Privacy Notice

GDP-PN-01 · Version 2.0 · Effective 18 August 2026
Articles 13 and 14 GDPR  |  Privacy Act 1988 (Cth) and the Australian Privacy Principles
Reviewed at least annually and on any change to purposes, providers, transfers or retention periods. Previous versions are retained and we can tell you what changed and when.

1. Who we are

Alfred AI Agent Services Pty Ltd (ABN 62 684 936 525), trading as AlfredAI, of Sydney, New South Wales, Australia, provides AI integration and automation services to businesses. Registered office: WOTSO, Level 1, George Street, North Strathfield NSW 2137, Australia.

For anything in this notice, including to exercise your rights, contact our Privacy Lead at enquiry@alfredai.bot or on +61 2 5759 8881. We have not appointed a statutory Data Protection Officer because we are not required to under Article 37; the Privacy Lead is the person accountable for data protection and is the contact point for individuals and for supervisory authorities.

We have no establishment in the European Union and have not appointed an Article 27 representative, because we do not offer goods or services to, or monitor the behaviour of, individuals in the European Union. That determination is recorded and reviewed; if it changes, this notice will change with it.

2. When we act for our clients rather than for ourselves

Much of what we do, we do on behalf of a business client. Where a client uses our platform or our services to process information about their own customers, staff or contacts, that client decides why and how the information is used and is the controller; we are the processor and act on their instructions. If you are one of their customers or contacts and you want to exercise your rights over that information, the client is the right party to ask, and if you contact us we will pass your request to them promptly and tell you that we have done so.

The rest of this notice describes the processing for which we ourselves are the controller. Where you are a business customer, our processing of the data you upload is additionally governed by the Data Processing Addendum set out below; where it applies and conflicts with this notice, it governs for that customer data.

3. What we process, why, on what basis, and for how long

PurposePersonal dataWhere it comes fromLawful basisRetention
Providing and administering an account on our platformName, email address, phone number, hashed credentials, account and usage recordsFrom youArticle 6(1)(b) performance of a contract; consent under Article 6(1)(a) for optional featuresFor the life of the account and 30 days after closure, then deleted
Responding to enquiries, including through the chat on our websitesName, email address, phone number, company, the content of your enquiryFrom youArticle 6(1)(f) legitimate interests — responding to a person who has approached us; consent where you opt in to further contact12 months from the last contact, unless you become a client
Business development and marketing to business contactsName, job title, business email address, business phone number, employer, publicly available professional informationFrom you, and from third-party business data providers and public sources — see section 4Article 6(1)(f) legitimate interests — business to business marketing, subject to the Spam Act 2003 (Cth)24 months from the last contact, then deleted
Billing and financial administrationName, email address, billing address, payment metadata (we do not store card numbers)From you and from our payment providerArticle 6(1)(b) contract and Article 6(1)(c) legal obligation7 years, as tax and accounting law requires
Operating and improving the AI workflows you useThe content you or your users put into a conversation, prompt or uploaded document, which may contain personal dataFrom you and your usersArticle 6(1)(b) contract, and the client’s instructions where we act as processorConversation content is retained for the period set on the account and is then purged automatically; the default period and how to change it are in your account settings
Security, monitoring and complianceAccount and security metadata, access logs, error and exception recordsGenerated by our systemsArticle 6(1)(f) legitimate interests — keeping our systems and our clients’ data secure; Article 6(1)(c) where a law requires itSecurity logs 12 months; compliance records for the period the relevant framework requires
Engaging and managing the people who work for usIdentity and contact details, engagement terms, screening assurance, training recordsFrom the individual and from the supplier that employs themArticle 6(1)(b) contract and Article 6(1)(c) legal obligation7 years after the engagement ends

4. Where we get data about you if not from you

For business development we obtain business contact information about people in roles relevant to our services from third-party business data providers — principally Apollo — and from publicly available sources such as company websites and search results, retrieved with the help of Apify, ScraperAPI and SerpAPI. The categories are: name, job title, business email address, business phone number, employer and publicly available professional information. We do not obtain special category data and we do not seek personal contact details.

If you were added this way, you have the same rights as anyone else, including the right to object at any time, and we will stop on request without asking for a reason. A fuller notice for this activity is published as our privacy notice for business contacts.

5. Who we share it with

We use service providers who process personal data on our instructions under a written agreement: cloud hosting and infrastructure (Amazon Web Services, Oracle Cloud, Google Workspace, Microsoft Azure), AI model providers (including OpenAI, Anthropic, Google via OpenRouter, and xAI), a vector search provider (Pinecone), voice and messaging providers (Vapi, Twilio, ElevenLabs, Recall.ai), business data providers (Apollo, Apify, ScraperAPI, SerpAPI), payment and finance providers (Stripe, Xero) and operational tooling. The current list, with what each provider does, is in the sub-processor list at the end of this page and is maintained in our sub-processor register, available on request.

