Privacy and acceptable use

How everyone who signs in to the Chetan Properties CRM looks after the personal details in it, and the cookies the CRM uses. Last updated 10 October 2026.

Who this is for

The CRM is a private tool for Chetan Properties staff ([agency's legal entity name], ABN [ABN]). Only people the agency invites can sign in. By using it you agree to handle the information in it as this page describes, alongside your employment agreement and the agency's workplace policies.

What the CRM holds

About homeowners, buyers and other contacts:

  • names, phone numbers, email and postal addresses, and date of birth where known
  • the properties they own or want to buy, and what they're looking for
  • whether they're on the Do Not Call Register and whether they've agreed to marketing email
  • notes from calls and meetings, callbacks and appointments

About staff:

  • your name, work email, role and the suburbs you work
  • your password and two-step login details, stored in a form that can't be read back
  • a history of the changes you make, so the agency can see who did what

Using it properly

  • Use the CRM only for Chetan Properties's work, never for yourself or anyone else.
  • Before calling, check the contact isn't on the Do Not Call Register. The CRM shows the flag, but it is only as current as the last check.
  • Only send marketing email to people marked as agreeing to it, and always include a way to opt out.
  • Don't copy, photograph, download or forward contact details outside the CRM. Exports are for admins, for the agency's business.
  • Keep your password and authenticator to yourself. Never share a login or sign in as someone else.
  • Record notes that are accurate and professional. The person they're about can ask to see them.
  • If you think details have been seen by someone who shouldn't have them, or your login has been misused, tell an admin straight away.

Who can see what

Admins see everything and manage the team. Telephone realtors see the suburbs they're assigned and the calls they're given, and can't edit records. Data entry staff maintain records but can't read call notes or the calendar. These rules are enforced by the CRM itself, not just by hiding buttons.

Requests from the people in it

Anyone can ask the agency what it holds about them, ask for it to be corrected, or ask not to be contacted. Pass any such request to an admin, who will respond on the agency's behalf. Mark people who ask not to be called as Do Not Call so nobody calls them again.

Where it's kept

The CRM's data is stored with the agency's hosting provider. If email is set up, invites, password resets and reminders are sent through an email delivery service. Neither may use the data for anything else. The agency doesn't sell or rent the information, and the CRM shows no advertising.

Records are kept while the agency needs them for its work. Admins can delete properties, contacts and team members; deletions are noted in the change history.

Cookies

The CRM only sets the cookies it needs to sign you in and keep that secure. There are no analytics, tracking or advertising cookies, so there's nothing to opt in or out of. If your browser blocks these cookies, you won't be able to sign in.

CookieWhat it's forHow long
authjs.session-tokenKeeps you signed inUntil you sign out, at most 30 days
authjs.csrf-tokenStops other websites submitting forms as youUntil you close the browser
authjs.callback-urlRemembers where to take you after signing inUntil you close the browser

On the live site the names start with a security prefix such as __Secure-.

Questions and changes

Ask an admin, or contact the agency's privacy contact at [privacy contact email]. If this page changes, the date at the top changes with it.