Legal
Privacy Policy.
What we collect, why we collect it, who else sees it, and how to get it back or get it deleted. Written from what our systems actually do — not from a template.
1. Our commitment
BIXSO is a small Australian company. Under the Privacy Act 1988 (Cth), businesses with an annual turnover of A$3 million or less are generally not covered by the Act. We are currently below that threshold.
We have chosen to handle your information according to the Australian Privacy Principles anyway, and this policy sets out how. We would rather hold one standard from the beginning than change the rules on you later. If our turnover crosses the threshold, the Act applies to us in full and this policy is already built for that.
2. What we collect
When you use the consulting service:
- Your name, email address, and your company name.
- Your market and preferred language.
- The content of your conversations with our AI — questions, answers and the analysis produced. This is stored so you can return to your work.
- Files you upload and the text extracted from them, so the AI can read them.
- What you tell us about your business: industry, offering, customers, revenue streams, workflows, pain points, systems and goals.
- If you ask us to arrange a conversation: your stated need and preferred time.
When you pay us: our payment provider handles your card. We keep your customer and subscription reference, your plan status, and a record of invoices and amounts. We never see or store your full card number.
When you visit the website: the marketing source you arrived from (campaign tags, the domain of the referring site, and the page you landed on). We deliberately do not keep the full referring address or its query string.
When you subscribe to updates: your email address, first name if given, and the page you subscribed from.
What we do not collect: our systems do not log your IP address or browser user-agent. Our business intake deliberately does not ask for personal identity details, budget, or buying authority. We do not seek health information, government identifiers, or payment details in conversation — please do not put them there.
3. Why we collect it
- To provide the service you asked for, and to let you return to your own work.
- To take payment and keep records we are required to keep for tax purposes.
- To follow up on a consultation — we send a small number of follow-up emails, and every one has a one-click unsubscribe.
- To improve the service. Where we use conversations to improve our systems, identifying details are removed first.
4. Automated decision-making
We use AI throughout the consulting service, so you should know where it makes decisions rather than just producing text. Our systems use the information you provide to:
- generate analysis, canvases and written recommendations;
- select which of our services suit your situation, and prepare an indicative price within limits approved in advance by a human;
- decide when a request must be escalated to a person rather than answered automatically.
A human makes the decisions that matter. Anything outside the approved limits, and every engagement involving human time or a build, is confirmed by a person before it is binding. You can ask for a human at any point — email us and we will take it out of the automated path.
From 10 December 2026, Australian privacy law introduces specific transparency duties for automated decision-making. This section is written to meet that standard now.
5. Who else sees your information
We keep the list short on purpose. We do not sell your personal information, and we do not disclose it to anyone in exchange for a benefit.
- Stripe — payment processing. Receives your name, email and payment details.
- Resend — email delivery. Receives your email address and the content of emails we send you.
- Google — website analytics and advertising measurement (Google Analytics and Google Ads tags). These see your browsing behaviour on our site, not your conversations or files.
- Google Cloud — hosting and AI processing of the service itself.
- The BIXSO expert network — only when you explicitly ask us to connect you with an expert. The brief we pass on has identifying details removed. Our system will not send it without your recorded consent.
We may also disclose information if the law requires it.
6. Where your information is stored
We run on Google Cloud. Different parts sit in different places, so here is the precise picture rather than a general statement:
- In Australia (Melbourne,
australia-southeast2): your account, your business profile, and the content of your conversations with our AI. This is the bulk of the personal information we hold. - In Singapore (
asia-southeast1): the files you upload, and the servers that run the service and process your requests. - Overseas, including the United States: our payment provider (Stripe), our email provider (Resend), and Google's analytics and advertising services.
So some of your information is handled outside Australia. We choose providers that offer contractual protections, and we tell you this plainly rather than burying it.
7. How long we keep it
We keep your account and conversation history while your account is open, so your work stays available to you. We keep financial records for seven years, as Australian tax law requires. If you close your account, we delete or de-identify the rest within a reasonable period.
8. Security
Access to customer records is restricted to the account owner and BIXSO administrators, enforced at the database level rather than only in the interface. Administrator actions are logged to an append-only audit trail. Payment card data never reaches our systems.
No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will tell you and the regulator.
9. Marketing emails
Every marketing email we send identifies Thanh Dao Pty Ltd and our ABN, and contains a one-click unsubscribe that does not require you to log in or give us more information. We act on unsubscribes within five business days, and normally immediately. Transactional messages — receipts, booking confirmations — are not marketing and continue while you have an account.
10. Cookies and tracking
We use Google Analytics and a Google Ads tag to understand how people find us and whether our advertising works. We store the marketing source of your visit in your browser's local storage. We do not use tracking to build a profile of you as an individual across other websites.
You can block these through your browser settings or Google's own opt-out tools. Blocking them does not affect your use of the service.
11. Access, correction and deletion
You can ask us to show you what we hold about you, correct anything wrong, or delete your information. Email admin@bixso.ai. We will respond within 30 days, and we do not charge for this.
Some information we must keep — financial records, for example — and we will tell you if that applies and why.
12. Complaints
If you think we have mishandled your information, email admin@bixso.ai with "Privacy complaint" in the subject line. We will acknowledge within 5 business days and give you a written answer within 30 days.
If you are not satisfied with our answer, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
13. Changes to this policy
If we change this policy in a way that materially affects you, we will tell you by email or in the product before the change takes effect. We keep the version number and effective date at the top so you can see which version applied when.
14. Contact
Thanh Dao Pty Ltd · ABN 50 622 303 539 · Melbourne, Australia · admin@bixso.ai