This is a working draft prepared from the OAIC's APP guidelines. It is not legal advice. Have it reviewed by a lawyer before you rely on it, particularly if you take on clients in regulated industries whose licensees will read it.
1. We respect your privacy
Alpine Advisory AI ("we", "us", "our") provides operations, AI and automation consulting to businesses.
We are committed to protecting your privacy and to handling personal information openly and transparently. This policy explains what personal information we collect, why we collect it, who we share it with, and how you can access it, correct it or complain.
Most small businesses in Australia are not currently bound by the Privacy Act 1988 (Cth) because of the small business exemption. We handle personal information in accordance with the Australian Privacy Principles (APPs) as a matter of practice, whether or not that exemption applies to us. We do this because our clients and their own regulators expect it.
2. What personal information we collect
We collect personal information that is reasonably necessary for our business. Depending on how you deal with us, that may include:
- Contact and identity details — your name, business name, role, email address, phone number and postal address.
- Engagement information — the business problems you describe to us, details of your systems and processes, and correspondence with us.
- Meeting transcripts and notes — made when we record a call, and used to write up what you asked for.
- Assessment and tool responses — answers you give in our online assessments, calculators or audits, and the results generated from them.
- Billing information — the details needed to invoice you and record payment. We do not collect or store your card numbers. Card details are entered directly with our payment provider and we never see them.
- Technical information — see section 14.
We do not seek to collect sensitive information (such as health information) and ask that you do not send it to us. If you provide it in the course of an engagement, we handle it with the same care as everything else and only use it for the purpose you gave it to us.
3. How we collect your personal information
We collect personal information:
- Directly from you — when you email or call us, book a meeting, complete a form, assessment or calculator on our website, engage us, or talk to us during a project.
- During an engagement — from the systems, documents and processes you ask us to review, which may contain personal information about your staff and your own customers.
- From your website or public sources — publicly available business information, where relevant to work you have asked us to do.
- Automatically — through our website, as described in section 14.
If you give us personal information about someone else, please make sure you are entitled to do so and that they know we may hold it.
4. How we use your personal information
We use personal information to:
- respond to your enquiry and provide you with information you have asked for;
- deliver the result of an assessment, audit or calculator you completed;
- provide, manage and improve our services;
- prepare proposals, agreements, invoices and project documentation;
- keep records of our work and meet our own legal and tax obligations; and
- send you occasional emails about our services, where you have consented — see section 10.
We will not use your personal information for a purpose unrelated to the one we collected it for unless you would reasonably expect it, or you consent, or we are required or authorised by law.
5. Who we disclose your personal information to
We do not sell personal information. We may disclose it to:
- Our service providers, who help us run our business — including email, calendar and document hosting, website hosting and analytics, customer relationship management, meeting transcription, invoicing and payments, and scheduling. They may only use it to provide services to us.
- Our professional advisers, such as accountants, insurers and lawyers, where reasonably necessary.
- Anyone you ask us to, or where you would reasonably expect us to.
- A purchaser, if our business or part of it is sold, subject to the same protections.
- Law enforcement or regulators, where required or authorised by law.
Where we work inside your systems, we handle personal information belonging to your business under your instructions and under our services agreement with you.
6. AI-assisted tools
We use third-party technology providers, including AI-assisted tools, to help deliver our services — for example to summarise meetings, draft documents and analyse processes.
Where we use these tools with information relating to you or your business, we choose providers that commit to not using customer content to train their public models, and we operate them under business or enterprise terms rather than consumer accounts. Some of these providers process information outside Australia — see section 7.
We do not put information into consumer AI tools that we would not put into any other third-party system.
7. Overseas storage and transfers
We are likely to disclose personal information to overseas recipients. Many of the providers we rely on are based in, or process data in, other countries — most commonly the United States, and in some cases the European Union or other regions where a provider's infrastructure operates.
