Alfred AI Agent Services Pty Ltd (ABN 62 684 936 525), trading as AlfredAI, of Sydney, New South Wales, Australia, provides AI integration and automation services to businesses. Registered office: WOTSO, Level 1, George Street, North Strathfield NSW 2137, Australia.
For anything in this notice, including to exercise your rights, contact our Privacy Lead at enquiry@alfredai.bot or on +61 2 5759 8881. We have not appointed a statutory Data Protection Officer because we are not required to under Article 37; the Privacy Lead is the person accountable for data protection and is the contact point for individuals and for supervisory authorities.
We have no establishment in the European Union and have not appointed an Article 27 representative, because we do not offer goods or services to, or monitor the behaviour of, individuals in the European Union. That determination is recorded and reviewed; if it changes, this notice will change with it.
Much of what we do, we do on behalf of a business client. Where a client uses our platform or our services to process information about their own customers, staff or contacts, that client decides why and how the information is used and is the controller; we are the processor and act on their instructions. If you are one of their customers or contacts and you want to exercise your rights over that information, the client is the right party to ask, and if you contact us we will pass your request to them promptly and tell you that we have done so.
The rest of this notice describes the processing for which we ourselves are the controller. Where you are a business customer, our processing of the data you upload is additionally governed by the Data Processing Addendum set out below; where it applies and conflicts with this notice, it governs for that customer data.
| Purpose | Personal data | Where it comes from | Lawful basis | Retention |
|---|---|---|---|---|
| Providing and administering an account on our platform | Name, email address, phone number, hashed credentials, account and usage records | From you | Article 6(1)(b) performance of a contract; consent under Article 6(1)(a) for optional features | For the life of the account and 30 days after closure, then deleted |
| Responding to enquiries, including through the chat on our websites | Name, email address, phone number, company, the content of your enquiry | From you | Article 6(1)(f) legitimate interests — responding to a person who has approached us; consent where you opt in to further contact | 12 months from the last contact, unless you become a client |
| Business development and marketing to business contacts | Name, job title, business email address, business phone number, employer, publicly available professional information | From you, and from third-party business data providers and public sources — see section 4 | Article 6(1)(f) legitimate interests — business to business marketing, subject to the Spam Act 2003 (Cth) | 24 months from the last contact, then deleted |
| Billing and financial administration | Name, email address, billing address, payment metadata (we do not store card numbers) | From you and from our payment provider | Article 6(1)(b) contract and Article 6(1)(c) legal obligation | 7 years, as tax and accounting law requires |
| Operating and improving the AI workflows you use | The content you or your users put into a conversation, prompt or uploaded document, which may contain personal data | From you and your users | Article 6(1)(b) contract, and the client’s instructions where we act as processor | Conversation content is retained for the period set on the account and is then purged automatically; the default period and how to change it are in your account settings |
| Security, monitoring and compliance | Account and security metadata, access logs, error and exception records | Generated by our systems | Article 6(1)(f) legitimate interests — keeping our systems and our clients’ data secure; Article 6(1)(c) where a law requires it | Security logs 12 months; compliance records for the period the relevant framework requires |
| Engaging and managing the people who work for us | Identity and contact details, engagement terms, screening assurance, training records | From the individual and from the supplier that employs them | Article 6(1)(b) contract and Article 6(1)(c) legal obligation | 7 years after the engagement ends |
For business development we obtain business contact information about people in roles relevant to our services from third-party business data providers — principally Apollo — and from publicly available sources such as company websites and search results, retrieved with the help of Apify, ScraperAPI and SerpAPI. The categories are: name, job title, business email address, business phone number, employer and publicly available professional information. We do not obtain special category data and we do not seek personal contact details.
If you were added this way, you have the same rights as anyone else, including the right to object at any time, and we will stop on request without asking for a reason. A fuller notice for this activity is published as our privacy notice for business contacts.
