Skip to main content

Privacy

Privacy policy

What this company holds today, what the assistant would collect if it is released, whose information is whose, how long anything is kept, and how to make us delete it.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who we are, and what this policy covers

This is the privacy policy of ANDY AI PTY LTD, ACN 697 510 562, ABN 72 697 510 562, an Australian proprietary company registered in South Australia. In this document "we", "us" and "our" mean that company. "Andy" is the name of the scheduling assistant the company is building, and it is a trading name of the same entity rather than a separate business.

The unusual thing about this policy, said first

Most privacy policies describe a product that exists. This one mostly describes a product that does not. The company was registered in 2026, has released no software, has no users and has no customers. The only personal information it actually holds today is the contents of its mailbox and the ordinary logs kept by the company that serves this website.

We could have waited until there was something to describe. We are not doing that, for two reasons. The first is that the rules for handling a caller's phone number are much easier to fix before any code depends on them. The second is that a policy written in advance can be held against us afterwards, and a policy written after the fact usually describes whatever was built.

So this document is in two halves that are kept clearly apart. Sections about what we hold today are written in the present tense and are true now. Sections about what Andy would collect are written in the conditional, and they are commitments about a product that does not exist yet rather than descriptions of one that does.

Who this policy is for

  • Visitors to andyai.link. Covered in full, and there is very little to cover.
  • Anybody who emails us. Covered in full.
  • Trades businesses who would one day use Andy. Covered in the conditional sections.
  • People who ring a trades business and end up speaking to Andy. Covered in its own section, because the answer for you is genuinely different and it is the section most policies would leave out.

What this policy does not cover

It does not cover the practices of any trades business that might one day use Andy. Each of those is a separate business making its own decisions about its own customers, and it has its own obligations under the Privacy Act 1988 (Cth) or, if it is a small business under the section 6D threshold, its own choice about whether to act as though the Act applies. It does not cover websites we link to. It does not cover your telephone carrier, which handles the call before anything of ours sees it.

2The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. ANDY AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

3Two roles, and which one we would be in

This is the most important section in the document, which is why it comes before the collection tables rather than after them.

Two roles, and the words for them

Australian privacy law does not divide the world into "controllers" and "processors" the way European law does. The Privacy Act asks whether an entity holds personal information and whether it is an APP entity, and it can catch you either way. But the distinction those two words describe is real, it decides who you should be talking to when you want something done, and Australian law gives us no better pair of words for it. So we use them, and we say plainly that we are borrowing them.

  • A controller decides why personal information is collected and what happens to it.
  • A processor holds it and acts on somebody else's instructions.

The same company can be both at once, for different information, and we would be. Getting this wrong is how a small software company ends up quietly treating its customers' customers as its own audience, and that is exactly the failure this section exists to prevent.

Where we would be the controller

We decide the purpose, so the responsibility is ours and you deal with us directly.

  • The email address and message of anybody who writes to hello@andyai.link.
  • The server log entries generated by a visit to this website.
  • If Andy is ever released, the account details of the trades business itself. The name of the business, the person we deal with, the contact address, the billing details and the record of which plan is in use.
  • Aggregate counts about how the software performs, such as how many calls failed to complete, where those counts are not tied back to an individual.

Where we would be the processor

This is the part that matters. If Andy answers a call for a plumber, everything the caller says belongs to the relationship between that caller and that plumber. The plumber decides why it is collected and what happens to it. We would only be holding it in order to do the thing the plumber asked for.

  • The caller's name.
  • The number they rang from, or the number they ask to be called back on.
  • The address or suburb of the job.
  • What they said was wrong, in their own words.
  • Any recording or transcript of the call, where the trades business has chosen to keep one and has told its callers so.
  • The time that was offered and whether it was accepted.

None of that is ours. We would not use it to improve a service for a different trades business unless it had been genuinely de-identified first, we would not use it to build a directory, and we would never approach the caller ourselves about anything.