We do not sell personal data. We disclose it to a regulator, a court or a law enforcement body only where we are legally required to.

6. Sending data outside Australia

Our platform is hosted in the United States (Amazon Web Services, us-east-1) and several of our providers are in the United States. Clients who require Australian data residency are served from a dedicated deployment in Sydney on Oracle Cloud.

Where a transfer is subject to Chapter V of the General Data Protection Regulation, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s data processing terms that incorporate them, together with supplementary measures: encryption in transit and at rest, restricted access, retention limits, and the minimisation and redaction of personal data placed in prompts sent to AI providers. You can obtain a copy of the safeguards for a particular transfer by emailing enquiry@alfredai.bot, and we will provide it within one month.

Model providers are reached through OpenRouter, and every request is restricted to providers that do not retain prompts or train on them. Under the Australian Privacy Principles we remain accountable for the information we send overseas and take reasonable steps to ensure our providers handle it consistently with those principles.

7. Automated decision-making

Our services use AI models to generate text, classify messages, summarise documents and hold voice conversations. These outputs support decisions made by people; we do not make decisions about you by automated means alone that have a legal effect on you or that similarly significantly affect you, and we do not carry out profiling for that purpose. Where a client configures a workflow that would do so, that client is the controller and is responsible for that decision; our AI Human Review Procedure sets out where human review is required.

8. Your rights

You may ask us to: give you access to your personal data and a copy of it; correct it; delete it; restrict how we use it; give you a portable copy in a machine-readable format; or stop using it where we rely on legitimate interests. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it, and withdrawal does not affect processing that already took place. You can ask us to stop marketing to you at any time and we will stop.

Email enquiry@alfredai.bot. We answer within one month and will tell you if we need a further two months because the request is complex. We do not charge for this except where a request is manifestly unfounded or excessive, and we will explain if that applies.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and, where the General Data Protection Regulation applies to your data, to the supervisory authority in your country or where the alleged infringement took place. You may also seek a judicial remedy.

9. Cookies and similar technologies

Our websites use cookies that are strictly necessary to make the site and the application work, including to keep you signed in and to protect against cross-site request forgery. These do not require consent. Where we use any cookie that is not strictly necessary, we ask for your consent first through the cookie banner, you can change or withdraw that choice at any time through the cookie settings link on the site, and the current list of cookies with their purpose and lifetime is available there.

10. Security and how long we keep things

We operate an information security management system certified to ISO/IEC 27001. Personal data is encrypted in transit and at rest, access is limited to the people who need it and protected by multi-factor authentication, and our web, application and data layers are separated at network level. The retention periods for each purpose are in the table above; where a period is set on your account, deletion is enforced automatically when it expires.

11. Changes to this notice

This notice carries a version number and an effective date. We review it at least annually and whenever our purposes, providers, transfers or retention periods change. We keep previous versions and can tell you what changed and when.


Data Processing Agreement (DPA)

Download the signed Data Processing Addendum (PDF) The addendum below forms part of the Terms and applies to every customer without further signature. The PDF is the same addendum, signed on behalf of Alfred AI Agent Services Pty Ltd, for customers who need a countersigned copy for their own records.

This Data Processing Agreement ("DPA") forms part of, and is subject to, the provisions of Alfred AI's Agreement (Terms and Conditions). All capitalised terms not defined in this DPA shall have the meanings set forth in the Agreement.

1. Definitions

"Affiliate": An entity that directly or indirectly Controls, is Controlled by, or is under common Control with another entity.

"Agreement": Alfred AI's Terms and Conditions, which govern the provision of the Services to the Customer, as may be updated by Alfred AI from time to time.

"Control": Ownership, voting, or similar interest representing fifty percent (50%) or more of the total interests then outstanding of the entity in question. The term "Controlled" shall be construed accordingly.

"Customer Data": Any Personal Data that Alfred AI processes on behalf of the Customer as a Data Processor in the course of providing Services, as more particularly described in this DPA.

"Data Protection Laws": All data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, where applicable, EU Data Protection Law, the Australian Privacy Act 1988, and relevant U.S. data protection laws such as the California Consumer Privacy Act (CCPA).

"Data Controller": An entity that determines the purposes and means of the processing of Personal Data.

"Data Processor": An entity that processes Personal Data on behalf of a Data Controller.

