Privacy Policy
How we handle personal information, in our own capacity as a business and in the automations we build for clients.
About This Policy
- Octopodia AI Automations (ABN 70 849 627 737) (“Octopodia”, “we”, “us”, “our”) is committed to protecting the privacy of personal information we handle. This Privacy Policy (this “Policy”) explains what personal information we collect, how we use and disclose it, and how you can access, correct, or raise concerns about that information.
- This Policy applies to personal information we collect from clients, prospective clients, client personnel, website visitors, and, where relevant, individuals whose information passes through automation systems we build and operate on behalf of clients.
- Where we process personal information on behalf of a client as part of a service engagement (for example, data flowing through an automation we have built), the client generally determines the purposes for which that information is processed and we process that information in accordance with our contractual arrangements with the client. This Policy describes how we handle personal information in our own capacity as a business.
- Where it is lawful and practicable, you may deal with us anonymously or by using a pseudonym, for example, when making a general enquiry. In many cases, however, we will not be able to provide our services, respond fully to your request, or communicate with you effectively unless you provide the information we need to identify you.
What Personal Information We Collect
- Depending on our relationship with you, we may collect:
- Contact details: name, business title, email address, phone number, business address;
- Business information: company name, ABN, industry, size, systems and tools in use;
- Engagement information: details shared during discovery, scoping, or advisory conversations, including operational and process information about your business;
- Communications: records of emails, calls, meetings, and support requests;
- Website usage data: if you visit octopodia.com.au, we may collect standard analytics data such as IP address, browser type, and pages visited, collected using analytics tools such as Google Analytics and Cloudflare Analytics; or
- Payment and billing information: for invoicing purposes, via an internal portal we have built for our own client management.
- We do not intentionally collect sensitive information (such as health, biometric, or government-identifier data) unless it is necessary for a specific engagement and the client has demonstrated to our satisfaction their entitlement under an appropriate lawful basis for that handling (including obtaining any required consents where applicable), in which case handling is governed by the applicable Scope of Works and any Data Processing Agreement.
- Our website may use cookies and similar tracking technologies to operate the site and to collect the website usage data described above. Where required by applicable law, including for visitors located in the EU/EEA, we will seek your consent before setting non-essential cookies (such as analytics cookies), and you can manage or withdraw your preferences at any time through your browser settings or any cookie consent tool provided on the site.
- Our services are directed to businesses and their personnel, and we do not knowingly collect personal information from children. If you believe we have inadvertently collected a child’s personal information, please contact us using the details in Section 13 and we will take reasonable steps to delete it.
How We Collect Personal Information
- We typically collect personal information directly from you through conversations, emails, meetings, our website, or documents you provide during an engagement. We may also collect information from:
- publicly available sources (e.g. LinkedIn, company websites) when researching prospective clients;
- referral partners, where you have been referred to us; and
- third-party systems we integrate with as part of a client engagement, strictly for the purpose of delivering that engagement.
Why We Collect and Use Personal Information
- We use personal information that we have collected for the following purposes:
- provide, deliver, and support our services;
- communicate with you about engagements, proposals, and invoicing;
- prepare discovery materials, briefs, and recommendations (including using AI tools, as described in Section 6);
- improve our services and internal processes;
- meet our legal, accounting, and regulatory obligations; and
- with your consent, send marketing communications such as newsletters or case studies (you can opt out at any time by using the unsubscribe link in any message, or by emailing us using the details in Section 13).
Disclosure of Personal Information
- We do not sell any personal information that we collect. We may disclose personal information to:
- our team members, on a need-to-know basis;
- infrastructure and software providers who host or process data on our behalf (see Section 7);
- AI service providers used to deliver our services, further particulars of which are set out in the Data Processing Agreement and section 6 of this Policy;
- our professional advisers (accountants, lawyers, insurers) where reasonably necessary; or
- regulators or authorities, where required by law.
- We require third parties who process personal information on our behalf to protect it under contractual obligations appropriate to the services they provide and applicable privacy laws.
Use of AI Tools
- As an AI automation business, we use artificial intelligence tools, including large language models, in the course of delivering services, for example, to help generate discovery briefs, process documentation, or power automations built for clients.
- Where personal information is processed by an AI provider, which we have disclosed to you under the Data Processing Agreement or otherwise in writing, as part of an engagement, that information is sent to the provider’s infrastructure for processing in accordance with the provider’s own data handling terms. We select AI providers and configurations (including data retention and training settings, where offered) with data protection in mind, and infrastructure/provider choices for a given client engagement are recorded in that client’s profile and Scope of Works.
