1. About this Privacy Policy
This Privacy Policy explains how TASII collects, holds, uses, discloses, protects and otherwise manages personal information in connection with this website, the TASII AI assistant, enquiries, project discussions and client relationships.
In this policy, TASII, we, us and our mean TASII (ABN 62 112 948 328), an Australian business operating from Exeter, Tasmania, Australia. You can contact us at hello@tasii.com.au.
This policy is designed to reflect the standards of the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. Some small businesses are exempt from some or all provisions of the Privacy Act unless an exception applies. TASII nevertheless manages personal information in accordance with the practices described in this policy and will comply with any privacy law that is legally applicable to the relevant processing.
This policy applies to information handled by TASII. It does not govern the independent privacy practices of third-party websites, payment providers, hosting providers or other services that you choose to access separately.
2. Personal information we may collect
The personal information TASII collects depends on how you interact with us. It may include:
- your name, email address, telephone number and other contact details;
- your business name, role, website address and other business contact information;
- information contained in a contact form, quote request, project enquiry, email or other correspondence;
- project requirements, budgets, timeframes, technical requirements, business processes, files or other information you choose to provide for a proposed or current project;
- TASII AI assistant messages, conversation history and, if you choose to submit a chat as a project enquiry, your name, email address and the submitted conversation;
- records relating to quotes, contracts, projects, support, invoicing, payments and the client relationship;
- account or access information where TASII provides a login or protected service;
- technical information such as IP address, browser and device information, date and time of access, referring pages, server logs, security events and session identifiers; and
- marketing preferences and records of consent or unsubscribe requests, where applicable.
Where a business email address or telephone number identifies an individual, it may be personal information even though it is used for business purposes.
Sensitive information
TASII does not ordinarily require sensitive information such as health information, biometric information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal history.
Please do not send passwords, payment-card numbers, identity documents, health information or other sensitive information through the TASII AI assistant or general contact forms unless TASII has specifically asked for that information and an appropriate method of collection has been agreed.
If TASII receives unsolicited sensitive or other personal information that is not reasonably required, we may delete, destroy or de-identify it where lawful and practicable.
TASII Client Portal information
If TASII gives you access to the secure TASII Client Portal, we may also hold information connected with that account, including your login email, a securely hashed password credential, project status and updates, files you upload or receive, approval responses, quotes and billing records, support requests and messages exchanged through the Client Portal.
Client-uploaded files are stored in protected server storage and are made available only through authorised Client Portal or TASII administration access. Please do not upload payment-card details, passwords for unrelated services or other sensitive information unless TASII has specifically asked for it through an appropriate method.
If you use the Client Portal AI assistant, your messages and relevant client-visible project/account information may be processed by OpenAI so the assistant can answer the request. If you explicitly ask the assistant to email TASII or create a support request, the relevant message and account details are used to perform that action. TASII does not use the Client Portal to store full payment-card numbers.
3. How we collect personal information
TASII may collect personal information:
- directly from you when you use a form, send an email, use the AI assistant, submit a project enquiry, request a quote, become a client or otherwise communicate with us;
- automatically through normal website operation, including server logs, security systems, session technologies and cookies;
- from a person you authorise to communicate with us;
- from referrals, business partners or service providers where appropriate; and
- from publicly available business sources where it is reasonable and lawful to do so.
You may browse most public pages without identifying yourself. You may also ask general questions of the AI assistant without providing your name. Identification is usually necessary when you ask TASII to contact you, submit a project enquiry, request a quote, enter into a contract or obtain client-specific services.
If you do not provide information reasonably required for a request, TASII may be unable to respond fully, prepare a quote, enter into a project or provide the requested service.
4. Why we collect, use and disclose personal information
TASII may collect, hold, use and disclose personal information for purposes including:
- responding to enquiries and communicating with you;
- discussing, assessing and scoping proposed projects;
- preparing quotes, proposals and project documentation;
- entering into and performing contracts;
- designing, developing, hosting, maintaining and supporting websites, ecommerce systems, booking systems, automation, portals, web applications and AI features;
- administering client relationships, accounts, projects, invoices and support;
- operating, securing, monitoring, troubleshooting and improving the TASII website and business systems;
- preventing misuse, fraud, unauthorised access and security incidents;
- keeping business, accounting, audit and legal records;
- complying with legal obligations, court orders and lawful regulatory requirements;
- establishing, exercising or defending legal claims;
- sending direct marketing where permitted by law and consistent with your choices; and
- other purposes that are reasonably related to the purpose for which the information was collected, or where you consent or the law otherwise permits.
Where European Union or United Kingdom data protection law applies, the legal basis for processing may include taking steps at your request before entering a contract, performance of a contract, compliance with a legal obligation, consent, or TASII's legitimate interests in operating and securing its business, responding to business enquiries and providing its services, subject to the requirements of the applicable law.
