Privacy Policy.
What we collect on this site, why we collect it, who it goes to and how to stop it - in plain words. We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and client systems we build are hosted in Australia by default - if a component of one ever sends data offshore, we say so in writing to that client (section 16).
01Who we are
This site is operated by TwinMind (Sergii Diatchenko trading as TwinMind), ABN 83 665 668 690, based in Brisbane, Queensland, Australia. We build custom AI and automation systems for Australian businesses.
In this policy, "we", "us" and "our" mean TwinMind. "You" means anyone who visits twinmind.au, books a meeting with us, talks to our on-site assistant, or otherwise gives us their information.
We are the entity responsible for the personal information described here. Our contact details are in section 27. As a small business we could rely on the small-business exemption in the Privacy Act - we do not. We apply the Australian Privacy Principles to everything described on this page, and we will keep doing so if we grow past the threshold.
02What this policy covers
This policy covers the public website twinmind.au (including www.twinmind.au) and the tools we run on it - the booking widget, the AI assistant, and the chat, voice and video contact options.
It also covers our own subdomains where the same practices apply: crm.twinmind.au (the backend our booking and chat call), lab.twinmind.au, projects.twinmind.au, meet.twinmind.au and phone.twinmind.au. Those are password-protected or client-specific and are not open to the public.
A second is deliberately open: studio.twinmind.au, the interactive demo of our own working panel, described in our article and embedded in it. Anyone may open it, no sign-in. Everything on it — the projects, the tasks, the agent’s answers, the amounts — is invented; it holds no client data and no real work of ours, and it never contacts an AI model. It keeps no record of your visit: no log, no cookie, no database. Its one working input is the microphone, and only if you press it — see section 08. The copy embedded inside our article deliberately has the microphone switched off.
One is deliberately open: dashboard.twinmind.au, the demo dashboard described in our article. Anyone may read it, no sign-in. It shows four invented Australian businesses we generated ourselves — there is no real client’s accounting data on it, and nothing on that page can be changed by a visitor. Like this site, it keeps a short server-side record of visits; what that record holds, and for how long, is in section 11.
A third is deliberately open: solutions.twinmind.au, an interactive concept we built to show one prospective client how their own quoting process could work. Anyone with the link may open it, no sign-in. Every company, person, ABN, address and dollar figure on it is invented by us — it holds no client’s data of any kind. It has no form, no microphone and no account; nothing you do on it is sent anywhere, and it never contacts an AI model. Because it is served by the same site, the analytics described in section 03 — Google Analytics, Microsoft Clarity and our own page-view beacon — run there as they do on the rest of twinmind.au, and are kept for the periods in section 11.
It also covers the personal information we handle away from the website in the ordinary course of running the business - the emails and calls we exchange with you, the meetings we hold, and the records we keep of a project.
It does not cover systems we build and hand over to a client and run inside their environment - see section 16. It does not cover third-party sites we link to - see section 24.
This policy is one half of a pair. It answers "what happens to my information". What you agree to by using the site - what the AI assistant is and is not, what the demos show, how a booking and the paid audit work, and where our liability sits - is in our Terms of Use.
03What we collect
Information you give us
- Booking a meeting - your name and email address are required, because we need them to send you the invitation, and if you pick an on-site meeting a business address is required too so we know where to come. A phone number, your website and any notes are optional. When you type in the address field, what you type is sent (through our server, so the API key stays ours) to Google Places to suggest matching Australian addresses.
Once the slot is confirmed we start preparing for the meeting automatically, so that the time you gave us is not spent on questions we could have answered ourselves. Our own system rings our phones and reads the booking out to us, and the working details of it - your name, your website, the domain of your email address, the meeting format and any address or notes you entered - are sent to Anthropic (section 08), whose Claude models look your business up in public sources on the web and write an internal briefing for our team. Your email address and phone number are not sent, the briefing is written for us and never sent to you, and nothing about you is decided by software - a person prepares and holds the meeting.
