Legal Frameworks
Fully Compliant Compliance Model
Last Updated: 24 May 2026
Privacy Policy
Compliance Framework: Australian Privacy Act 1988 (Cth)
At W3AI (represented by W3AI.com.au), we are committed to protecting your privacy in accordance with the 13 Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth). This policy outlines how we collect, hold, use, disclose, and secure your personal and organizational information.
1. Information We Collect
In the course of providing AI consultation, workflow diagnostics, custom LLM integration, and system orchestration services, we collect:
- Business Details: Trading names, representative executives, company size, region of operation, structural business constraints, and operational bottlenecks.
- Contact Details: Business email addresses and active online messaging handles.
- Diagnostic Reference Data: System schematics, database schemas, process map documents, or file uploads outlining your local technology stacks.
2. Purpose of Collection & Data Minimization
We compile project discovery details exclusively to:
- Synthesize technical scoping briefs and AI systems roadmaps.
- Interface safely with backend Large Language Models (LLMs) to formulate architectural proposals.
- Provide active customer support and project implementation delivery.
We enforce the practice of Data Minimization. Clients are instructed never to upload files containing Tax File Numbers (TFNs), credit card PANs, or health indices unless covered under an explicit Business Associate Agreement (BAA).
3. Safe LLM Pipeline Protocols (Data Sanitization)
W3AI maintains modern privacy layers. Any data mapped from our Project Discovery Form to secondary generative nodes (such as OpenAI GPT or Anthropic Claude API endpoints) is programmatically stripped of identifiable private labels unless private isolated enterprise models are specified.
4. Disclosures & Cross-Border Transfers
We do not sell or rent customer lists. We only disclose information to verified technical subcontractors assisting in client project execution, or to fulfill legislative warrants under Australian law.
5. Security, Storage & Notifiable Data Breaches
All client metadata and uploaded diagnostic files are stored in encrypted Supabase storage instances protected by multi-factor admin auth. We maintain full compliance with the Notifiable Data Breaches (NDB) scheme. In the highly unlikely event of a structural breach, W3AI will immediately notify the Office of the Australian Information Commissioner (OAIC) and impacted system users.
6. Correction & Access Rights
Under APP 12, you have a right to query the exact parameters of personal details W3AI holds about you. To request rectification, access, or deletion, kindly submit a written request to [email protected].