"EU Data Protection Law": (i) Prior to 25 May 2018, Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of Personal Data and on the free movement of such data ("Directive"); and on and after 25 May 2018, Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation) ("GDPR"); and (ii) Directive 2002/58/EC concerning the processing of Personal Data and the protection of privacy in the electronic communications sector and applicable national implementations of it (as may be amended, superseded, or replaced).

"EEA": For the purposes of this DPA, the European Economic Area, United Kingdom, and Switzerland.

"Group": Any and all Affiliates that are part of an entity's corporate group.

"Personal Data": Any information relating to an identified or identifiable natural person.

"Processing": As defined in the GDPR, and "process," "processes," and "processed" shall be interpreted accordingly.

"Security Incident": Any unauthorised or unlawful breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.

"Services": Any product or service provided by Alfred AI to the Customer pursuant to the Agreement.

"Sub-processor": Any Data Processor engaged by Alfred AI or its Affiliates to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA. Sub-processors may include third parties or members of the Alfred AI Group.

2. Relationship with the Agreement

2.1

The parties agree that this DPA shall replace any existing DPA the parties may have previously entered into in connection with the Services.

2.2

Except for the changes made by this DPA, the Agreement remains unchanged and in full force and effect. If there is any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of that conflict.

2.3

Any claims brought under or in connection with this DPA shall be subject to the terms and conditions, including but not limited to, the exclusions and limitations set forth in the Agreement.

2.4

No one other than a party to this DPA, its successors, and permitted assignees shall have any right to enforce any of its terms.

2.5

This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement, unless required otherwise by applicable Data Protection Laws.

3. Scope and Applicability of this DPA

3.1

This DPA applies where and only to the extent that Alfred AI processes Customer Data that originates from the EEA, Australia, the United States, and/or that is otherwise subject to EU Data Protection Law, the Australian Privacy Act 1988, or relevant U.S. data protection laws on behalf of the Customer as Data Processor in the course of providing Services pursuant to the Agreement.

4. Roles and Scope of Processing

4.1 Role of the Parties

As between Alfred AI and the Customer, the Customer is the Data Controller of Customer Data, and Alfred AI shall process Customer Data only as a Data Processor acting on behalf of the Customer.

4.2 Customer Processing of Customer Data

The Customer agrees that (i) it shall comply with its obligations as a Data Controller under Data Protection Laws in respect of its processing of Customer Data and any processing instructions it issues to Alfred AI; and (ii) it has provided notice and obtained (or shall obtain) all consents and rights necessary under Data Protection Laws for Alfred AI to process Customer Data and provide the Services pursuant to the Agreement and this DPA.

4.3 Alfred AI Processing of Customer Data

Alfred AI shall process Customer Data only for the purposes described in this DPA and only in accordance with the Customer's documented lawful instructions. The parties agree that this DPA and the Agreement set out the Customer's complete and final instructions to Alfred AI in relation to the processing of Customer Data, and processing outside the scope of these instructions (if any) shall require prior written agreement between the Customer and Alfred AI.

4.4 Details of Data Processing

(a) Subject matter: The subject matter of the data processing under this DPA is the Customer Data.

(b) Duration: As between Alfred AI and the Customer, the duration of the data processing under this DPA is until the termination of the Agreement in accordance with its terms.

(c) Purpose: The purpose of the data processing under this DPA is the provision of the Services to the Customer and the performance of Alfred AI's obligations under the Agreement (including this DPA) or as otherwise agreed by the parties.

(d) Nature of the processing: The Services as described in the Agreement and initiated by the Customer from time to time.

(e) Categories of data subjects: The Customer, the Customer's End Users, and any other individuals whose personal data is included in Content.

(f) Types of Customer Data: Personal Data related to the Customer, the Customer's End Users, or other individuals whose personal data is included in Content, which is processed as part of the Services in accordance with instructions given through the Customer's Account.

4.5 Legitimate Business Purposes

Notwithstanding anything to the contrary in the Agreement (including this DPA), the Customer acknowledges that Alfred AI has the right to use and disclose data related to the operation, support, and/or use of the Services for legitimate business purposes, such as billing, account management, technical support, product development, and marketing. To the extent any such data is considered Personal Data under Data Protection Laws, Alfred AI acts as the Data Controller and will process such data in compliance with the Alfred AI Privacy Policy and Data Protection Laws.

5. Subprocessing

5.1 Authorized Sub-processors

The Customer agrees that Alfred AI may engage Sub-processors to process Customer Data on the Customer's behalf. The Sub-processors currently engaged by Alfred AI are listed at the end of this page and are maintained in our sub-processor register. The list published here is reconciled against that register, and the register is available to the Customer on request.