We use service providers who process personal data on our instructions under a written agreement: cloud hosting and infrastructure (Amazon Web Services, Oracle Cloud, Google Workspace, Microsoft Azure), AI model providers (including OpenAI, Anthropic, Google via OpenRouter, and xAI), a vector search provider (Pinecone), voice and messaging providers (Vapi, Twilio, ElevenLabs, Recall.ai), business data providers (Apollo, Apify, ScraperAPI, SerpAPI), payment and finance providers (Stripe, Xero) and operational tooling. The current list, with what each provider does, is in the sub-processor list at the end of this page and is maintained in our sub-processor register, available on request.
We do not sell personal data. We disclose it to a regulator, a court or a law enforcement body only where we are legally required to.
Our platform is hosted in the United States (Amazon Web Services, us-east-1) and several of our providers are in the United States. Clients who require Australian data residency are served from a dedicated deployment in Sydney on Oracle Cloud.
Where a transfer is subject to Chapter V of the General Data Protection Regulation, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s data processing terms that incorporate them, together with supplementary measures: encryption in transit and at rest, restricted access, retention limits, and the minimisation and redaction of personal data placed in prompts sent to AI providers. You can obtain a copy of the safeguards for a particular transfer by emailing enquiry@alfredai.bot, and we will provide it within one month.
Model providers are reached through OpenRouter, and every request is restricted to providers that do not retain prompts or train on them. Under the Australian Privacy Principles we remain accountable for the information we send overseas and take reasonable steps to ensure our providers handle it consistently with those principles.
Our services use AI models to generate text, classify messages, summarise documents and hold voice conversations. These outputs support decisions made by people; we do not make decisions about you by automated means alone that have a legal effect on you or that similarly significantly affect you, and we do not carry out profiling for that purpose. Where a client configures a workflow that would do so, that client is the controller and is responsible for that decision; our AI Human Review Procedure sets out where human review is required.
You may ask us to: give you access to your personal data and a copy of it; correct it; delete it; restrict how we use it; give you a portable copy in a machine-readable format; or stop using it where we rely on legitimate interests. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it, and withdrawal does not affect processing that already took place. You can ask us to stop marketing to you at any time and we will stop.
Email enquiry@alfredai.bot. We answer within one month and will tell you if we need a further two months because the request is complex. We do not charge for this except where a request is manifestly unfounded or excessive, and we will explain if that applies.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and, where the General Data Protection Regulation applies to your data, to the supervisory authority in your country or where the alleged infringement took place. You may also seek a judicial remedy.
Our websites use cookies that are strictly necessary to make the site and the application work, including to keep you signed in and to protect against cross-site request forgery. These do not require consent. Where we use any cookie that is not strictly necessary, we ask for your consent first through the cookie banner, you can change or withdraw that choice at any time through the cookie settings link on the site, and the current list of cookies with their purpose and lifetime is available there.
We operate an information security management system certified to ISO/IEC 27001. Personal data is encrypted in transit and at rest, access is limited to the people who need it and protected by multi-factor authentication, and our web, application and data layers are separated at network level. The retention periods for each purpose are in the table above; where a period is set on your account, deletion is enforced automatically when it expires.
This notice carries a version number and an effective date. We review it at least annually and whenever our purposes, providers, transfers or retention periods change. We keep previous versions and can tell you what changed and when.
Download the signed Data Processing Addendum (PDF) The addendum below forms part of the Terms and applies to every customer without further signature. The PDF is the same addendum, signed on behalf of Alfred AI Agent Services Pty Ltd, for customers who need a countersigned copy for their own records.
This Data Processing Agreement ("DPA") forms part of, and is subject to, the provisions of Alfred AI's Agreement (Terms and Conditions). All capitalised terms not defined in this DPA shall have the meanings set forth in the Agreement.
"Affiliate": An entity that directly or indirectly Controls, is Controlled by, or is under common Control with another entity.
"Agreement": Alfred AI's Terms and Conditions, which govern the provision of the Services to the Customer, as may be updated by Alfred AI from time to time.
"Control": Ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question. The term "Controlled" shall be construed accordingly.
