Skip to main content
AI Web3 Services

Privacy

Privacy policy

An instrument in twenty-five Parts. Part 1 defines the terms the rest of the document uses; every Part after it names the Australian Privacy Principle it gives effect to.

Effective 12 August 2026Version 2.0Privacy Act 1988 (Cth)

Part 1Interpretation and defined terms

Australian Privacy Principle 1.3 — a clearly expressed policy

1.1 The terms defined in this Part carry those meanings wherever they appear in this instrument. Terms are defined once, here, so that no Part has to redefine them and no two Parts can drift apart.

1.2 Parties

  • "we", "us" and "our" mean AI WEB3 SERVICES PTY LTD, ACN 696 596 406, ABN 43 696 596 406, a proprietary company limited by shares registered in New South Wales, Australia. The expression extends to no parent, no subsidiary and no affiliate, because none exists.
  • "you" means the individual reading this website or writing to the address published on it.
  • "a service provider" means a third party engaged by us to perform a function on our behalf, and does not include a party that receives data as principal in its own right.

1.3 Instruments

  • "the Act" means the Privacy Act 1988 (Cth) as in force from time to time.
  • "the APPs" means the Australian Privacy Principles set out in Schedule 1 to the Act, and a reference to a numbered Australian Privacy Principle is a reference to the principle bearing that number in that Schedule.
  • "the Commissioner" means the Australian Information Commissioner, and "the OAIC" means the office supporting that Commissioner.
  • "this instrument" means this privacy policy, including its Parts, headings and tables.

1.4 Categories of information

  • "personal information" carries the meaning given to it by section 6(1) of the Act, and "sensitive information" carries the meaning given by that same section.
  • "correspondence data" means everything contained in an email exchanged between you and our published address: the sending and receiving addresses, any display name, the subject line, the message body, transport headers, delivery timestamps, and any attachment a sender elects to include.
  • "log data" means the record a web server or content delivery network writes when it answers a request: the requesting internet protocol address, the time of the request, the method and path requested, the response status code, the number of bytes returned, the user agent string, and the referring page where a browser supplies one.
  • "public ledger data" means data that a permissionless blockchain publishes to every person who asks for it, including block headers, transaction records, account and contract addresses, calldata, emitted event logs, balances and derived state, obtained by reading a node or an archival provider without any credential, permission or signature.
  • "a view" means an analytical presentation constructed from public ledger data that we build or intend to build.

1.5 Construction

1.5.1 A reference to a statute includes any statutory instrument made under it and any provision substituted for it. 1.5.2 The singular includes the plural. 1.5.3 Headings and the table of contents assist navigation and do not affect meaning. 1.5.4 "Includes" and "including" are not words of limitation. 1.5.5 "business day" means a day other than a Saturday, a Sunday or a public holiday in New South Wales. 1.5.6 A period expressed in days runs from the day after the triggering event.

Part 2Scope and application

Australian Privacy Principle 1 — open and transparent management

2.1 This instrument applies to the handling of personal information by us in the course of the following activities, and to nothing else.

  • Operation of the website published at aiweb3.co.im.
  • Receipt, reading, storage and answering of email sent to the address published on that website.
  • Construction of a view, once any view exists. Clause 2.3 governs the position until then.

2.2 This instrument does not apply to, and we accept no responsibility for, the following.

  • A permissionless blockchain. No person operates one on your behalf; we did not cause any record on one to be written; and no entity, ourselves included, is able to remove a finalised block from one.
  • A website operated by another party and reached from a link in our text. Its own policy governs it.
  • An account, channel, group or message that uses our name without our authority. Part 19 and the terms of use address impersonation.

2.3 Our holdings contain no user account, no login, no subscription, no payment instrument, no billing record and no usage profile, because no view is yet in the hands of a user. Where a Part below describes how a view would be governed, it states a commitment binding on us at the moment a view is released, and not a description of something already running.

2.4 We are an APP entity as that expression is used in the Act. We do not rely on the small business operator exemption in section 6D, and this instrument is drafted on the footing that the Act applies to us in full.

