Loading…
Loading…
If you run a school, a practice, a community group or any business that holds information about real people, the sensible instinct is caution. Here is our position in plain terms, including the things we will not do.
Every automation, tool and integration lives under your own logins. You can revoke our access at any moment and everything keeps working. Nothing is held hostage, and there is no scenario where leaving us means losing your data.
Client, student, patient and member details do not go into consumer AI tools. Where AI is genuinely useful on sensitive material, it gets a proper arrangement with terms we have read — or we do that part differently.
Anything that reaches a customer, a regulator or a file gets prepared by the system and sent by a person. Automatic sending is reserved for factual acknowledgements that contain nothing capable of being wrong.
Before a build goes live you get a plain list of every third party involved and what each one does. No surprise sub-processors, and no "it is in the cloud" as an answer.
We ask for the minimum access needed and we ask for it as a named account, not a shared password. When the work is done, access comes off. If the only way in is a shared login, we treat that as something to fix.
We do not take copies of your databases for convenience. What we do hold for the engagement gets deleted when it is no longer needed, and you can ask us to do that sooner.
These sectors are the reason this page exists. All of them hold information that matters, all of them are under-resourced, and most have been pitched to by someone who did not understand their obligations.
The approach that works is boring and it works everywhere: automate the administrative layer around the sensitive information, not the sensitive information itself. Chasing a permission form does not require knowing anything about the child. Booking a recall does not require the clinical note. Almost all of the time saving lives in that outer layer.
Where a sector has its own rules — departmental policy, professional obligations, funding conditions — those take precedence over anything we would suggest, and checking them is part of the work rather than your problem to raise.
An honest boundary. Nothing on this page is legal advice, and we are not qualified to give it. Australian privacy law has been under reform, so for anything about your specific obligations, check the current position with the Office of the Australian Information Commissioner or a professional who knows your circumstances. What we can do is make sure the systems we build are not the weak point.
Not by us, and we choose tools and tiers with that in mind. It is a fair question to ask any supplier, and the honest general position is that consumer free tiers and paid business tiers often differ in how providers describe handling your data — and that those terms change. So rather than quote a policy at you, we will tell you which specific tools a build uses and what their current terms say, and you can decide.
Wherever your existing systems already store it, in most cases, because we build inside your accounts rather than moving your data somewhere new. Where a build introduces a new component we will tell you where it lives before it is used. If data residency matters to you — it often does for schools and health services — say so at the start and it becomes a design constraint.
The minimum needed to do the work, granted through your own systems as a named account rather than a shared password, and removed when the work finishes or whenever you ask. If you can only give us access by sharing a login, we will treat that as a problem to fix rather than a convenience.
Not a no, but a much more careful conversation and a smaller scope. Those categories carry heightened expectations and often sector-specific rules on top of general privacy law. The practical approach is to automate the administrative layer around the sensitive information rather than the sensitive information itself — which is usually where the time goes anyway.
Yes, and often the most useful thing we do. The free data safety check is the same list we would work through with you, and most of what it recommends costs nothing. If you want help implementing it, that is straightforward work.
See also: Is it safe to put our information into AI? and Australian privacy obligations in plain English. Our own privacy notice covers what happens to information you send us through this website.
If you have been told automation is off the table for your sector, it is worth twenty minutes to find out what is actually possible and what genuinely is not.