"Customer Data": Any Personal Data that Alfred AI processes on behalf of the Customer as a Data Processor in the course of providing Services, as more particularly described in this DPA.
"Data Protection Laws": All data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, EU Data Protection Law, the Australian Privacy Act 1988, and relevant U.S. data protection laws such as the California Consumer Privacy Act (CCPA).
"Data Controller": An entity that determines the purposes and means of the processing of Personal Data.
"Data Processor": An entity that processes Personal Data on behalf of a Data Controller.
"EU Data Protection Law": (i) Prior to 25 May 2018, Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of Personal Data and on the free movement of such data ("Directive"); and on and after 25 May 2018, Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); and (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector and applicable national implementations of it (as may be amended, superseded, or replaced).
"EEA": For the purposes of this DPA, the European Economic Area, United Kingdom, and Switzerland.
"Group": Any and all Affiliates that are part of an entity's corporate group.
"Personal Data": Any information relating to an identified or identifiable natural person.
"Processing": As defined in the GDPR, and "process," "processes," and "processed" shall be interpreted accordingly.
"Security Incident": Any unauthorised or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
"Services": Any product or service provided by Alfred AI to the Customer pursuant to the Agreement.
"Sub-processor": Any Data Processor engaged by Alfred AI or its Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA. Sub-processors may include third parties or members of the Alfred AI Group.
The parties agree that this DPA shall replace any existing DPA the parties may have previously entered into in connection with the Services.
Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.
Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement.
No one other than a party to this DPA, its successors, and permitted assignees shall have any right to enforce any of its terms.
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.
This DPA applies where and only to the extent that Alfred AI processes Customer Data that originates from the EEA, Australia, the United States, and/or that is otherwise subject to EU Data Protection Law, the Australian Privacy Act 1988, or relevant U.S. data protection laws on behalf of the Customer as Data Processor in the course of providing Services pursuant to the Agreement.
As between Alfred AI and the Customer, the Customer is the Data Controller of Customer Data, and Alfred AI shall process Customer Data only as a Data Processor acting on behalf of the Customer.
The Customer agrees that (i) it shall comply with its obligations as a Data Controller under Data Protection Laws in respect of its processing of Customer Data and any processing instructions it issues to Alfred AI; and (ii) it has provided notice and obtained (or shall obtain) all consents and rights necessary under Data Protection Laws for Alfred AI to process Customer Data and provide the Services pursuant to the Agreement and this DPA.
Alfred AI shall process Customer Data only for the purposes described in this DPA and only in accordance with the Customer's documented lawful instructions. The parties agree that this DPA and the Agreement set out the Customer's complete and final instructions to Alfred AI in relation to the processing of Customer Data, and processing outside the scope of these instructions (if any) shall require prior written agreement between the Customer and Alfred AI.
(a) Subject matter: The subject matter of the data processing under this DPA is the Customer Data.
(b) Duration: As between Alfred AI and the Customer, the duration of the data processing under this DPA is until the termination of the Agreement in accordance with its terms.
(c) Purpose: The purpose of the data processing under this DPA is the provision of the Services to the Customer and the performance of Alfred AI's obligations under the Agreement (including this DPA) or as otherwise agreed by the parties.
(d) Nature of the processing: The Services as described in the Agreement and initiated by the Customer from time to time.
(e) Categories of data subjects: The Customer, the Customer's End Users, and any other individuals whose personal data is included in Content.
(f) Types of Customer Data: Personal Data related to the Customer, the Customer's End Users, or other individuals whose personal data is included in Content, which is processed as part of the Services in accordance with instructions given through the Customer's Account.
Notwithstanding anything to the contrary in the Agreement (including this DPA), the Customer acknowledges that Alfred AI has the right to use and disclose data related to the operation, support, and/or use of the Services for legitimate business purposes, such as billing, account management, technical support, product development, and marketing. To the extent any such data is considered Personal Data under Data Protection Laws, Alfred AI acts as the Data Controller and will process such data in compliance with the Alfred AI Privacy Policy and Data Protection Laws.
