Privacy
Privacy policy
What this company holds today, what the assistant would collect if it is released, whose information is whose, how long anything is kept, and how to make us delete it.
Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)
1Who we are, and what this policy covers
This is the privacy policy of ANDY AI PTY LTD, ACN 697 510 562, ABN 72 697 510 562, an Australian proprietary company registered in South Australia. In this document "we", "us" and "our" mean that company. "Andy" is the name of the scheduling assistant the company is building, and it is a trading name of the same entity rather than a separate business.
The unusual thing about this policy, said first
Most privacy policies describe a product that exists. This one mostly describes a product that does not. The company was registered in 2026, has released no software, has no users and has no customers. The only personal information it actually holds today is the contents of its mailbox and the ordinary logs kept by the company that serves this website.
We could have waited until there was something to describe. We are not doing that, for two reasons. The first is that the rules for handling a caller's phone number are much easier to fix before any code depends on them. The second is that a policy written in advance can be held against us afterwards, and a policy written after the fact usually describes whatever was built.
So this document is in two halves that are kept clearly apart. Sections about what we hold today are written in the present tense and are true now. Sections about what Andy would collect are written in the conditional, and they are commitments about a product that does not exist yet rather than descriptions of one that does.
Who this policy is for
- Visitors to andyai.link. Covered in full, and there is very little to cover.
- Anybody who emails us. Covered in full.
- Trades businesses who would one day use Andy. Covered in the conditional sections.
- People who ring a trades business and end up speaking to Andy. Covered in its own section, because the answer for you is genuinely different and it is the section most policies would leave out.
What this policy does not cover
It does not cover the practices of any trades business that might one day use Andy. Each of those is a separate business making its own decisions about its own customers, and it has its own obligations under the Privacy Act 1988 (Cth) or, if it is a small business under the section 6D threshold, its own choice about whether to act as though the Act applies. It does not cover websites we link to. It does not cover your telephone carrier, which handles the call before anything of ours sees it.
2The law this policy answers to
The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.
Australian Privacy Principle 1, and why this document exists
APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.
The small business threshold, and why it does not get us out of this
Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. ANDY AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.
We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.
If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.
Other Australian law that applies
- Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
- Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
- Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.
3Two roles, and which one we would be in
This is the most important section in the document, which is why it comes before the collection tables rather than after them.
Two roles, and the words for them
Australian privacy law does not divide the world into "controllers" and "processors" the way European law does. The Privacy Act asks whether an entity holds personal information and whether it is an APP entity, and it can catch you either way. But the distinction those two words describe is real, it decides who you should be talking to when you want something done, and Australian law gives us no better pair of words for it. So we use them, and we say plainly that we are borrowing them.
- A controller decides why personal information is collected and what happens to it.
- A processor holds it and acts on somebody else's instructions.
The same company can be both at once, for different information, and we would be. Getting this wrong is how a small software company ends up quietly treating its customers' customers as its own audience, and that is exactly the failure this section exists to prevent.
Where we would be the controller
We decide the purpose, so the responsibility is ours and you deal with us directly.
- The email address and message of anybody who writes to hello@andyai.link.
- The server log entries generated by a visit to this website.
- If Andy is ever released, the account details of the trades business itself. The name of the business, the person we deal with, the contact address, the billing details and the record of which plan is in use.
- Aggregate counts about how the software performs, such as how many calls failed to complete, where those counts are not tied back to an individual.
Where we would be the processor
This is the part that matters. If Andy answers a call for a plumber, everything the caller says belongs to the relationship between that caller and that plumber. The plumber decides why it is collected and what happens to it. We would only be holding it in order to do the thing the plumber asked for.
- The caller's name.
- The number they rang from, or the number they ask to be called back on.
- The address or suburb of the job.
- What they said was wrong, in their own words.
- Any recording or transcript of the call, where the trades business has chosen to keep one and has told its callers so.
- The time that was offered and whether it was accepted.
