Legal
Privacy Policy
Effective date: 19 August 2026 · Last reviewed: 19 August 2026 · Version: 2.0
This policy explains what personal information Automatrix collects, why we collect it, how we use and disclose it, how we use artificial intelligence in our work, and how you can access, correct, or complain about how we handle your information.
The short version. We collect what we need to quote, deliver, invoice, and support your work, and nothing else. We do not sell your information. We do not use your data or your clients' data to train AI models. Anything we send to an AI provider goes under no-training commercial terms, and only where it is necessary to do the job you hired us for. You can ask for a copy of what we hold, ask us to fix it, or ask us to delete it, by emailing privacy@automatrix.au.
1. Who We Are
Automatrix Digital Pty Ltd (trading as Automatrix) ABN 89 700 072 608 ("Automatrix", "we", "us", "our") is a technology and business automation services company registered and operating in New South Wales, Australia. We provide business automation, software development, search engine optimisation, website development, systems integration, artificial intelligence implementation, and related digital services.
This Privacy Policy applies to all personal information collected by Automatrix through our website at www.automatrix.au (the "Site"), through our client portals and admin systems, through our service delivery activities, through our client onboarding and application processes, and in connection with any contract or engagement we enter into.
Applicable law: This policy is prepared in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act, the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth), the Surveillance Devices Act 2007 (NSW) where relevant to recorded conversations, and relevant guidelines issued by the Office of the Australian Information Commissioner (OAIC).
1.1 Our Position on the Small Business Exemption
The Privacy Act contains an exemption for businesses with an annual turnover of $3 million or less. Whether or not that exemption applies to us in a given financial year, we handle personal information as though we are bound by the Australian Privacy Principles in full. We hold ourselves to that standard because our clients trust us with their systems and their customers' data, and a turnover threshold is a poor reason to offer anyone less protection. Where this policy describes an obligation, treat it as a commitment we have made to you.
1.2 Open and Transparent Management (APP 1)
We maintain internal practices, procedures, and systems designed to keep us compliant with the APPs and to handle privacy enquiries and complaints. This policy is available free of charge at automatrix.au/privacy-policy, and we will provide a copy in another format on request.
2. Dealing With Us Anonymously (APP 2)
You have the option of dealing with us anonymously or under a pseudonym where it is lawful and practicable for us to allow it. You can read our website, download a resource, or ask a general question by phone without telling us your name.
It is not practicable for us to deal with you anonymously when we are quoting, contracting, invoicing, delivering services, or providing support, because we need to know who you are to do those things and to meet our tax and record keeping obligations. If you would prefer to limit what you give us, tell us and we will tell you what is genuinely required.
3. Information We Collect
Automatrix collects personal information only to the extent reasonably necessary to provide our services and conduct our business. The types of personal information we may collect are described below.
3.1 Contact and Identity Information
- Full name (first and last)
- Business name and trading name
- Email address (personal and/or business)
- Phone number (mobile and/or landline)
- Postal and/or business address
- ABN or ACN (where provided for invoicing)
- Job title and role within your business
3.2 Business and Engagement Information
- Business industry, size, and operational details provided in our application questionnaire
- Details of your business challenges, goals, and operational pain points
- Budget ranges and project timelines you choose to disclose
- Service requirements and project scope information
- Communications and correspondence with us (emails, SMS, notes, meeting records)
- Information you provide during onboarding audits or consultations
3.3 Financial and Transaction Information
- Invoice details and payment history
- Bank account or payment method details (processed securely via our payment providers, and we do not store raw card numbers)
- GST registration status where applicable
- Receipts and expense records where you have engaged us to process them
3.4 Technical and Usage Information
- IP address and approximate geographic location
- Browser type and version, operating system
- Pages visited on our Site, time and date of visit, time spent on pages
- Referring URLs (how you found us)
- Device identifiers and screen resolution
- Interaction data from our website analytics tools
3.5 Credentials and Access Information
To deliver services we often need access to systems you control, such as hosting accounts, domain registrars, content management systems, analytics properties, advertising accounts, and business software. Where you give us credentials or delegated access:
- We prefer delegated or invited access over shared passwords, so you can revoke us at any time without changing your own login
- Credentials we do hold are stored in an encrypted vault, not in email, chat, spreadsheets, or project notes
- Access is limited to the people working on your engagement
- We remove or hand back access at the end of an engagement, or earlier on request
3.6 Recorded Calls and Meetings
We sometimes record or transcribe calls and video meetings to produce notes and summaries. We will tell you at the start of the meeting if recording or an AI notetaker is running, and you can ask us to turn it off. We do not record without telling you.