5.2 Sub-processor Obligations

Alfred AI shall (i) enter into written agreements with Sub-processors that impose data protection terms requiring Sub-processors to protect Customer Data to the standard required by Data Protection Laws; and (ii) remain responsible for compliance with obligations under this DPA, as well as any actions or omissions by the Sub-processor that would cause Alfred AI to breach its obligations.

6. Security

6.1 Security Measures

Alfred AI will implement and maintain appropriate technical and organizational security measures to protect Customer Data from Security Incidents, in accordance with Alfred AI's security standards. This includes adhering to the Privacy Act 1988 and relevant U.S. state laws, such as the California Consumer Privacy Act (CCPA) and Virginia Consumer Data Protection Act (VCDPA).

6.2 Updates to Security Measures

The Customer is responsible for reviewing Alfred AI's available data security information and making an independent determination on the Services' adequacy for meeting the Customer's requirements and obligations under Data Protection Laws. Alfred AI reserves the right to update or modify its Security Measures without reducing overall security.

6.3 Customer Responsibilities

The Customer agrees that except as provided by this DPA, it is responsible for its secure use of the Services, including securing account credentials, protecting the security of Customer Data when in transit, and encrypting or backing up Customer Data.

7. International Transfers

7.1 Data Center Locations

Alfred AI may transfer and process Customer Data globally where Alfred AI, its Affiliates, or Sub-processors maintain data processing operations, and will ensure adequate protection for Customer Data per Data Protection Laws.

7.2 Australia Compliance

Alfred AI agrees not to disclose Customer Data to overseas recipients unless taking reasonable steps to ensure compliance with the Australian Privacy Principles (APPs) under the Privacy Act 1988.

7.3 U.S. Compliance

Alfred AI will implement appropriate safeguards to ensure compliance with applicable U.S. state privacy laws, including measures specified by the CCPA and VCDPA.

8. Additional Security

8.1 Confidentiality of Processing

Alfred AI will ensure that any person authorized by Alfred AI to process Customer Data is under an obligation of confidentiality.

8.2 Security Incident Response

Upon becoming aware of a Security Incident, Alfred AI will notify the Customer promptly and provide timely updates as information becomes available or upon the Customer's request.

9. Changes to Sub-processors

9.1 Notification of Changes

Alfred AI will provide an updated list of Sub-processors upon the Customer's written request and notify the Customer of changes at least 10 days in advance.

9.2 Objections to New Sub-processors

The Customer may object in writing to Alfred AI's appointment of a new Sub-processor within five calendar days based on reasonable grounds related to data protection. The parties will discuss such concerns in good faith, aiming to resolve them; if unresolved, the Customer may suspend or terminate the Agreement.

10. Deletion of Data

Upon termination or expiration of the Agreement, Alfred AI will, at the Customer's election, delete all Customer Data in its possession, except where retention is required by law or applies to archived backups, which Alfred AI will securely isolate and protect.

The Customer can request data deletion by contacting Alfred AI via support, fulfilled within 72 hours.

11. Cooperation

11.1 GDPR and Data Subject Rights

Alfred AI provides tools for the Customer to retrieve, correct, delete, or restrict Customer Data, assisting with GDPR obligations. If unable to access data independently, Alfred AI will assist with data subject requests (at the Customer's expense).

11.2 Law Enforcement Requests

Alfred AI will attempt to redirect law enforcement requests for Customer Data directly to the Customer and provide notice unless legally prohibited.

11.3 Impact Assessments

When required under Data Protection Laws, Alfred AI will assist the Customer in carrying out data protection impact assessments and consultations with authorities.

11.4 Information and Audit

Alfred AI makes available to the Customer all information necessary to demonstrate compliance with Article 28 of the General Data Protection Regulation, and allows for and contributes to audits, including inspections, conducted by the Customer or by an auditor mandated by the Customer. Alfred AI may satisfy an audit request by providing its current ISO/IEC 27001 certificate, its most recent penetration test summary and its completed security questionnaire. Where those do not answer the Customer's question, the Customer may audit on 30 days' notice, no more than once in any twelve months except following a personal data breach, during business hours, subject to confidentiality and without access to any other customer's data. (Article 28(3)(h).)

11.5 Infringing Instructions

Alfred AI informs the Customer immediately if, in its opinion, an instruction infringes the General Data Protection Regulation or another applicable data protection provision, and may suspend the affected processing until the instruction is confirmed or withdrawn. (Article 28(3), final paragraph.)