None of that is ours. We would not use it to improve a service for a different trades business unless it had been genuinely de-identified first, we would not use it to build a directory, and we would never approach the caller ourselves about anything.
| Information | Whose customer is it about | Our role | Who you ask about it |
|---|---|---|---|
| A visitor's IP address in a server log | Ours | Controller | Us |
| An email you send us | Ours | Controller | Us |
| A trades business account and its billing details | Ours | Controller | Us |
| A caller's name and phone number | The trades business's | Processor | The business you rang, who then instructs us |
| A caller's description of the job | The trades business's | Processor | The business you rang |
| A recording or transcript of a call | The trades business's | Processor | The business you rang |
| A calendar entry written into the trade's diary | The trades business's | Processor | The business you rang |
| Counts of how often the software failed to understand a caller | Nobody's, once aggregated | Controller | Us |
What being a processor would commit us to
These are the terms we would put in the contract with a trades business, written here so that a caller can read them without being a party to it.
- We act on the trades business's documented instructions and on nothing else, except where an Australian law requires otherwise, in which case we tell them unless the law forbids it.
- We do not use call information for our own purposes. Not for advertising, not for a lead product, not for training a general model that is offered to anybody else.
- We help the trades business answer an access, correction or deletion request from one of its callers, within a timeframe that lets them meet their own 30 day obligation.
- We tell the trades business about a suspected data breach affecting their callers without undue delay, so that they can meet their own obligations under Part IIIC of the Privacy Act.
- On the day the relationship ends, we return or delete the call information. We do not keep a copy as an asset.
- We do not engage a further supplier who touches call information without telling the trades business first and binding that supplier to the same terms.
What the trades business would be responsible for
The other half of the split, said out loud because callers are entitled to know who to hold to it. A business using Andy would be responsible for telling its own callers what happens on the call, including whether it is recorded, for having a lawful basis for anything it asks Andy to collect beyond the four ordinary details, for answering its callers' requests about their information, and for its own privacy policy. We would give it the tools and the record it needs to do all of that. We cannot do it for them, and a software company that pretends otherwise is selling comfort rather than compliance.
If you are a caller and you want something done about your details, ask the business you rang first. They decide, and they can instruct us the same day. We will not delete, disclose or alter another business's customer record because a stranger asked us to, and that refusal protects you as much as it protects them.
4What we actually hold today
Written in the present tense, because all of it is true today.
| Category | Fields | Where it comes from | Why we have it | How long |
|---|---|---|---|---|
| Correspondence | Your email address, your name if you sign it, whatever you chose to write, and any attachment | You, when you write to us | To read it and answer it. There is no other purpose | 24 months from the last message in the thread, then deleted |
| Website request logs | IP address, timestamp, the page requested, the referring page if your browser sent one, and the user agent string | Generated automatically by the hosting provider when your browser fetches a page | Keeping the site available and diagnosing faults and abuse | Retained by the hosting provider on its own short rolling cycle. We do not copy these into any system of our own |
| Domain and mailbox administration | Login records for the accounts that run the domain and the mailbox | Generated when we sign in | Detecting unauthorised access to the two accounts that matter | Kept by the provider for its own security period |
What is not on that list
- No analytics. No page view counter, no heat map, no session recording, no A/B testing tool.
- No advertising, no advertising identifiers, no conversion pixels and no remarketing tags.
- No cookies set by this website. The cookie notice explains the position in detail.
- No customer database, because there are no customers.
- No call recordings, no transcripts and no phone numbers, because nothing answers a phone yet.
- No mailing list. Writing to us does not add you to anything, because there is nothing to be added to.
This is the shortest a collection table gets, and we are aware that it will grow. When it does, this section is where the growth will show up, and the section that follows sets the limits we intend to hold it to.
5What the assistant would collect, and what it would refuse
Written in the conditional, because none of it exists. Treat this section as a set of commitments about a product being designed rather than a description of one that runs.
