Drawn AI builds custom AI software for other businesses. This policy explains what we collect, how we use it, where it is stored, and how you can access or correct it. It also draws the line that matters most: information we collect for ourselves is handled differently from information we process for a client under contract. We follow the Australian Privacy Principles and disclose our automated decision-making ahead of the December 2026 deadline.
1. Who we are
Drawn AI is a partnership between two founders, Liam (Melbourne, Victoria) and Jacob (Queensland), trading as Drawn AI (ABN 89 787 755 848). We are not a company. There are two of us, and every promise here is one two people can keep.
We build custom AI software for businesses Australia-wide — dashboards, automations, integrations, client portals, workflow automation, risk and compliance systems, document and knowledge intelligence, and field and mobile tools. Our clients work in retail, construction, financial and insurance services, mining and resources, healthcare, education, hospitality, logistics, professional services, real estate, manufacturing, automotive, fitness and wellness, and trades. We sell on subscription and have operated since 2025.
2. How the Privacy Act applies to us
The Privacy Act 1988 (Cth) and its 13 Australian Privacy Principles (APPs) set the rules for handling personal information in Australia. The Act currently exempts many small businesses turning over under $3 million a year, but that exemption is scheduled for removal under the next round of reforms, not yet law.
Rather than argue about which side of a moving line we sit on: Drawn AI handles personal information in accordance with the APPs regardless of our turnover, and regardless of whether the Act binds us directly. If the exemption goes, our obligations become legal rather than voluntary, but our practices will not change. Our finance, insurance and mining clients require APP-equivalent terms of suppliers anyway.
The APPs are at legislation.gov.au.
3. Two very different kinds of data
This is the most important section here: we handle personal information in two roles, and your rights differ depending on which applies.
Information we collect for ourselves
When you use an enquiry form on drawnai.app, book a discovery call, email us or become a client, we decide what happens to that information and we are responsible for it. Sections 4 to 8 cover this role.
Information we process for a client
Most of our builds connect to systems our clients already run — CRM, accounting, email, forms and spreadsheets, ERP, payments, booking systems, document stores, HR, inventory and project management — holding information about their customers, staff, patients, tenants and suppliers.
When we build, host, integrate or support software touching that information, we act as a service provider processing personal information on behalf of that client. We do not decide what it is for, and we never use it for our own purposes. We handle it only as the client instructs, under a written agreement.
If you are a customer or employee of one of our clients, start with that client — their data, their system, their policy. We help where we can, but usually refer you to them.
4. What we collect and why
| What we collect | Where it comes from | Why |
|---|---|---|
| Full name, business name, work email, phone, preferred contact method, consent checkbox | Enquiry form, discovery-call booking | To reply as you asked, hold the meeting, and record that you agreed |
| Industry, business size, systems and software you use | Enquiry form | To judge fit and integration effort |
| Services of interest, main business challenge, project goals, timeline | Enquiry form | To scope the work before we talk |
| Name, email, short message | Hero form on our home page | To answer a quick question |
| Contract and subscription records | Client onboarding | Invoicing and tax records |
| Staff names, roles, contact details; support requests | Delivery and support | Account setup, testing, fixing what you report |
| IP address, browser and device type, pages requested | Automatic, in our web server logs | Keeping the site up and secure, and diagnosing faults. We run no analytics product and build no profile from it |
We do not collect sensitive information (health, race, political or religious views, sexual orientation, criminal record, biometrics) for our own purposes. Some systems we build do — a healthcare portal, a compliance system holding incident records — and there we act only as a service provider under section 3. Please keep it out of our enquiry forms.
You can deal with us anonymously for general information. For a quote or a call, we need to know who you are.
5. How we use and disclose your information
We use this information to answer enquiries, prepare proposals, deliver and support the software you engaged us to build, bill you, keep required records and improve our services.
We disclose it only to: the service providers we rely on to operate (section 8); our accountant or lawyer; anyone you ask us to; and a regulator or court where required by law. We do not sell personal information, rent contact lists, or disclose one client's information to another.
6. AI models, training and product improvement
We build AI software, so we owe you a direct answer.
We never use client data in its raw form to train AI models — not our own, not anyone else's, not a shared model other clients benefit from. The content of your documents, customer records and business data stays inside the system we built for you.
We may use de-identified and aggregated information to improve how our products work. "De-identified" has a specific meaning under the Privacy Act: information is de-identified when it is no longer about an identified individual, or one reasonably identifiable. That is a higher bar than deleting a name column. In practice we strip direct identifiers, exclude unreviewed free-text fields, and aggregate so results describe patterns across many records, not any one. De-identification is not a guarantee — nobody can promise data could never be re-identified — so we keep it narrow: accuracy measures, error patterns and usage statistics, never content.
