---
title: "Privacy Policy | Data-Driven AI"
canonical: "https://data-driven.com/privacy-policy/"
description: "How Data-Driven AI handles personal information across its website, business operations, recruitment and consulting engagements."
---

Legal

# Privacy _policy._

How Data-Driven AI handles personal information across its business and consulting work.

Document scope

## Website privacy policy

This policy covers our corporate activities and explains the separate role we may have when handling customer- or agency-controlled information.

## Privacy Policy

_Effective: 31 August 2026._

### 1\. Scope

Data-Driven AI Pty Ltd (ABN 58 635 718 455) (**Data-Driven AI**, **we**, **us** or **our**) respects your privacy. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

This Policy explains how we handle personal information for our own business purposes. It covers public website visits, enquiries, meetings, marketing, recruitment, workforce administration and general business contacts.

Our website and public marketing are directed to people and organisations in Australia. This Policy is framed by the Australian privacy laws that apply to our activities.

During a consulting engagement, we may instead act on a customer’s or government agency’s instructions. The applicable contract, order, statement of work and privacy, security or data schedules define that role. This Policy does not replace those documents or any applicable law.

Some products and services have additional notices and agreements. CloudMonitor has a separate [product Privacy Policy](https://cloudmonitor.ai/privacy-policy/). A product notice does not replace the terms agreed for a consulting engagement.

### 2\. Information we collect

When you contact us or book a meeting through a service linked from the Website, we may collect basic contact and scheduling information. This may include your name, role, organisation, work contact details and the content of your enquiry. We use it to respond, arrange the meeting and decide whether to discuss an engagement.

When you use the Website, we may collect technical information about your device and visit. This may include your IP address, browser and device type, operating system, pages viewed, referring page, access times and cookie or similar identifiers.

During ordinary business dealings, we may collect contact, proposal, contract, billing, service and support information needed to manage our relationship with your organisation.

For recruitment and workforce administration, we may collect application and employment information. This can include qualifications, work history, references, work eligibility, professional memberships, training and security-clearance status. Where lawful and reasonably necessary, we may also collect identity, background-check, emergency-contact, payroll or health information.

During consulting work, we may handle customer or agency contact details, project roles, account identifiers, access records and support material. We may also encounter personal information in project systems or data. The engagement documents determine what we may access and how we may use it.

We collect sensitive information only where the law permits it and it is reasonably necessary for our work, or where an applicable contract or law requires it.

The public Website, booking links and general email address are public enquiry channels, not approved channels for project material. Other than the contact details needed to respond, do not send:

-   classified, protected or security-sensitive government information;
-   passwords, keys, tokens or other access credentials;
-   production data;
-   personal or health information, other than your own basic contact details; or
-   commercial-in-confidence or other protected agency material.

We will agree an approved channel and handling requirements before receiving project material.

### 3\. How we collect information

We may collect personal information:

-   directly from you, including by phone, email, meeting or other interaction;
-   through the Website, cookies and similar technology;
-   through booking, analytics and other service providers linked to or used by the Website;
-   from your employer, agency, authorised representative or another person involved in an engagement; and
-   from recruiters, referees, screening providers, professional bodies or former employers where relevant and lawful; and
-   from public or government sources where lawful and relevant to our work.

If you give us personal information about another person, you must be authorised to do so and, where required, tell them about this Policy.

We may hold personal information in our business systems, through service providers, or within a customer- or agency-controlled environment. The applicable purpose and engagement requirements determine where information is held.

### 4\. How we use information

We may use personal information to:

-   respond to enquiries and arrange meetings;
-   prepare proposals and discuss, provide or support an agreed engagement;
-   assess candidates and manage employees, contractors, training, access and engagement eligibility;
-   manage contracts, billing, records and our relationship with your organisation;
-   secure and operate our Website and business systems;
-   meet legal, regulatory, contractual, insurance, audit and reporting obligations;
-   understand and improve the Website and our services; and
-   send relevant business updates or marketing where permitted by law.

You can opt out of marketing at any time by using the unsubscribe option in the message or contacting us. We do not use engagement information for an unrelated purpose unless authorised or required by law.

### 5\. Disclosure and overseas processing

We may disclose personal information where reasonably necessary and permitted by law to:

-   our personnel and related entities;
-   a customer or government agency responsible for an engagement;
-   service providers that support our business or delivery work;
-   recruiters, referees, screening providers and professional bodies where relevant and authorised; and
-   professional advisers, auditors and insurers.

Applicable legal, professional and contractual obligations continue to apply to those disclosures.

We may also disclose information where authorised or required by law, a court or regulator, or where needed to protect a person’s safety or our legal rights.