Australian Privacy Principle 3, and the discipline it imposes
APP 3 says that an organisation must not collect personal information unless it is reasonably necessary for one or more of its functions or activities, and that it must collect it by lawful and fair means and, where reasonable and practicable, from the individual concerned. That is a genuine constraint on a product like this one, because the temptation in a phone assistant is to keep everything the caller said in case it turns out to be useful. Reasonably necessary is a narrower test than useful.
| Category | Fields | Whose it is | Why it would be needed | Planned retention |
|---|---|---|---|---|
| Caller identity | Given name, and a surname only if the caller offers one | The trades business's | So the tradesperson knows who is expecting them | Kept by the trades business in its own diary. Deleted from our systems 30 days after the job date |
| Callback number | The number dialled from, or a different number the caller gives | The trades business's | So somebody can ring back, and so a confirmation text can be sent | Deleted from our systems 30 days after the job date |
| Job location | Suburb, and a street address only where the caller gives one for a booking | The trades business's | So the tradesperson can judge travel and turn up at the right place | Deleted from our systems 30 days after the job date |
| What the caller said | A short transcript of the caller's own description of the problem | The trades business's | Because a summary written by software loses the detail that decides how urgent a job is | Deleted from our systems 30 days after the job date |
| Call audio | The recording itself, only where the trades business has turned recording on and its callers have been told | The trades business's | Quality and dispute resolution, at the choice of the trades business | Deleted on a period the trades business sets, with a ceiling we would impose rather than leave open |
| Diary availability | Free and busy times read from the calendar the trades business already uses | The trades business's | So an offered time is real | Read at the moment of the call. Not stored beyond the call |
| Account record | Business name, contact person, email address, plan, billing records | Ours | To run the account and meet tax and record keeping obligations | 7 years for records with a tax character, 24 months for the rest |
| Fault diagnostics | Error codes, timings, and whether a call completed | Ours | To find out why something broke | 90 days |
What it would refuse to collect, by design
- No payment details. No card numbers, no bank details, no deposits taken over the phone. The assistant would end the call rather than accept a card number.
- No government related identifiers. No driver licence, no Medicare number, no tax file number. See the section on Australian Privacy Principle 9 below.
- No sensitive information as defined in section 6 of the Privacy Act. Health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record are all outside the scope of a booking. If a caller volunteers something in that class while describing a job, it would not be indexed, and the transcript rules would treat it as material to strip rather than to keep.
- No profile of a caller across different trades businesses. Two plumbers using Andy would not share a view of the same caller. There would be no cross business identifier at all, which is the only reliable way to make that promise true rather than merely policy.
- No contact list access. The assistant would not read the tradesperson's phone contacts, photos, messages or location.
The 30 day figure in the table is deliberate and it is short. The trades business keeps the job in its own diary, which is where a customer record belongs. Our copy exists to make the booking happen and to fix it if it goes wrong, and after a month it is neither of those things. It is just risk.
6If you are the person who rang a trades business
This section is addressed to you if you rang a trades business, got an automated voice, and want to know where you stand. It is written on the assumption that you did not choose any of this and had no interest in it.
The short version
Nothing has been built, so today the answer is that no call has ever been handled and nothing about you exists here. If that changes, the answers below are the ones we intend to be held to.
You will be told
Andy would say what it is in its first sentence, on every call, without being asked. Not a name that sounds like a person, not an evasion, and not a disclosure buried at the end. If you would rather speak to a human, saying so should end the automated part of the call and get a message to the tradesperson.
Who has your details
The business you rang. They asked for the call to be answered, they decide what happens to what you said, and they are the one with a relationship with you. We would be holding it for them, under instruction. That is set out in full in the section on the two roles above.
What to do if you want something changed or deleted
- Ask the business you rang. They can tell us the same day and we act on it. This is the fastest route and it is the one that also clears their own records, which we cannot reach.
- If that fails, write to us at hello@andyai.link. We would tell you what we hold that relates to your call, and we would put the request to the trades business. What we will not do is delete another business's customer record on the word of somebody we cannot verify, because doing that on request is itself an attack.
- If you get nowhere, complain. To us, and then to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. You can also complain about the trades business directly, and if their turnover is over the section 6D threshold they are bound by the Act in their own right.
Recording
Whether a call is recorded would be the choice of the trades business, and recording law in Australia is state law rather than Commonwealth law. Where recording is on, the assistant would say so before anything is recorded, and we would not offer a trades business a way to turn the announcement off. A product that lets a customer record silently is a product that has decided the customer's convenience outweighs your rights, and we would rather lose that customer.