Part 3Accountable entity and governance

Australian Privacy Principle 1.2 — practices, procedures and systems

3.1 The entity accountable for every act and practice described in this instrument is the company named in clause 1.2. Accountability is not delegated to a contractor, an agency or a group function.

3.2 We have not appointed a privacy officer as a distinct office and we do not name one here. The company is small enough that correspondence is read by the people who run it, and inventing a title would misdescribe how a message is actually handled. Every privacy matter is directed to [email protected] and is dealt with by those persons.

3.3 The measures we do operate are stated plainly in Part 13. They are proportionate to holding a mailbox and serving static pages.

3.4 Where a practice described in this instrument changes, Part 25 governs how the change is published and from what date it operates.

Part 4Anonymity and pseudonymity

Australian Privacy Principle 2 — anonymity and pseudonymity

4.1 Reading this website requires no identification of any kind. No page asks who you are, no page requires an account, and no page contains a form that transmits anything you type to us.

4.2 Where you write to us, you may use a pseudonymous address and a name that is not your legal name. We will answer such a message on the same terms as any other. We will not require identity documents as a condition of replying, and we will not attempt to resolve a pseudonymous sender to a legal identity.

4.3 The single practical limit on clause 4.2 is arithmetic rather than policy. A request under Part 15 or Part 17 can be answered only in relation to material we can actually locate, and the only reliable key we hold is the address a message arrived from. Where a request arrives from an address unconnected to the correspondence it concerns, we will say so and ask for something that ties the two together.

4.4 Clause 4.3 is not an identity verification process and must not be read as one. Part 15 states what we will and will not ask for.

Part 5Collection of solicited personal information

Australian Privacy Principle 3 — collection of solicited personal information

5.1 Personal information is collected only where doing so is reasonably necessary for one or more of our functions or activities, and only by means that are lawful and fair. The complete inventory of what is collected appears in the table below. Nothing outside that table is collected.

Every category of personal information within our holdings
CategoryConstituent fieldsNecessary forSource
Correspondence dataSender and recipient addresses, display name, subject, body, transport headers, timestamps, attachmentsReading and answering the message, and evidencing that it was answeredSupplied by you when you write
Log dataInternet protocol address, request time, method and path, status code, bytes returned, user agent, referrerDelivering the page and resisting abuse of the serviceGenerated automatically by the infrastructure serving the page
Complaint fileThe correspondence constituting a complaint, our assessment, and the outcome recorded against itHandling the complaint and demonstrating how it was handledDerived from correspondence data

5.2 We do not collect sensitive information. We do not solicit it, no field on this website invites it, and Part 6 governs the position if a sender volunteers some.

5.3 The following are not collected, in any circumstance, and their absence is structural rather than a matter of current preference.

  • A private key, a seed phrase, a keystore file, a mnemonic, or any other credential capable of authorising a transfer of value.
  • A wallet connection. This website does not request one, does not probe a browser for an injected provider, and executes no code that would do either.
  • A payment instrument, card number, bank account or transaction identifier belonging to you. Nothing is offered for sale.
  • Identity documents, a photograph of a licence or passport, a biometric template, or a government issued number.
  • Precise geolocation, device sensor output, contact lists, or any signal derived from a device beyond the log data defined in clause 1.4.
  • Data purchased or licensed from a broker, an attribution vendor or an aggregator that maps blockchain addresses to named persons.

5.4 Collection of log data occurs because a web server cannot answer a request without receiving the address to which the answer must be returned. That collection is a necessary incident of delivering a page and is limited to the fields listed in the table at clause 5.1.

Part 6Unsolicited personal information

Australian Privacy Principle 4 — unsolicited personal information

6.1 A person occasionally sends more than the matter requires. A message reporting an impersonation attempt may attach a screenshot containing a third party's name; a message about a view may quote a conversation involving someone else.

6.2 On receiving personal information we did not solicit, we determine whether we could lawfully have collected it under Part 5 had we solicited it.

  • Where we could have, the information is handled from that point exactly as if it had been solicited, and every other Part of this instrument applies to it.
  • Where we could not have, and provided the material sits in no Commonwealth record and no law forbids its destruction, we erase it, or strip out whatever identifies a person, as soon as that is practicable. The file records that this was done, without reproducing what was removed.