This matters legally as well as courteously. Under section 7 of the Surveillance Devices Act 2007 (NSW), recording a private conversation without the consent of all principal parties is an offence, even where you are one of the parties, unless a narrow exception applies. Recording rules differ in Victoria, Queensland, and the Northern Territory. We work to the strictest of them, which means we ask.
3.7 Sensitive Information
We do not intentionally collect sensitive information as defined under the Privacy Act, such as health information, racial or ethnic origin, political opinions, membership of a professional or trade association, religious beliefs, sexual orientation, criminal records, or biometric data. If you inadvertently provide sensitive information to us, we will handle it with the same level of care as other personal information and will use it only for the purpose for which it was disclosed. We will not use or disclose sensitive information for any other purpose without your consent.
If your business holds sensitive information and you want us to build or automate systems that touch it, tell us before the project starts. That changes how we scope the work, which AI tools we are willing to use, and where the data is allowed to sit.
3.8 Information About Third Parties
If you provide us with personal information about another individual, such as a business partner, employee, customer, or referee, you warrant that you are authorised to provide that information to us and that we may use it in accordance with this policy. You also agree to inform that individual of the matters set out in this policy.
4. How We Collect Your Information
We collect personal information in the following ways.
4.1 Directly From You
- When you complete and submit our online application or contact forms on the Site
- When you correspond with us by email, phone, SMS, or any other means
- When you engage us to provide services (contract onboarding)
- When you participate in a discovery call, audit session, or strategy meeting
- When you subscribe to any communications from us
- When you provide feedback or testimonials
- When you use a client portal, proposal link, invoice payment page, or booking page we have issued to you
4.2 Automatically Via the Site
When you visit our Site, our web servers and analytics tools automatically collect certain technical information. This is standard practice and does not identify you as an individual unless combined with other information you have provided. See Section 10 for more detail.
4.3 From Third Parties
Occasionally we may receive information about you from third parties, including:
- Referrals from existing clients or business contacts who recommend you to us
- Publicly available sources such as LinkedIn, ASIC records, ABN Lookup, Google Business Profile, or your own business website
- Payment processors and financial institutions in connection with invoicing and payment
- SEO and market data providers we use to prepare audits and proposals
- Integration platforms such as Zapier or Make, where your business has engaged us to configure systems on your behalf
APP 5 compliance: Where practicable, we collect personal information directly from you. When we collect from a third party, we will notify you of the collection as soon as reasonably practicable, unless notification would be unreasonable in the circumstances.
4.4 Unsolicited Information (APP 4)
If we receive personal information we did not ask for, we assess within a reasonable period whether we could have collected it under this policy. If we could not, and the information is not contained in a Commonwealth record and we are not required by law to keep it, we destroy or de-identify it as soon as practicable and where it is lawful and reasonable to do so.