The two roles applied to real categories of information
InformationWhose customer is it aboutOur roleWho you ask about it
A visitor's IP address in a server logOursControllerUs
An email you send usOursControllerUs
A trades business account and its billing detailsOursControllerUs
A caller's name and phone numberThe trades business'sProcessorThe business you rang, who then instructs us
A caller's description of the jobThe trades business'sProcessorThe business you rang
A recording or transcript of a callThe trades business'sProcessorThe business you rang
A calendar entry written into the trade's diaryThe trades business'sProcessorThe business you rang
Counts of how often the software failed to understand a callerNobody's, once aggregatedControllerUs

What being a processor would commit us to

These are the terms we would put in the contract with a trades business, written here so that a caller can read them without being a party to it.

  1. We act on the trades business's documented instructions and on nothing else, except where an Australian law requires otherwise, in which case we tell them unless the law forbids it.
  2. We do not use call information for our own purposes. Not for advertising, not for a lead product, not for training a general model that is offered to anybody else.
  3. We help the trades business answer an access, correction or deletion request from one of its callers, within a timeframe that lets them meet their own 30 day obligation.
  4. We tell the trades business about a suspected data breach affecting their callers without undue delay, so that they can meet their own obligations under Part IIIC of the Privacy Act.
  5. On the day the relationship ends, we return or delete the call information. We do not keep a copy as an asset.
  6. We do not engage a further supplier who touches call information without telling the trades business first and binding that supplier to the same terms.

What the trades business would be responsible for

The other half of the split, said out loud because callers are entitled to know who to hold to it. A business using Andy would be responsible for telling its own callers what happens on the call, including whether it is recorded, for having a lawful basis for anything it asks Andy to collect beyond the four ordinary details, for answering its callers' requests about their information, and for its own privacy policy. We would give it the tools and the record it needs to do all of that. We cannot do it for them, and a software company that pretends otherwise is selling comfort rather than compliance.

If you are a caller and you want something done about your details, ask the business you rang first. They decide, and they can instruct us the same day. We will not delete, disclose or alter another business's customer record because a stranger asked us to, and that refusal protects you as much as it protects them.

4What we actually hold today

Written in the present tense, because all of it is true today.

Everything ANDY AI PTY LTD actually holds as at the effective date of this policy
CategoryFieldsWhere it comes fromWhy we have itHow long
CorrespondenceYour email address, your name if you sign it, whatever you chose to write, and any attachmentYou, when you write to usTo read it and answer it. There is no other purpose24 months from the last message in the thread, then deleted
Website request logsIP address, timestamp, the page requested, the referring page if your browser sent one, and the user agent stringGenerated automatically by the hosting provider when your browser fetches a pageKeeping the site available and diagnosing faults and abuseRetained by the hosting provider on its own short rolling cycle. We do not copy these into any system of our own
Domain and mailbox administrationLogin records for the accounts that run the domain and the mailboxGenerated when we sign inDetecting unauthorised access to the two accounts that matterKept by the provider for its own security period

What is not on that list

  • No analytics. No page view counter, no heat map, no session recording, no A/B testing tool.
  • No advertising, no advertising identifiers, no conversion pixels and no remarketing tags.
  • No cookies set by this website. The cookie notice explains the position in detail.
  • No customer database, because there are no customers.
  • No call recordings, no transcripts and no phone numbers, because nothing answers a phone yet.
  • No mailing list. Writing to us does not add you to anything, because there is nothing to be added to.

This is the shortest a collection table gets, and we are aware that it will grow. When it does, this section is where the growth will show up, and the section that follows sets the limits we intend to hold it to.

5What the assistant would collect, and what it would refuse

Written in the conditional, because none of it exists. Treat this section as a set of commitments about a product being designed rather than a description of one that runs.