6.3 Sensitive information volunteered in correspondence is treated under clause 6.2 and, where it is retained because it is inseparable from the matter being handled, it is used for that matter alone and for no other purpose.

6.4 We ask that a message contain only what the matter requires. This is a request and not a condition; a message is never refused for containing more.

Part 7Notification at the point of collection

Australian Privacy Principle 5 — notification of collection

7.1 Australian Privacy Principle 5 requires that certain matters be notified at or before the time of collection, or as soon as practicable afterwards. There is no interface here at which a notice could be displayed, because there is no form and no account. This instrument, published at a stable address and linked from the footer of every page, is the notification.

7.2 The matters required by Australian Privacy Principle 5.2 are addressed as follows.

Australian Privacy Principle 5.2 matters, and where each is given
Matter requiredWhere stated
Identity and contact details of the entityClause 1.2 and Part 25
Facts and circumstances of collectionPart 5, including the source column of the table at clause 5.1
Whether collection is required or authorised by lawClause 7.3
Purposes of collectionPart 5 and Part 8
Consequences of not providing the informationClause 7.4
Usual disclosures of the informationPart 8 and Part 10
How to seek access and correctionPart 15 and Part 16
How to complain, and how a complaint is dealt withPart 23
Whether disclosure overseas is likely, and to which countriesPart 10

7.3 No collection described in Part 5 is required or authorised by an Australian law or a court order. Collection occurs because you wrote to us, or because a page was requested.

7.4 There is no consequence to withholding information from us, other than the obvious one that a question we cannot read cannot be answered. Nothing on this website is withheld from a person who declines to identify themselves.

Part 8Use and disclosure

Australian Privacy Principle 6 — use or disclosure of personal information

8.1 Personal information collected under Part 5 is used for the primary purpose for which it was collected and for no other purpose, unless a secondary use is one you would reasonably expect and is related to the primary purpose, or you consent, or the use is required or authorised by law.

8.2 The primary purposes are exhaustively these: reading and answering your message; keeping a record sufficient to show that a request or complaint was dealt with and within what period; delivering the pages of this website; and identifying and resisting abuse directed at the service.

8.3 Disclosure occurs only in the circumstances set out in the following table. The table is exhaustive.

Every circumstance in which personal information leaves our control
RecipientInformationBasis
The provider carrying our emailCorrespondence data, necessarily, because it transports and stores the messageService provider performing a function on our behalf
The content delivery network and host serving this websiteLog data, generated by that infrastructure and held on its cycleService provider performing a function on our behalf
A regulator, court or law enforcement agencyOnly what a valid instrument compels, and no moreRequired or authorised under an Australian law
A professional adviser under obligations of confidenceOnly what a specific matter requiresReasonably expected secondary purpose related to handling the matter

8.4 We do not sell personal information. We do not rent, licence, barter or otherwise supply it to any person for that person's own purposes. We participate in no advertising exchange, no data cooperative, no enrichment arrangement and no lead generation arrangement.

8.5 Where an instrument described in the third row of the table at clause 8.3 permits us to tell you that it was served, we will tell you. Where it prohibits that, we will not, and the prohibition rather than our preference is the reason.

Part 9Direct marketing and electronic messages

Australian Privacy Principle 7 — direct marketing; Spam Act 2003 (Cth)

9.1 We conduct no direct marketing. There is no mailing list, no newsletter, no announcement list and no waiting list. Writing to us adds you to nothing, and there is nothing to be added to.

9.2 An address that reaches us in correspondence is used to answer that correspondence. It is not used to send you anything you did not ask for, and it is not disclosed to another party for that party to market to you.

9.3 If an announcement list is ever created, three conditions bind us in advance. Subscription will require a positive act by you, so that consent is express rather than inferred from silence or from having once written to us. Every message will identify the sender and give a functional unsubscribe facility, as the Spam Act 2003 (Cth) requires. An unsubscribe instruction will take effect within five business days and will not be met with a request to explain the decision.

9.4 Nothing published by us is a commercial electronic message soliciting an investment, a subscription or a token allocation, because we offer no such thing.