5. Why We Collect Your Information
We collect, hold, use, and disclose personal information only for purposes that are directly related to our business functions and are reasonably necessary for those functions. Those purposes are:
- Responding to enquiries and preparing quotes, audits, and proposals
- Delivering the services you have engaged us for, including building, configuring, hosting, and supporting your systems
- Managing the engagement, including project communication, approvals, scheduling, and reporting
- Billing and collection, including issuing invoices, processing payments, and following up overdue accounts
- Meeting our legal obligations, including tax, corporate record keeping, and responding to lawful requests
- Improving our services, including analysing how the Site is used and where our own process falls down
- Direct marketing within the limits set out in Section 15
- Protecting our systems, including fraud prevention, security monitoring, and enforcing our Terms of Service
5.1 Using Information for a Secondary Purpose
We will not use or disclose personal information for a secondary purpose unless:
- The secondary purpose is directly related to the primary purpose for which it was collected, and you would reasonably expect us to use or disclose it for that secondary purpose
- You have consented to the use or disclosure for the secondary purpose
- We are required or authorised to do so by or under Australian law or a court or tribunal order
- Use or disclosure is reasonably necessary for the enforcement of a criminal law or of a law imposing a pecuniary penalty, or for the protection of public revenue
- We reasonably believe it is necessary to lessen or prevent a serious threat to life, health, or safety
6. Artificial Intelligence and Automated Processing
Automation and AI are what we sell, so we are specific about how we use them on your information. This section covers our own use of AI. Where we build AI into a system for you, Section 7 and your service agreement govern that work.
6.1 What We Use AI For
We use AI systems, primarily large language models, to assist with:
- Drafting proposals, contracts, reports, and website copy
- Summarising meetings, emails, and call transcripts
- Reading receipts and invoices to extract line items for accounting
- Producing SEO audits, technical analysis, and competitor research
- Assisting with code we write for client projects
- Answering internal questions about a project's history
6.2 Which Providers We Send Data To
Our primary AI provider is Anthropic (the Claude family of models), accessed through Anthropic's commercial API. We also use AI features built into tools we already run, and speech and voice platforms where a project calls for them. Our current AI and voice providers are listed in the table in Section 8.1.
6.3 Training: Our Commitment
We do not permit your data to be used to train AI models. Specifically:
- We use commercial API access, not consumer chat products, for anything containing client or prospect information. Commercial API terms with our providers exclude customer inputs and outputs from model training by default
- We do not paste client data into free or personal-tier AI tools, which commonly reserve training rights
- We do not sell, license, or contribute your information to any dataset, model, or AI product
- Where a tool we use changes its training position, we review whether to keep using it, and we stop using it for client data if we cannot turn training off
6.4 Human Oversight
AI drafts, people decide. No AI system we run makes a final decision that legally or significantly affects you. Every proposal, contract, report, invoice adjustment, and piece of published work passes a human review before it leaves us. If an AI output is wrong, that is our error to fix, and it does not change what we owe you under our Terms of Service.
6.5 Automated Decisions
We do not use automated decision making, including profiling, to make decisions that produce legal effects for you or similarly significantly affect you. We do use automation for routine operational steps such as routing an enquiry to the right person, flagging an overdue invoice, scoring an enquiry for follow-up priority, and scheduling reminders. A person can review any of these, and you can ask us to have one reviewed by contacting our Privacy Officer.
Amendments to the Privacy Act require in-scope organisations to disclose the use of computer programs in decisions that significantly affect an individual's rights or interests, with those requirements taking effect from 10 December 2026. We will update this section before that date if our practices change.
6.6 Accuracy and Limits
AI systems make mistakes, including confident ones. We treat AI output as a first draft, verify facts, figures, legal references, and code before they reach you, and never present raw model output as professional advice. Do not rely on AI-assisted material we provide as legal, financial, tax, or medical advice.
6.7 Your Choice
If you would prefer that we do not run your information through third-party AI systems, tell us before the engagement starts. We can usually accommodate it. It will affect turnaround times and, for some services, pricing, and we will tell you honestly which parts of the work become impractical.
7. Client Data We Handle on Your Behalf
When we build, host, integrate, or automate systems for you, we usually end up handling personal information that belongs to your customers, staff, patients, members, or suppliers. That is a different relationship from the one we have with you as our client, so it gets its own section.