5. TASII AI assistant and automated processing
The TASII website includes an AI assistant intended to answer questions about TASII, business and digital projects and, where appropriate, help a visitor turn a conversation into a project enquiry.
Messages submitted to the AI assistant are processed by TASII's systems and may be transmitted to OpenAI through its API so that a response can be generated. TASII also stores chat records in its website database for conversation continuity, security, transcript review and project-enquiry handling.
At the date of this policy, OpenAI states that business and API inputs and outputs are not used to train its models by default unless the customer explicitly opts in. OpenAI also states that API inputs and outputs may be retained for up to 30 days for service operation and abuse monitoring for relevant API features, unless different retention controls apply or longer retention is legally required.
The AI assistant may use automated classification to help determine matters such as whether a message is business-related, social or outside TASII's business scope, and whether a conversation appears to be developing into a potential project enquiry. These classifications support the website conversation flow only.
The AI assistant does not make binding decisions about whether TASII will accept a project, what a project will cost, contractual rights, credit, employment, or any other decision that could reasonably be expected to have a legal or similarly significant effect on an individual. Quotes, project acceptance and contractual commitments are confirmed by a person or through an expressly authorised contractual process.
AI output may be incomplete or inaccurate. Do not rely on the AI assistant as the sole basis for a significant business, legal, financial, technical or security decision.
6. Cookies, sessions and technical information
TASII uses technical storage and session mechanisms that are reasonably necessary to operate and secure the website. These may include:
- PHP or equivalent session cookies;
- a chatbot session identifier used to maintain conversation continuity;
- security and anti-abuse information; and
- server-side logs.
These technologies may process IP addresses and other technical identifiers.
At the date of this policy, the TASII website is not intended to use behavioural advertising cookies or to sell browsing data for targeted advertising. If TASII later introduces non-essential analytics, advertising or similar tracking technologies, we will review this policy and implement any notice or consent mechanism required by applicable law.
You can control cookies through your browser, but blocking strictly necessary cookies may prevent some website or chatbot functions from working correctly.
7. Disclosure of personal information
TASII may disclose personal information where reasonably necessary to:
- website hosting, cloud infrastructure, database, backup, security and technical service providers;
- OpenAI and related AI infrastructure providers when the AI assistant is used;
- email and communications providers;
- payment processors where a payment service is used;
- contractors or specialist service providers engaged to assist TASII, subject to appropriate confidentiality and access controls;
- accountants, insurers, legal advisers and other professional advisers;
- regulators, courts, law enforcement or government bodies where required or authorised by law; and
- a purchaser, successor or adviser in connection with a genuine proposed or completed sale, restructuring or transfer of all or part of the TASII business, subject to appropriate confidentiality and legal requirements.
TASII does not sell or rent personal information or customer lists.
TASII will not use personal information supplied for a project enquiry as a public testimonial, case study or marketing endorsement without appropriate permission.
8. Overseas processing and disclosure
Some of TASII's service providers operate internationally. Personal information may therefore be processed, stored or made accessible outside Australia.
At the date of this policy:
- TASII uses Namecheap for the hosting of this website. Depending on the hosting configuration, Namecheap publishes shared-hosting locations in the United States, United Kingdom, the Netherlands and Singapore. TASII may migrate this website to another hosting provider, including an Australian provider, and will update this policy when a material hosting arrangement changes.
- TASII's AI provider, OpenAI, uses global infrastructure and subprocessors. Its current published processing locations include Australia, the United States, the United Kingdom, Singapore, Canada, Japan, India and countries in the European Economic Area, among other locations.
- Client websites may be hosted under arrangements selected for the particular project. The applicable hosting location and provider may therefore differ from the hosting used for tasii.com.au.
Provider infrastructure and subprocessor locations may change. Where practicable, TASII will keep this policy reasonably current. OpenAI publishes a current subprocessor list, and Namecheap publishes information about its hosting and privacy practices.
Where APP 8 of the Privacy Act applies, TASII will take reasonable steps required by law in relation to cross-border disclosures. Where EU or UK international-transfer rules apply, TASII will use an available lawful transfer mechanism where required, such as an adequacy mechanism, contractual safeguards or another permitted basis.
9. Security of personal information
TASII takes reasonable technical and organisational measures appropriate to the nature of the information and the risks involved. Measures may include:
- HTTPS/TLS encryption in transit;
- access controls and role-based administration;
- password hashing for authentication credentials;
- encryption or protected storage for selected secrets and credentials;
- restricted administrative access;
- logging and audit records;
- software updates and security maintenance;
- backups and recovery measures; and
- reasonable controls around service providers and contractors.
No internet transmission, cloud service or information system is completely secure. TASII cannot guarantee absolute security, but will take reasonable steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.
