Public document

Privacy Policy

How Bots & Pieces collects, uses, stores and protects personal information, what we do and do not put into AI services, and how to get at what we hold about you.

Document
BP-PRI-001
Version
1.0
Effective
1 September 2026
Next review
1 September 2027
Contents

1. Who this policy applies to

Bots & Pieces is the business name of Jacob Roberts, a sole trader with ABN 18 813 409 919. In this policy, “we”, “us” and “our” mean that business.

This policy applies to everyone we hold personal information about. That includes people who contact us through this website, clients and their staff, people who attend our training, people who use a system we have built, suppliers and job applicants.

It applies to information we hold in our own systems. Where we work inside a client’s own systems as their service provider, that client controls the information and their own privacy policy governs it.

2. Our position under the Privacy Act

Most Australian businesses with an annual turnover of $3 million or less are not automatically covered by the Privacy Act 1988. We are currently under that threshold. There are exceptions, and a business under the threshold can still be covered, for example if it trades in personal information or provides a service under a Commonwealth contract.

We have chosen to follow the Australian Privacy Principles as our working standard regardless of whether we are legally required to. We assess coverage again whenever our services, turnover or client types change, and we treat any client contract that imposes privacy obligations on us as binding.

3. What personal information we collect

CategoryWhat it includes
Contact detailsName, business name, role, email address, phone number and the postal address you give us.
Enquiry contentWhat you write in a website enquiry, an email, a text message or a support request, and our notes of calls and meetings about it.
Client and billing recordsSigned agreements, statements of work, quotes, invoices, payment records and correspondence.
Support and technical dataAccount names, system logs, error messages, screenshots, configuration details and other information needed to diagnose and fix a fault.
Training recordsAttendance, the organisation you attended for, and any feedback you choose to give.
Website technical dataInformation your browser sends when you visit the site, such as approximate location, browser type and the pages you viewed.
Client-supplied informationInformation a client chooses to give us, and is authorised to give us, so that we can build, test or support a system for them.

We do not ask for sensitive information such as health, racial or ethnic origin, political or religious views, or criminal record. We do not ask for government identity documents, full payment card numbers, passwords or multi-factor authentication codes. If you send us any of these without being asked, we will delete them and tell you we have done so.

4. How we collect it

  • Directly from you, when you complete the enquiry form on this website, email us, call us, message us, meet with us or attend our training.
  • From your employer or the client who engaged us, where you are one of their staff and we need to work with you.
  • From the systems we are engaged to build, test or support, where the work genuinely requires it and the client has authorised it.
  • From publicly available sources, such as a company website or a professional networking profile, when researching a prospective client.

Where it is reasonable and practical, we collect personal information directly from the person it is about. Where we collect it from somebody else, we take reasonable steps to make sure that person is told.

5. Why we collect and use it

  • To answer your enquiry and work out whether we can help.
  • To prepare quotes, agreements and statements of work.
  • To deliver the services we have been engaged to deliver, including builds, training and ongoing support.
  • To administer accounts, issue invoices and collect payment.
  • To keep our own systems and our clients’ systems secure, and to investigate faults and security incidents.
  • To meet our legal, tax, insurance and record-keeping obligations.
  • To improve our services and our written material.
  • To send you information about our services where you have agreed to receive it, or where you would reasonably expect it because you are an existing client.

We do not sell personal information. We do not share it with anybody for their own marketing.

6. This website

Our enquiry form asks for your name, your business name and your email address, and asks which service you are interested in. Only the name and email address are needed for us to reply. We use what you send to answer your enquiry and to follow it up.

This website and its hosting provider record standard technical information about visits, such as the pages requested and the browser used. This is used to keep the site working and secure and to understand which pages are useful. We do not use it to build a profile of you as an individual.

This website may set small files called cookies in your browser to make the site work properly and to remember your display preferences. You can block or delete cookies in your browser settings, though some parts of the site may then not work as intended.

7. Artificial intelligence and automated processing

Artificial intelligence is central to what we build, so we are specific about how it touches personal information.

  • We use AI services only where they are reasonably necessary for the work and where their use has been approved for that engagement.
  • We tell clients which material third-party AI providers will be used with their information before we connect it, and we record that approval in writing.
  • We do not knowingly put personal or confidential information into a general consumer AI service that has not been approved for the engagement.
  • We do not allow personal or confidential client information to be used to train a provider’s general model unless the client has expressly approved that in writing. Our default position is that it must not be.
  • We do not use AI to make a decision that has a legal or similarly significant effect on a person without a human reviewing it first.