7.1 Who Is Responsible for What
For that data, you are the controlling entity and we act on your instructions. You decide what is collected, why, and how long it is kept. You are responsible for having a lawful basis to collect it, for your own privacy policy and collection notices, and for the consents you rely on. We are responsible for handling it securely and only for the purposes of your engagement.
7.2 What We Commit To
- We use your data only to deliver the services you have engaged us for, and on your documented instructions
- We do not use your data or your customers' data for our own purposes, for marketing, or for AI training
- We apply the security measures in Section 11 to it
- We restrict access to personnel and providers who need it
- We tell you without undue delay if we become aware of a security incident affecting it, so you can meet your own notification obligations
- We assist you, at your cost where the work is substantial, in responding to access, correction, and deletion requests from your customers
- On termination we return or delete it as set out in your service agreement, subject to backup retention cycles and any legal hold
7.3 What You Should Tell Us
If your customers' data includes sensitive information, health records, financial data beyond ordinary invoicing, children's information, or data about individuals in the EU or UK, tell us before we design the system. It changes the architecture, the hosting location, and the AI tooling we are willing to use. Retrofitting compliance costs more than building for it.
8. Disclosure to Third Parties
Automatrix does not sell, rent, trade, or otherwise transfer your personal information to external parties for their own marketing purposes. We may disclose your personal information to third parties only in the following circumstances.
8.1 Service Providers
We engage trusted third-party service providers who assist us in operating our business. They are bound by confidentiality obligations and are only permitted to use your information to the extent necessary to provide their service to us.
| Category | Providers we use | What they receive | Where processed |
|---|---|---|---|
| Website hosting and delivery | Netlify | Form submissions, technical and usage data | USA, global edge network |
| Database and authentication | Supabase | Client records, project data, messages | Australia (Sydney region) |
| Email hosting and sending | VentraIP, Google Workspace | Correspondence and attachments | Australia, USA |
| SMS and voice | Twilio, LiveKit, Vapi | Phone numbers, message content, call audio where used | USA, Australia |
| Artificial intelligence | Anthropic (Claude) | Text and documents submitted for processing, under no-training commercial terms | USA |
| Payments | Stripe | Name, email, billing details, transaction data (PCI DSS compliant) | USA, Australia |
| Accounting and tax | Xero | Invoice, expense, and payment records | Australia, New Zealand |
| Analytics | Google Analytics 4 | Anonymised IP, page and event data | USA, global |
| SEO and market data | DataForSEO, Ahrefs, Semrush | Domain and keyword queries, not personal information | USA, EU |
| Automation platforms | Zapier, Make, n8n | Only data you have engaged us to move between your systems | USA, EU, or self-hosted |
This list reflects our providers as at the review date at the top of this policy. We add and remove providers as our stack changes. To request the current list at any time, email privacy@automatrix.au.
8.2 Professional Advisors
We may disclose information to our accountants, lawyers, insurers, or other professional advisors where strictly necessary for the provision of professional services to us, subject to professional confidentiality obligations.
8.3 Legal Requirements and Law Enforcement
We may disclose personal information where we are required to do so by Australian law, a court order, or a lawful request from a government or law enforcement agency, including the ATO, ASIC, the OAIC, or the NSW Police Force. We will notify you of any such disclosure where we are permitted to do so by law.
8.4 Business Transactions
In the event of a merger, acquisition, sale of business assets, or other structural change, personal information held by Automatrix may be transferred to a successor entity. We will notify affected individuals and ensure the successor entity is bound by equivalent privacy obligations.
8.5 With Your Consent
We may disclose your personal information to other parties with your express consent, for example if you ask us to share project outcomes or case study material with a referral partner.
9. Overseas Disclosure
Some of our third-party service providers are based or operate infrastructure outside Australia, including in the United States, the European Union, New Zealand, and Singapore. The countries in which recipients are likely to be located are set out in the table in Section 8.1.