10. Retention and deletion
TASII retains personal information only for as long as reasonably necessary for the purpose for which it was collected and for legitimate business, security, contractual, accounting, dispute-resolution and legal requirements.
Retention periods vary according to the type of information. Factors include:
- whether an enquiry becomes a client project;
- the duration of a client or support relationship;
- legal and tax record-keeping requirements;
- limitation periods and the need to establish or defend claims;
- security, fraud-prevention and audit requirements;
- backup and disaster-recovery cycles; and
- whether there is an unresolved enquiry, complaint or dispute.
When personal information is no longer reasonably required and TASII is not legally required to retain it, TASII will take reasonable steps to delete, destroy or de-identify it. Information may remain temporarily in secure backups until the relevant backup cycle expires.
11. Access, correction and deletion requests
You may contact TASII to request access to personal information we hold about you or to ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information.
You may also request deletion of personal information. Australian privacy law does not create an unrestricted right to deletion in every circumstance, but TASII will delete information where legally required or where it is no longer reasonably required and there is no lawful reason to retain it.
TASII may need to verify your identity before giving access to, correcting or deleting information. We may refuse or limit a request where the law permits or requires us to do so, including where disclosure would unreasonably affect another person's privacy or reveal legally protected material. If a request is refused, TASII will provide reasons where required by law.
Requests can be sent to hello@tasii.com.au.
12. Direct marketing and electronic messages
TASII may send business-related marketing or service information where permitted by law.
Where the Spam Act 2003 (Cth) applies to a commercial electronic message, TASII will use the required consent or other lawful basis, identify the sender and provide a functional unsubscribe mechanism. Unsubscribe requests will be honoured within the period required by law.
You may opt out of marketing at any time. Opting out of marketing does not prevent TASII from sending communications reasonably necessary for an enquiry, quote, contract, project, invoice, support request, security matter or other existing business relationship.
13. Data breaches
TASII maintains procedures for responding to suspected loss, unauthorised access or unauthorised disclosure of personal information.
Where the Notifiable Data Breaches scheme under the Privacy Act applies, TASII will assess a suspected eligible data breach and notify affected individuals and the Office of the Australian Information Commissioner where notification is legally required, including where a breach is likely to result in serious harm and the risk has not been prevented by remedial action.
TASII may also notify individuals or authorities where another applicable law requires notification or where notification is otherwise appropriate to reduce a material risk of harm.
14. International visitors and additional privacy rights
TASII's services are presently directed primarily to businesses in Tasmania and Australia. The fact that this website can be accessed from another country does not, by itself, mean every foreign privacy law applies to TASII.
Where an overseas privacy law applies on a mandatory basis, TASII will comply with the rights and obligations that apply to the relevant processing.
For example, where the EU GDPR or UK GDPR applies, an individual may have rights including access, rectification, erasure in specified circumstances, restriction, objection, data portability, withdrawal of consent and the right to complain to an applicable supervisory authority.
Where the California Consumer Privacy Act or another United States state privacy law applies to TASII, applicable residents may have additional statutory rights. TASII does not currently sell personal information or share it for cross-context behavioural advertising.
A request relying on an overseas privacy law should identify the jurisdiction concerned so TASII can assess the applicable legal requirements.
15. Children
TASII's website and services are intended for business users and are not directed to children.
TASII does not knowingly seek personal information from children through the public website. If you believe a child has provided personal information without appropriate authority, contact TASII so the circumstances can be assessed and appropriate action taken.
16. Privacy complaints
If you believe TASII has mishandled your personal information, please contact us first at hello@tasii.com.au and provide enough information for us to understand and investigate the issue.
TASII will acknowledge and investigate a privacy complaint within a reasonable period. Where the Australian Privacy Principles apply, TASII will ordinarily aim to provide a substantive response within 30 days, although a complex matter may reasonably take longer.
If the Privacy Act applies and you are not satisfied with TASII's response, you may be able to complain to the Office of the Australian Information Commissioner.
If another mandatory privacy regime applies, you may also have a right to complain to the competent regulator or supervisory authority in that jurisdiction.
17. Collection notices
This Privacy Policy provides general information about TASII's handling of personal information. It is not necessarily a substitute for a shorter collection notice required at the point where particular personal information is collected.
Where required, TASII may provide a collection notice beside a form, chatbot feature, account process or other collection point explaining the particular purpose, likely disclosures and relevant choices.
18. Changes to this policy
TASII may update this Privacy Policy when its services, technology, providers or legal obligations change.
The current version will be published on this page with its last-updated date. Material changes will apply prospectively from publication unless the law requires another form of notice or consent.
19. Contact
TASII ABN 62 112 948 328 Exeter, Tasmania, Australia
Email: hello@tasii.com.au
For privacy access, correction, deletion or complaint requests, use the subject line Privacy request where practical.
