Privacy Notice

GDP-PN-01 · Version 2.1 · Effective 26 September 2026
Articles 13 and 14 GDPR  |  Privacy Act 1988 (Cth) and the Australian Privacy Principles
Reviewed at least annually and on any change to purposes, providers, transfers or retention periods. Previous versions are retained and we can tell you what changed and when.

1. Who we are

Alfred AI Agent Services Pty Ltd (ABN 62 684 936 525), trading as AlfredAI, of Sydney, New South Wales, Australia, provides AI integration and automation services to businesses. Registered office: WOTSO, Level 1, George Street, North Strathfield NSW 2137, Australia.

For anything in this notice, including to exercise your rights, contact our Privacy Lead at enquiry@alfredai.bot or on +61 2 5759 8881. We have not appointed a statutory Data Protection Officer because we are not required to under Article 37; the Privacy Lead is the person accountable for data protection and is the contact point for individuals and for supervisory authorities.

We have no establishment in the European Union and have not appointed an Article 27 representative, because we do not offer goods or services to, or monitor the behaviour of, individuals in the European Union. That determination is recorded and reviewed; if it changes, this notice will change with it.

2. When we act for our clients rather than for ourselves

Much of what we do, we do on behalf of a business client. Where a client uses our platform or our services to process information about their own customers, staff or contacts, that client decides why and how the information is used and is the controller; we are the processor and act on their instructions. If you are one of their customers or contacts and you want to exercise your rights over that information, the client is the right party to ask, and if you contact us we will pass your request to them promptly and tell you that we have done so.

The rest of this notice describes the processing for which we ourselves are the controller. Where you are a business customer, our processing of the data you upload is additionally governed by the Data Processing Addendum set out below; where it applies and conflicts with this notice, it governs for that customer data.

3. What we process, why, on what basis, and for how long

PurposePersonal dataWhere it comes fromLawful basisRetention
Providing and administering an account on our platformName, email address, phone number, hashed credentials, account and usage recordsFrom youArticle 6(1)(b) performance of a contract; consent under Article 6(1)(a) for optional featuresFor the life of the account and 30 days after closure, then deleted
Responding to enquiries, including through the chat on our websitesName, email address, phone number, company, the content of your enquiryFrom youArticle 6(1)(f) legitimate interests — responding to a person who has approached us; consent where you opt in to further contact12 months from the last contact, unless you become a client
Business development and marketing to business contactsName, job title, business email address, business phone number, employer, publicly available professional informationFrom you, and from third-party business data providers and public sources — see section 4Article 6(1)(f) legitimate interests — business to business marketing, subject to the Spam Act 2003 (Cth)24 months from the last contact, then deleted
Billing and financial administrationName, email address, billing address, payment metadata (we do not store card numbers)From you and from our payment providerArticle 6(1)(b) contract and Article 6(1)(c) legal obligation7 years, as tax and accounting law requires
Operating and improving the AI workflows you useThe content you or your users put into a conversation, prompt or uploaded document, which may contain personal dataFrom you and your usersArticle 6(1)(b) contract, and the client’s instructions where we act as processorConversation content is retained for the period set on the account and is then purged automatically; the default period and how to change it are in your account settings
Security, monitoring and complianceAccount and security metadata, access logs, error and exception recordsGenerated by our systemsArticle 6(1)(f) legitimate interests — keeping our systems and our clients’ data secure; Article 6(1)(c) where a law requires itSecurity logs 12 months; compliance records for the period the relevant framework requires
Engaging and managing the people who work for usIdentity and contact details, engagement terms, screening assurance, training recordsFrom the individual and from the supplier that employs themArticle 6(1)(b) contract and Article 6(1)(c) legal obligation7 years after the engagement ends

4. Where we get data about you if not from you

For business development we obtain business contact information about people in roles relevant to our services from third-party business data providers — principally Apollo — and from publicly available sources such as company websites and search results, retrieved with the help of Apify, ScraperAPI and SerpAPI. The categories are: name, job title, business email address, business phone number, employer and publicly available professional information. We do not obtain special category data and we do not seek personal contact details.

If you were added this way, you have the same rights as anyone else, including the right to object at any time, and we will stop on request without asking for a reason. A fuller notice for this activity is published as our privacy notice for business contacts.

5. Who we share it with

We use service providers who process personal data on our instructions under a written agreement: cloud hosting and infrastructure (Amazon Web Services, Oracle Cloud, Google Workspace, Microsoft Azure), AI model providers (including OpenAI, Anthropic, Google via OpenRouter, and xAI), a vector search provider (Pinecone), voice and messaging providers (Vapi, Twilio, ElevenLabs, Recall.ai), business data providers (Apollo, Apify, ScraperAPI, SerpAPI), payment and finance providers (Stripe, Xero) and operational tooling. The current list, with what each provider does, is in the sub-processor list at the end of this page and is maintained in our sub-processor register, available on request.

