1. Introduction and Commitment to Privacy
Aiverse Solutions ("we," "our," "us," "Company") is committed to protecting your privacy and ensuring a transparent, secure experience when you interact with our services. This Data Privacy Policy ("Policy") explains how we collect, use, disclose, retain, and safeguard personal information in accordance with applicable privacy laws, including the Australian Privacy Act 1988 (Cth), the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other relevant international data protection legislation.
This Policy applies to all personal data we collect through:
- Our consulting and advisory services
- AI implementation and deployment services
- Software platform and applications
- Website and digital properties
- Email communications
- Mobile applications
- Third-party integrations and partnerships
By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with our practices, please do not use our services.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, company affiliations, usage data, and payment information.
"Processing" means any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.
"Data Controller" means the entity (Aiverse Solutions) that determines the purposes and means of processing personal data.
"Data Processor" means an entity that processes personal data on behalf of a Data Controller.
"Data Subject" means the individual to whom personal data relates.
3. Information We Collect
3.1 Categories of Personal Data
Contact Information:
- Full name
- Email address
- Phone number
- Postal address
- Company name and organization details
- Job title and role
Usage and Service Data:
- Interaction history with our services and platform
- Features and tools accessed
- Login times and session duration
- Device information (IP address, browser type, operating system)
- Service preferences and settings
- Communication history and inquiries
- Mickey chatbot messages, AI replies, human support replies, conversation status, and the website page where the conversation started
- Privacy-preserving security fingerprints derived from IP address and browser information, request counters, and human-verification results used to prevent chatbot abuse
Financial Information:
- Payment method details (processed by Stripe; we do not retain full card details)
- Billing address
- Invoice and transaction history
- Subscription and pricing tier information
Business Data:
- Project details and scope
- Consultation notes and recommendations
- Client feedback and testimonials
- Performance metrics and analytics related to services delivered
Technical Data:
- Cookies and tracking identifiers
- Analytics data from Google Analytics and Hotjar
- Website activity logs
- Error reports and system diagnostics
3.2 Data Collection Methods
We collect personal data through:
- Direct input via forms, registration pages, and contact submissions
- Messages entered into Mickey, including when you request or continue a conversation with a team member
- Automatic collection through cookies, analytics tools, and tracking technologies
- Communications with our team (email, meetings, calls)
- Third-party integrations and partner services
- Payment processing through Stripe
- Client-provided information during service engagement
3.3 Data We Do Not Collect
We do not intentionally collect:
- Health or medical information
- Government-issued identification numbers
- Biometric data
- Financial account details (beyond payment method information)
- Criminal history or sensitive personal information
4. Legal Basis and Purpose for Processing
4.1 Purposes of Processing
Service Delivery:
- Provision of AI consulting, implementation, and advisory services
- Delivery and maintenance of our software platform and applications
- Customization and personalization of services to your needs
- Technical support and customer service
Communication:
- Responding to inquiries and requests
- Sending service updates, announcements, and notifications
- Marketing communications (with your consent or where lawful)
- Conducting surveys and gathering feedback
Legal and Compliance:
- Compliance with applicable laws and regulations
- Responding to lawful government requests and legal obligations
- Enforcing our Terms of Service and other agreements
- Protecting against fraud, security incidents, and illegal activity
4.2 Legal Basis
Under GDPR: We process personal data based on contract performance, legal obligation, legitimate interest, and consent.
Under CCPA: We collect and share personal data to the extent permitted and as disclosed in this Policy.
Under Australian Privacy Act: We comply with the Australian Privacy Principles (APPs) in collecting and handling personal data.
5. Data Sharing and Third Parties
5.1 Third-Party Service Providers
Payment Processing:
This website does not currently collect card details or process online payments.
Cloud Infrastructure and Hosting:
- Vercel hosts the website and server functions
- Upstash provides restricted server storage for CMS content, subscriber records, and Mickey conversation transcripts
- Monday.com receives enquiries, assessment details, generated reports, and report documents for customer follow up
- Cloudflare Turnstile performs a managed human-verification check only when chatbot activity appears suspicious
Artificial Intelligence Services:
- Vercel AI Gateway routes assessment and chatbot requests to approved OpenAI, Microsoft Azure, Google, or Google Vertex AI providers
- Obvious visitor-supplied email addresses, Australian phone numbers, and long account-like numbers are removed before model processing where technically practical
- AI requests are sent with prompt training disabled. Zero Data Retention is enforced when enabled for the applicable Vercel plan and route
Appointment Booking:
If Mickey offers an appointment link and you choose it, you may be taken to our configured Calendly or Microsoft Bookings page. Information entered there is handled by that provider under its terms and privacy policy. Mickey does not receive calendar passwords or private calendar credentials.
