Skip to content

Privacy policy

Last updated 11 August 2026

1. Who we are

Kelpie Group Pty Ltd (ABN 33 698 874 092) (Kelpie, we, us, our) provides managed AI agent services. We design, build, deploy, manage and support AI agents for business workflows. This policy explains how we collect, use, store, secure and disclose personal information about website visitors, prospective clients, clients, their personnel and our suppliers.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as amended, including the 2024 to 2025 reforms.

1.1 Two different roles

It is important to distinguish two situations:

  • Information we collect for our own purposes, for example enquiry, billing and website data. Here Kelpie is the entity responsible under the APPs, and this policy governs how we handle it.
  • Information inside a client's own systems that a Kelpie agent accesses to perform the service (Client System Data). Here we act on behalf of and under the instructions of the client, who remains responsible for that information and for the privacy notices and consents that apply to it. Our handling of Client System Data is governed by our agreement with that client and their own privacy policy.

2. Information we collect

2.1 Information you give us directly

Names, contact details, business details, enquiry details, workflow requirements, support requests, meeting notes, billing information and setup documentation.

2.2 Client System Data

Where you engage us, a Kelpie agent may access approved information in your systems, such as inbox data, documents, CRM records, job and task data, and calendar information, strictly within the scope agreed in writing. You are responsible for ensuring you have the right to give us this access and for any consents or notices required.

2.3 Website and technical data

IP address, browser and device details, and usage analytics collected through cookies, analytics tools and similar technologies.

2.4 Sensitive information

We do not seek sensitive information, as defined in the Privacy Act, unless it is necessary for an agreed service, and we handle it in line with the agreed scope, applicable law and written client instructions. For clients in regulated industries, we recognise that data may include confidential, market sensitive or non-public information, and we handle it accordingly. See section 6.

3. How we use information

We use personal information to:

  • respond to enquiries and prepare proposals;
  • design, configure, test, deploy, monitor, support and improve Kelpie agent workflows;
  • manage billing and our client relationship;
  • maintain the security and integrity of our systems; and
  • comply with our legal obligations.

We do not sell personal information.

4. AI services, model training and your data

Our service relies on third party providers for hosting, AI models, workflow tools and cloud services (Third Party Providers, or subprocessors). In delivering the service:

  • We apply scoped access and least privilege permissions so an agent can only reach what is needed for the agreed workflows.
  • We do not use your business data or Client System Data to train shared, general or publicly available AI models, and we configure the service to prevent this where the setting is available. We use AI providers on enterprise or API terms under which your inputs and outputs are not used to train their models and are subject to limited retention, where such terms are offered.
  • Each client's data is kept segregated to that client's engagement and is not used to benefit another client.
  • AI outputs can be inaccurate or incomplete, so a human reviews and approves outputs before they are relied on for anything sensitive or business critical.

4.1 Automated decision making

Kelpie agents are designed to assist and to operate on a draft first, human approval basis, and a human remains in the loop for decisions that significantly affect individuals. Where automated processing is used in a way that could significantly affect an individual, we will describe that processing consistent with the Privacy Act's automated decision transparency requirements, which take effect from December 2026.

5. Disclosure of information

We may disclose personal information to:

  • our employees and contractors who need it to deliver the service, under confidentiality obligations;
  • Third Party Providers that host, process, transmit, secure or support the service;
  • professional advisers; and
  • regulators, law enforcement or others where required or authorised by law.

5.1 Cross border disclosure (APP 8)

Some of our Third Party Providers, including AI model and cloud providers, may store or process data outside Australia, for example in the United States or other regions. Where practical for a client engagement we can host data in an Australian region.

Where data is disclosed overseas, we use reputable providers and appropriate contractual, technical and organisational controls. We will identify the relevant subprocessors and, for client engagements, set out data residency arrangements in the applicable agreement.

6. Confidential and market sensitive information (regulated clients)

We understand that clients in financial services and other regulated industries operate under confidentiality and information barrier obligations and may handle material non-public or price sensitive information. Where we act for such a client, we:

  • scope agent access to what is agreed;
  • keep the client's data segregated;
  • work within the client's information barrier, confidentiality and security policies as agreed; and
  • during pilots, can work on de-identified or low sensitivity data so that no live sensitive information is exposed while the service is being evaluated.

7. Security

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, consistent with APP 11. Our measures include encryption in transit and at rest, multifactor authentication, role based least privilege access controls, scoped permissions, secure credential handling, access logging, and backups, together with the technical controls of our Third Party Providers.

You should not send passwords, API keys, private keys, recovery codes, OAuth secrets or one time passcodes through ordinary chat or email unless we direct you to an approved secure process.

8. Data breaches

We maintain processes to detect, assess and respond to data security incidents. If we become aware of a data breach affecting a client's data, we will notify the affected client without undue delay and support their response.

We comply with the Notifiable Data Breaches scheme under the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals where an eligible data breach involving personal information we are responsible for is likely to result in serious harm. For Client System Data, the client generally holds the primary notification obligation, and we will assist them to meet it.

9. Retention and deletion

We keep personal information only as long as reasonably needed for the purposes described in this policy, for billing, and to meet legal, audit and record keeping obligations, after which we delete or de-identify it.

On termination of a client engagement, at the client's request and within a reasonable period, we will return or delete Client System Data in our control, except where we are required to retain it by law or for backup integrity, security logs, audit records or dispute handling. We understand that clients in regulated industries may have their own record retention obligations, for example financial services record keeping, and we will accommodate agreed retention arrangements.

10. Access, correction and choices

You may request access to, or correction of, the personal information we hold about you. We may decline where the law permits, for example where access would affect another person's privacy, reveal confidential commercial information, or prejudice security, and we will explain why.

You can unsubscribe from our marketing communications at any time. Requests relating to information inside a client's systems should generally be directed to that client, and we will assist them as needed.

11. Client responsibilities

Clients:

  • decide what information their Kelpie agent may access, process, store, summarise or act on;
  • must ensure the required consents, notices and legal bases are in place;
  • must review outputs before they are relied on;
  • must maintain secure, least privilege permissions; and
  • must comply with the laws and industry obligations that apply to their business.

12. Complaints and contact

For any privacy question, access or correction request, or complaint, contact us using the details below. We will acknowledge and respond within a reasonable time.

If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Location
53 Doggett Street, Newstead QLD 4006

13. Changes to this policy

We may update this policy from time to time. The current version will be published on our website with the last updated date shown above.