Australian Privacy Principle 3, and the discipline it imposes

APP 3 says that an organisation must not collect personal information unless it is reasonably necessary for one or more of its functions or activities, and that it must collect it by lawful and fair means and, where reasonable and practicable, from the individual concerned. That is a genuine constraint on a product like this one, because the temptation in a phone assistant is to keep everything the caller said in case it turns out to be useful. Reasonably necessary is a narrower test than useful.

What the assistant would collect if it is released, and what it would refuse to collect
CategoryFieldsWhose it isWhy it would be neededPlanned retention
Caller identityGiven name, and a surname only if the caller offers oneThe trades business'sSo the tradesperson knows who is expecting themKept by the trades business in its own diary. Deleted from our systems 30 days after the job date
Callback numberThe number dialled from, or a different number the caller givesThe trades business'sSo somebody can ring back, and so a confirmation text can be sentDeleted from our systems 30 days after the job date
Job locationSuburb, and a street address only where the caller gives one for a bookingThe trades business'sSo the tradesperson can judge travel and turn up at the right placeDeleted from our systems 30 days after the job date
What the caller saidA short transcript of the caller's own description of the problemThe trades business'sBecause a summary written by software loses the detail that decides how urgent a job isDeleted from our systems 30 days after the job date
Call audioThe recording itself, only where the trades business has turned recording on and its callers have been toldThe trades business'sQuality and dispute resolution, at the choice of the trades businessDeleted on a period the trades business sets, with a ceiling we would impose rather than leave open
Diary availabilityFree and busy times read from the calendar the trades business already usesThe trades business'sSo an offered time is realRead at the moment of the call. Not stored beyond the call
Account recordBusiness name, contact person, email address, plan, billing recordsOursTo run the account and meet tax and record keeping obligations7 years for records with a tax character, 24 months for the rest
Fault diagnosticsError codes, timings, and whether a call completedOursTo find out why something broke90 days

What it would refuse to collect, by design

  • No payment details. No card numbers, no bank details, no deposits taken over the phone. The assistant would end the call rather than accept a card number.
  • No government related identifiers. No driver licence, no Medicare number, no tax file number. See the section on Australian Privacy Principle 9 below.
  • No sensitive information as defined in section 6 of the Privacy Act. Health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation and criminal record are all outside the scope of a booking. If a caller volunteers something in that class while describing a job, it would not be indexed, and the transcript rules would treat it as material to strip rather than to keep.
  • No profile of a caller across different trades businesses. Two plumbers using Andy would not share a view of the same caller. There would be no cross business identifier at all, which is the only reliable way to make that promise true rather than merely policy.
  • No contact list access. The assistant would not read the tradesperson's phone contacts, photos, messages or location.

The 30 day figure in the table is deliberate and it is short. The trades business keeps the job in its own diary, which is where a customer record belongs. Our copy exists to make the booking happen and to fix it if it goes wrong, and after a month it is neither of those things. It is just risk.

6If you are the person who rang a trades business

This section is addressed to you if you rang a trades business, got an automated voice, and want to know where you stand. It is written on the assumption that you did not choose any of this and had no interest in it.

The short version

Nothing has been built, so today the answer is that no call has ever been handled and nothing about you exists here. If that changes, the answers below are the ones we intend to be held to.

You will be told

Andy would say what it is in its first sentence, on every call, without being asked. Not a name that sounds like a person, not an evasion, and not a disclosure buried at the end. If you would rather speak to a human, saying so should end the automated part of the call and get a message to the tradesperson.

Who has your details

The business you rang. They asked for the call to be answered, they decide what happens to what you said, and they are the one with a relationship with you. We would be holding it for them, under instruction. That is set out in full in the section on the two roles above.