The Customer agrees that Alfred AI may engage Sub-processors to process Customer Data on the Customer's behalf. The Sub-processors currently engaged by Alfred AI are listed at the end of this page and are maintained in our sub-processor register. The list published here is reconciled against that register, and the register is available to the Customer on request.
Alfred AI shall (i) enter into written agreements with Sub-processors that impose data protection terms requiring Sub-processors to protect Customer Data to the standard required by Data Protection Laws; and (ii) remain responsible for compliance with obligations under this DPA, as well as any actions or omissions by the Sub-processor that would cause Alfred AI to breach its obligations.
Alfred AI will implement and maintain appropriate technical and organizational security measures to protect Customer Data from Security Incidents, in accordance with Alfred AI's security standards. This includes adhering to the Privacy Act 1988 and relevant U.S. state laws, such as the California Consumer Privacy Act (CCPA) and Virginia Consumer Data Protection Act (VCDPA).
The Customer is responsible for reviewing Alfred AI's available data security information and making an independent determination on the Services' adequacy for meeting the Customer's requirements and obligations under Data Protection Laws. Alfred AI reserves the right to update or modify its Security Measures without reducing overall security.
The Customer agrees that except as provided by this DPA, it is responsible for its secure use of the Services, including securing account credentials, protecting the security of Customer Data when in transit, and encrypting or backing up Customer Data.
Alfred AI may transfer and process Customer Data globally where Alfred AI, its Affiliates, or Sub-processors maintain data processing operations, and will ensure adequate protection for Customer Data per Data Protection Laws.
Alfred AI agrees not to disclose Customer Data to overseas recipients unless taking reasonable steps to ensure compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988.
Alfred AI will implement appropriate safeguards to ensure compliance with applicable U.S. state privacy laws, including measures specified by the CCPA and VCDPA.
Alfred AI will ensure that any person authorized by Alfred AI to process Customer Data is under an obligation of confidentiality.
Upon becoming aware of a Security Incident, Alfred AI will notify the Customer promptly and provide timely updates as information becomes available or upon the Customer's request.
Alfred AI will provide an updated list of Sub-processors upon the Customer's written request and notify the Customer of changes at least 10 days in advance.
The Customer may object in writing to Alfred AI's appointment of a new Sub-processor within five calendar days based on reasonable grounds related to data protection. The parties will discuss such concerns in good faith, aiming to resolve them; if unresolved, the Customer may suspend or terminate the Agreement.
Upon termination or expiration of the Agreement, Alfred AI will, at the Customer's election, delete all Customer Data in its possession, except where retention is required by law or applies to archived backups, which Alfred AI will securely isolate and protect.
The Customer can request data deletion by contacting Alfred AI via support, fulfilled within 72 hours.
Alfred AI provides tools for the Customer to retrieve, correct, delete, or restrict Customer Data, assisting with GDPR obligations. If unable to access data independently, Alfred AI will assist with data subject requests (at the Customer's expense).
Alfred AI will attempt to redirect law enforcement requests for Customer Data directly to the Customer and provide notice unless legally prohibited.
When required under Data Protection Laws, Alfred AI will assist the Customer in carrying out data protection impact assessments and consultations with authorities.
Alfred AI makes available to the Customer all information necessary to demonstrate compliance with Article 28 of the General Data Protection Regulation, and allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer. Alfred AI may satisfy an audit request by providing its current ISO/IEC 27001 certificate, its most recent penetration test summary and its completed security questionnaire. Where those do not answer the Customer's question, the Customer may audit on 30 days' notice, no more than once in any twelve months except following a personal data breach, during business hours, subject to confidentiality and without access to any other customer's data. (Article 28(3)(h).)
Alfred AI informs the Customer immediately if, in its opinion, an instruction infringes the General Data Protection Regulation or another applicable data protection provision, and may suspend the affected processing until the instruction is confirmed or withdrawn. (Article 28(3), final paragraph.)