Part 10Overseas disclosure

Australian Privacy Principle 8 — cross-border disclosure; Act, s 16C

10.1 We do not transfer personal information overseas for any commercial purpose of our own. We operate in no other market, have no overseas establishment, and send nothing abroad for processing, enrichment or analysis.

10.2 Two arrangements nevertheless involve infrastructure that may sit outside Australia, and Australian Privacy Principle 8 requires that they be disclosed.

  • Mail transport and storage. Correspondence data passes through and rests on the systems of the provider carrying our email. Mail infrastructure is ordinarily distributed across several countries, and a message may transit or rest outside Australia.
  • Page delivery. This website is served through a content delivery network with points of presence in many countries. Log data is generated at the point of presence that answers the request, which for a reader outside Australia will ordinarily be outside Australia.

10.3 A third movement is not a disclosure by us and is described here so that the record is complete. Where your browser requests the three type families this site uses, it contacts Google's font hosts directly and supplies its own address and user agent to them. That request is made by your browser under its own configuration; we neither receive nor observe it. Part 22 and the cookie notice set out how to prevent it.

10.4 We do not publish the identity of the providers referred to in clause 10.2 on this page, because naming a vendor that we may change is a commitment about our supply chain rather than about your information. We will identify either provider by name to a person who asks at the address in Part 25.

10.5 Under section 16C of the Act, an act of an overseas recipient that would breach the APPs had we done it ourselves remains our responsibility. We do not contract out of that, and no provision of this instrument should be read as attempting to.

10.6 Public ledger data is not disclosed by us to anyone, overseas or otherwise, for a reason given in Part 18: it is already published to the world by the chain itself, and we are a reader of it rather than a source.

Part 11Government related identifiers

Australian Privacy Principle 9 — adoption, use or disclosure of government related identifiers

11.1 We adopt no government related identifier as our own identifier of any individual. We hold no tax file number, no Medicare number, no driver licence number, no passport number and no Centrelink reference belonging to a reader or a correspondent.

11.2 The identifiers that appear across this website — an Australian Company Number and an Australian Business Number — identify the company itself and not any individual. They are published so that a reader can confirm who is behind the site from a public register rather than taking our word for it.

11.3 If a correspondent volunteers a government related identifier, it is handled under Part 6 as unsolicited information and is destroyed unless retaining it is required by law.

Part 12Quality of personal information

Australian Privacy Principle 10 — quality of personal information

12.1 Australian Privacy Principle 10 calls for reasonable steps to keep personal information accurate, current and complete, judged against the purpose it is held for.

12.2 Our holdings are almost entirely a record of what a person actually wrote. A message is accurate as a record for so long as it is not altered, so the quality measure that matters here is integrity: correspondence is retained as received, and we do not edit the substance of a message we hold.

12.3 Where information we hold is inaccurate because circumstances have changed — an address is no longer in use, or a fact stated in an earlier message has been superseded — Part 16 gives you the means to have the record corrected, and clause 16.4 governs annotation where correction by amendment is not appropriate.

12.4 We form no derived attribute about you. There is no profile, no score, no segment and no inferred characteristic in our holdings, so there is no derived attribute capable of being wrong about you. Part 19 states the prohibition in terms.

Part 13Security of personal information

Australian Privacy Principle 11.1 — security of personal information

13.1 We take steps reasonable in the circumstances to keep personal information safe: safe from misuse, from interference and from loss, and safe from access, modification or disclosure by anyone holding no authority for it. The circumstances here are those of a company that keeps a mailbox and serves static pages, and the measures are listed below without embellishment.

  • The mailbox is protected by multi-factor authentication, and account recovery routes are configured against the same factor.
  • The website is served over TLS, with HTTP Strict Transport Security asserted, so a browser refuses an unencrypted connection after its first visit.
  • A Content Security Policy restricts the origins from which the page may load resources, and forbids the page from being framed by another site.
  • Access to correspondence is limited to the persons who run the company. There is no support desk, no outsourced inbox and no contractor with a mailbox credential.
  • Every page on this site is static. There is no application server, no database and no administrative console exposed to the internet, which removes the categories of failure that most commonly expose correspondence.

