Alfred AI Agent Services Pty Ltd (ABN 62 684 936 525), trading as AlfredAI, of Sydney, New South Wales, Australia, provides AI integration and automation services to businesses. Registered office: WOTSO, Level 1, George Street, North Strathfield NSW 2137, Australia.
For anything in this notice, including to exercise your rights, contact our Privacy Lead at enquiry@alfredai.bot or on +61 2 5759 8881. We have not appointed a statutory Data Protection Officer because we are not required to under Article 37; the Privacy Lead is the person accountable for data protection and is the contact point for individuals and for supervisory authorities.
We have no establishment in the European Union and have not appointed an Article 27 representative, because we do not offer goods or services to, or monitor the behaviour of, individuals in the European Union. That determination is recorded and reviewed; if it changes, this notice will change with it.
Much of what we do, we do on behalf of a business client. Where a client uses our platform or our services to process information about their own customers, staff or contacts, that client decides why and how the information is used and is the controller; we are the processor and act on their instructions. If you are one of their customers or contacts and you want to exercise your rights over that information, the client is the right party to ask, and if you contact us we will pass your request to them promptly and tell you that we have done so.
The rest of this notice describes the processing for which we ourselves are the controller. Where you are a business customer, our processing of the data you upload is additionally governed by the Data Processing Addendum set out below; where it applies and conflicts with this notice, it governs for that customer data.
| Purpose | Personal data | Where it comes from | Lawful basis | Retention |
|---|---|---|---|---|
| Providing and administering an account on our platform | Name, email address, phone number, hashed credentials, account and usage records | From you | Article 6(1)(b) performance of a contract; consent under Article 6(1)(a) for optional features | For the life of the account and 30 days after closure, then deleted |
| Responding to enquiries, including through the chat on our websites | Name, email address, phone number, company, the content of your enquiry | From you | Article 6(1)(f) legitimate interests — responding to a person who has approached us; consent where you opt in to further contact | 12 months from the last contact, unless you become a client |
| Business development and marketing to business contacts | Name, job title, business email address, business phone number, employer, publicly available professional information | From you, and from third-party business data providers and public sources — see section 4 | Article 6(1)(f) legitimate interests — business to business marketing, subject to the Spam Act 2003 (Cth) | 24 months from the last contact, then deleted |
| Billing and financial administration | Name, email address, billing address, payment metadata (we do not store card numbers) | From you and from our payment provider | Article 6(1)(b) contract and Article 6(1)(c) legal obligation | 7 years, as tax and accounting law requires |
| Operating and improving the AI workflows you use | The content you or your users put into a conversation, prompt or uploaded document, which may contain personal data | From you and your users | Article 6(1)(b) contract, and the client’s instructions where we act as processor | Conversation content is retained for the period set on the account and is then purged automatically; the default period and how to change it are in your account settings |
| Security, monitoring and compliance | Account and security metadata, access logs, error and exception records | Generated by our systems | Article 6(1)(f) legitimate interests — keeping our systems and our clients’ data secure; Article 6(1)(c) where a law requires it | Security logs 12 months; compliance records for the period the relevant framework requires |
| Engaging and managing the people who work for us | Identity and contact details, engagement terms, screening assurance, training records | From the individual and from the supplier that employs them | Article 6(1)(b) contract and Article 6(1)(c) legal obligation | 7 years after the engagement ends |
For business development we obtain business contact information about people in roles relevant to our services from third-party business data providers — principally Apollo — and from publicly available sources such as company websites and search results, retrieved with the help of Apify, ScraperAPI and SerpAPI. The categories are: name, job title, business email address, business phone number, employer and publicly available professional information. We do not obtain special category data and we do not seek personal contact details.
If you were added this way, you have the same rights as anyone else, including the right to object at any time, and we will stop on request without asking for a reason. A fuller notice for this activity is published as our privacy notice for business contacts.
We use service providers who process personal data on our instructions under a written agreement: cloud hosting and infrastructure (Amazon Web Services, Oracle Cloud, Google Workspace, Microsoft Azure), AI model providers (including OpenAI, Anthropic, Google via OpenRouter, and xAI), a vector search provider (Pinecone), voice and messaging providers (Vapi, Twilio, ElevenLabs, Recall.ai), business data providers (Apollo, Apify, ScraperAPI, SerpAPI), payment and finance providers (Stripe, Xero) and operational tooling. The current list, with what each provider does, is in the sub-processor list at the end of this page and is maintained in our sub-processor register, available on request.