Clients can opt out. If you would rather nothing derived from your environment informed our product improvement, tell us and we will exclude you. No charge, no reduction in service.
Where software we build sends data to a third-party AI or large language model provider, we name that provider to the client beforehand and disable provider-side training where that setting exists. We do not promise a setting a provider does not offer.
7. Automated decision-making
From 10 December 2026, Australian privacy policies must disclose how personal information is used in automated decisions. We are publishing ours now, because automation is what we build.
In our own business
We make no automated decisions about you. What we quote, and who we work with, is decided by Liam or Jacob. Nothing on drawnai.app decides anything — our forms collect information for a human to read.
In what we build for clients
Software we build does include automated steps: an automation that routes a job, a compliance system that flags a file for review, a document tool that classifies and extracts. Whether that amounts to a decision significantly affecting someone's rights or interests depends on the client's use. When we build these systems we:
- Identify in writing any part that makes, or substantially contributes to, a decision about an individual — before it is built.
- Tell the client what kinds of personal information feed that decision, so they can disclose it in their own policy.
- Separate the two categories the law distinguishes — decisions made solely by a computer program, and decisions where a program does something substantially and directly related to a decision a person then makes.
- Recommend a human in the loop wherever a decision could significantly affect rights or interests — credit, employment, insurance, service access, a compliance finding — and record it when a client declines.
- Build for explainability, so a client can tell an affected person what drove an outcome.
The client discloses that decision-making in their own policy; we give them what they need.
8. Where information is stored, and overseas disclosure
We host in Australian data centres, in Melbourne. That includes the AI processing — a point worth making plainly, because it is the question clients ask most often. APP 8 requires us to name any country your information may reach.
| Purpose | Provider | Where information is held |
|---|---|---|
| Cloud hosting, application infrastructure, storage and backups | Amazon Web Services | Australia — Asia Pacific (Melbourne) |
| AI and large language model processing | Anthropic Claude, accessed through Microsoft Azure and Amazon Bedrock | Australia — Azure Australia Southeast (Melbourne) and AWS Asia Pacific (Melbourne) |
| Error monitoring and application logging | Self-hosted by Drawn AI | Australia |
| Website analytics | None. We run no analytics on drawnai.app | Not applicable |
| Invoicing and payments | Invoices issued by us; payment by bank transfer to an Australian bank, or by card through Stripe | Australia; Stripe also processes card data in the United States |
| Business email | Private Email (Namecheap) | United States |
What this means in practice. Your project data, the AI processing we run on it, our application logs and our backups are all held in Melbourne. Two things are not:
- Our business email. It is hosted in the United States. This matters more than it first appears: email is how you send us support requests, and those often carry screenshots, error messages, record extracts and attachments. Anything you email us goes to a US-hosted mailbox. If that is a problem for your industry, tell us during scoping — we can arrange onshore email, or take support through a channel that stays in Australia.
- Card payments, where Stripe also processes in the United States. Paying by bank transfer avoids this entirely.
Two honest caveats. First, our Australian hosting is provided by companies headquartered overseas; the data sits in Melbourne, but we do not claim that alone puts us outside APP 8, and we do not have the bargaining power to negotiate the standard terms of AWS, Microsoft, Anthropic or Stripe. Second, we take reasonable steps to satisfy ourselves each recipient handles information consistently with the APPs, which in practice means relying on their published contract and security terms rather than an agreement we have written ourselves. We would rather tell you that than imply a level of control we do not have.
9. How we hold and protect information
We are a two-person partnership, so here is what we actually do.
- Information sits in reputable cloud services, not on unmanaged personal devices.
- Access is limited to Liam and Jacob, and to a client's environment only while the work requires it.
- Multi-factor authentication is on for the accounts we control; our devices are encrypted and password-protected.
- Production access is separated from development, where we use test or de-identified data wherever we can.
- We review access when a project ends and remove credentials we no longer need.
We hold no security certifications — no ISO 27001, no SOC 2, no dedicated security team, no round-the-clock monitoring. If your procurement requires a certified supplier, tell us early. More detail: Data Security.
10. How long we keep information
These are working assumptions. Where a contract or law requires otherwise, that wins.
- Enquiries that do not become projects — 2 years from your last contact.
- Discovery-call bookings — 12 months after the call.
- Project records and contracts — 7 years after the engagement ends.
- Financial and tax records — at least 5 years, as tax law requires.
- Client data in systems we host or support — while the subscription runs; on termination we return or delete it as the agreement says. You can request an export for 30 days after termination, and we delete our working copies within 30 days after that window closes. Backups age out within a further 30 days.
- Server logs — 12 months. We run no website analytics at all — see our Cookie Policy.
- De-identified, aggregated product-improvement data — indefinitely, as it is no longer about an identifiable person.
