenue North handles personal information, please contact us at privacy@partneraiindex.com. Please provide enough information for us to understand and investigate the issue.
We aim to acknowledge complaints promptly and provide a substantive response within 30 days.
If you remain dissatisfied, you may be entitled to contact the privacy regulator in your jurisdiction, including the Office of the Australian Information Commissioner in Australia or the Office of the Privacy Commissioner in New Zealand, where applicable.
17. Children
The Partner AI Index is a business diagnostic and is not intended for children or anyone under 18 years of age. We do not knowingly collect personal information from children.
18. Changes to this policy
We may update this Privacy Policy as the Partner AI Index, our service providers, our business practices or applicable laws change. The current version will show its effective date. Where a change materially affects how we handle existing personal information, we will take reasonable steps to provide additional notice.
19. Contact us
Partner AI Index / Revenue North
| Legal operator | Murray Jess |
|---|---|
| Business name | Revenue North |
| ABN | 59 414 885 869 |
| Business address | Suite 6, 11 Oaks Avenue, Dee Why NSW 2099, Australia |
| Postal address | PO Box 1485, Dee Why NSW 2099, Australia |
| Privacy email | privacy@partneraiindex.com |
Revenue North | Effective 3 August 2026