Legal
Privacy Policy
How we look after personal information, in plain English.
1. About this policy
XSIV AI (ABN 29 287 374 812) is an AI consultancy based on the Gold Coast, Queensland. In this policy, “we”, “us” and “our” means XSIV AI, and “you” means anyone whose personal information we handle: people who visit our website or contact us, our clients and their staff, and people who attend our training.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Personal information means information or an opinion about an identified person, or a person who can reasonably be identified.
2. What we collect
| When | What we collect |
|---|---|
| You contact us or send an enquiry | Your name, business name, email, phone number, team size and message, the page you sent it from and, if you arrived from one of our links, which campaign it was (for example an email or LinkedIn post). |
| You become a client | Contact and billing details for the people we work with, and information about your business, its workflows and the software it uses. |
| We run an AI Automation Audit | Notes from interviews with you and your team, details of how work is done, and responses to our team readiness survey. Survey responses are confidential and reported to you only as a group. |
| We run training | Attendee names, roles and attendance. |
| You visit our website | Technical information such as IP address, browser and pages visited, used to keep the site secure and working well. See section 12 for analytics. |
We do not ask for sensitive information, such as health information, unless a client engagement specifically needs it. If it does, we agree how it will be protected in writing first. You can contact us without giving your full name where that is practical, but we will need a way to reply.
3. How we collect it
Mostly directly from you, through our website forms, email, phone and meetings. We may also receive information about you from your employer when your business is our client (for example, so we can interview you for an audit), from our service providers, or from public sources such as business directories.
4. How we use it
- To reply to your enquiry and arrange a conversation.
- To deliver our services, including audits, implementation, training and ongoing care, and to manage our relationship with you.
- To send quotes, agreements and invoices, and to keep proper business records.
- To improve our services, using anonymised and combined information that does not identify you.
- To send you occasional updates, but only as allowed under section 13.
- To meet our legal obligations.
We do not use your information for any other purpose unless you agree, you would reasonably expect it, or the law allows or requires it.
5. How we use AI with your information
We are an AI consultancy, so we want to be especially clear about this.
- We only put personal or confidential information into business grade AI tools and services that, by default, do not use it to train their models. We never put it into free or consumer AI tools.
- We use the least information needed for each task, and a person reviews anything that matters before it is used or sent.
- When you send an enquiry, it is saved in our database and emailed to us automatically. A person reads and replies to every enquiry.
- We do not make decisions about you that are made only by a computer program, or where a computer program substantially helps make a decision that significantly affects you. If that ever changes, we will update this policy first to explain what kinds of decisions and information are involved.
- We never use your information, or our clients’ information, to train AI models.
You can read more about how we use AI in our responsible AI statement.
6. Who we share it with
We never sell personal information. We share it only with providers who help us run our business and deliver our services, and only as much as they need:
| Provider type | What they do for us |
|---|---|
| Cloudflare | Hosts our website, stores enquiries in its database (located in the Oceania region) and delivers our enquiry emails. |
| Email and productivity software | Our email, calendar and documents. |
| AI providers, such as Anthropic (Claude) and OpenAI (ChatGPT) | AI assistants and models used in our work and in the systems we build, on business plans that do not train on your data by default. |
| Automation hosting | The servers that run the automations we host for clients. |
| Accounting and payment services | Invoicing and payments. |
| Analytics, if enabled | Understanding how our website is used. See section 12. |
| Professional advisers | Our accountant, lawyer and insurer, when needed. |
We may also disclose information where the law requires it, or to a buyer of our business, who would need to keep handling it in line with this policy.
7. Information sent overseas
Some of our providers store or process information outside Australia. AI providers such as Anthropic and OpenAI mainly process data in the United States, and Cloudflare operates a global network. Other providers may use data centres in other countries. Before using a provider, we check its security and privacy commitments and prefer providers that offer business terms and Australian or regional hosting where available.
If you would like to know which providers are involved in a particular service we provide to you, ask us and we will tell you.
8. Information we handle for our clients
When we build or host systems for a client, those systems may handle personal information about the client’s own customers, patients or staff. In that situation we act on the client’s behalf and under our agreement with them: we use the information only to deliver the services, protect it as described in this policy, and delete it when the engagement ends.
If you are a customer of one of our clients and have a question about your information, please contact that business first. We will help them respond.
9. Keeping it secure
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, including multi factor authentication, access limited to the people who need it, logged access to client systems we host, encrypted connections, reputable providers and regular updates. No system is perfectly secure, but we work to keep risks low and review our practices regularly.
10. If something goes wrong
If we suspect a data breach, we act quickly to contain it and assess it. Where a breach is likely to result in serious harm, we notify the people affected and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. If a breach involves information we handle for a client, we tell that client promptly and help them respond.
11. How long we keep it
| Information | How long |
|---|---|
| Enquiries that do not become clients | 2 years after our last contact, then deleted. |
| Client records, agreements and invoices | At least 5 years, as tax law requires. |
| Audit interview notes, recordings and survey responses | Deleted within 90 days of the audit debrief. The report itself is kept as a client record. |
| Run logs from automations we host | No more than 30 days. |
| Client data in automations we host | Deleted within 30 days after the care plan ends. |
When we no longer need information, we delete it or remove anything that identifies you.
12. Cookies and analytics
Our website does not use advertising cookies. Cloudflare may set a small number of essential cookies to keep the site secure. We may use analytics tools, such as Microsoft Clarity or Google Analytics, to understand how people use our website so we can improve it. These tools use cookies and may collect information such as pages viewed, clicks and approximate location. We do not use them to identify you personally. You can block or delete cookies in your browser settings, and the site will still work.
13. Marketing messages
We only send marketing emails or messages where you have agreed, or where you would reasonably expect them because of an existing relationship, as the Spam Act 2003 allows. Every message tells you who it is from and includes an easy way to unsubscribe, which we action within 5 business days.
14. Seeing and correcting your information
You can ask to see the personal information we hold about you, or ask us to correct it, by emailing craig@xsiv.au. We will need to confirm who you are. We respond within 30 days and do not charge for requests. If we cannot give you access or make a correction, we will explain why in writing.
15. Complaints
If you are concerned about how we have handled your information, please contact us first at craig@xsiv.au or 0411 175 256. We will look into it and respond within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
16. Changes to this policy
We may update this policy as our services, providers or the law change. The latest version is always on this page, with the date it was last updated. If we make a significant change that affects how we use your information, we will tell our clients directly.
Questions about this page? Email craig@xsiv.au or call 0411 175 256.