When we disclose personal information to overseas recipients, we take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles. Specifically, we will:
- Ensure the recipient is subject to a law, binding scheme, or contractual obligations that provide at least comparable privacy protections to the APPs; or
- Obtain your consent to the overseas disclosure after advising you that APP 8.1 will not apply to that disclosure
Where a provider offers an Australian processing region, we choose it. Our primary database sits in the Sydney region for that reason.
APP 8 note: By submitting your information through our website and engaging our services, you acknowledge that your personal information may be processed by overseas service providers as described above. If you wish to opt out of particular overseas transfers, contact us and we will tell you what remains possible.
10. Cookies and Tracking Technologies
10.1 What Are Cookies?
Cookies are small text files placed on your device by a website you visit. They are widely used to make websites work efficiently, to remember your preferences, and to provide information to website owners.
10.2 Cookies and Storage We Use
| Name or type | Set by | Purpose | Duration |
|---|---|---|---|
amx-theme | Automatrix (local storage) | Remembers whether you chose light or dark mode | Until you clear site data |
| Session and auth tokens | Automatrix and Supabase | Keeps you signed in to a client portal, proposal, or invoice page and protects it from misuse | Session, or up to 30 days if you stay signed in |
_ga, _ga_* | Google Analytics 4 | Distinguishes visitors and measures how the Site is used, with IP anonymisation enabled | Up to 2 years |
| Payment session cookies | Stripe | Processes a payment and detects fraud on the pay page | Session to 12 months |
| Embedded content cookies | YouTube, Google Maps, and similar | Set only if a page loads an embed, and governed by that provider's policy | Varies by provider |
We do not run advertising or retargeting pixels on this Site. If that changes, we will update this section and the review date before the change goes live.
10.3 Managing Cookies
You may control or delete cookies through your browser settings. Most browsers allow you to refuse all cookies, to accept only certain cookies, or to be notified when a cookie is set. Disabling cookies may affect the functionality of the Site, and signed-in areas such as client portals will not work without session cookies.
To opt out of Google Analytics tracking, you may install the Google Analytics Opt-out Browser Add-on.
10.4 Do Not Track and Global Privacy Control
Our Site checks for a "Do Not Track" signal from your browser. If one is present, we do not load Google Analytics for your visit. We will extend the same treatment to the Global Privacy Control signal as support for it becomes standard.
11. Data Security
Automatrix takes reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security measures include:
- HTTPS encryption across our entire website and all form submissions, with HTTP Strict Transport Security enabled
- Encryption of data at rest in our database and file storage
- Row level security policies, so a signed-in user can reach only their own records
- Access controls limiting staff access to personal information on a need-to-know basis
- Multi-factor authentication on every administrative account that supports it
- Client credentials held in an encrypted vault, never in email, chat, or documents
- Secure email services with transport layer encryption
- Payment processing through PCI DSS compliant providers, with no raw card data stored by us
- Signed, expiring links for shared files rather than permanently public URLs
- Review of third-party provider security practices before and during engagement
- Device level encryption and screen locks on any hardware used in service delivery
- An internal data breach response plan, reviewed at least annually
While we take reasonable precautions, no method of data transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal information. If you believe your personal information has been compromised, contact us immediately using the details in Section 20.