What would never happen
- We would never ring you, text you or email you about anything of our own.
- We would never pass your details to a different trade, a lead broker, a comparison site or an advertiser.
- We would never use the fact that you rang about a burst pipe to target you with anything.
7Telling you at the point of collection
Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. The list includes who we are, how to contact us, the purposes of collection, the consequences of not providing the information, who we usually disclose it to, and whether it is likely to go overseas.
How that obligation is met today
There are only two collection points, and each carries its own notice.
- This website. Every page links to this policy from the footer, and the cookie notice sets out what a page request causes to happen. Nothing on this site asks you for anything.
- The mailbox. When you email us you are choosing what to send. What happens next is in the collection table above, including the 24 month figure and the fact that nobody else receives it.
How it would be met by the assistant
APP 5 becomes much harder on a phone call, because there is no page to link and the person has not chosen to deal with us at all. Our position on the four things that would have to be said out loud, in the first few seconds:
- That the caller is speaking to an automated assistant.
- Which business it is answering for, by name.
- That the details will be passed to that business.
- Whether the call is being recorded, before anything is recorded.
Longer detail cannot be read out on a phone call without the caller hanging up, which would satisfy nobody. The rest would be reachable in the confirmation text, which would carry a link to the trades business's own privacy information, and a caller who asks for more on the call should get a person rather than a recital.
Consequences of not providing information
APP 5 also requires us to say what happens if you do not provide something. Today, if you do not email us, nothing happens and we never learn you existed. On a call, a caller who declines to give a number cannot be rung back, and a caller who declines to say what the job is cannot be given a realistic time. Neither refusal would end the call, and the message to the tradesperson would say what was not given rather than guessing at it.
8Dealing with us anonymously
Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.
There is nothing on this website that asks who you are. No account, no form, no sign up, no comment field. You can read every page, including this one, without giving us anything, and we would not know you had.
Email is the one place where an address necessarily comes with the message, and a pseudonymous address is perfectly acceptable. We will answer a question from an obviously invented address on exactly the same terms as one from a company domain, and we will not ask who you really are.
Where the option genuinely falls away is a request to access or correct personal information. To answer that we have to be satisfied you are the person the information is about, which is dealt with in the access and correction section below. The practical effect for a pseudonymous correspondent is that the only thing we can match you against is the address you wrote from, and we will say so rather than pretend to a confidence we do not have.
On the assistant, a caller who declines to give a name would still get a booking if they give a number, because a tradesperson can work with that. Anonymity is harder on a phone call than on a website, but "the caller would not say" is a legitimate entry in a diary and the design treats it as one.
9Information we did not ask for
Australian Privacy Principle 4 deals with personal information we receive without having asked for it.
The way it would happen here is somebody forwarding us a voicemail, a screenshot of a message thread, or a photograph of a job sheet with a customer's name and address on it, in order to explain a problem. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.
10Use and disclosure
Australian Privacy Principle 6 governs what we may do with personal information once we hold it. Information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.
What we use it for today
- Reading your email and answering it.
- Keeping the website up and finding out why something broke.
- Meeting a legal obligation where one applies.
That is the complete list. There is no analytics use, no marketing use and no research use, because there is nothing to analyse, nobody to market to and no product to research for.
What the assistant would use it for
- Answering the call and taking the details.
- Reading the diary and offering a time that is genuinely free.
- Sending the caller the confirmation the tradesperson asked us to send.
- Writing the booking into the tradesperson's own calendar.
- Sending the tradesperson the summary of what happened.
- Diagnosing a fault, using the smallest slice of information that shows the fault.
What we would not do, in either role
- We do not sell personal information. Not to data brokers, not to advertisers, not as an audience product, and not as part of a sale of the business without the obligations in this policy travelling with it.
- We would not train a general purpose model on your callers. Where machine learning is used to make the assistant better at hearing Australian speech, it would run on material that has been de-identified first, and any trades business would be able to say no to even that.