The notes box also has a "Dictate" button. Press it and - once your browser has asked you for microphone permission - what you say is streamed straight from your browser to OpenAI in the United States, which turns it into the text that appears in the box. If that live path is unavailable, your browser instead records the whole clip and sends it to our own server, which has OpenAI transcribe it. Nothing is captured until you press the button, and you can always just type instead. Same rules as the assistant's microphone - section 06.
Once you press Confirm booking, our own systems alert us at once: a note in our private team channel, and an automated call to our own phones that reads out your name and the time you picked - nothing else, and never your notes. If you later cancel, or decline the calendar invitation, the same channel tells us and the time goes straight back on offer to someone else.
What you type into this form is also kept in your own browser as you go, so a closed popup does not lose your work - section 04. With one exception, none of it reaches us until you press Confirm booking: the address box is the exception, because fetching those suggestions means sending what you have typed to our server as you type it. So a form you start and abandon stays with you - unless you had begun typing an address. - Talking to the assistant - the text you type, any file or image you attach, and (only if you press the microphone and grant permission) the audio of what you say plus its transcript. See section 06.
- The homepage game - if you play it and claim the reward, the name and email you enter, so we can note the discount against you.
- Calling or emailing us - the content of your message, your email address or phone number, and any files you send. Email that arrives in our own mailboxes is sorted automatically: the message is summarised and categorised by OpenAI (the same provider named in section 08) so that a real letter reaches a founder quickly and a delivery failure retires the address. A person - never the software on its own - decides what is actually sent back to you.
- Becoming a client - the details needed to scope, quote, invoice and deliver the work: business name and ABN, billing contact, and whatever a specific project needs (agreed in writing, not collected through this website).
We never ask for, and you should never send us through this website, sensitive information as the Privacy Act defines it - health information, government identifiers such as a TFN or Medicare number, racial or ethnic origin, political or religious beliefs, sexual orientation, criminal record, or biometric data - and we do not ask for financial account credentials. If a project genuinely requires access to a client system, that is arranged separately under a written agreement, not through this site. If you send us sensitive information anyway, see section 21.
Information collected automatically
- Standard web-server records - IP address, date and time, the page requested, HTTP status, browser user-agent and referring page. These are ordinary server and CDN logs, kept for security and troubleshooting.
- Analytics - which pages you viewed, roughly how long, your approximate location (city/country level, derived from IP), device type, browser and screen size, and which buttons you clicked. We also count the moments that matter to us as a business - that a conversation with the assistant got going, that a call was requested or that we joined it and for how long, that a meeting was booked. Those are counts of what happened, never a record of what was said: no message text, no audio, and if you give us an email or phone number in the chat we count only that you gave us one, not the address itself. Google Analytics 4 does not log or store full IP addresses, and we set the IP-anonymisation flag on top of that.
If the link you arrived on carried personal details in its web address - for example an invitation we emailed you that already has your name and company in the link, so the booking form arrives pre-filled - those details are stripped out of the address before it is handed to the analytics tools. Google Analytics and Clarity receive the page you were on and the campaign tags, never your name, company, email address or phone number. The pre-filling still works, because your browser reads the original link directly. - Campaign attribution - if you arrive from a link that carries campaign parameters (
utm_source,utm_campaign,gclidand similar), we remember the first one for up to 90 days in your browser so we can tell which campaign led to an enquiry. If you go on to book a meeting, those campaign tags and the page you first landed on are sent to us together with the booking and kept with your contact record in our own CRM, so we know which ad, article or referral brought you to us instead of having to guess. What is stored is the campaign, not a profile of you or your browsing elsewhere, and no third-party ad network receives any of it. - Outreach link opens - if you arrive from an email or PDF we sent you, that link carries an opaque token identifying which message it was. We record that the link was opened so it appears on that contact's timeline in our own CRM. This is our own system - no third-party ad network is involved - and it is skipped for our internal team visits. Because it is a record of our own correspondence with you rather than third-party tracking, this one thing is not switched off by the Do Not Track / GPC signal (section 13); telling us to stop contacting you ends it.