12. Data Retention
We retain personal information for as long as is necessary to fulfil the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes and enforce our agreements. Our general retention periods are:
| Information type | Retention period | Reason |
|---|---|---|
| Enquiry and quote records that did not convert | 2 years from last contact | Follow-up, and to show how a quote was reached if it is later disputed |
| Client records and project files | 7 years from the end of the engagement | Contractual limitation periods and professional record keeping |
| Invoices, payments, and financial records | 7 years from the transaction | Required under the Income Tax Assessment Act 1936 and Corporations Act 2001 |
| Correspondence (email and SMS) | 7 years from the end of the engagement | Evidence of scope, instructions, and approvals |
| Meeting recordings and transcripts | 12 months, or sooner on request | Only needed while the work is live |
| Client credentials and access tokens | Deleted at the end of the engagement or on request | No reason to hold access we no longer need |
| Marketing subscriber records | Until you unsubscribe, plus a suppression record kept indefinitely | The suppression record exists so we do not contact you again by mistake |
| Website analytics data | 14 months | Trend analysis, set by our Google Analytics retention setting |
| Server and security logs | 90 days | Security monitoring and incident investigation |
| Backups | Rolling 35 days | Disaster recovery. Deleted records disappear from backups as the cycle rolls over |
When personal information is no longer required, we take reasonable steps to destroy or de-identify it securely and permanently. We do not retain personal information in a form that allows identification for longer than necessary. Where you ask us to delete information that we are legally required to keep, we delete what we can and tell you what has to stay and why.
13. Your Rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights in relation to your personal information held by Automatrix.
13.1 Right of Access (APP 12)
You have the right to request access to the personal information we hold about you. We will respond to your access request within 30 days of receipt. We will provide access free of charge unless the request is unusually complex or time consuming, in which case we may charge a reasonable fee, which we will advise you of in advance.
We may refuse access in certain circumstances permitted by law, such as where providing access would have an unreasonable impact on the privacy of other individuals, or where the request is frivolous or vexatious. If we refuse access, we will provide written reasons and tell you how to complain.
13.2 Right to Correction (APP 13)
If you believe that personal information we hold about you is inaccurate, incomplete, out of date, irrelevant, or misleading, you have the right to request correction. We will correct the information within 30 days of your request, or if we are unable to agree that the information requires correction, we will make a note on the record that you dispute its accuracy. Where we have disclosed the incorrect information to a third party, you can ask us to notify them of the correction.
13.3 Right to Deletion
You can ask us to delete personal information we hold about you. We will do so unless we are required to keep it by law, need it to establish or defend a legal claim, or need it to complete work you have asked us to do. See Section 12 for what we are obliged to keep and for how long.
13.4 Right to Withdraw Consent
Where our processing is based on your consent, for example marketing communications, you may withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent prior to its withdrawal.
13.5 Right to Opt Out of Direct Marketing (APP 7)
You may opt out of receiving direct marketing communications from us at any time by using the unsubscribe mechanism in any commercial electronic message we send, or by contacting us directly. We will give effect to your opt-out within 5 business days. You can also ask us where we got your details from, and we will tell you.
13.6 Right to a Copy of Your Data
Where it is reasonable and technically practicable, we will provide the personal information we hold about you in a common, machine readable format such as CSV or JSON, so you can take it elsewhere.
13.7 Right to Complain
You have the right to lodge a privacy complaint with us, using the details in Section 20, or with the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.
To exercise any of the above rights, submit a written request to privacy@automatrix.au. We will ask you to verify your identity before we act on the request, which protects you from someone else making it in your name.
13.8 Requests About Data We Hold for a Client
If you are a customer of one of our clients and your information sits in a system we built or host, we are not the right first stop. Contact the business you dealt with, because they decide what happens to that data. If you contact us instead, we will pass the request to them promptly and help them action it.
14. Notifiable Data Breaches
We operate in line with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If a data breach occurs that is likely to result in serious harm to one or more individuals whose personal information is involved, we will:
- Contain the breach and begin assessing its severity immediately, completing that assessment within 30 days
- Notify the Office of the Australian Information Commissioner as soon as practicable after forming the view that an eligible data breach has occurred
- Notify all affected individuals directly, and where that is not practicable, publish a prominent notice on our website
- Notify any client whose data, or whose customers' data, is involved without undue delay, so they can meet their own obligations
- Remediate the breach, then review what let it happen and fix that too
We maintain an internal data breach response plan and review our security measures regularly to reduce the risk of a breach occurring. If you believe your personal information held by us may have been subject to unauthorised access or disclosure, contact us immediately at privacy@automatrix.au.