- We would not build a cross business profile. There would be no shared identifier for a caller, so the profile would have nowhere to live.
- We would not use one trade's callers to sell to another trade. No "businesses near you", no coverage maps built from real jobs, no industry reports assembled out of somebody's customer base.
- We do not use your correspondence with us to target anything, because we do not target anything.
Disclosure to law enforcement and courts
We may disclose personal information where the Act permits it. That means where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists, including a serious threat to life, health or safety, or where an enforcement body reasonably needs it for an enforcement related activity.
Where we make such a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where we would be acting as processor for a trades business, we would also tell that business unless the law forbids it, because it is their customer's information and they may want to contest the request. Where the law allows us to tell the individual, we will.
We do not have a standing arrangement with any agency, we do not offer a self service portal for requests, and we would require lawful process rather than a polite email on letterhead.
11Direct marketing and the Spam Act
Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime. It requires consent, accurate identification of the sender, and a functional unsubscribe facility that remains live for at least 30 days and is actioned within 5 working days. The Do Not Call Register Act 2006 (Cth) covers unsolicited telemarketing calls, which we do not make.
Where we stand
We do not run a marketing list. No marketing email has ever been sent under this company name, and there is no list to send one to. Writing to our address does not subscribe you to anything. That is worth saying explicitly, because quietly treating an inbound enquiry as consent is the most common way a small company builds a list it is not entitled to.
If that ever changes, it will be opt in, the consent will be recorded with a timestamp and the exact wording agreed to, every message will identify ANDY AI PTY LTD as the sender, and the first message will say where the address came from.
Transactional messages are not marketing
If Andy is released, a caller would receive a confirmation text and a tradesperson would receive an end of day summary. Neither is a commercial electronic message for the purposes of the Spam Act, because neither is offering to supply anything. They are the thing that was asked for. We would not attach a promotion to either of them, which is the point at which a transactional message becomes marketing and the consent question comes back.
Marketing to a caller is out of the question
A person who rang a plumber has no relationship with us at all. We would never market to them, never pass their number to anybody who would, and never treat the fact of the call as a lead. The assistant is not a customer acquisition channel for this company, and any version of it that became one would have stopped being the product described on this site.
Opting out
Since there is nothing to opt out of, the only meaningful control is the one you already have. Tell us to stop writing to you and we will, permanently, and we will keep the smallest possible record of that instruction so that it can be honoured.
12Who else can reach it, and where they are
The shortest way to keep a supplier list honest is to name every supplier that could touch personal information, rather than to describe them as trusted partners. The list below is complete as at the effective date of this policy.
| Supplier | What they do for us | What they can reach | Where |
|---|---|---|---|
| Domain registrar | Holds the registration of the domain name | Our own administrative contact details. No visitor or correspondent information | United States |
| DNS and website host | Serves the pages of this website through a global network | Request logs, which include visitor IP addresses, for a short period | Global network with points of presence in Australia and elsewhere |
| Mailbox provider | Runs the mailbox behind the published address | Everything you email us, for as long as the thread is retained | United States, with storage regions that may include Australia |
What is deliberately absent from that table
No analytics provider. No advertising network. No customer relationship management system. No support desk product. No newsletter platform. No payment processor, because nothing is sold. No artificial intelligence provider, because nothing yet sends anything to one. Each of those would be an entry in the table on the day it became true, and we would update the table before turning the thing on rather than afterwards.
Suppliers the assistant would need
A released product could not run on three suppliers. It would need, at minimum, a telephony provider to carry the call, a speech provider to turn audio into text, a language model provider to conduct the conversation, and a cloud provider to run the rest. Every one of those would be named in this table with what it can reach and where it is, before a single real call is handled. We would also state which of them process in Australia and which do not, because for call audio that is a question a trades business will reasonably want answered before signing anything.
Other recipients
- Professional advisers. An accountant or a solicitor, bound by their own professional duties, where a matter genuinely requires it.
- Regulators and courts, as set out in the use and disclosure section.
- A buyer of the business. If the company is ever sold, personal information may transfer as part of it. Where we were acting as a processor, the obligations in the two roles section would transfer with the information, and the trades business would be told before the transfer rather than after.