Before using a provider we take reasonable steps to satisfy ourselves that it offers appropriate protection, which may include contractual data protection terms, recognised certifications, and commitments about where data is stored.
If you would like to know which providers we currently use and where they are located, email us and we will tell you.
8. Security of your personal information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include access controls and multi-factor authentication on the systems we use, encryption in transit, limiting access to those who need it, and choosing reputable providers.
No method of transmission or storage is completely secure. While we do our best to protect your information, we cannot guarantee the security of information you send us over the internet.
If we become aware of a data breach likely to cause you serious harm, we will notify you and, where the Privacy Act requires it, the Office of the Australian Information Commissioner.
9. Assessments, calculators and tools
Some of our online tools score your answers and show you a result. Unless you ask us to email you the result, your answers stay in your browser and are not sent to us.
If you ask us to email you a result, we collect your name and email address for that purpose, along with your answers and the result. We use these to send you the result and, as described in section 10, to follow up.
10. Direct marketing and how to opt out
If you have consented, we may send you occasional emails about our services, articles and events.
Every marketing email we send includes a way to opt out. You can also opt out at any time by replying to any email from us and asking, or by emailing daniel@alpineadvisory.ai. We will action it promptly and at no cost to you.
We will not send you marketing emails if you have not consented, and we do not sell or rent our email list.
We will still send you emails necessary to provide a service you have asked for — such as the result of an assessment you completed, meeting confirmations, or correspondence about a project.
11. How long we keep your personal information
We keep personal information only as long as we need it for the purposes described in this policy, or as long as the law requires.
As a guide:
| What we hold | How long we keep it |
|---|---|
| Invoices, payments and expense records | 7 years. The ATO requires 5; we keep 7 so that amended assessments are covered |
| Client engagement records — proposals, agreements, deliverables and project correspondence | 7 years after the engagement ends |
| Meeting transcripts and notes | 12 months, or when the project closes if that is sooner |
| Enquiries that don't become engagements | 24 months from our last contact with you |
| Assessment and calculator submissions | 24 months from submission |
| Marketing list | Until you opt out |
| Unsubscribe records | Kept indefinitely — we keep your email address on a suppression list so that we can be certain we never email you again |
| Website analytics | 14 months |
| Information held inside your own systems | We don't keep copies. Anything we access while working in your systems stays in your systems |
When we no longer need personal information, we take reasonable steps to destroy it or de-identify it.
12. Access to, and correction of, your personal information
You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it if it is wrong, out of date, incomplete or misleading.
Email daniel@alpineadvisory.ai. We will respond within 30 days. There is no charge for making a request, though we may charge a reasonable amount for the cost of providing access in some cases — we will tell you before we do.
We may need to verify your identity first. If we can't give you access, or we decide not to make a correction you've asked for, we will tell you why in writing and explain how to complain.
13. Complaints about privacy
If you think we have mishandled your personal information, please tell us so we can put it right.
Email daniel@alpineadvisory.ai with the details. We will acknowledge your complaint within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:
- Web: oaic.gov.au
- Phone: 1300 363 992
14. Our website, cookies and analytics
When you visit our website we may collect technical information automatically, including your IP address, browser type and version, device type, the pages you viewed and the time you spent on them.
We use cookies and similar technologies to make the site work and to understand how it is used. You can set your browser to refuse cookies or to alert you when one is set. Some parts of the site may not work properly if you do.
We use third-party analytics to help us understand how our site is used. These providers may set their own cookies and may store data outside Australia.
15. Third-party sites
Our website may link to other websites. We are not responsible for their content or their privacy practices, and this policy does not apply to them. We encourage you to read the privacy policy of any site you visit.
16. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Updated" date at the top, and the updated version applies from the date it is published.
If we make a change that materially affects how we handle personal information we already hold, we will take reasonable steps to tell you.
17. Contact us
Alpine Advisory AI
Email: daniel@alpineadvisory.ai