15. Marketing and Spam Act Compliance
Automatrix complies with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth). We will only send you commercial electronic messages, including email and SMS, if:
- You have given us your express consent to receive such messages; or
- You are an existing client and we are sending messages relating to similar services we have provided to you, and you have not previously opted out. This is inferred consent under the Spam Act
Every commercial electronic message we send will:
- Clearly identify Automatrix as the sender
- Include our contact details
- Contain a clear and functional unsubscribe mechanism that works without you having to log in or reply
We will honour all unsubscribe requests within 5 business days of receipt. Once you have unsubscribed, we will not send you further commercial electronic messages unless you re-subscribe. Transactional messages, such as an invoice, a booking confirmation, or a security notice, are not marketing and will continue.
Where we make marketing calls, we check numbers against the Do Not Call Register before calling, unless an exemption applies.
16. Children's Privacy
Our services are directed exclusively at businesses and their adult representatives. We do not knowingly collect personal information from individuals under the age of 18 years. Our website is not intended for use by children.
If you become aware that a child has provided us with personal information without parental or guardian consent, contact us at privacy@automatrix.au and we will delete that information as soon as practicable.
Where we build a service for a client that is likely to be accessed by children, we design it against the requirements of the Children's Online Privacy Code being developed by the OAIC, and we tell that client what those requirements mean for their build.
17. Third-Party Links and Integrations
Our website and materials may contain links to third-party websites, platforms, or services, such as client websites, tool providers, or referral sources. We are not responsible for the privacy practices of third parties and this policy does not apply to any third-party website or service.
Review the privacy policies of any third-party services you use in connection with our work, including platforms such as Google, Anthropic, Stripe, Zapier, Make, and Netlify.
Where we build integrations or automations for clients that involve third-party services, we act on your instructions in the way described in Section 7, and our obligations are governed by your service agreement with us.
18. If You Are in the EU or UK
We are an Australian business serving Australian clients, and we do not target the European Economic Area or the United Kingdom. If you contact us from there, or if we handle data about individuals located there as part of a client engagement, we will:
- Process personal data on the lawful bases of contract performance, legitimate interests, legal obligation, or consent, as applicable
- Honour requests for access, rectification, erasure, restriction, portability, and objection
- Apply Standard Contractual Clauses or an equivalent transfer mechanism where a client engagement requires one
- Support the client, as their processor, in meeting their own GDPR or UK GDPR obligations
If you are in the EU or UK and want to exercise a right, email privacy@automatrix.au and say so, and we will treat it under the applicable regime.
19. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology, legal requirements, or other factors. When we update this policy, we will:
- Update the effective date, review date, and version number at the top of this page
- Post the updated policy to this URL: automatrix.au/privacy-policy
- Where changes are material, notify you by email if you are a current client, or by a prominent notice on our website, at least 14 days before the change takes effect where practicable
Your continued use of the Site or our services after any changes to this policy constitutes your acceptance of those changes. We keep prior versions and will provide one on request.
20. Contact and Complaints
If you have any questions about this Privacy Policy, wish to access or correct your personal information, or wish to make a privacy complaint, contact our Privacy Officer.
Automatrix Digital Pty Ltd, Privacy Officer
Email: privacy@automatrix.au
Phone: 0490 760 526
Post: Automatrix Digital Pty Ltd, Albury NSW 2640, Australia
Web: automatrix.au
20.1 Complaints Process
- We will acknowledge receipt of your complaint within 5 business days
- We will investigate the complaint and provide you with a written response within 30 days of receipt
- If we require additional time to investigate, we will notify you of the extended timeframe and the reasons for the delay
- If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner
20.2 Office of the Australian Information Commissioner
Phone: 1300 363 992
Online: oaic.gov.au/privacy/privacy-complaints
Post: GPO Box 5218, Sydney NSW 2001
Related reading: our Terms of Service set out the commercial terms that sit alongside this policy, and our guide to AI and the Privacy Act explains what these obligations mean for your own business.