13.2 The measures listed in clause 13.1 are reviewed whenever the way this site is served or this mailbox is operated changes, and this Part is amended under Part 25 to match. A measure appears in that list only once it is actually in force.

13.3 The strongest protection here is the smallness of the holding. There is no key material, no payment data and no identity document to lose, because Part 5 prevents any of it from being collected in the first place.

13.4 A suspected vulnerability in this website should be reported to [email protected] with "Security" in the subject line. A report is answered on the same or the next business day. We will not threaten legal action against a person who reports a defect in good faith and does not exfiltrate data belonging to another person.

Part 14Retention and destruction

Australian Privacy Principle 11.2 — destruction or de-identification

14.1 Once personal information is no longer needed for a purpose set out in Part 8, we erase it or strip out whatever identifies a person — unless it forms part of a Commonwealth record, or an Australian law or a court order requires that it be kept. The retention periods we apply are these.

Retention periods, and the reason each period is what it is
HoldingPeriodReason for the period
Ordinary correspondence24 monthsLong enough that a thread resumed months later still makes sense, short enough that a mailbox does not become an archive of everyone who ever asked a question
Complaint files7 yearsMatches the general limitation period applying in New South Wales, so the file survives as long as a claim about its subject matter could
Access, correction and deletion requests7 yearsProof that a statutory request was answered, and of the period within which it was answered
Impersonation and security reports7 yearsImpersonation recurs in patterns, and an old report is frequently what identifies a new one
Accounting and taxation records7 yearsRequired of an Australian company by taxation and corporations legislation
Log dataUnder 30 daysThe provider's own cycle. Sufficient to investigate an attack, too short to become a record of who reads what
Backups of the aboveOverwritten on rotation, complete within 35 daysA deleted record is not restored from a backup in order to bring it back into use

14.2 Destruction of correspondence means deletion from the live mailbox at the end of the applicable period. A copy persisting in a backup is not returned to use and is overwritten within the period stated in the final row of the table at clause 14.1.

14.3 Public ledger data is outside this Part. We cannot destroy a record on a chain, nobody can, and our copy of a public record is not a holding of personal information for the reasons given in Part 18.

Part 15Access to personal information

Australian Privacy Principle 12 — access to personal information

15.1 You may require us to show you what personal information about you we hold. Ask by writing to [email protected], putting "Privacy request" in the subject. No form is prescribed and no particular wording is needed.

15.2 We respond within 30 days of receiving the request. Any step we take to satisfy ourselves that the request comes from the person it concerns happens inside that period and does not extend it.

15.3 Access is given in a form that is useful. In practice that means the correspondence itself, supplied as text or as an export of the thread, and a statement of what else is held about you if anything is.

15.4 No charge is made for a request or for the response to it. We do not levy an access fee, an administration fee or a fee for a second request.

15.5 Verification is limited to what is proportionate. We will not ask for an identity document, a photograph of a licence, a signature from a wallet, a screenshot of a holding, or a statutory declaration. Where the only holding is correspondence, the address a message came from is the meaningful key, and requiring more would collect more personal information than the request itself concerns.

15.6 Where access is refused in reliance on a ground in Australian Privacy Principle 12.3, the refusal is given in writing, identifies the ground relied on, explains why it applies to the request, and sets out how to complain about the refusal under Part 23.

Part 16Correction of personal information

Australian Privacy Principle 13 — correction of personal information

16.1 You may require correction of any personal information about you that we hold, where — measured against the purpose it is held for — it is inaccurate, out of date, incomplete, irrelevant or misleading.

16.2 A correction request is made in the same way as an access request and is answered within the same period of 30 days. Tell us what the record says and what it should say instead; nothing further is required.

16.3 Where we have disclosed the information to another person before correcting it, and you ask us to notify that person of the correction, we will do so unless it is impracticable or unlawful. Given the disclosures listed at clause 8.3, this will rarely arise.