What to do if you want something changed or deleted

  1. Ask the business you rang. They can tell us the same day and we act on it. This is the fastest route and it is the one that also clears their own records, which we cannot reach.
  2. If that fails, write to us at hello@andyai.link. We would tell you what we hold that relates to your call, and we would put the request to the trades business. What we will not do is delete another business's customer record on the word of somebody we cannot verify, because doing that on request is itself an attack.
  3. If you get nowhere, complain. To us, and then to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. You can also complain about the trades business directly, and if their turnover is over the section 6D threshold they are bound by the Act in their own right.

Recording

Whether a call is recorded would be the choice of the trades business, and recording law in Australia is state law rather than Commonwealth law. Where recording is on, the assistant would say so before anything is recorded, and we would not offer a trades business a way to turn the announcement off. A product that lets a customer record silently is a product that has decided the customer's convenience outweighs your rights, and we would rather lose that customer.

What would never happen

  • We would never ring you, text you or email you about anything of our own.
  • We would never pass your details to a different trade, a lead broker, a comparison site or an advertiser.
  • We would never use the fact that you rang about a burst pipe to target you with anything.

7Telling you at the point of collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. The list includes who we are, how to contact us, the purposes of collection, the consequences of not providing the information, who we usually disclose it to, and whether it is likely to go overseas.

How that obligation is met today

There are only two collection points, and each carries its own notice.

  • This website. Every page links to this policy from the footer, and the cookie notice sets out what a page request causes to happen. Nothing on this site asks you for anything.
  • The mailbox. When you email us you are choosing what to send. What happens next is in the collection table above, including the 24 month figure and the fact that nobody else receives it.

How it would be met by the assistant

APP 5 becomes much harder on a phone call, because there is no page to link and the person has not chosen to deal with us at all. Our position on the four things that would have to be said out loud, in the first few seconds:

  1. That the caller is speaking to an automated assistant.
  2. Which business it is answering for, by name.
  3. That the details will be passed to that business.
  4. Whether the call is being recorded, before anything is recorded.

Longer detail cannot be read out on a phone call without the caller hanging up, which would satisfy nobody. The rest would be reachable in the confirmation text, which would carry a link to the trades business's own privacy information, and a caller who asks for more on the call should get a person rather than a recital.

Consequences of not providing information

APP 5 also requires us to say what happens if you do not provide something. Today, if you do not email us, nothing happens and we never learn you existed. On a call, a caller who declines to give a number cannot be rung back, and a caller who declines to say what the job is cannot be given a realistic time. Neither refusal would end the call, and the message to the tradesperson would say what was not given rather than guessing at it.

8Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

There is nothing on this website that asks who you are. No account, no form, no sign up, no comment field. You can read every page, including this one, without giving us anything, and we would not know you had.

Email is the one place where an address necessarily comes with the message, and a pseudonymous address is perfectly acceptable. We will answer a question from an obviously invented address on exactly the same terms as one from a company domain, and we will not ask who you really are.

Where the option genuinely falls away is a request to access or correct personal information. To answer that we have to be satisfied you are the person the information is about, which is dealt with in the access and correction section below. The practical effect for a pseudonymous correspondent is that the only thing we can match you against is the address you wrote from, and we will say so rather than pretend to a confidence we do not have.

On the assistant, a caller who declines to give a name would still get a booking if they give a number, because a tradesperson can work with that. Anonymity is harder on a phone call than on a website, but "the caller would not say" is a legitimate entry in a diary and the design treats it as one.

9Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

The way it would happen here is somebody forwarding us a voicemail, a screenshot of a message thread, or a photograph of a job sheet with a customer's name and address on it, in order to explain a problem. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.

10Use and disclosure

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. Information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.

What we use it for today

  • Reading your email and answering it.
  • Keeping the website up and finding out why something broke.
  • Meeting a legal obligation where one applies.

That is the complete list. There is no analytics use, no marketing use and no research use, because there is nothing to analyse, nobody to market to and no product to research for.