Liability for each party under this DPA is subject to exclusions and limitations in the Agreement. The Customer agrees to be responsible for regulatory penalties or claims incurred due to non-compliance with data protection obligations.
When you connect your WhatsApp Business Account through Meta's WhatsApp Embedded Signup, Alfred AI processes certain data to enable the integration:
We collect only the necessary information to enable WhatsApp Business integration, including:
We use this data exclusively to:
We do not sell or share your WhatsApp integration data with third parties for marketing. Data is only shared with Meta as required for the integration and stored securely using industry-standard encryption. Access tokens are managed securely and never exposed to unauthorized parties.
You can revoke our app's access to your WhatsApp Business Account at any time through Facebook Business Manager. Upon disconnection, all related data and tokens are deleted from our systems within 30 days.
Our WhatsApp integration fully complies with Meta Platform Terms, Developer Policies, and WhatsApp Business Terms of Service.
Alfred AI integrates with Google services (including Gmail and Google Calendar) to enable automated email and scheduling functionality within our chatbot platform.
We use Google services exclusively to automate our chatbots' ability to send emails and manage calendar events on behalf of our users. This integration allows our AI chatbots to:
When using Google services for email and calendar automation, we process only the data necessary to perform the actions instructed by our users. This may include email addresses, message content, delivery preferences, calendar event details (title, description, attendees, start/end times), and availability information as configured in the chatbot settings.
Your Google data is NOT used to train AI models. Alfred AI does not use your Gmail content, email messages, Google Calendar data, or any other Google-related data to train, fine-tune, or improve any AI or machine learning models. Your data is processed solely to provide the email drafting and calendar scheduling services and is not retained for training purposes.
The following AI providers are NOT used for processing any Gmail content, Google Calendar data, or other Google-related data:
Alfred AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to all Google Workspace APIs we access, including Gmail and Google Calendar. In particular, Alfred AI affirms that:
The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.
The following Sub-processors may process Customer Data. This list is reconciled against our sub-processor register and was last reviewed on 18 August 2026. We notify the Customer of changes at least 10 days in advance, as clause 9.1 provides, and the register with the agreement reference held for each Sub-processor is available on request.
| Sub-processor | What it does for us | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage and managed databases for the shared platform | United States (us-east-1) |
| Oracle Cloud | Dedicated per-client hosting, including deployments for clients requiring Australian data residency | Australia (Sydney) |
| Microsoft Azure | Client mailbox and document integration | Per client — recorded in the register |
| Google Workspace | Email, identity and document services | United States |
| GitHub | Source code management | United States |
| OpenRouter | AI model routing, including the Google Gemini and DeepSeek models reached through it | United States |
| OpenAI | AI model inference | United States |
| Anthropic | AI model inference | United States |
| xAI | AI model inference | United States |
| Pinecone | Vector search over document and conversation content | United States |
| Vapi | Voice assistant platform | United States |
| Twilio | Telephony and messaging | United States |
| ElevenLabs | Speech synthesis | United States |
| Recall.ai | Meeting recording and transcription | United States |
| Apify | Public web retrieval for business development | United States |
| ScraperAPI | Public web retrieval for business development | United States |
| SerpAPI | Search result retrieval for business development | United States |
| Apollo | Business contact data for business development | United States |
| Stripe | Payment processing | United States |
| Xero | Financial administration and invoicing | New Zealand |
| Slack | Internal collaboration | United States |
| Dropbox | Document storage and transfer | United States |
| MailerSend | Transactional and outreach email delivery | United States |
| Better Stack | Uptime and log monitoring | Recorded in the register |
| Cloudflare | Network and DNS protection — being adopted; not yet processing any personal data. Listed here as advance notice under clause 9.1. | United States, once live |
| Expo | Mobile application build and delivery | United States |
| Pipedrive | Customer relationship management | Australia |
| Vanta | Compliance monitoring | United States |
Error monitoring is operated on our own infrastructure and is not provided by a third party, so no Sub-processor is engaged for it. Providers listed in our vendor register that do not receive Customer Data are not Sub-processors and are not listed here.
The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.