Legal

Data Privacy Policy

Aiverse Solutions · ABN 70 682 307 204 Canberra, ACT, Australia Email: info@aiversesolutions.com.au Effective: December 2, 2025 Last updated: December 2, 2025

1. Introduction and Commitment to Privacy

Aiverse Solutions ("we," "our," "us," "Company") is committed to protecting your privacy and ensuring a transparent, secure experience when you interact with our services. This Data Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and safeguard personal information in accordance with applicable privacy laws, including the Australian Privacy Act 1988 (Cth), the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant international data protection legislation.

This Policy applies to all personal data we collect through:

By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with our practices, please do not use our services.

2. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, company affiliations, usage data, and payment information.

"Processing" means any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.

"Data Controller" means the entity (Aiverse Solutions) that determines the purposes and means of processing personal data.

"Data Processor" means an entity that processes personal data on behalf of a Data Controller.

"Data Subject" means the individual to whom personal data relates.

3. Information We Collect

3.1 Categories of Personal Data

Contact Information:

Usage and Service Data:

Financial Information:

Business Data:

Technical Data:

3.2 Data Collection Methods

We collect personal data through:

3.3 Data We Do Not Collect

We do not intentionally collect:

4. Legal Basis and Purpose for Processing

4.1 Purposes of Processing

Service Delivery:

Communication:

Legal and Compliance:

4.2 Legal Basis

Under GDPR: We process personal data based on contract performance, legal obligation, legitimate interest, and consent.

Under CCPA: We collect and share personal data to the extent permitted and as disclosed in this Policy.

Under Australian Privacy Act: We comply with the Australian Privacy Principles (APPs) in collecting and handling personal data.

5. Data Sharing and Third Parties

5.1 Third-Party Service Providers

Payment Processing:

This website does not currently collect card details or process online payments.

Cloud Infrastructure and Hosting:

Artificial Intelligence Services:

Appointment Booking:

If Mickey offers an appointment link and you choose it, you may be taken to our configured Calendly or Microsoft Bookings page. Information entered there is handled by that provider under its terms and privacy policy. Mickey does not receive calendar passwords or private calendar credentials.

5.2 International Data Transfers

Personal data may be transferred to, stored in, and processed in countries outside your country of residence, including Australia, United States, European Union, and Asia-Pacific region.

Where Australian Privacy Principle 8 applies, we take reasonable steps appropriate to the circumstances before disclosing personal information to an overseas recipient. Measures may include data minimisation, provider restrictions, contractual privacy terms, prompt training controls, retention controls, and reviewing where the selected provider processes information.

6. Data Retention

We retain personal data only as long as reasonably necessary to fulfill the purposes for which it was collected, including legal, regulatory, tax, accounting, and reporting requirements.

Upon expiration of the retention period, personal data is securely deleted, destroyed, or anonymized to prevent re-identification.

7. Data Security and Protection Measures

7.1 Security Measures

Technical Safeguards:

Organizational Safeguards:

7.2 Security Limitations

While we are committed to maintaining high security standards, we cannot guarantee absolute security of any information transmitted to or by us over the Internet.

Users are encouraged to use secure passwords, protect account credentials, and report security concerns immediately.

8. Data Breach Notification

In the event of a confirmed data breach involving personal data, Aiverse Solutions commits to:

To report a suspected breach or security incident, contact: info@aiversesolutions.com.au

9. Cookies and Tracking Technologies

9.1 Cookie Use

Our website and applications use cookies and similar tracking technologies, including:

9.2 Cookie Consent and Control

We obtain explicit consent for non-essential cookies prior to placement. Users may opt out of marketing and analytics cookies through browser settings or our cookie consent banner.

Third-party tracking services (Google Analytics and Hotjar) collect data subject to their own privacy policies.

10. Your Rights and Choices

10.1 General Rights (All Jurisdictions)

10.2 GDPR Rights (EU Data Subjects)

EU data subjects have additional rights including:

10.3 CCPA Rights (California Residents)

California residents have the following rights:

10.4 Australian Privacy Act Rights

Australian residents have rights under the Australian Privacy Principles, including access, correction, and complaint rights.

Contact the Office of the Australian Information Commissioner: https://www.oaic.gov.au/

10.5 Exercising Your Rights

To exercise any of the above rights, contact:

Email: info@aiversesolutions.com.au
Mail: Aiverse Solutions, Canberra, Australian Capital Territory, Australia

Response Timeline: We will respond to rights requests within 30 days (or as required by applicable law). Complex requests may require up to 90 days.

11. Marketing Communications

We send marketing communications (newsletters, promotions, product updates) based on your explicit consent or existing business relationship.

Opt-Out and Unsubscribe

You can opt out of marketing communications by:

Opt-out requests are typically processed within 10 business days. We will continue to send transactional and service-related communications as necessary for service delivery.

12. Children's Privacy

Our services are not intended for children under the age of 13 (or equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children.

If we become aware that personal data has been collected from a child, we will delete such data promptly and notify the child's parent or guardian.

Parents or guardians who believe their child's data has been collected should contact info@aiversesolutions.com.au immediately.

13. Policy Updates and Changes

Aiverse Solutions may update this Policy periodically to reflect changes in our business practices, applicable laws and regulations, or improvements in security and privacy practices.

Material Changes

Non-Material Changes

We will update the "Last Updated" date at the top of this Policy. Continued use of our services constitutes acceptance of updated terms.

14. Contact Information

For questions, concerns, requests, or complaints regarding our privacy practices, contact:

Aiverse Solutions
Data Protection Officer / Privacy Officer
Email: info@aiversesolutions.com.au
Address: Canberra, Australian Capital Territory, Australia
ABN: 70 682 307 204

Response Time: We will respond to privacy inquiries and data subject rights requests within 30 days (or as required by applicable law).

Escalation and Complaints

If you believe your privacy rights have been violated or are dissatisfied with our response:

Appendix A: Key Service Providers

The following organisations may process information for Aiverse Solutions under their applicable service and privacy terms:

Service ProviderPurposeLocationSafeguards
VercelWebsite hosting, server functions, and AI routingGlobalServer-only credentials, platform security controls, and applicable contractual terms
UpstashRestricted CMS and subscriber storageConfigured service regionServer-only credentials and access restrictions
Monday.comLead management and report delivery workflowGlobalServer-only credentials, restricted board access, and applicable contractual terms
Vercel AI GatewayAI routing, usage controls, and provider restrictionGlobalServer-only authentication, no prompt training, provider allowlist, and optional Zero Data Retention
OpenAI / Microsoft AzureAssessment report generation and fallback chat processingUnited States or selected provider regionData minimisation and Gateway-enforced provider controls
Google / Google Vertex AIChat processing and fallback assessment generationUnited States, European Union, or selected provider regionData minimisation and Gateway-enforced provider controls
Cloudflare TurnstileAdaptive bot and abuse verification for MickeyGlobalChallenge shown only after suspicious activity; server-side token validation; no Turnstile secret sent to the browser
Calendly or Microsoft Bookings, when enabledCustomer-selected appointment schedulingProvider-selected service regionVisitor initiated transfer to an approved HTTPS booking page; no calendar credentials are exposed to the chatbot

This Data Privacy Policy is effective as of July 29, 2026. For the most current version, visit our website or contact info@aiversesolutions.com.au.