- Our own click counters - alongside Google Analytics we keep a small first-party count of which page was opened and which button was pressed (for example "Book a call", the voice assistant, a project card). It is deliberately thin: the action, the page path with any query string removed, which of our own sites served that page (the host name itself, for example
twinmind.auorsolutions.twinmind.au- our address, not yours, so that a visit to one of our sites is never counted as a visit to another), a short label such as which Book button it was, the campaign tags, and how many seconds into the visit it happened. The same counter also records how long the page stayed open - a plain stopwatch that ticks at 30 seconds, at two minutes and once more as you leave, so that a page someone actually read can be told apart from one that was closed instantly. It is a number of seconds and nothing else: no scroll trail, no reading position, nothing about what is on your screen. Once per visit the counter also records that a person was here at all - the first time a pointer moves, a wheel turns, a key is pressed or the screen is touched, we store that single fact together with the name of the input that produced it (for example "pointermove"), and then stop listening for the rest of the visit. It is one yes: no coordinates, no keystroke values, no text. It exists because a mail-security scanner opening a link we emailed looks exactly like a reader if all you have is a stopwatch, and we would rather not treat a firewall as an interested customer. We also keep the site you arrived from - the host name on its own, for examplelinkedin.com, never the page you were on there, its web address or anything that address carried. It holds no cookie, no IP address and no browser fingerprint.
So that those clicks can be read as one visit rather than as loose numbers, each visit is given a random identifier which is kept in your browser's session storage (tm_sid, section 04). It is generated when you arrive, it is deleted when you close the tab, it is never sent to any third party, and it cannot link you to another visit, to another device, or to anything you do on other websites. It groups our own rows together; it does not identify you.
If you arrived by clicking one of our ads, the Google click identifier (gclid) from that ad's link is stored alongside those clicks as well - the same campaign tag described above - so we can see what the visit we paid for actually did, instead of guessing it from the city and device type. Like the other campaign tags it is remembered in your browser for up to 90 days, so on that browser it can ride along with later visits too.
If you arrived on a link from an email or PDF we sent you, that opaque token rides along with these counts as well, so the button press is attached to your contact record in our CRM the way the link open is - also for up to 90 days on that browser, not just for the one visit. If your browser sends Do Not Track or GPC, this counter is switched off entirely. These clicks are kept for up to 12 months. - Session context for the assistant - when you open a chat we note the city and country your IP resolves to, plus a short technical description of the device you are on: screen size, browser language and time zone, and the browser and operating system your request already reports. That is so whoever answers knows roughly who they are talking to. It is attached to the conversation, not to a profile of you.
04Cookies & local storage
We use a small number of cookies and browser storage entries. We do not run advertising or retargeting pixels on this site, and we do not sell or trade any of this data.