There are no other recipients. We have no affiliates, no group companies, no resellers and no partners.
13Sending personal information overseas
Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.
We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".
How we meet APP 8
Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.
We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.
Where the data actually goes
The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.
14Government related identifiers
Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.
We do not collect any government related identifier. We have no reason to, nothing being built has an age check or an identity check that would need one, and no field in any system we operate is intended to hold one.
If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.
This is a live question for something that answers a telephone, because callers volunteer things nobody asked for. A caller reading out a Medicare number to prove who they are, or quoting a licence number to explain a job, is not far fetched. The assistant would never prompt for any of it, would not index it, and the transcript rules described earlier treat that class of material as something to strip rather than to keep.
15Keeping information accurate
Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.
Almost everything we hold today is something a person chose to write to us, so it is accurate in the narrow sense that it faithfully records what was sent. What goes stale is the address itself, because people change jobs and close accounts. We do not periodically re-verify addresses, since doing so would mean writing to people who have finished dealing with us.
Accuracy is a much harder problem for a phone assistant, and it belongs here rather than buried in the section on automated decisions. A transcript records what was heard, which is not always what was said. The design answer is that the tradesperson would see the caller's own words and not only a summary, that the confirmation text gives a caller the chance to correct a wrong number before anybody drives anywhere, and that a caller who says an address is wrong should have it fixed rather than argued with.
The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.
16Security, and what we do not have
Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.
What "reasonable steps" means for a company this size
- Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address is carried over TLS wherever the sending server offers it.
- Encryption at rest for stored data, provided by the underlying platform.
- Multi-factor authentication on every administrative account that exists, which today means the domain registration, the mailbox and the hosting account. There is no fourth one.
- Access on a need to know basis. The number of people who can reach the mailbox is small, and it is reviewed whenever anybody joins or leaves.
- Nothing running to breach. There is no application, no account system, no customer database and no administrative console behind this site, so what has to be defended is a set of static files, one mailbox and two supplier accounts.
- Collecting less. The most reliable security control available to a company of this size is not holding the data at all, which is why the collection tables above are as short as they are.
What we do not have, stated plainly
ANDY AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.
We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.
What would have to be true before a single real call is handled
Call audio and transcripts are a different class of risk from an inbox, and the controls above are not sufficient for them. Before Andy handles any real call, the following would have to be in place, and this list is a commitment rather than a description.
- Encryption in transit and at rest for audio and transcripts, with keys held separately from the data.
- Separation between one trades business's information and another's, enforced by the system rather than by a query that remembers to filter.
- A hard retention job that deletes on schedule without anybody remembering to run it, because a retention promise that depends on a person is not a control.
- An access log for any occasion on which a human at this company looks at a call, and a reason recorded next to it.
- An external review of the design by somebody who does not work here.
None of that exists today, because there is nothing to protect yet. If it does not exist on the day it is needed, the correct decision is to delay the product rather than to launch and add it afterwards.
17How long anything is kept
Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed under the Australian Privacy Principles, unless it is contained in a Commonwealth record or we are required by law to keep it. Retention is therefore not a matter of preference. A retention period that is longer than the purpose is a breach, not a habit.
| Category | Period | Why that period |
|---|---|---|
| Email correspondence | 24 months from the last message in the thread | Long enough to pick up a conversation that resumes a year later. Short enough that an old enquiry does not sit in a mailbox for a decade |
| Correspondence that becomes a legal matter | 7 years | The general limitation period for contract actions in South Australia is 6 years, and we round up rather than cut it fine |
| Website request logs | The hosting provider's own short rolling period | We do not copy them anywhere, so the provider's cycle is the whole of it |
| Records with a tax character | 7 years | Section 262A of the Income Tax Assessment Act 1936 (Cth) requires records to be kept for 5 years, and the Corporations Act 2001 (Cth) requires financial records for 7. We apply the longer one |
| A privacy request and our answer | 3 years | So that we can show a request was answered, and so that a repeat request can be handled consistently |
| A record that somebody asked us never to contact them | Indefinitely, as the minimum needed to honour it | Deleting a suppression record is how a suppression fails |
| Call details, if the assistant is released | 30 days after the job date | Set out in the planned collection section. The trades business keeps its own diary; our copy exists to make the booking work |
| Call audio, if the assistant is released | A period the trades business sets, under a ceiling we impose | Recording is their decision, but an unbounded retention period is not one we would offer |
What deletion actually means here
Deleted means removed from the live system, and then removed from backups as those backups age out of their own rotation rather than being surgically edited. This is the honest position for a company of this size, and the alternative claim, that a single record can be plucked out of every historical backup on demand, is usually untrue when a small company makes it. A record sitting in a backup is not used, not searched and not disclosed, and it goes when the backup goes.