We do not sell personal data. We disclose it to a regulator, a court or a law enforcement body only where we are legally required to.

6. Sending data outside Australia

Our platform is hosted in the United States (Amazon Web Services, us-east-1) and several of our providers are in the United States. Clients who require Australian data residency are served from a dedicated deployment in Sydney on Oracle Cloud.

Where a transfer is subject to Chapter V of the General Data Protection Regulation, we rely on the European Commission’s Standard Contractual Clauses, or on the provider’s data processing terms that incorporate them, together with supplementary measures: encryption in transit and at rest, restricted access, retention limits, and minimisation of the personal data placed in prompts sent to AI providers — prompts carry no account, user or session identifier, and the providers are restricted to those that do not retain prompts beyond the request or train on them, save where stated otherwise in our sub-processor register. You can obtain a copy of the safeguards for a particular transfer by emailing enquiry@alfredai.bot, and we will provide it within one month.

Chatbot model providers are reached through OpenRouter, and every such request is pinned to routing that restricts it to providers which state that they do not retain prompts beyond the request or train on them. OpenRouter designates those providers from their published policies and does not itself guarantee that they comply. Voice assistants are provided through Vapi, which selects the model provider on its own side; the terms we hold with Vapi permit it to process the data to perform and improve its service. Under the Australian Privacy Principles we remain accountable for the information we send overseas and take reasonable steps to ensure our providers handle it consistently with those principles.

7. Automated decision-making

Our services use AI models to generate text, classify messages, summarise documents and hold voice conversations. These outputs support decisions made by people; we do not make decisions about you by automated means alone that have a legal effect on you or that similarly significantly affect you, and we do not carry out profiling for that purpose. Where a client configures a workflow that would do so, that client is the controller and is responsible for that decision; our AI Human Review Procedure sets out where human review is required.

8. Your rights

You may ask us to: give you access to your personal data and a copy of it; correct it; delete it; restrict how we use it; give you a portable copy in a machine-readable format; or stop using it where we rely on legitimate interests. Where we rely on your consent, you can withdraw it at any time, as easily as you gave it, and withdrawal does not affect processing that already took place. You can ask us to stop marketing to you at any time and we will stop.

Email enquiry@alfredai.bot. We answer within one month and will tell you if we need a further two months because the request is complex. We do not charge for this except where a request is manifestly unfounded or excessive, and we will explain if that applies.

If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, and, where the General Data Protection Regulation applies to your data, to the supervisory authority in your country or where the alleged infringement took place. You may also seek a judicial remedy.

9. Cookies and similar technologies

Our websites use cookies that are strictly necessary to make the site and the application work, including to keep you signed in and to protect against cross-site request forgery. These do not require consent. Where we use any cookie that is not strictly necessary, we ask for your consent first through the cookie banner, you can change or withdraw that choice at any time through the cookie settings link on the site, and the current list of cookies with their purpose and lifetime is available there.

10. Security and how long we keep things

We operate an information security management system certified to ISO/IEC 27001. Personal data is encrypted in transit and at rest, access is limited to the people who need it and protected by multi-factor authentication, and our web, application and data layers are separated at network level. The retention periods for each purpose are in the table above; where a period is set on your account, deletion is enforced automatically when it expires.

11. Changes to this notice

This notice carries a version number and an effective date. We review it at least annually and whenever our purposes, providers, transfers or retention periods change. We keep previous versions and can tell you what changed and when.


Data Processing Addendum (DPA)

Where you are a business customer and we process personal data on your behalf, our Data Processing Addendum applies. It forms part of the Terms and applies to every customer without further signature. It sets out our obligations as your processor under Article 28 of the GDPR and the Australian Privacy Act 1988, and includes Annex 1 (the processing), Annex 2 (technical and organisational measures) and Annex 3 (authorised sub-processors). The PDF is approved and signed on behalf of Alfred AI Agent Services Pty Ltd. A copy signed by both parties is provided on request to enquiry@alfredai.bot.

Download the Data Processing Addendum v2.3 (PDF) Version 2.3, effective 29 September 2026. Previous versions: v2.2 (effective 28 September 2026), v2.0 (effective 13 August 2026). The current list of sub-processors is also published at the end of this page.