What the assistant would use it for

  • Answering the call and taking the details.
  • Reading the diary and offering a time that is genuinely free.
  • Sending the caller the confirmation the tradesperson asked us to send.
  • Writing the booking into the tradesperson's own calendar.
  • Sending the tradesperson the summary of what happened.
  • Diagnosing a fault, using the smallest slice of information that shows the fault.

What we would not do, in either role

  • We do not sell personal information. Not to data brokers, not to advertisers, not as an audience product, and not as part of a sale of the business without the obligations in this policy travelling with it.
  • We would not train a general purpose model on your callers. Where machine learning is used to make the assistant better at hearing Australian speech, it would run on material that has been de-identified first, and any trades business would be able to say no to even that.
  • We would not build a cross business profile. There would be no shared identifier for a caller, so the profile would have nowhere to live.
  • We would not use one trade's callers to sell to another trade. No "businesses near you", no coverage maps built from real jobs, no industry reports assembled out of somebody's customer base.
  • We do not use your correspondence with us to target anything, because we do not target anything.

Disclosure to law enforcement and courts

We may disclose personal information where the Act permits it. That means where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists, including a serious threat to life, health or safety, or where an enforcement body reasonably needs it for an enforcement related activity.

Where we make such a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where we would be acting as processor for a trades business, we would also tell that business unless the law forbids it, because it is their customer's information and they may want to contest the request. Where the law allows us to tell the individual, we will.

We do not have a standing arrangement with any agency, we do not offer a self service portal for requests, and we would require lawful process rather than a polite email on letterhead.

11Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime. It requires consent, accurate identification of the sender, and a functional unsubscribe facility that remains live for at least 30 days and is actioned within 5 working days. The Do Not Call Register Act 2006 (Cth) covers unsolicited telemarketing calls, which we do not make.

Where we stand

We do not run a marketing list. No marketing email has ever been sent under this company name, and there is no list to send one to. Writing to our address does not subscribe you to anything. That is worth saying explicitly, because quietly treating an inbound enquiry as consent is the most common way a small company builds a list it is not entitled to.

If that ever changes, it will be opt in, the consent will be recorded with a timestamp and the exact wording agreed to, every message will identify ANDY AI PTY LTD as the sender, and the first message will say where the address came from.

Transactional messages are not marketing

If Andy is released, a caller would receive a confirmation text and a tradesperson would receive an end of day summary. Neither is a commercial electronic message for the purposes of the Spam Act, because neither is offering to supply anything. They are the thing that was asked for. We would not attach a promotion to either of them, which is the point at which a transactional message becomes marketing and the consent question comes back.

Marketing to a caller is out of the question

A person who rang a plumber has no relationship with us at all. We would never market to them, never pass their number to anybody who would, and never treat the fact of the call as a lead. The assistant is not a customer acquisition channel for this company, and any version of it that became one would have stopped being the product described on this site.

Opting out

Since there is nothing to opt out of, the only meaningful control is the one you already have. Tell us to stop writing to you and we will, permanently, and we will keep the smallest possible record of that instruction so that it can be honoured.

12Who else can reach it, and where they are

The shortest way to keep a supplier list honest is to name every supplier that could touch personal information, rather than to describe them as trusted partners. The list below is complete as at the effective date of this policy.

Every supplier that can reach personal information today
SupplierWhat they do for usWhat they can reachWhere
Domain registrarHolds the registration of the domain nameOur own administrative contact details. No visitor or correspondent informationUnited States
DNS and website hostServes the pages of this website through a global networkRequest logs, which include visitor IP addresses, for a short periodGlobal network with points of presence in Australia and elsewhere
Mailbox providerRuns the mailbox behind the published addressEverything you email us, for as long as the thread is retainedUnited States, with storage regions that may include Australia

What is deliberately absent from that table

No analytics provider. No advertising network. No customer relationship management system. No support desk product. No newsletter platform. No payment processor, because nothing is sold. No artificial intelligence provider, because nothing yet sends anything to one. Each of those would be an entry in the table on the day it became true, and we would update the table before turning the thing on rather than afterwards.