| What | Set by | Purpose | Lifetime |
|---|---|---|---|
| _ga, _ga_* | Google Analytics 4 | Distinguishes one browser from another so we can count visitors and see which pages work. | Up to 2 years |
| _clck, _clsk | Microsoft Clarity | Ties page views into one session for heatmaps and session replay (see section 05). | Up to 1 year |
| tm_utm | TwinMind (local storage) | Remembers the first campaign you arrived from, so an enquiry weeks later is still attributed correctly. | 90 days |
| va-sid, va-thread, va-name, va-email, other va-* entries | TwinMind (local storage) | Keeps your assistant conversation - and any meeting you booked - on this device, so you can come back to it without creating an account, along with small preferences such as the assistant's volume and whether you muted it. Stored in your browser, not a tracking cookie. | Until you clear your browser storage |
| tmb-draft, tmb-booking | TwinMind (local storage) | Saves the booking form as you fill it in - name, email, address, website, phone, notes, the slot you picked and any discount - so closing the popup or reloading the page does not lose your typing, and remembers a booking you completed. It stays on your device - nothing reaches us until you press "Confirm booking", except what you type in the address box, which is sent as you type so we can offer suggestions (section 03). | Until you clear your browser storage |
| tm_internal, tm_dev | TwinMind (local storage) | Marks a browser as belonging to our own team, so our testing is excluded from the analytics reports. | Until cleared |
| tm_open_* | TwinMind (session storage) | Remembers within this browser tab that we already counted your opening of a link we emailed you, so one visit is not counted twice. | Until you close the tab |
| tm_sid | TwinMind (session storage) | A random identifier for this visit, so the pages and buttons of one visit can be read together instead of as loose numbers (section 03). Never sent to a third party; cannot link this visit to another one, to another device, or to anything you do elsewhere. | Until you close the tab |
| Cloudflare security cookies | Cloudflare | Bot filtering and abuse protection for the site. | Up to 1 year |
You can delete or block cookies in your browser settings. Blocking the TwinMind local-storage entries will not break the site, but the assistant will forget your conversation between visits and the booking form will no longer bring back what you had typed. We do not use a cookie banner: the only non-essential tools here are the two analytics products above, and we switch both off automatically for any browser that asks us to (section 13).
05Session recording & heatmaps
We use Microsoft Clarity to understand how people actually use the site - where they scroll, what they click, and where a page confuses them. Clarity records a reconstruction of your visit (mouse movement, clicks, scrolling and the pages you saw) as a replay we can watch back. It is aggregated behavioural data used to improve the site; it is not used to identify you and it is not linked to advertising.
Clarity masks text input by default - what you type into the booking form is not captured in the replay. We do not enable unmasked recording.
To opt out entirely, see section 13.
06The AI assistant, voice & calls
This site has an AI assistant that can answer questions about what we do. You choose whether to use it - it does nothing until you open it.
Text chat
What you type is sent to our own backend (crm.twinmind.au) and from there to OpenAI, which generates the reply. The conversation is stored so the assistant has context, and so our team can see what people are asking and improve the answers. A copy of the thread stays in your browser's local storage so the conversation survives a refresh. Separately from the conversation itself, our analytics count that a chat got going and how many messages you sent - numbers only, with no text attached (section 03).
Live voice, voice messages and attachments
If you press the microphone button, your browser asks for microphone permission. Nothing is captured before you grant it, and you can revoke it at any time in your browser. When active, your audio is streamed directly from your browser to OpenAI's speech service for real-time transcription, using a short-lived token our server issues. A recorded voice message, or a file or image you attach to the chat, is uploaded to our backend; audio is transcribed by OpenAI. We keep all of it on the same basis as text chat.
The "Dictate" button in the booking form (section 03) works exactly the same way and on the same terms - live audio to OpenAI's speech service, or one recorded clip through our backend if the live path is unavailable - and the text it produces simply lands in the notes box for you to edit or delete before you send anything.
A real person may be reading
The assistant is not a sealed box: your conversation - the messages, any files or voice notes, and the session context in section 03 - is mirrored live into a private TwinMind team channel on Telegram so a founder can step in and answer you personally. That is the whole point of it. Treat a chat here like talking to us, because that is what it is.
Opening the chat is itself a notification. The moment the chat or assistant panel opens - before you type a single word - that same team channel gets a short note: that a chat was opened, which page you opened it from, and the city and device context described in section 03. If you arrived on a link we emailed you personally, the note names you, because that link identifies you to us (section 03). It carries no message text - you have not written any - and it exists so a human can greet you rather than leave you talking to a robot. Close the panel without writing and nothing further is sent.
Voice & video calls
The "call us" options connect you to our team through Twilio (telephony) or a browser-to-browser connection. Call metadata (number, time, duration) is retained by the telephony provider and by us for support and billing.
Phone calls are recorded, and we say so at the start of the call. This applies both ways - when you ring our number, and when we ring you. On a call we place, you hear who is calling and that the call is recorded before anyone from our team can speak to you, and you can say you would rather not be recorded; say so and we stop. The browser-to-browser video calls from this site are not recorded - only their live transcript is kept.