Our website, booking and corporate service providers may process information outside Australia. Our published booking links use zcal. Its [data processing addendum](https://zcal.co/dpa) says it processes personal data in the United States. It may also process that data in other jurisdictions outside a person’s country of residence.

Provider locations may change. Contact us for current information relevant to your interaction. Where Australian Privacy Principle 8 applies, we take the steps it requires unless an exception applies.

The location of customer or government engagement information is agreed for the specific engagement. We do not treat an Australian hosting region as proof that all support, administrative access or subprocessors are located in Australia.

### 6\. Government and customer engagement information

If an engagement proceeds, its documents define how project information is handled. This may include requirements for authorised purposes, access, security, data location, subcontracting, incident response, retention, return and deletion.

Our [Government Information Handling Statement](/government-information-handling/) explains this boundary for Australian Government and NSW Government consulting work.

Government information may also be subject to statutory recordkeeping, audit, access-to-information and lawful disclosure requirements. A confidentiality term does not prevent a disclosure that the law or the applicable government contract permits or requires.

An initial enquiry does not create a consulting relationship or special confidentiality obligation. Use an agreed secure channel and any applicable confidentiality agreement before providing protected project information.

We do not use customer- or agency-controlled personal information for unrelated marketing. We also do not use it to train a general-purpose AI model unless the responsible customer or agency expressly authorises that use and it is lawful.

### 7\. Security, retention and data breaches

We take reasonable technical, physical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. No public internet or email channel is completely secure, which is why protected project information must use an agreed channel.

We retain personal information only for as long as reasonably needed for the purpose for which it was collected and to meet legal, contractual, insurance, audit and recordkeeping requirements. When it is no longer required, we take reasonable steps to destroy or de-identify it where lawful.

We assess and respond to suspected data breaches under applicable law, including the Notifiable Data Breaches scheme where it applies. For customer- or agency-controlled information, we also notify and assist the responsible organisation within the time and process required by the engagement.

### 8\. Access and correction

You may ask to access or correct personal information we hold about you. Use our [contact page](/contact-us/) to start the request with basic contact details, or write to Data-Driven AI Pty Ltd, 111 Harrington Street, The Rocks NSW 2000, Australia. We will arrange an appropriate channel if identity documents or other sensitive material are needed.

We may need to verify your identity. We will respond within the period required by law and explain any lawful reason for refusing or limiting access or correction.

If your request concerns personal information controlled by a customer or government agency, that organisation may need to decide the request. We will explain this and assist or refer the request where appropriate and authorised.

### 9\. Privacy complaints

You may start a privacy complaint through our [contact page](/contact-us/) or by writing to the postal address above. Do not include sensitive material in a public booking or general email. We will arrange an appropriate channel for any detailed material needed to investigate, acknowledge the complaint and respond within a reasonable time.

If you are not satisfied with our response, you may contact the [Office of the Australian Information Commissioner](https://www.oaic.gov.au/privacy/privacy-complaints).

If the complaint concerns information controlled by a government agency, the agency and its privacy or information-access regulator may be the appropriate recipients. We will explain the relevant path where we can.

### 10\. Website analytics, cookies and external links

The Website uses Google Tag Manager to load Google Analytics and LinkedIn Insight Tag. These services help us understand website traffic, improve content, measure campaign performance and, where relevant, show or measure Data-Driven AI advertising on LinkedIn. They may collect technical and activity information such as IP address, browser and device information, pages viewed, referring page, approximate location and cookie or similar identifiers. Google and LinkedIn may process that information outside Australia.

We configure website measurement for the stated purposes and do not intentionally send form contents or sensitive information to these services. You can turn off future website measurement in this browser below. This choice prevents our Google Tag Manager container from loading on later page views. It cannot recall information already received by a provider, and it does not control tracking by other websites or services.

### Website measurement

Google Analytics and LinkedIn Insight Tag help us understand website use and campaign performance.

The Website’s fonts are served with the Website rather than requested from Google.

You can restrict cookies through your browser, although parts of the Website may not work as intended.

The Website links to services and websites that we do not control, including booking services. Their terms and privacy policies apply when you use them. A link does not mean we endorse their privacy practices.

### 11\. Changes and contact

We may update this Policy when our practices or legal obligations change. We will publish the revised Policy with a new effective date. Changes do not amend an existing customer or government agreement.

For privacy questions, access or correction requests, or complaints, email the Privacy Officer at [info@data-driven.com](mailto:info@data-driven.com). You can also use our [contact page](/contact-us/) or write to Data-Driven AI Pty Ltd, 111 Harrington Street, The Rocks NSW 2000, Australia.

Use only basic contact details in the first message. We will arrange an appropriate channel if more sensitive material is required.