Suppliers the assistant would need

A released product could not run on three suppliers. It would need, at minimum, a telephony provider to carry the call, a speech provider to turn audio into text, a language model provider to conduct the conversation, and a cloud provider to run the rest. Every one of those would be named in this table with what it can reach and where it is, before a single real call is handled. We would also state which of them process in Australia and which do not, because for call audio that is a question a trades business will reasonably want answered before signing anything.

Other recipients

  • Professional advisers. An accountant or a solicitor, bound by their own professional duties, where a matter genuinely requires it.
  • Regulators and courts, as set out in the use and disclosure section.
  • A buyer of the business. If the company is ever sold, personal information may transfer as part of it. Where we were acting as a processor, the obligations in the two roles section would transfer with the information, and the trades business would be told before the transfer rather than after.

There are no other recipients. We have no affiliates, no group companies, no resellers and no partners.

13Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

14Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, nothing being built has an age check or an identity check that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

This is a live question for something that answers a telephone, because callers volunteer things nobody asked for. A caller reading out a Medicare number to prove who they are, or quoting a licence number to explain a job, is not far fetched. The assistant would never prompt for any of it, would not index it, and the transcript rules described earlier treat that class of material as something to strip rather than to keep.

15Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Almost everything we hold today is something a person chose to write to us, so it is accurate in the narrow sense that it faithfully records what was sent. What goes stale is the address itself, because people change jobs and close accounts. We do not periodically re-verify addresses, since doing so would mean writing to people who have finished dealing with us.

Accuracy is a much harder problem for a phone assistant, and it belongs here rather than buried in the section on automated decisions. A transcript records what was heard, which is not always what was said. The design answer is that the tradesperson would see the caller's own words and not only a summary, that the confirmation text gives a caller the chance to correct a wrong number before anybody drives anywhere, and that a caller who says an address is wrong should have it fixed rather than argued with.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

16Security, and what we do not have

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address is carried over TLS wherever the sending server offers it.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every administrative account that exists, which today means the domain registration, the mailbox and the hosting account. There is no fourth one.
  • Access on a need to know basis. The number of people who can reach the mailbox is small, and it is reviewed whenever anybody joins or leaves.
  • Nothing running to breach. There is no application, no account system, no customer database and no administrative console behind this site, so what has to be defended is a set of static files, one mailbox and two supplier accounts.
  • Collecting less. The most reliable security control available to a company of this size is not holding the data at all, which is why the collection tables above are as short as they are.

What we do not have, stated plainly

ANDY AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

What would have to be true before a single real call is handled

Call audio and transcripts are a different class of risk from an inbox, and the controls above are not sufficient for them. Before Andy handles any real call, the following would have to be in place, and this list is a commitment rather than a description.

  • Encryption in transit and at rest for audio and transcripts, with keys held separately from the data.
  • Separation between one trades business's information and another's, enforced by the system rather than by a query that remembers to filter.
  • A hard retention job that deletes on schedule without anybody remembering to run it, because a retention promise that depends on a person is not a control.
  • An access log for any occasion on which a human at this company looks at a call, and a reason recorded next to it.
  • An external review of the design by somebody who does not work here.

None of that exists today, because there is nothing to protect yet. If it does not exist on the day it is needed, the correct decision is to delay the product rather than to launch and add it afterwards.

17How long anything is kept

Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed under the Australian Privacy Principles, unless it is contained in a Commonwealth record or we are required by law to keep it. Retention is therefore not a matter of preference. A retention period that is longer than the purpose is a breach, not a habit.