We do not sell personal data. We disclose it to a regulator, a court or a law enforcement body only where we are legally required to.
Our platform is hosted in the United States (Amazon Web Services, us-east-1) and several of our providers are in the United States. Clients who require Australian data residency are served from a dedicated deployment in Sydney on Oracle Cloud.
Where a transfer is subject to Chapter V of the General Data Protection Regulation, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s data processing terms that incorporate them, together with supplementary measures: encryption in transit and at rest, restricted access, retention limits, and minimisation of the personal data placed in prompts sent to AI providers — prompts carry no account, user or session identifier, and the providers are restricted to those that do not retain prompts beyond the request or train on them, save where stated otherwise in our sub-processor register. You can obtain a copy of the safeguards for a particular transfer by emailing enquiry@alfredai.bot, and we will provide it within one month.
Chatbot model providers are reached through OpenRouter, and every such request is pinned to routing that restricts it to providers which state that they do not retain prompts beyond the request or train on them. OpenRouter designates those providers from their published policies and does not itself guarantee that they comply. Voice assistants are provided through Vapi, which selects the model provider on its own side; the terms we hold with Vapi permit it to process the data to perform and improve its service. Under the Australian Privacy Principles we remain accountable for the information we send overseas and take reasonable steps to ensure our providers handle it consistently with those principles.
Our services use AI models to generate text, classify messages, summarise documents and hold voice conversations. These outputs support decisions made by people; we do not make decisions about you by automated means alone that have a legal effect on you or that similarly significantly affect you, and we do not carry out profiling for that purpose. Where a client configures a workflow that would do so, that client is the controller and is responsible for that decision; our AI Human Review Procedure sets out where human review is required.
You may ask us to: give you access to your personal data and a copy of it; correct it; delete it; restrict how we use it; give you a portable copy in a machine-readable format; or stop using it where we rely on legitimate interests. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it, and withdrawal does not affect processing that already took place. You can ask us to stop marketing to you at any time and we will stop.
Email enquiry@alfredai.bot. We answer within one month and will tell you if we need a further two months because the request is complex. We do not charge for this except where a request is manifestly unfounded or excessive, and we will explain if that applies.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and, where the General Data Protection Regulation applies to your data, to the supervisory authority in your country or where the alleged infringement took place. You may also seek a judicial remedy.
Our websites use cookies that are strictly necessary to make the site and the application work, including to keep you signed in and to protect against cross-site request forgery. These do not require consent. Where we use any cookie that is not strictly necessary, we ask for your consent first through the cookie banner, you can change or withdraw that choice at any time through the cookie settings link on the site, and the current list of cookies with their purpose and lifetime is available there.
We operate an information security management system certified to ISO/IEC 27001. Personal data is encrypted in transit and at rest, access is limited to the people who need it and protected by multi-factor authentication, and our web, application and data layers are separated at network level. The retention periods for each purpose are in the table above; where a period is set on your account, deletion is enforced automatically when it expires.
This notice carries a version number and an effective date. We review it at least annually and whenever our purposes, providers, transfers or retention periods change. We keep previous versions and can tell you what changed and when.
Where you are a business customer and we process personal data on your behalf, our Data Processing Addendum applies. It forms part of the Terms and applies to every customer without further signature. It sets out our obligations as your processor under Article 28 of the GDPR and the Australian Privacy Act 1988, and includes Annex 1 (the processing), Annex 2 (technical and organisational measures) and Annex 3 (authorised sub-processors). The PDF is approved and signed on behalf of Alfred AI Agent Services Pty Ltd. A copy signed by both parties is provided on request to enquiry@alfredai.bot.
Download the Data Processing Addendum v2.3 (PDF) Version 2.3, effective 29 September 2026. Previous versions: v2.2 (effective 28 September 2026), v2.0 (effective 13 August 2026). The current list of sub-processors is also published at the end of this page.