5.2 International Data Transfers
Personal data may be transferred to, stored in, and processed in countries outside your country of residence, including Australia, United States, European Union, and Asia-Pacific region.
Where Australian Privacy Principle 8 applies, we take reasonable steps appropriate to the circumstances before disclosing personal information to an overseas recipient. Measures may include data minimisation, provider restrictions, contractual privacy terms, prompt training controls, retention controls, and reviewing where the selected provider processes information.
6. Data Retention
We retain personal data only as long as reasonably necessary to fulfill the purposes for which it was collected, including legal, regulatory, tax, accounting, and reporting requirements.
- Client/Service Data: Retained during engagement and for 7 years following termination
- Payment Information: Transaction records retained for 7 years
- Email Communications: Marketing emails retained for 2 years or until unsubscribe
- Website Analytics: Analytics data retained for 26 months
- Log Files: System logs retained for 90 days
- Mickey Conversations: Chat transcripts and human handoff status retained for up to 30 days
- Mickey Security Counters: Pseudonymous abuse counters and successful verification status retained for approximately one hour
Upon expiration of the retention period, personal data is securely deleted, destroyed, or anonymized to prevent re-identification.
7. Data Security and Protection Measures
7.1 Security Measures
Technical Safeguards:
- Encryption of data in transit (TLS/SSL protocols)
- Encryption of data at rest using industry-standard algorithms
- Secure authentication and access controls (multi-factor authentication)
- Regular security testing and penetration testing
- Intrusion detection and prevention systems
- Firewalls and network segmentation
- Database security and access logging
Organizational Safeguards:
- Staff training on data protection and privacy
- Confidentiality agreements with all employees and contractors
- Principle of least privilege for data access
- Regular security audits and compliance reviews
- Incident response procedures
- Backup and disaster recovery systems
7.2 Security Limitations
While we are committed to maintaining high security standards, we cannot guarantee absolute security of any information transmitted to or by us over the Internet.
Users are encouraged to use secure passwords, protect account credentials, and report security concerns immediately.
8. Data Breach Notification
In the event of a confirmed data breach involving personal data, Aiverse Solutions commits to:
- Contain the breach and prevent further unauthorized access
- Assess the scope and nature of the breach
- Notify affected individuals without undue delay (typically within 72 hours for GDPR-regulated data)
- Notify relevant authorities as required by law
- Provide transparent communication about the incident
- Conduct thorough investigation and implement remediation steps
To report a suspected breach or security incident, contact: info@aiversesolutions.com.au
9. Cookies and Tracking Technologies
9.1 Cookie Use
Our website and applications use cookies and similar tracking technologies, including:
- Essential Cookies: Session management, authentication, security and fraud prevention
- Analytics Cookies: Google Analytics and Hotjar for website traffic and user behavior analysis
- Marketing Cookies: Tracking user engagement with marketing campaigns
9.2 Cookie Consent and Control
We obtain explicit consent for non-essential cookies prior to placement. Users may opt out of marketing and analytics cookies through browser settings or our cookie consent banner.
Third-party tracking services (Google Analytics and Hotjar) collect data subject to their own privacy policies.
10. Your Rights and Choices
10.1 General Rights (All Jurisdictions)
- Right to Access: Request access to personal data we hold about you
- Right to Correction: Request correction of inaccurate, incomplete, or outdated personal data
- Right to Deletion: Request deletion of personal data (subject to legal retention requirements)
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
10.2 GDPR Rights (EU Data Subjects)
EU data subjects have additional rights including:
- Right to Rectification
- Right to Erasure ("Right to be Forgotten")
- Right to Restrict Processing
- Right to Data Portability
- Right to Object to processing for direct marketing
- Right to lodge a complaint with a Data Protection Authority
10.3 CCPA Rights (California Residents)
California residents have the following rights:
- Right to Know what personal information is collected, used, shared, or sold
- Right to Delete personal information
- Right to Opt-Out of sale or sharing of personal information
- Right to Correct inaccurate personal information
- Right to Non-Discrimination for exercising CCPA rights
10.4 Australian Privacy Act Rights
Australian residents have rights under the Australian Privacy Principles, including access, correction, and complaint rights.