How long each category is kept, and the reason for each period
CategoryPeriodWhy that period
Email correspondence24 months from the last message in the threadLong enough to pick up a conversation that resumes a year later. Short enough that an old enquiry does not sit in a mailbox for a decade
Correspondence that becomes a legal matter7 yearsThe general limitation period for contract actions in South Australia is 6 years, and we round up rather than cut it fine
Website request logsThe hosting provider's own short rolling periodWe do not copy them anywhere, so the provider's cycle is the whole of it
Records with a tax character7 yearsSection 262A of the Income Tax Assessment Act 1936 (Cth) requires records to be kept for 5 years, and the Corporations Act 2001 (Cth) requires financial records for 7. We apply the longer one
A privacy request and our answer3 yearsSo that we can show a request was answered, and so that a repeat request can be handled consistently
A record that somebody asked us never to contact themIndefinitely, as the minimum needed to honour itDeleting a suppression record is how a suppression fails
Call details, if the assistant is released30 days after the job dateSet out in the planned collection section. The trades business keeps its own diary; our copy exists to make the booking work
Call audio, if the assistant is releasedA period the trades business sets, under a ceiling we imposeRecording is their decision, but an unbounded retention period is not one we would offer

What deletion actually means here

Deleted means removed from the live system, and then removed from backups as those backups age out of their own rotation rather than being surgically edited. This is the honest position for a company of this size, and the alternative claim, that a single record can be plucked out of every historical backup on demand, is usually untrue when a small company makes it. A record sitting in a backup is not used, not searched and not disclosed, and it goes when the backup goes.

18Access and correction

Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.

How to ask

Email hello@andyai.link with "Privacy request" in the subject line. Tell us what you want and give us enough to find it. Today the only thing we could hold about you is correspondence, so the address you wrote from is the whole of what we can match against. If the assistant is running and your request is about a call you made to a trades business, read the section on the two roles above first, because that request goes to the business rather than to us.

Verifying who you are

We have to be satisfied you are the person the information is about, or an authorised representative. Where a request relates to an account, we verify through the email address on the account. Where it relates only to an email address, possession of that address is what we can verify, and we will say so rather than pretend to a higher level of confidence. We will not ask you to send identity documents.

Timing and cost

We respond within 30 days. Access is free. We do not charge for making a request, and we do not charge for correction. If giving access in a particular form imposes a genuine cost, for example producing a bulk export in an unusual format, we will tell you the charge before doing the work and it will not be excessive.

When we can refuse

The Act lists the grounds, and they are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.

If we refuse, in whole or in part, we will give you written reasons, tell you which ground we rely on, and tell you how to complain. Where we can give you part of the information, or give it in another way that meets your need, we will offer that instead of a flat refusal.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed the information to someone else and you ask us to notify them of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful.

If we refuse to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we will take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is often overlooked and it is worth knowing about.

19Deleting what we hold

Deletion is dealt with separately from correction because people ask for it far more often, and because the answer depends on which of the two roles we would be in.

Where we are the controller

Write to hello@andyai.link with "Delete my data" in the subject line. Today that means the correspondence we hold from you, which is very likely all we have. We complete it within 30 days and confirm when it is done. There is no charge, no form and no requirement to explain why.

What survives is the smallest possible record that the deletion happened and, if you asked us not to contact you again, the fact of that instruction. Keeping that is the only way to honour it. Anything with a tax character stays for the period in the retention table, because we do not have a choice about that one.

Where we would be the processor

If the assistant is running and the request is about a call to a trades business, the instruction has to come from that business. Ask them. They can tell us the same day and we act on it. If they refuse or do not answer, write to us anyway and we will tell you what we hold that relates to your call and put the request to them ourselves. What we will not do is delete a business's customer record on the word of a person we cannot verify.

Where the whole relationship ends

If a trades business stops using Andy, everything of theirs goes. The account, the call details, any audio, the diagnostics tied to their account. We would do it within 30 days of the end of the relationship and confirm it in writing. We would not keep an anonymised copy as a training asset, which is the quiet exception most of this industry writes into its terms.

There is no dark pattern here to survive. No account to close through three screens, no retention offer, no "your data will be kept for 90 days in case you change your mind" unless you ask for exactly that. One email, 30 days, done.