- We do not retain personal information to train our own AI systems. For each engagement we apply behavioural instructions and guardrails, tailored to the client’s requirements where you have made them known to us, to control how the AI tools we operate handle information, and, where a provider offers them, we prefer configurations that avoid retaining client data or using it to train the provider’s models. The underlying AI models we use are operated by third-party providers. Although we configure available privacy settings where appropriate, those providers process information under their own terms and privacy practices, which may differ depending on the provider and services selected for a particular engagement.
Overseas Disclosure and Data Storage
- We currently use infrastructure and AI providers that may store or process personal information outside Australia. At the date of this Policy, these include:
- our default infrastructure provider, Hetzner, operates data centres in Europe (Germany/Finland);
- where a client requires Australian data residency, we use DigitalOcean’s Sydney data centre instead; and
- AI service providers we use (see those disclosed in the Data Processing Agreement or Scope of Works) may process data on infrastructure located outside Australia, primarily in the United States.
- Before disclosing personal information overseas, we take reasonable steps to ensure overseas recipients handle it consistently with the Australian Privacy Principles, including via the terms we agree with those providers. Clients with data residency or data sovereignty requirements can request Australian-based infrastructure, as set out in the applicable Scope of Works.
GDPR: Where It May Apply
- Although Octopodia is based in Australia and primarily serves Australian businesses, some engagements may be subject to the GDPR or other overseas privacy laws depending on the nature of the engagement and the applicable legal requirements. Where this occurs, we will comply with those additional requirements to the extent they apply.
- In some cases, we act as a data controller in our own right under the GDPR: for example, in relation to EU-based website visitors, prospective clients, and marketing contacts, where we determine the purposes and means of processing their personal data. Where we act as a controller, we rely on an appropriate lawful basis under Article 6 of the GDPR (such as your consent, our legitimate interests, or the performance of a contract with you), and EU individuals may exercise their GDPR rights directly with us using the details in Section 13.
- Where GDPR applies to a specific engagement:
- we will process personal data only on the client’s documented instructions, and the client (as data controller) remains responsible for establishing a valid legal basis for the underlying collection and use of that data;
- Octopodia will conduct itself as a data processor (or sub-processor, where an AI or infrastructure provider is also involved) for that engagement, and will enter into appropriate data processing terms with the client on request;
- transfers of EU personal data to infrastructure or AI providers located outside the EU (including our Hetzner and Sydney hosting options, and other providers disclosed to you in the Data Processing Agreement or Scope of Works) will rely on an appropriate transfer safeguard, such as the European Commission’s Standard Contractual Clauses (SCCs), as confirmed with the client and provider on a per-engagement basis; and
- EU individuals have rights broadly similar to those described in Section 11 (access, correction) as well as additional rights under GDPR (e.g. erasure, portability, restriction of processing, and the right to lodge a complaint with a supervisory authority).
Data Security
- We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:
- use of appropriate technical and organisational security measures, including encryption where appropriate;
- access restricted to authorised team members on a need-to-know basis; and
- secure, access-controlled infrastructure for hosting client systems and data.
- No method of transmission or storage is completely secure. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
Data Retention
- We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Policy, or as required by law (for example, financial records under Australian tax law).
- When personal information is no longer required, we take reasonable steps to securely delete or de-identify it unless we are required or authorised by law to retain it.
Access and Correction
- You may request access to, or correction of, the personal information we hold about you by contacting us using the details in Section 13. We will respond within a reasonable time (and in any event, within 30 days) and may need to verify your identity before providing access. There is no charge for making a request, though we may charge a reasonable fee to cover the cost of retrieving and providing information in some cases.
- If we refuse a request for access or correction, we will explain why and, where relevant, how you can seek review of that decision.
Complaints
- If you have a concern about how we’ve handled your personal information, please contact us using the details below. We will investigate and respond within a reasonable time, and in any event within 30 days.
- If you’re not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
Contact Us
- Questions about this Policy, or requests for information, can be directed to either Partner:
- Lachlan Barr, Partner, Octopodia AI Automations. lachlan@octopodia.com.au
- ZurEl Chong, Partner, Octopodia AI Automations. el@octopodia.com.au
- Website: octopodia.com.au
Changes to This Policy
- We may update this Policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available at octopodia.com.au/privacy, with the effective date shown at the top.
- Material changes will take effect when the updated Policy is published on our website, unless another effective date is specified.