Privacy Policy
What personal information we actually collect, exactly who receives it, and how to get it back, corrected or deleted. Written to match what our systems really do — not a template.
01Scope and commitment
This policy explains how Jesse A Mckenzie trading as Automated Australia (ABN 61 183 020 382) handles personal information. It covers this website, our sales and onboarding process, and the services we deliver to clients.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As a small business we may fall below the $3 million turnover threshold that makes APP compliance mandatory — we comply anyway, and we treat the obligations in this policy as binding on us.
"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
02What we collect
We collect only what we need to quote, build, deliver, support and bill. In practice:
Contact and business details
- your name and the business you represent;
- email address and phone number;
- your business location (suburb and state), industry or profession;
- your current website address, if you have one;
- anything you choose to write in the notes field, or send us by email.
Order and payment information
- the services or templates you select, quantities, prices and order history;
- billing address, which is collected by Stripe on its own hosted checkout page;
- we never see, receive or store your full card number, expiry or CVC. Card details go directly to Stripe. We receive only a confirmation, the last four digits and the card type.
Technical information
Aggregate page-view and visitor-count data from Vercel Web Analytics, which is privacy-preserving and does not use cookies or build a cross-site profile of you. Our hosting provider also keeps standard server and function logs which may briefly include IP addresses for security and debugging.
Project information
Content you supply for the work — copy, images, logins we need to deploy, and any material you ask us to publish. Where that content contains other people's personal information (for example staff photos or customer testimonials), section 10 applies.
We do not collect sensitive information as defined in the Privacy Act — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record or biometric data — and we ask that you do not send it to us. If it turns out we need it for a project, we will ask for your consent first and explain why.
03How we collect it
Wherever possible we collect personal information directly from you:
- when you complete the checkout form on this website;
- when you email us, call us, or message us on social media;
- when you book a call through our scheduling link;
- during discovery, onboarding and the day-to-day running of a project;
- when you reply to one of our emails.
We also collect information indirectly from publicly available sources — see section 4, which explains this in full because we think you are entitled to know exactly how it works.
If we receive personal information about you that we did not ask for and did not need, we will destroy or de-identify it as soon as practicable, provided it is lawful to do so.
04Business data we research
Part of how we find clients is researching Australian businesses that might benefit from what we do. We want to be straight about this rather than bury it.
We compile business information from publicly available sources — business directories, public search results, publicly listed business websites and public social media business profiles. That may include a business name, trading address, public phone number and email, industry category, website address, and publicly posted reviews or ratings.
This is business contact information. Where it identifies an individual — for example a sole trader whose business email is their own name — it is personal information, and this policy applies to it in full.
You can stop it immediately. Use the unsubscribe link in any email, or reply with "remove", or email jesse@automatedaustralia.com. We will suppress your details permanently — which means we keep the minimum needed to make sure we never contact you again, and nothing else.
You can also ask us to tell you what we hold about your business and to delete it entirely. We will do that free of charge.
We do not buy or sell contact lists, we do not harvest personal email addresses of individuals for marketing, and we do not use address-harvesting software of the kind prohibited by the Spam Act 2003 (Cth).
05Why we collect it
We use personal information only for purposes you would reasonably expect:
- to prepare quotes and respond to enquiries;
- to deliver, host and support the services you have engaged us for;
- to process payments and issue tax invoices;
- to communicate about your project — updates, approvals, support;
- to send occasional marketing about our services, subject to section 6 and always with an unsubscribe;
- to improve this website and our services using aggregate, non-identifying data;
- to meet our legal obligations — tax and business records, and responding to lawful requests.
We do not use personal information for automated decision-making that produces a legal or similarly significant effect on you, and we do not sell personal information to anyone, ever.
06Marketing and the Spam Act
Commercial electronic messages we send comply with the Spam Act 2003 (Cth). That means every marketing email:
- clearly identifies Automated Australia as the sender, with real contact details;
- contains a working unsubscribe that we honour within 5 business days;
- is sent either with your consent, or on the inferred-consent basis the Act allows for published business contact addresses relevant to the recipient's role.
Unsubscribing from marketing does not stop necessary service messages about work in progress — invoices, deployment notices, security alerts. If you want those to stop too, you are asking us to end the engagement, which is fine, just say so directly.
08Who we share it with
We disclose personal information only where it is necessary. The full list of categories is:
- Stripe
- Payment processing. Receives your email and order details, and collects your billing address and card details directly on its own checkout page.
- Vercel
- Website hosting, serverless functions and cookieless analytics. Handles all traffic to this site and standard server logs.