18Access and correction
Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.
How to ask
Email hello@andyai.link with "Privacy request" in the subject line. Tell us what you want and give us enough to find it. Today the only thing we could hold about you is correspondence, so the address you wrote from is the whole of what we can match against. If the assistant is running and your request is about a call you made to a trades business, read the section on the two roles above first, because that request goes to the business rather than to us.
Verifying who you are
We have to be satisfied you are the person the information is about, or an authorised representative. Where a request relates to an account, we verify through the email address on the account. Where it relates only to an email address, possession of that address is what we can verify, and we will say so rather than pretend to a higher level of confidence. We will not ask you to send identity documents.
Timing and cost
We respond within 30 days. Access is free. We do not charge for making a request, and we do not charge for correction. If giving access in a particular form imposes a genuine cost, for example producing a bulk export in an unusual format, we will tell you the charge before doing the work and it will not be excessive.
When we can refuse
The Act lists the grounds, and they are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.
If we refuse, in whole or in part, we will give you written reasons, tell you which ground we rely on, and tell you how to complain. Where we can give you part of the information, or give it in another way that meets your need, we will offer that instead of a flat refusal.
Correction
If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed the information to someone else and you ask us to notify them of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful.
If we refuse to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we will take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is often overlooked and it is worth knowing about.
19Deleting what we hold
Deletion is dealt with separately from correction because people ask for it far more often, and because the answer depends on which of the two roles we would be in.
Where we are the controller
Write to hello@andyai.link with "Delete my data" in the subject line. Today that means the correspondence we hold from you, which is very likely all we have. We complete it within 30 days and confirm when it is done. There is no charge, no form and no requirement to explain why.
What survives is the smallest possible record that the deletion happened and, if you asked us not to contact you again, the fact of that instruction. Keeping that is the only way to honour it. Anything with a tax character stays for the period in the retention table, because we do not have a choice about that one.
Where we would be the processor
If the assistant is running and the request is about a call to a trades business, the instruction has to come from that business. Ask them. They can tell us the same day and we act on it. If they refuse or do not answer, write to us anyway and we will tell you what we hold that relates to your call and put the request to them ourselves. What we will not do is delete a business's customer record on the word of a person we cannot verify.
Where the whole relationship ends
If a trades business stops using Andy, everything of theirs goes. The account, the call details, any audio, the diagnostics tied to their account. We would do it within 30 days of the end of the relationship and confirm it in writing. We would not keep an anonymised copy as a training asset, which is the quiet exception most of this industry writes into its terms.
There is no dark pattern here to survive. No account to close through three screens, no retention offer, no "your data will be kept for 90 days in case you change your mind" unless you ask for exactly that. One email, 30 days, done.
20Children and young people
Neither this website nor the assistant is directed at children, and neither is designed to appeal to children. This is a business tool for people who own vans.
The Australian position
The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless there is something to suggest otherwise. We apply that presumption.
The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force. We are not going to guess at its terms in advance and write a paragraph that turns out to be wrong.
The realistic case
The situation that would actually arise is a child answering the phone, or ringing a plumber because a parent asked them to. The assistant would not ask a caller's age, and asking would be worse than not asking, because it would mean collecting a new category of information about every caller in order to protect a rare one. What it would do is take the same four ordinary details from any caller, which is the smallest thing that makes the booking work, and hand it to the tradesperson to sort out with the household.