12. Liability

Liability for each party under this DPA is subject to exclusions and limitations in the Agreement. The Customer agrees to be responsible for regulatory penalties or claims incurred due to non-compliance with data protection obligations.

13. WhatsApp Business Integration Privacy

When you connect your WhatsApp Business Account through Meta's WhatsApp Embedded Signup, Alfred AI processes certain data to enable the integration:

13.1 Data Collection from Meta (Facebook)

We collect only the necessary information to enable WhatsApp Business integration, including:

13.2 Use of WhatsApp Integration Data

We use this data exclusively to:

13.3 Data Sharing and Security

We do not sell or share your WhatsApp integration data with third parties for marketing. Data is only shared with Meta as required for the integration and stored securely using industry-standard encryption. Access tokens are managed securely and never exposed to unauthorized parties.

13.4 Your Control

You can revoke our app's access to your WhatsApp Business Account at any time through Facebook Business Manager. Upon disconnection, all related data and tokens are deleted from our systems within 30 days.

13.5 Meta Compliance

Our WhatsApp integration fully complies with Meta Platform Terms, Developer Policies, and WhatsApp Business Terms of Service.

14. Google Services Integration

Alfred AI integrates with Google services (including Gmail and Google Calendar) to enable automated email and scheduling functionality within our chatbot platform.

14.1 Purpose of Google Integration

We use Google services exclusively to automate our chatbots' ability to send emails and manage calendar events on behalf of our users. This integration allows our AI chatbots to:

14.2 Google Data Processing

When using Google services for email and calendar automation, we process only the data necessary to perform the actions instructed by our users. This may include email addresses, message content, delivery preferences, calendar event details (title, description, attendees, start/end times), and availability information as configured in the chatbot settings.

14.3 No Training on Google Data

Your Google data is NOT used to train AI models. Alfred AI does not use your Gmail content, email messages, Google Calendar data, or any other Google-related data to train, fine-tune, or improve any AI or machine learning models. Your data is processed solely to provide the email drafting and calendar scheduling services and is not retained for training purposes.

14.4 AI Providers NOT Used for Google Workspace Data

The following AI providers are NOT used for processing any Gmail content, Google Calendar data, or other Google-related data:

14.5 Limited Use Disclosure

Alfred AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This applies to all Google Workspace APIs we access, including Gmail and Google Calendar. In particular, Alfred AI affirms that:

15. Miscellaneous

The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.

Alfred AI's Sub-processors:

The following Sub-processors may process Customer Data. This list is reconciled against our sub-processor register and was last reviewed on 18 August 2026. We notify the Customer of changes at least 10 days in advance, as clause 9.1 provides, and the register with the agreement reference held for each Sub-processor is available on request.

Sub-processorWhat it does for usLocation
Amazon Web ServicesCloud hosting, storage and managed databases for the shared platformUnited States (us-east-1)
Oracle CloudDedicated per-client hosting, including deployments for clients requiring Australian data residencyAustralia (Sydney)
Microsoft AzureClient mailbox and document integrationPer client — recorded in the register
Google WorkspaceEmail, identity and document servicesUnited States
GitHubSource code managementUnited States
OpenRouterAI model routing, including the Google Gemini and DeepSeek models reached through itUnited States
OpenAIAI model inferenceUnited States
AnthropicAI model inferenceUnited States
xAIAI model inferenceUnited States
PineconeVector search over document and conversation contentUnited States
VapiVoice assistant platformUnited States
TwilioTelephony and messagingUnited States
ElevenLabsSpeech synthesisUnited States
Recall.aiMeeting recording and transcriptionUnited States
ApifyPublic web retrieval for business developmentUnited States
ScraperAPIPublic web retrieval for business developmentUnited States
SerpAPISearch result retrieval for business developmentUnited States
ApolloBusiness contact data for business developmentUnited States
StripePayment processingUnited States
XeroFinancial administration and invoicingNew Zealand
SlackInternal collaborationUnited States
DropboxDocument storage and transferUnited States
MailerSendTransactional and outreach email deliveryUnited States
Better StackUptime and log monitoringRecorded in the register
CloudflareNetwork and DNS protection — being adopted; not yet processing any personal data. Listed here as advance notice under clause 9.1.United States, once live
ExpoMobile application build and deliveryUnited States
PipedriveCustomer relationship managementAustralia
VantaCompliance monitoringUnited States

Error monitoring is operated on our own infrastructure and is not provided by a third party, so no Sub-processor is engaged for it. Providers listed in our vendor register that do not receive Customer Data are not Sub-processors and are not listed here.

The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.