Contact the Office of the Australian Information Commissioner: https://www.oaic.gov.au/
10.5 Exercising Your Rights
To exercise any of the above rights, contact:
Email: info@aiversesolutions.com.au
Mail: Aiverse Solutions, Canberra, Australian Capital Territory, Australia
Response Timeline: We will respond to rights requests within 30 days (or as required by applicable law). Complex requests may require up to 90 days.
11. Marketing Communications
We send marketing communications (newsletters, promotions, product updates) based on your explicit consent or existing business relationship.
Opt-Out and Unsubscribe
You can opt out of marketing communications by:
- Clicking the "Unsubscribe" link in any marketing email
- Contacting us at info@aiversesolutions.com.au with "Unsubscribe" in the subject line
- Updating preferences in your account settings
Opt-out requests are typically processed within 10 business days. We will continue to send transactional and service-related communications as necessary for service delivery.
12. Children's Privacy
Our services are not intended for children under the age of 13 (or equivalent minimum age in your jurisdiction). We do not knowingly collect personal data from children.
If we become aware that personal data has been collected from a child, we will delete such data promptly and notify the child's parent or guardian.
Parents or guardians who believe their child's data has been collected should contact info@aiversesolutions.com.au immediately.
13. Policy Updates and Changes
Aiverse Solutions may update this Policy periodically to reflect changes in our business practices, applicable laws and regulations, or improvements in security and privacy practices.
Material Changes
- We will notify you via email or prominent website notice
- We will provide at least 30 days' notice before material changes take effect
- We may request your explicit consent for significant changes
Non-Material Changes
We will update the "Last Updated" date at the top of this Policy. Continued use of our services constitutes acceptance of updated terms.
14. Contact Information
For questions, concerns, requests, or complaints regarding our privacy practices, contact:
Aiverse Solutions
Data Protection Officer / Privacy Officer
Email: info@aiversesolutions.com.au
Address: Canberra, Australian Capital Territory, Australia
ABN: 70 682 307 204
Response Time: We will respond to privacy inquiries and data subject rights requests within 30 days (or as required by applicable law).
Escalation and Complaints
If you believe your privacy rights have been violated or are dissatisfied with our response:
- Australia: Office of the Australian Information Commissioner: oaic.gov.au
- European Union: Your national Data Protection Authority
- California (USA): California Attorney General: oag.ca.gov/privacy
Appendix A: Key Service Providers
The following organisations may process information for Aiverse Solutions under their applicable service and privacy terms:
| Service Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Vercel | Website hosting, server functions, and AI routing | Global | Server-only credentials, platform security controls, and applicable contractual terms |
| Upstash | Restricted CMS and subscriber storage | Configured service region | Server-only credentials and access restrictions |
| Monday.com | Lead management and report delivery workflow | Global | Server-only credentials, restricted board access, and applicable contractual terms |
| Vercel AI Gateway | AI routing, usage controls, and provider restriction | Global | Server-only authentication, no prompt training, provider allowlist, and optional Zero Data Retention |
| OpenAI / Microsoft Azure | Assessment report generation and fallback chat processing | United States or selected provider region | Data minimisation and Gateway-enforced provider controls |
| Google / Google Vertex AI | Chat processing and fallback assessment generation | United States, European Union, or selected provider region | Data minimisation and Gateway-enforced provider controls |
| Cloudflare Turnstile | Adaptive bot and abuse verification for Mickey | Global | Challenge shown only after suspicious activity; server-side token validation; no Turnstile secret sent to the browser |
| Calendly or Microsoft Bookings, when enabled | Customer-selected appointment scheduling | Provider-selected service region | Visitor initiated transfer to an approved HTTPS booking page; no calendar credentials are exposed to the chatbot |
This Data Privacy Policy is effective as of July 29, 2026. For the most current version, visit our website or contact info@aiversesolutions.com.au.