Overview
We at Trellis Data are passionate about keeping your information safe and respecting your ownership of it. This privacy policy explains how we collect, use, store and protect the data you share with us in line with the Australian Privacy Principles (APPs) and, where applicable, the EU GDPR.
We are committed to protecting your privacy. We provide this privacy policy under the Privacy Act 1988 (Cth) to provide you with details about our practices in relation to the collection, use, disclosure and handling of Personal Information.
1. Privacy Policy
This Privacy Policy is governed by the Australian Privacy Principles under the Privacy Act 1988 (Cth) and where we obtain Personal Information from a citizen of a member state of the European Union, the EU General Data Protection Regulation (Regulation (EU) 2016/679).
2. Collection of Personal Information
We collect Personal Information when you:
- (a) subscribe to our mailing list;
- (b) enter our competitions or promotions; or
- (c) apply for positions with us, or when you act as a contractor for us.
For your AI-powered platform we also collect:
- (a) User prompts you type into the system;
- (b) AI-generated responses returned to you;
- (c) Documents you upload to the platform; and
- (d) Documents and other outputs you create using our tools.
These items are treated as Customer Data and are covered by the same protections outlined below.
We collect Personal Information to:
- (a) improve our products and services;
- (b) deliver the AI product and/or service you have subscribed to or otherwise consume;
- (c) communicate with you;
- (d) offer you promotional product or market our product that you are interested in;
- (e) keep a record of your order for refund or exchange;
- (f) maintain our customer database;
- (g) investigate complaints or potential breaches of our terms;
- (h) verify your identity;
- (i) comply with the law; and
- (l) any other purposes that are reasonably related to the above.
We collect and hold the following types of Personal Information:
- (a) Contact details (name, business name, phone number, address, email)
- (b) Optional demographic information that you consent to provide (including interests, gender, age); and
- (c) Survey responses that you submit voluntarily.
We will only collect your Personal Information using fair and lawful means.
We do not collect an individual's payment information for any reason.
If we receive unsolicited Personal Information, we may destroy it or ensure that it is de-identified if it is lawful and reasonable to do so.
3. Consent, Withdrawal, and Right to Erasure
Providing your Personal Information is required to deliver the goods and services you request.
You may withdraw consent or request erasure at any time by contacting us.
- (a) Withdrawal of consent limits further processing but does not delete existing data until the request is acted on.
- (b) A request for erasure (the "Right to be Forgotten") will be honoured when any of the following conditions are met:
- (i) the Personal Information provided is no longer necessary in relation to the purpose of collection;
- (ii) you have withdrawn your consent for us to hold your Personal Information;
- (iii) the legal retention period for holding your Personal Information has expired;
- (iv) you object to the use of your Personal Information; or
- (v) the processing of your Personal Information was not in accordance with the EU GDPR.
We will mark the relevant records as "restricted" while your request is being processed and will complete the action as soon as practicable.
4. Not Used
6. Security
All Customer Data – including prompts, AI responses, uploaded and generated documents – is encrypted at rest and in transit with US Defence-Grade (AES-256 GCM) encryption leveraging cryptographic modules at the level of FIPS 140-3.
Our infrastructure is hosted solely in Australia, giving the data Australian sovereign control and ensuring it is subject to Australian privacy and data-governance laws.
We employ firewalls, antivirus, intrusion-detection, regular security-audit hardening and continuous monitoring to safeguard the confidentiality, integrity and availability of your information.
7. Anonymity and Pseudonymity
You may interact anonymously or by using a pseudonym, for example when you:
- (a) call us;
- (b) use our online forms;
- (c) email us,
and you may refuse to give your details.
You must provide your Personal Information when you:
- (a) sign up for a mailing list;
- (b) lodge a complaint; and
- (c) are required to provide Personal Information under the law.
8. Disclosure of Personal Information
We only disclose Personal Information where the purpose is reasonably related to our business.
We never sell, licence or otherwise commercialise any Customer Data (refer to section 15 for more details).
We may share Personal Information with third-party service providers (e.g. cloud hosting, backup, monitoring) solely to operate the platform. These providers are bound by contracts that reflect the APPs and GDPR.
We may also disclose your Personal Information:
- (a) to provide the service you have requested;
- (b) comply with legal obligations or protect our legal rights; or
- (c) with your explicit consent.
Any overseas disclosure is subject to comparable privacy safeguards.
9. Retention of Personal Information and Customer Data
Personal Information held by us is retained until:
- (a) such time as we deem this Personal Information to no longer be active, timely or correct (Inactive Personal Information); or
- (b) you withdraw your consent to us holding your Personal Information.