When you connect your WhatsApp Business Account through Meta's WhatsApp Embedded Signup, Alfred AI processes certain data to enable the integration:
We collect only the necessary information to enable WhatsApp Business integration, including:
We use this data exclusively to:
We do not sell or share your WhatsApp integration data with third parties for marketing. Data is only shared with Meta as required for the integration and stored securely using industry-standard encryption. Access tokens are managed securely and never exposed to unauthorized parties.
You can revoke our app's access to your WhatsApp Business Account at any time through Facebook Business Manager. Upon disconnection, all related data and tokens are deleted from our systems within 30 days.
Our WhatsApp integration fully complies with Meta Platform Terms, Developer Policies, and WhatsApp Business Terms of Service.
Alfred AI integrates with Google services (including Gmail and Google Calendar) to enable automated email and scheduling functionality within our chatbot platform.
We use Google services exclusively to automate our chatbots' ability to send emails and manage calendar events on behalf of our users. This integration allows our AI chatbots to:
When using Google services for email and calendar automation, we process only the data necessary to perform the actions instructed by our users. This may include email addresses, message content, delivery preferences, calendar event details (title, description, attendees, start/end times), and availability information as configured in the chatbot settings.
Your Google data is NOT used to train AI models. Alfred AI does not use your Gmail content, email messages, Google Calendar data, or any other Google-related data to train, fine-tune, or improve any AI or machine learning models. Your data is processed solely to provide the email drafting and calendar scheduling services and is not retained for training purposes.
The following AI providers are NOT used for processing any Gmail content, Google Calendar data, or other Google-related data:
Alfred AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
This applies to all Google Workspace APIs we access, including Gmail and Google Calendar. In particular, Alfred AI affirms that:
The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.
The following Sub-processors may process Customer Data. This list is reconciled against our sub-processor register and was last reviewed on 28 September 2026. We notify the Customer of any intended addition or replacement at least 30 days in advance, as clause 3(b) of the Data Processing Addendum provides, and the register with the agreement reference held for each Sub-processor is available on request.
| Sub-processor | What it does for us | Location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage and managed databases for the shared platform | United States (us-east-1) |
| Oracle Cloud | Dedicated per-client hosting, including deployments for clients requiring Australian data residency | Australia (Sydney) |
| Microsoft Azure | Client mailbox and document integration | Per client — recorded in the register |
| Google Workspace | Email, identity and document services | United States |
| GitHub | Source code management | United States |
| OpenRouter | AI model routing, including the Google Gemini and DeepSeek models reached through it | United States; for DeepSeek models, routed hosts include providers in the United States, Europe and China |
| OpenAI | AI model inference | United States |
| Anthropic | AI model inference | United States |
| xAI | AI model inference | United States |
| Pinecone | Vector search over document and conversation content | United States |
| Vapi | Voice assistant platform | United States |
| Twilio | Telephony and messaging | United States |
| ElevenLabs | Speech synthesis | United States |
| Recall.ai | Meeting recording and transcription | United States |
| Apify | Public web retrieval for business development | United States |
| Apollo | Business contact data for business development | United States |
| Stripe | Payment processing | United States |
| Xero | Financial administration and invoicing | New Zealand |
| Slack | Internal collaboration | United States |
| Dropbox | Document storage and transfer | United States |
| MailerSend | Transactional and outreach email delivery | United States |
| Meta (WhatsApp Business Platform) | Delivery of WhatsApp messages to and from client contacts | Ireland (WhatsApp Ireland Limited), with onward transfer to the United States |
| Bitly | Link shortening for shared chatbot links | United States |
| Ignition | Reporting over the client's proposals and engagements, under the client's authorisation | United States and Australia |
| Apple | In-app purchase receipt validation for the mobile app | United States |
| Better Stack | Uptime monitoring of the public endpoints | United States |
| Cloudflare | Network and DNS protection — being adopted; not yet processing any personal data. Listed here as advance notice under clause 3(b) of the Data Processing Addendum. | United States, once live |
| Expo | Mobile application build and delivery | United States |
| Pipedrive | Customer relationship management | Australia |
| Vanta | Compliance monitoring | United States |
Error monitoring is operated on our own infrastructure and is not provided by a third party, so no Sub-processor is engaged for it. Providers listed in our vendor register that do not receive Customer Data are not Sub-processors and are not listed here.
The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.