- Cal.com
- Scheduling, if you choose to book a call through our booking link.
- Google Fonts, Cloudflare, unpkg, jsDelivr
- Content delivery for fonts and JavaScript libraries.
- Email, accounting and messaging
- Our email provider, accounting software and internal notification tools, used to correspond with you, invoice you and meet tax record obligations.
- Contracted sales representatives
- Independent representatives who sell on our behalf may access business contact details for prospects they are working. Each is bound by written confidentiality and privacy obligations, access is limited and logged, and all data is returned or destroyed when their engagement ends.
- Professional advisers
- Accountants and lawyers, where genuinely required and under confidentiality.
- Law enforcement and regulators
- Where we are required or authorised by law to disclose.
Where we deliver a project, we may also set up services in your name — hosting, domains, email, AI providers, analytics. We will tell you which ones before we do it. Your relationship with those providers is direct, and their privacy policies apply to you.
If our business is ever sold or restructured, personal information may transfer to the buyer as part of the business, subject to this policy continuing to apply.
09Overseas disclosure
Several providers above store or process data outside Australia — most commonly in the United States, and in the case of global CDNs, at edge locations worldwide. Stripe and Vercel are both United States companies.
By using this website or engaging us, you acknowledge that your personal information may be disclosed to overseas recipients. We take reasonable steps to use reputable providers with published privacy commitments and appropriate contractual protections. However, once information is held overseas it may be subject to foreign laws, and we cannot guarantee an overseas recipient will handle it in a way that meets the Australian Privacy Principles.
10Data we handle for clients
When we build or run systems for a client — a website, a CRM, an AI agent, an automation — we may process personal information belonging to their customers. In that situation:
- the client remains responsible for that information and for having a lawful basis to collect it;
- we act on the client's instructions and use it only to provide the service;
- we do not use it for our own marketing, do not sell it, and do not use it to train models;
- we return or delete it when the engagement ends, subject to the backup window in our Terms of Service.
Demo sites. We publish sample builds for prospective clients. Those demo pages include a small view counter that records the demo identifier, timestamp, referring page and a one-way hashed form of the visitor's IP address used purely to avoid counting the same visit twice. Raw IP addresses are never stored, and this data is not used to identify or market to visitors.
If you are a customer of one of our clients and want your information accessed or deleted, contact that business directly — they control it. Tell us as well and we will help them action it.
11Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. That includes encrypted connections (HTTPS) across the site, multi-factor authentication on our critical accounts, secrets held in environment variables rather than in code, restricted access on a need-to-know basis, and reputable infrastructure providers.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we will act on it immediately and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
12How long we keep it
We keep personal information only as long as we need it, then destroy or de-identify it:
- Enquiries that go nowhere — up to 24 months, then deleted.
- Client and project records — for the engagement plus 7 years, to meet Australian tax and business record-keeping obligations.
- Financial records — 7 years, as required by the ATO.
- Hosted client data after an engagement ends — 30 days of backup, then permanent deletion.
- Unsubscribe and suppression records — kept indefinitely, because that is the only way to guarantee we never contact you again.
13Access and correction
You have the right to ask what personal information we hold about you, to get a copy of it, and to have it corrected if it is wrong.
Email jesse@automatedaustralia.com with enough detail for us to identify you. We will respond within 30 days. There is no charge for making a request; if a request requires substantial work we may charge a reasonable cost, but we will always tell you before we do and give you the chance to withdraw.
We may need to verify your identity before releasing information. In rare cases we may refuse access — for example where it would unreasonably affect someone else's privacy, or where we are required by law to refuse. If we do, we will tell you why in writing and explain how to complain.
You can also ask us to delete what we hold. We will do that unless we are legally required to keep it, in which case we will tell you exactly what we must retain and why.
14Complaints
If you think we have mishandled your personal information, tell us first — most things are fixable quickly. Email jesse@automatedaustralia.com with "Privacy complaint" in the subject line.
We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner:
- Phone
- 1300 363 992
- Post
- GPO Box 5218, Sydney NSW 2001
15Changes and contact
We review this policy as our systems change. The "last updated" date at the top of this page always reflects the current version. Material changes affecting existing clients are notified by email.
- Privacy contact
- Jesse A Mckenzie · Automated Australia · ABN 61 183 020 382
- Phone
- +61 468 484 006
- Location
- Brisbane, Queensland, Australia
These terms are written to be read, not to hide things. If anything here is unclear, or you think something is wrong, email jesse@automatedaustralia.com and we will explain it in plain English or fix it.