Legal

Privacy Policy

How we handle your personal information

Organisation Atomi Agency (ABN 28 128 587 332)
Effective date 28 July 2026
Jurisdiction Australia

Atomi Agency (we, us or our) is an Australian AI and automation consultancy. This policy explains how we collect, use, store and disclose personal information through atomiagency.com and while providing our services.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and otherwise in accordance with this policy.

1. Information we collect

Information you provide. When you contact us, book a call, purchase a service or work with us, we may collect:

  • your name, email address and phone number;
  • your organisation, role and business contact details;
  • the contents of your enquiry and correspondence; and
  • information needed to provide the service you have requested.

AI Time Audit information. If you purchase an AI Time Audit, we collect the information supplied through the intake form. This may include descriptions of a business process, the roles involved, process frequency and volume, time and labour estimates, delays, errors, rework and other operational information needed to prepare the report.

Please do not submit passwords, payment-card details, system credentials, patient information, health records, or personal or restricted information that is not necessary for the Audit. If sensitive information is genuinely required, contact us before submitting it.

Billing and payment information. Stripe processes payments and collects payment-card details directly. We do not see or store your full card number. We keep transaction, invoice and payment-status records for accounting, customer service and legal purposes. We may also record transactions in Zoho Books.

Website and device information. When you visit our website, we and our service providers may collect limited technical information such as your IP address, browser and device type, pages visited, referring site, approximate location and cookie or advertising identifiers.

2. How we use information

We use personal information to:

  • respond to enquiries and communicate with you;
  • schedule calls and manage client relationships;
  • process payments and maintain accounting records;
  • provide the AI Time Audit and our consulting services;
  • calculate and analyse process estimates;
  • prepare, review and deliver reports;
  • operate, secure and improve our website and systems;
  • understand website use and measure advertising performance;
  • send marketing communications where you have consented or would reasonably expect them; and
  • meet legal, tax, accounting and regulatory obligations.

We do not sell personal information.

3. AI-assisted processing and human review

We may use software and AI-assisted tools, including services provided by Anthropic, to help structure and analyse AI Time Audit information and prepare draft report content.

These tools support our work; they do not make the final recommendation independently. Jeremy reviews every AI Time Audit report before it is delivered.

You should not include unnecessary personal, sensitive or restricted information in an Audit intake. Information processed using AI-assisted tools remains subject to this policy and the applicable provider arrangements.

4. Cookies, analytics and advertising

Website analytics. We use Umami Cloud to understand website traffic. It is configured as a privacy-focused analytics service without advertising cookies or individual behavioural profiles. It may process limited technical information and provides us with aggregated traffic reports.

Website security. We use Cloudflare services, including Turnstile, to protect website forms from abuse. Cloudflare may process technical information about your device and connection to provide those security functions.

Advertising tools. Our website uses:

  • Meta Pixel, which helps us measure advertising on Facebook and Instagram and show ads to people who have visited our website; and
  • LinkedIn Insight Tag, which helps us measure LinkedIn advertising and reach relevant audiences.

These services may receive information about your visit, including pages viewed, device information, IP address and cookie or advertising identifiers.

For visitors from the European Economic Area, United Kingdom or Switzerland, these advertising tools only run after consent through our cookie banner. For visitors elsewhere, they may run by default. You can change your choice at any time through Privacy Settings, your browser controls, Meta's ad preferences or LinkedIn's opt-out controls.

5. Service providers and disclosures

We disclose information only where reasonably required to run the business, provide a requested service, obtain professional advice or comply with the law.

Service providers we use include:

  • Stripe — payment processing;
  • Typeform — AI Time Audit intake forms;
  • Airtable — customer relationship, engagement and Audit records;
  • n8n — workflow automation and routing information between our systems;
  • Anthropic — AI-assisted analysis and draft report content;
  • Google Workspace — report templates, document generation and storage;
  • Microsoft 365 — email, documents and business administration;
  • Zoho Books — accounting and invoicing records;
  • Calendly — call scheduling;
  • Umami Cloud — website analytics;
  • Cloudflare — website delivery and form security; and
  • Meta and LinkedIn — advertising and campaign measurement as described above.

We may also disclose information to accountants, lawyers and other professional advisers where reasonably necessary, or to regulators, courts and law-enforcement bodies where required by law.

Operational providers handle information under their own privacy terms and our applicable service arrangements. Advertising platforms may also handle information as independent organisations under their own privacy policies.

6. Overseas processing

Some providers listed above operate or use infrastructure outside Australia, including in the United States, the European Union and other countries in which they or their subprocessors operate.

Because privacy protections vary between countries, overseas recipients may be subject to different laws. We take reasonable steps appropriate to the circumstances when selecting and using service providers, including considering their security practices, privacy terms and contractual protections.

7. Direct marketing

We may send marketing communications where you have asked to receive them or where an existing business relationship means you would reasonably expect them.

Marketing emails include an unsubscribe option. You can also opt out by contacting us. We will action opt-out requests promptly in accordance with the Spam Act 2003 (Cth).

8. How long we retain information

We retain information only for as long as reasonably needed for the purpose for which it was collected and to meet legal obligations.

Generally:

  • accounting, invoice and payment records are kept for at least five years;
  • client service records, Audit intakes and delivered reports may be kept for up to five years after the engagement so we can support the work, maintain appropriate business records and respond to questions or disputes;
  • enquiries that do not become client engagements may be kept for up to two years; and
  • marketing contact details are retained until you opt out or they are no longer required.

Some information may remain temporarily in secure backups or be retained longer where required by law, a dispute, or another legitimate business need.

9. Security

We take reasonable steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. These measures include encryption in transit, multi-factor authentication on key business systems, access controls and reputable service providers.

No internet transmission or storage system is completely secure. If we become aware of a data breach, we will assess and respond to it in accordance with applicable law.

10. Access, correction, deletion and complaints

You may ask for access to personal information we hold about you or request that we correct inaccurate information by emailing privacy@atomiagency.com.

You may also ask us to delete information. We will comply where reasonably possible, subject to legal obligations and legitimate needs to retain business records. We may need to verify your identity before responding. We generally respond within 30 days.

If you have a privacy concern or complaint, contact us first so we can investigate and respond. If you are not satisfied and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

11. Visitors from the EEA, UK or Switzerland

If the GDPR, UK GDPR or applicable Swiss privacy law applies to our handling of your information, our legal bases may include:

  • consent, for advertising cookies and consent-based marketing;
  • performance of a contract, for services you purchase;
  • legitimate interests, for operating, securing and improving the business; and
  • legal obligation, for tax, accounting and regulatory records.

Where applicable, you may have rights to access, correct, delete or receive a copy of your information, restrict or object to processing, and withdraw consent. Withdrawing consent does not affect processing that occurred before withdrawal.

To exercise a right, email privacy@atomiagency.com. You may also complain to your local data-protection authority.

12. Changes to this policy

We may update this policy from time to time. The current version will be published at atomiagency.com/privacy with its effective date. We will identify significant changes where appropriate.

13. Contact

Atomi Agency
ABN 28 128 587 332
Email: privacy@atomiagency.com