20Children and young people

Neither this website nor the assistant is directed at children, and neither is designed to appeal to children. This is a business tool for people who own vans.

The Australian position

The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless there is something to suggest otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force. We are not going to guess at its terms in advance and write a paragraph that turns out to be wrong.

The realistic case

The situation that would actually arise is a child answering the phone, or ringing a plumber because a parent asked them to. The assistant would not ask a caller's age, and asking would be worse than not asking, because it would mean collecting a new category of information about every caller in order to protect a rare one. What it would do is take the same four ordinary details from any caller, which is the smallest thing that makes the booking work, and hand it to the tradesperson to sort out with the household.

If a child's information has reached us

Write to hello@andyai.link. We will delete it without requiring you to prove a legal relationship beyond what is needed to be satisfied that the request is genuine, and we will confirm when it is done.

21Automated decisions

The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026. This section is written in advance of that date rather than on it.

Today

Nothing is automated because nothing exists. No decision of any kind is made about anybody by any system this company runs.

What the assistant would decide, and what it would not

The assistant would decide things, and honesty requires saying which. It would decide which two times to offer, whether a call sounds urgent enough to hand straight to the tradesperson, and how to summarise what a caller said. Those are decisions and they can be wrong.

None of them meet the statutory threshold of significantly affecting a person's rights or interests. Nothing here decides whether somebody gets credit, a job, a benefit, housing, insurance or a legal entitlement. The worst outcome of a wrong decision is a booking at an inconvenient time or a message that undersells how bad a leak is, and both are recoverable by a person picking up a phone.

The commitments that go with that

  • A caller could always ask for a person. Saying so on the call would stop the automated part of it.
  • The tradesperson would see the caller's own words, not only the assistant's summary, so a bad summary can be caught.
  • The urgency judgement would be recorded with the call, so a trades business can audit how often it was wrong in each direction.
  • No caller would ever be refused a booking by the software on the basis of anything about them. It has no scoring of callers, and we would not add one.

If any of that changes, this section is where it would be described, and it would be described before the processing started rather than afterwards.

22Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to hello@andyai.link with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

23The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

24Cookies on this website

This website sets no cookies of its own, uses no analytics, carries no advertising and shows no consent banner. The full explanation, including what the absence of a banner does and does not mean under Australian law, is in the cookie notice.

The short version is that two things reach beyond this page. The first is the request for the page itself, which reaches the hosting provider and appears in its logs. The second is the request for the two typefaces the pages use, which goes to Google's font servers and tells them your IP address and user agent. Both are named in the cookie notice, and the second one is a genuine trade off that is described there rather than glossed over.

Nothing on this site stores anything in your browser's local storage or session storage either, which is worth saying because "no cookies" has become a phrase people use while storing an identifier by another means.

25Complaints

Step one: tell us

Email hello@andyai.link with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

26If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to hello@andyai.link and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising anywhere on this website, none is planned in the assistant, and there is therefore no sharing to opt out of. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

27Changes to this policy

We may change this policy. When we do, the effective date and the version number in the header of this page change with it.

Two changes are certain rather than possible. The first is the day the supplier table grows, because a working assistant needs telephony and speech processing that we do not have today. The second is the day the collection tables move from the conditional into the present tense. Both are the kind of change that has to be visible.

Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect, by putting a note at the top of this page for at least 30 days and, if there are customers by then, by writing to them. We will not make a material change effective retrospectively, and we will not treat continued use of a website that asks nothing of you as consent to anything.

Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances. A trades business considering software that handles its customers' details should get its own advice rather than relying on a supplier's policy, including this one.

28How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of the information we hold about youDelete my data30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: hello@andyai.link

Entity: ANDY AI PTY LTD, ACN 697 510 562, ABN 72 697 510 562, an Australian proprietary company, South Australia.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 697 510 562 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.