Personal Information held by us may undergo review to ascertain whether Personal Information can be classified as Inactive Personal Information. This type of review will take place from time to time, at our reasonable discretion.
Inactive Personal Information is then deleted after it is no longer required/necessary to be held. Personal Information that is relevant to a pending complaint or breach investigation shall not be deleted until the matter is resolved, but will be deleted as soon as practical after resolution of any outstanding matters.
Other types of information (i.e. order number, order date etc) relating to a transaction with us is kept for the statutory required period of time for record keeping.
Your Customer Data remains with us as long as you hold an active subscription, contract or other pre-agreed arrangement with us. Refer to clause 15 for additional information.
When you request deletion of Customer Data, we permanently erase the data from our live systems and do not retain backup copies.
Inactive or obsolete Customer Data that is no longer required for any purpose is removed in accordance with your instructions or the statutory retention periods for transaction records.
10. Direct Marketing to You
We will not send you unsolicited commercial electronic messages in contravention of the Spam Act 2003 (Cth).
We may use the non-sensitive information you gave us for the purpose of promoting and marketing our products and services to you if we:
- (a) use the information that you reasonably expected us to use for promoting and marketing our products and services to you; and
- (b) provide you a simple method to opt-out.
We will not contact you to promote or market our products and services if you requested us not to.
11. Accessing and Correcting Your Personal Information
Accessing Your Personal Information
You may request access to your Personal Information that we hold and we will:
- (a) verify your identity;
- (b) may charge a reasonable fee to cover the direct costs of providing access, in accordance with the APP. No fee will be charged for the request itself; and
- (c) within a reasonable period of time, comply with your request.
We may refuse to allow you to access your Personal Information if we are not required to do so under the Australian Privacy Principles.
Correcting Your Information
You may request to correct your Personal Information that we hold and we will update your Personal Information so that it is up-to-date, accurate, complete, relevant and not misleading.
Members of our Website may change their details online.
How to Contact Us
If you would like to access or correct your Personal Information, please contact us by email: [email protected]
12. Complaints
If you believe we breached the Australian Privacy Principles under the Privacy Act 1988 (Cth) or a registered Australian Privacy Principles Code, or the EU GDPR you may lodge a complaint as follows:
- (a) firstly, contact us in writing to the email or postal address in clause 11.5 and include the following in your complaint:
- (i) your contact details;
- (ii) section or provision of the Australian Privacy Principles or Code or EU GDPR that you believe we breached; and
- (iii) our practice or policy that you believe breaches the relevant Australian Privacy Principle or Code,
- (b) and you must allow us a reasonable time (up to 30 days) to reply to your complaint; and
- (c) secondly, you may complain to the Office of the Australian Information Commissioner if:
- (i) you are not satisfied with our response; or
- (ii) we do not respond to you within a reasonable time without sufficient explanation.
13. Personal Information Breach
In the unlikely event of a breach of privacy:
- (a) we employ practices to notify the relevant bodies under the Privacy Act 1988 (Cth) and the EU GDPR within the required timeframes.
- (b) We will notify you as soon as practicable (no later than 30 days) if the breach is likely to result in serious harm to you.
14. Definitions and Interpretation
Unless contrary intention appears:
- (a) Australian Privacy Principles means the principles under Schedule 1 of the Privacy Act 1988 (Cth).
- (b) Customer Data is a subset of Personal Information specific to the AI platform. It is defined in detail in section 2.2.
- (c) Personal Information means personal information as defined under Privacy Act 1988 (Cth).
- (d) Sensitive Information means sensitive information as defined under Privacy Act 1988 (Cth).
- (e) We (whether in capitals or not) means Trellis Data Pty Ltd.
- (f) Website means any current or future websites we create, which may be amended from time to time.
- (g) You (whether in capitals or not) means the user of our Website and Products, and Your and Yours have corresponding meanings.
The word 'include' is used without any limitation.
15. Key AI-Specific Guarantees
No Use of Customer Data for AI Training – We never use any Customer Data (prompts, responses, uploaded or generated documents) to train, improve or fine-tune our underlying AI models. When using our Internal Protected Models, you can be assured your data will not be added to a future AI model.
No Human Viewing of Customer Data – Our staff do not view, access, copy, or otherwise act upon your data unless you explicitly request assistance (e.g., support tickets). In such cases, access is logged, limited in scope and performed under strict confidentiality.
Data Ownership – All Customer Data remains your property. We act only as a processor on your behalf, following your instructions regarding storage, retention and deletion.
No Backups Retained After Deletion – When you delete data, both the primary store and any temporary backup copies are permanently removed as soon as practical (usually within 24 hours).
Sovereign Australian Hosting – All AI services and Customer Data are hosted on Australia-based data centres that comply with Australian Government-Level security standards.