16.4 Correction of correspondence has a limit worth stating. We will not rewrite the text of a message that was actually sent, because the record of what was written is the thing being kept. Where the content of a message is disputed, we associate a statement of your position with the record, so that the record cannot be read without the correction being apparent, which is the mechanism Australian Privacy Principle 13.4 contemplates.

16.5 A refusal to correct is given in writing with reasons, identifies the ground relied on, and explains the complaint route in Part 23.

Part 17Deletion of data on request

Australian Privacy Principle 11.2, read with Part 14 of this instrument

17.1 You may ask us to delete your data at any time and without giving a reason. Write to [email protected], putting "Delete my data" in the subject, and send it where you can from the address whose correspondence is at issue.

17.2 A deletion request is completed within 30 days of receipt. We confirm in writing what was deleted and identify anything retained, together with the provision requiring its retention.

17.3 There is no account to close, because no account exists. Deletion of data therefore means deletion of correspondence and of anything derived from it, which is the entirety of what we hold that is connected to you.

Effect of a deletion request on each holding
HoldingOn requestWhy
Ordinary correspondenceDeleted within 30 daysNothing requires it to be kept once you have asked
Complaint and privacy request filesRetained for the balance of 7 yearsEvidence that a statutory request or complaint was handled; deleting it would destroy the proof that your own rights were honoured
Accounting and taxation recordsRetained for the balance of 7 yearsRetention required by Australian taxation and corporations law
Log dataExpires on the provider cycle, under 30 daysNot indexed by identity and not searchable by reference to a person, so it cannot be located to be deleted individually
BackupsOverwritten on rotation within 35 daysA backup is not searched to remove a single record, and a deleted record is never restored into use
Public ledger dataOutside our powerNo entity can delete a finalised block, and our reading of a public record is not a holding about you

17.4 Where a holding is retained under the second or third row of the table at clause 17.3, it is quarantined from ordinary use: it is kept as evidence and is not consulted for any other purpose.

Part 18Public ledger data and identifiability

Act, s 6(1) — "personal information"; Australian Privacy Principle 3

18.1 This Part is the reason this instrument is longer than the size of our holdings would suggest. A company reading chains has to be precise about when a public record becomes information about a person.

18.2 The statutory test is whether an individual is identified, or is reasonably identifiable, from the information. Whether a blockchain address satisfies that test is a question of fact that depends on what else is available, and it is capable of being answered differently on different days.

18.3 Our position is stated as three propositions.

  • An address standing alone is a string. In our hands it is not associated with a name, a mailbox, a device or a document, and no individual is reasonably identifiable from it.
  • An address stops being merely a string once somebody joins it to identifying material. The joining is what creates personal information, and the joining is the step we decline to take.
  • Where we do come to hold a link between an address and an individual, because a correspondent volunteered one in a message, that link is personal information in our hands, is held under Part 6, and is subject to every Part of this instrument including Part 17.

18.4 Consequently we do not maintain, purchase, licence, build or consult an attribution dataset mapping addresses to persons; we do not cluster addresses for the purpose of inferring a common owner and then labelling that owner; and we do not publish an assertion that a particular address belongs to a particular person.

18.5 Reading a public chain is not a collection of personal information from you, and no notice under Part 7 is owed for it. What follows from that is a duty of restraint about what is then done with the reading, and Part 19 sets out where that restraint binds.

Part 19Processing this company does not carry out

Australian Privacy Principle 6, read with Part 18 of this instrument

19.1 The prohibitions in this Part are undertakings. They describe processing we will not perform, and a departure from any of them would require an amendment published under Part 25 before the processing began.

  • No risk scoring. We assign no risk score, trust score, reputation grade or sanctions likelihood to an address or to a person, and we publish no list of addresses characterised as suspicious.
  • No de-anonymisation. We do not attempt to resolve an address to a legal identity, and we do not combine our reading of a chain with an off-chain dataset for the purpose of doing so.
  • No automated decisions. No decision producing a legal effect or a similarly significant effect on any individual is made by us, whether automatically or otherwise. We decide nothing about you, because there is nothing here to decide.
  • No surveillance product. We will not build a monitoring or alerting product on behalf of a party seeking to observe a named individual's activity.
  • No tracking of readers. This website runs no analytics, sets no advertising identifier, and makes no attempt to recognise a returning reader.