If a child's information has reached us
Write to hello@andyai.link. We will delete it without requiring you to prove a legal relationship beyond what is needed to be satisfied that the request is genuine, and we will confirm when it is done.
21Automated decisions
The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026. This section is written in advance of that date rather than on it.
Today
Nothing is automated because nothing exists. No decision of any kind is made about anybody by any system this company runs.
What the assistant would decide, and what it would not
The assistant would decide things, and honesty requires saying which. It would decide which two times to offer, whether a call sounds urgent enough to hand straight to the tradesperson, and how to summarise what a caller said. Those are decisions and they can be wrong.
None of them meet the statutory threshold of significantly affecting a person's rights or interests. Nothing here decides whether somebody gets credit, a job, a benefit, housing, insurance or a legal entitlement. The worst outcome of a wrong decision is a booking at an inconvenient time or a message that undersells how bad a leak is, and both are recoverable by a person picking up a phone.
The commitments that go with that
- A caller could always ask for a person. Saying so on the call would stop the automated part of it.
- The tradesperson would see the caller's own words, not only the assistant's summary, so a bad summary can be caught.
- The urgency judgement would be recorded with the call, so a trades business can audit how often it was wrong in each direction.
- No caller would ever be refused a booking by the software on the basis of anything about them. It has no scoring of callers, and we would not add one.
If any of that changes, this section is where it would be described, and it would be described before the processing started rather than afterwards.
22Data breaches and the notification scheme
Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.
The process we follow
- Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
- Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
- Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
- Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.
What a notification will contain
Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.
If you think a breach has happened
Write to hello@andyai.link with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.
23The statutory tort of serious invasion of privacy
A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.
This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.
24Cookies on this website
This website sets no cookies of its own, uses no analytics, carries no advertising and shows no consent banner. The full explanation, including what the absence of a banner does and does not mean under Australian law, is in the cookie notice.
The short version is that two things reach beyond this page. The first is the request for the page itself, which reaches the hosting provider and appears in its logs. The second is the request for the two typefaces the pages use, which goes to Google's font servers and tells them your IP address and user agent. Both are named in the cookie notice, and the second one is a genuine trade off that is described there rather than glossed over.
Nothing on this site stores anything in your browser's local storage or session storage either, which is worth saying because "no cookies" has become a phrase people use while storing an identifier by another means.
25Complaints
Step one: tell us
Email hello@andyai.link with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.
Step two: the Commissioner
If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.
The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.
What we will not do
We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.
26If you are outside Australia
This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.
European Economic Area and United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Send any such request to hello@andyai.link and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.
California
Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising anywhere on this website, none is planned in the assistant, and there is therefore no sharing to opt out of. Global Privacy Control signals sent by your browser to this website are honoured.
Everywhere else
If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.
27Changes to this policy
We may change this policy. When we do, the effective date and the version number in the header of this page change with it.
Two changes are certain rather than possible. The first is the day the supplier table grows, because a working assistant needs telephony and speech processing that we do not have today. The second is the day the collection tables move from the conditional into the present tense. Both are the kind of change that has to be visible.
Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect, by putting a note at the top of this page for at least 30 days and, if there are customers by then, by writing to them. We will not make a material change effective retrospectively, and we will not treat continued use of a website that asks nothing of you as consent to anything.
Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.
This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances. A trades business considering software that handles its customers' details should get its own advice rather than relying on a supplier's policy, including this one.
28How to contact us
All privacy matters reach one address.
| Matter | Subject line | Response |
|---|---|---|
| Access to your personal information (APP 12) | Privacy request | 30 days |
| Correction of your personal information (APP 13) | Privacy request | 30 days |
| Deletion of the information we hold about you | Delete my data | 30 days |
| Complaint about our handling of personal information | Privacy complaint | Acknowledged in 5 business days, answered in 30 days |
| Suspected security incident or data breach | Security | Same or next business day |
| Anything else | Anything sensible | 5 business days |
Email: hello@andyai.link
Entity: ANDY AI PTY LTD, ACN 697 510 562, ABN 72 697 510 562, an Australian proprietary company, South Australia.
We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 697 510 562 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.
If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.