13. WhatsApp Business Integration Privacy

When you connect your WhatsApp Business Account through Meta's WhatsApp Embedded Signup, Alfred AI processes certain data to enable the integration:

13.1 Data Collection from Meta (Facebook)

We collect only the necessary information to enable WhatsApp Business integration, including:

13.2 Use of WhatsApp Integration Data

We use this data exclusively to:

13.3 Data Sharing and Security

We do not sell or share your WhatsApp integration data with third parties for marketing. Data is only shared with Meta as required for the integration and stored securely using industry-standard encryption. Access tokens are managed securely and never exposed to unauthorized parties.

13.4 Your Control

You can revoke our app's access to your WhatsApp Business Account at any time through Facebook Business Manager. Upon disconnection, all related data and tokens are deleted from our systems within 30 days.

13.5 Meta Compliance

Our WhatsApp integration fully complies with Meta Platform Terms, Developer Policies, and WhatsApp Business Terms of Service.

14. Google Services Integration

Alfred AI integrates with Google services (including Gmail and Google Calendar) to enable automated email and scheduling functionality within our chatbot platform.

14.1 Purpose of Google Integration

We use Google services exclusively to automate our chatbots' ability to send emails and manage calendar events on behalf of our users. This integration allows our AI chatbots to:

14.2 Google Data Processing

When using Google services for email and calendar automation, we process only the data necessary to perform the actions instructed by our users. This may include email addresses, message content, delivery preferences, calendar event details (title, description, attendees, start/end times), and availability information as configured in the chatbot settings.

14.3 No Training on Google Data

Your Google data is NOT used to train AI models. Alfred AI does not use your Gmail content, email messages, Google Calendar data, or any other Google-related data to train, fine-tune, or improve any AI or machine learning models. Your data is processed solely to provide the email drafting and calendar scheduling services and is not retained for training purposes.

14.4 AI Providers NOT Used for Google Workspace Data

The following AI providers are NOT used for processing any Gmail content, Google Calendar data, or other Google-related data:

14.5 Limited Use Disclosure

Alfred AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

This applies to all Google Workspace APIs we access, including Gmail and Google Calendar. In particular, Alfred AI affirms that:

15. Miscellaneous

The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.

Alfred AI's Sub-processors:

The following Sub-processors may process Customer Data. This list is reconciled against our sub-processor register and was last reviewed on 28 September 2026. We notify the Customer of any intended addition or replacement at least 30 days in advance, as clause 3(b) of the Data Processing Addendum provides, and the register with the agreement reference held for each Sub-processor is available on request.

Sub-processorWhat it does for usLocation
Amazon Web ServicesCloud hosting, storage and managed databases for the shared platformUnited States (us-east-1)
Oracle CloudDedicated per-client hosting, including deployments for clients requiring Australian data residencyAustralia (Sydney)
Microsoft AzureClient mailbox and document integrationPer client — recorded in the register
Google WorkspaceEmail, identity and document servicesUnited States
GitHubSource code managementUnited States
OpenRouterAI model routing, including the Google Gemini and DeepSeek models reached through itUnited States; for DeepSeek models, routed hosts include providers in the United States, Europe and China
OpenAIAI model inferenceUnited States
AnthropicAI model inferenceUnited States
xAIAI model inferenceUnited States
PineconeVector search over document and conversation contentUnited States
VapiVoice assistant platformUnited States
TwilioTelephony and messagingUnited States
ElevenLabsSpeech synthesisUnited States
Recall.aiMeeting recording and transcriptionUnited States
ApifyPublic web retrieval for business developmentUnited States
ApolloBusiness contact data for business developmentUnited States
StripePayment processingUnited States
XeroFinancial administration and invoicingNew Zealand
SlackInternal collaborationUnited States
DropboxDocument storage and transferUnited States
MailerSendTransactional and outreach email deliveryUnited States
Meta (WhatsApp Business Platform)Delivery of WhatsApp messages to and from client contactsIreland (WhatsApp Ireland Limited), with onward transfer to the United States
BitlyLink shortening for shared chatbot linksUnited States
IgnitionReporting over the client's proposals and engagements, under the client's authorisationUnited States and Australia
AppleIn-app purchase receipt validation for the mobile appUnited States
Better StackUptime monitoring of the public endpointsUnited States
CloudflareNetwork and DNS protection — being adopted; not yet processing any personal data. Listed here as advance notice under clause 3(b) of the Data Processing Addendum.United States, once live
ExpoMobile application build and deliveryUnited States
PipedriveCustomer relationship managementAustralia
VantaCompliance monitoringUnited States

Error monitoring is operated on our own infrastructure and is not provided by a third party, so no Sub-processor is engaged for it. Providers listed in our vendor register that do not receive Customer Data are not Sub-processors and are not listed here.

The Customer is responsible for any additional costs arising from Alfred AI's compliance with instructions falling outside standard functionality.