19.2 The four commercial prohibitions published on the home page — no custody, no advice, no exchange, no token — have privacy consequences that belong in this instrument. A company holding no assets needs no key material. A company operating no exchange needs no identity verification file. A company issuing no token needs no allocation register. The categories of personal information that would ordinarily dominate a policy in this sector are absent here because the activities that generate them are absent.

19.3 We will never ask you to connect a wallet, sign a message, approve an allowance, disclose a seed phrase or send funds anywhere. Any communication bearing our name that asks for one of those things did not come from us. Report it to [email protected] with "Impersonation" in the subject line.

Part 20Children and young persons

Act, s 6(1); OAIC guidance on capacity and consent

20.1 This website is not directed at children. Its subject matter is the regulatory position of a company that reads blockchains, there is nothing here to buy, and nothing on it is designed to attract a child's attention.

20.2 Personal information is not knowingly collected here from a child. We operate no age gate, because an age gate would mean taking a date of birth from every reader, gathering more personal information about more people than the practice it is meant to guard against.

20.3 The Act sets no fixed age at which an individual can consent for themselves. Capacity is assessed individually, and the Commissioner's guidance treats a person aged 15 or over as ordinarily having capacity where an individual assessment is not practicable. We apply that approach if the question ever arises.

20.4 Where we become aware that we hold personal information about a child, and there is no lawful basis for continuing to hold it, we delete it without waiting for a request. A parent or guardian may write to [email protected] and we will act on that message within the period stated in clause 17.2.

20.5 Nothing published by us is a financial promotion, and no view will be marketed to a young person as a means of making money. This matters more in this sector than in most.

Part 21Eligible data breaches

Act, Part IIIC — the Notifiable Data Breaches scheme

21.1 The Notifiable Data Breaches scheme in Part IIIC of the Act applies to us. A breach is an eligible one where personal information in our holdings is accessed or disclosed without authority, or is lost, and a reasonable person would conclude that serious harm to an affected individual is a likely consequence.

21.2 Where grounds arise to suspect an eligible data breach, the assessment the scheme requires begins that day. It is conducted reasonably and expeditiously, and it finishes no later than the thirtieth day after those grounds first came to our attention.

21.3 Where the assessment concludes that an eligible data breach has occurred, we prepare a statement and give it to the Commissioner as soon as practicable, and we notify each affected individual, or each individual at risk of serious harm, by writing to the address we hold for them. The statement identifies us, describes what happened, says which kinds of information were caught up in it, and recommends what an affected individual should now do.

21.4 Where notifying an individual directly is not practicable, the statement goes up on this website, and we take reasonable steps to put it in front of the people at risk.

21.5 Remedial action taken before serious harm is likely may mean no notification is required. We will not treat that provision as a reason to delay an assessment, and we will not characterise a breach as remediated in order to avoid notifying it.

21.6 A breach affecting correspondence data would expose what people wrote to us. That is not trivial, and it is the reason the retention periods in Part 14 are short rather than indefinite.

Part 22Device storage and log data

Australian Privacy Principle 3 and Australian Privacy Principle 5

22.1 No cookie is written by this website. Nothing here stores an identifier in your browser for the purpose of recognising you, and no consent banner is displayed because there is no non-essential storage to consent to.

22.2 Three things nevertheless cross the boundary of the page, and each is itemised in the cookie notice, which forms part of the disclosure required by Australian Privacy Principle 5.

  • A strictly necessary security cookie that the content delivery network may set where it presents a challenge, so that a reader who passes the challenge is not challenged again immediately.
  • A request your browser makes to Google's font hosts for the three type families this site uses, as described in clause 10.3.
  • Log data, defined in clause 1.4 and retained for the period in the table at clause 14.1.

22.3 Australia runs no separate statutory consent regime for cookies. The Act is what applies: anything a cookie or a comparable technology records about an identified or reasonably identifiable individual is personal information, so Australian Privacy Principle 3 governs whether it may be collected at all, and Australian Privacy Principle 6 governs its use afterwards.