- Marketing contacts — until you unsubscribe, plus a suppression record.
11. Data breaches
The Notifiable Data Breaches scheme (Part IIIC of the Privacy Act) applies where a breach is likely to result in serious harm. If we suspect an eligible breach we assess it within 30 days, and where serious harm is likely we notify the Office of the Australian Information Commissioner and the individuals affected as soon as practicable.
Where the breach involves data we hold for a client, we tell that client immediately. They lead the response for their own data; we do not notify their customers without them.
12. Direct marketing and email
We send marketing email only where you have ticked the separate, optional marketing box on our contact form, or where you are a client and the message relates to services like the ones we already provide you.
The consent box on our enquiry form — "I agree to Drawn AI contacting me about this enquiry" — is exactly that, and nothing more. It lets us reply to what you asked about. It is not consent to a newsletter or to marketing about anything else, and we do not treat it as such.
As the Spam Act 2003 (Cth) requires, every marketing email identifies Drawn AI, gives our contact details and carries a working unsubscribe link. We action unsubscribes within 5 working days, which is the statutory maximum, and usually the same day.
Unsubscribing does not stop operational messages — invoices, outage notices, security notifications and support replies. Those are not marketing, and you cannot opt out of them while you are a client.
13. Cookies and analytics
drawnai.app sets no cookies and runs no analytics. It stores nothing on your device, and loads nothing from another company's servers — no analytics, no advertising, no tracking pixels, no embedded fonts or scripts from elsewhere.
Our web server keeps standard request logs (IP address, time, page requested, browser type) because a server that logs nothing cannot be secured or debugged. Those logs are not joined to anything else and are deleted after 12 months.
If that ever changes we will update this policy and our Cookie Policy before turning anything on, not afterwards.
14. Children
Our services are business-to-business. We do not market to children and we do not knowingly collect personal information from anyone under 18 through our website or our own systems.
Some client systems we build may hold information about children — a school platform, a healthcare portal, a junior fitness membership. There we act only as a service provider under section 3, and consent is the client's responsibility. If a child has given us information through a form, email us and we will delete it.
15. Accessing and correcting your information
Under APP 12 and APP 13 you can ask for a copy of the personal information we hold about you, and ask us to correct it if it is wrong, out of date or misleading.
Email policies@drawnai.app with enough detail for us to find it. We may ask you to verify your identity, and we respond within 30 days. Access is free; for an unusually large request we may charge a reasonable cost-based fee, quoted first. We can refuse in the limited situations the Privacy Act allows, and will say why in writing.
If your information sits in a client's system, we usually cannot give it to you directly — our contracts do not allow it. We pass the request to the client and confirm that we have.
16. If you are in the EU or the UK
Where we handle personal data of people in the European Union or United Kingdom, the GDPR or UK GDPR may apply alongside Australian law. You then also have rights to erasure, restriction, portability and objection, and can complain to your local supervisory authority. Email us and we will apply whichever framework gives you more.
17. Complaints
If you think we have mishandled your personal information, tell us first.
- Email policies@drawnai.app with "Privacy complaint" in the subject and describe what happened.
- We acknowledge within 5 business days.
- We investigate and respond in writing within 30 days, setting out what we found, what we did, and what we will do differently. If it will take longer, we say why and give a date.
If our answer does not satisfy you. We should be straight with you about how this works. The Privacy Act binds "APP entities", and a small business under the $3 million turnover threshold is not automatically one — so depending on our size at the time, the Office of the Australian Information Commissioner may or may not be able to accept a complaint about us.
We are not going to hide behind that. We hold ourselves to the Australian Privacy Principles by choice, we will not refuse a complaint on the ground that we are too small to be covered, and we will give you our findings in writing either way.
You can still contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992 for advice, and the OAIC will tell you whether it can act. Separately, a statutory tort for serious invasions of privacy has been available since 2025 and does not depend on our size.
Contact us
For an access request, correction, complaint, opt-out, or a question about data on a project:
- Email: policies@drawnai.app
- Website: drawnai.app
- Business: Drawn AI, ABN 89 787 755 848 — a partnership operating from Melbourne, VIC and Queensland, serving clients Australia-wide.
Privacy enquiries go straight to Liam and Jacob. See also our Terms and Conditions, Cookie Policy and Data Security.
Changes to this policy
We update this policy when our practices change, when we add or replace a service provider, or when the law changes — and Australian privacy law is changing. The date at the top shows the current version. Material changes go up on drawnai.app before they take effect, and where one affects information we already hold, we email you.
Two changes are already on our calendar: the automated decision-making disclosure requirement commencing 10 December 2026, which section 7 anticipates, and the proposed removal of the small business exemption, which would make our APP obligations legal rather than voluntary.