From 10 December 2026, Australian privacy law expands what a covered organisation must disclose about computer programs that substantially and directly make decisions affecting a person’s rights or interests. We do not operate any such program in our own business. If that changes, we will set out here what the program does, what information it uses and how a decision can be questioned.

8. Who we disclose information to

WhoWhy
Cloud, hosting and email providersTo store our files and run our email, website and business systems.
AI and software providersTo deliver the service, where the provider has been approved for that engagement.
Accounting and payment providersTo issue invoices, take payment and meet our tax obligations.
Professional advisers and insurersWhere we need legal, accounting or insurance advice, or need to make or defend a claim.
SubcontractorsWhere we engage somebody to help deliver an engagement. We name them to the client first and bind them to the same confidentiality and security obligations we carry.
Law enforcement and regulatorsWhere we are required or authorised by law to disclose the information.

We give a provider only what they reasonably need. We check a provider’s own terms for how they use, keep and locate information before we send them anything about you.

9. Storage outside Australia

Some of the providers we rely on store or process information outside Australia. Where a provider offers an Australian region and it is practical to use it, we use it. Where information for a specific client engagement will be processed overseas and that is material, we say so before the work starts and record it in the engagement documents.

10. How we keep it secure

Our written Information Security Policy sets the standard we work to and is available to clients on request. It requires:

  • Multi-factor authentication on email, cloud storage, banking, our domain registrar and our password manager.
  • A password manager, with a unique password for every account and no shared logins.
  • Encrypted devices with automatic updates, current security software and a screen lock.
  • Named accounts with the least access needed, and removal of access when an engagement ends.
  • Client information kept in business cloud storage, separated per client, and never in a personal consumer account.
  • Automatic backups of business-critical files, with a restore test scheduled each quarter.
  • A written incident and data breach process, set out in our Data Breach Response Plan.

These controls are reviewed against the evidence we keep, and the review dates are recorded in our compliance registers. Where a client needs to see the current position on a specific control before engaging us, we will tell them what it is rather than pointing at this list.

No system is completely secure. We cannot guarantee that information sent to us over the internet is safe in transit, and we ask that you never send us a password or a multi-factor authentication code.

11. How long we keep it

InformationHow long we keep it
Enquiries that do not become workUp to 24 months, then deleted.
Client agreements and statements of workAt least 7 years after the engagement ends.
Invoices, receipts and tax recordsAt least 5 years, as required by the Australian Taxation Office.
Working copies of client dataDeleted within 30 days after acceptance, unless the engagement or the law requires longer.
Support tickets and system logsUp to 24 months, unless needed for an open matter.
Incident and breach recordsAt least 7 years.
Training attendance recordsUp to 7 years.

When we no longer need personal information and no law requires us to keep it, we delete it or make it permanently unidentifiable.

12. Access and correction

You can ask us what personal information we hold about you and ask for a copy. You can ask us to correct anything that is wrong, out of date or incomplete. Email Jacob.Roberts@botsandpieces.com.au.

We will confirm we have received your request within 2 business days and aim to respond in full within 30 days. We may need to verify who you are before we release information. If we refuse a request, we will tell you why in writing and how to have that decision reviewed. We do not charge for making a request, though we may charge a reasonable cost for supplying a large volume of material.

13. Marketing and how to opt out

We only send marketing email or messages to people who have agreed to receive them, or who are existing clients and would reasonably expect them. Every marketing message identifies us and carries a working way to unsubscribe. We action an unsubscribe request within 5 working days, and usually straight away. You can also opt out at any time by emailing Jacob.Roberts@botsandpieces.com.au.

14. Complaints

If you think we have mishandled your personal information, email Jacob.Roberts@botsandpieces.com.au with enough detail for us to investigate. We will confirm receipt within 2 business days and aim to give you a written answer within 30 days.

If you are not satisfied with our answer, you can take the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

15. Changes to this policy

We update this policy when our services, our providers or our legal obligations change. The current version and its effective date are always published at botsandpieces.com.au/privacy.html. Where a change is significant, we will tell affected clients directly.

16. How to contact us

Bots & Pieces
Jacob Roberts, sole trader, ABN 18 813 409 919

Email Jacob.Roberts@botsandpieces.com.au
Phone 0416 591 313
Adelaide, South Australia

We do not publish a street address. If you need to send us something by post, email us first and we will give you a postal address.

See also our Collection Notice, which is the short notice given at the moment we collect your details, and our Website Terms of Use.