22.4 If analytics or advertising is ever introduced to this website, consent will be sought before the technology loads, declining will be as easy as accepting, declining will not degrade the site, and the cookie notice will be amended before the change takes effect rather than after a reader notices it.

Part 23Complaints and external review

Act, s 36 — complaints to the Commissioner

23.1 A complaint that we have interfered with your privacy is made by writing to [email protected], placing "Privacy complaint" at the front of the subject. Set out the events and the outcome sought; no particular form is required.

23.2 Receipt is acknowledged within 5 business days. Our determination follows within 30 days of receipt, and states what we found, what we did about it, and what we will do differently if anything.

23.3 An escalation route inside the company would be fiction at this size, and we do not offer one. The persons who answer the complaint are the persons who run the company, and the meaningful escalation is external.

23.4 If our answer does not satisfy you, or none arrives, the matter may be taken to the Commissioner.

Office
Office of the Australian Information Commissioner
Postal
GPO Box 5218, Sydney NSW 2001
Telephone
1300 363 992
Online
oaic.gov.au

23.5 Two practical points about that route. Nothing is charged to lodge, and nobody needs a lawyer to do it; the Commissioner accepts complaints directly from individuals. And the Commissioner ordinarily requires that the complaint first be put to the entity complained about, with 30 days allowed for an answer, before taking it up — though that requirement can be dispensed with where the circumstances warrant it.

23.6 Two other regulators may be relevant, depending on the subject matter. Conduct said to be misleading may be reported to the Australian Competition and Consumer Commission at accc.gov.au. Conduct said to cross a financial services boundary may be reported to the Australian Securities and Investments Commission at asic.gov.au. Neither requires our agreement, and we would rather a concern were raised than assumed to be someone else's problem.

Part 24Persons outside Australia

Act, s 5B — extraterritorial operation

24.1 This instrument is drafted to the Act and the APPs. That is the regime we are subject to, and stating it plainly is more useful than claiming a compliance posture under laws we are not equipped to answer to.

24.2 Where a reader is located in a jurisdiction whose own law confers rights on them in respect of information held by us, we will answer a request from that reader on the footing described in Parts 15 to 17. In practical terms the outcome is much the same: you may see what we hold, have it corrected, and have it deleted, without charge and within 30 days.

24.3 We do not offer goods or services to individuals in any other jurisdiction, we do not monitor behaviour anywhere, and we do not maintain a representative outside Australia. We make no claim to a European adequacy mechanism, to a standard contractual clause arrangement, or to registration with any overseas supervisory authority.

24.4 A person outside Australia may complain under Part 23 on the same terms as a person within it.

Part 25Amendment, versioning and notices

Australian Privacy Principle 1.3 — keeping the policy current

25.1 This instrument carries a version number and an effective date, both shown beneath the title. A change of substance increments the version number; a correction of a typographical error does not.

25.2 Where an amendment cuts back a right this instrument gives you, or broadens what we collect, this page carries a notice saying so, and that notice runs for thirty days or more before the amendment begins to operate. An amendment operates prospectively; it does not retrospectively authorise a use of information already collected.

25.3 The publication of a new version is the notice. We do not hold a mailing list capable of announcing one, for the reason given in Part 9.

25.4 The address for every matter arising under this instrument is below. It is the only channel we operate; we run no telephone line, no social account and no messaging channel, and any of those bearing our name belongs to somebody else.

Entity
AI WEB3 SERVICES PTY LTD
ACN
696 596 406
ABN
43 696 596 406
Jurisdiction
New South Wales, Australia
Email
[email protected]
Access or correction
Subject line "Privacy request", answered within 30 days under Parts 15 and 16
Deletion
Subject line "Delete my data", completed within 30 days under Part 17
Complaint
Subject line "Privacy complaint", acknowledged within 5 business days and determined within 30 days under Part 23
Service of documents
Effected at the registered office recorded against ACN 696 596 406 in the company register ASIC keeps. No second address is published here, because a second address would not carry that effect

Standing position

The entire holding of personal information behind this instrument is a mailbox and a short-lived server log. It is written for the company that exists rather than for the one it might become, and Part 25 governs what happens when that changes.