From a recorded call we keep the audio in our own storage (not the telephony provider's), a written transcript, and a short summary that is filed against your contact record in our CRM so the team has an accurate account of what was agreed. Transcription and summarising are done by OpenAI as a service provider, on the same terms as the assistant above. Recordings and their transcripts are kept as enquiry records under section 11, and you can ask us to delete a specific call - see section 13.
Meetings we attend
For client project meetings we sometimes record the audio and generate a transcript and summary, because getting the detail of a process right matters. We tell you before recording starts and you can say no - the meeting simply goes ahead unrecorded. Those recordings are client project records, kept under section 16.
What we do not do: we do not use your conversations to train public AI models. Our AI providers process this content on our instructions as a service provider, under API terms that exclude training on customer data by default.
Please do not paste confidential material - client names, credentials, or anything under NDA - into a chat on a public marketing website. If you want to discuss something sensitive, book a meeting and we will handle it properly.
07Why we use it
We only use personal information for purposes you would reasonably expect from a business you have contacted:
- To respond to you - confirm a meeting, send the calendar invitation, answer your question, prepare for the conversation.
- To provide the AI Opportunity Audit and, if you go ahead, to scope, quote and deliver the work. If you give us your website address when you book, we look over that public site beforehand so we turn up with ideas that fit your business rather than generic ones.
- To run and improve the site - see which pages help and which do not, fix what is broken, make it faster.
- To keep the site secure - detect abuse, spam and attacks.
- To measure our marketing - understand which campaign or article actually led to a conversation, so we stop wasting effort on the ones that do not.
- To meet our legal and record-keeping obligations as an Australian business.
If we ever want to use your information for something genuinely different from the above, we will ask you first, or tell you clearly and give you a way out before we do it.
We do not sell personal information. Ever. On automated decisions, see section 20.
08Who we share it with
We share personal information only with the service providers that make this site and our business work, and only so far as they need it. They act on our instructions and are not permitted to use it for their own purposes.
| Provider | What it handles | Where |
|---|---|---|
| Google Cloud (Cloud Run) | Hosting for this site and our CRM backend, including booking data | Sydney, Australia |
| Cloudflare | DNS, CDN and security in front of the site; server logs | Global edge (incl. Australia) |
| Google Analytics 4 | Site usage statistics | United States / global |
| Microsoft Clarity | Heatmaps and session replay | United States |
| OpenAI | Generating assistant replies; speech-to-text for live voice and voice messages; summarising and categorising email that arrives in our own mailboxes, and drafting a reply for a founder to review. It also transcribes a voice clip if you press the microphone on our public panel demo (studio.twinmind.au, section 02): the clip goes to OpenAI, the text comes back into the box on your screen, and neither is stored by us. Nothing else on that demo reaches a model at all | United States |
| ipwho.is | Turns the IP address of a visitor to our public demo dashboard (dashboard.twinmind.au) into an approximate city and network name, so we can tell a real reader from a crawler. It receives the IP address and nothing else — no name, no email, no page content | Global |
| Google Places | Address suggestions while you type in the booking form | United States / global |
| Google Workspace | Our email and the calendar your meeting is booked into | Global (Google infrastructure) |
| Twilio | Our phone line and the browser call options; it also places the internal alert call that reads out your booking to us - your name, the time you picked, and the details you entered on the form, including what you wrote in the notes box - so we hear about it straight away | United States / global |
| Anthropic | Preparing us for a meeting you booked: the details from your booking form are sent to Anthropic's Claude models, which research your business from public sources on the web and write an internal briefing our team reads before the call. Nothing it writes is sent to you, and it makes no decision about you | United States |
| Telegram | The private team channel your site chat is mirrored into (see section 06), and our internal notifications when a meeting is booked or cancelled | Global |
| Microsoft Teams | An optional way to reach us: the contact block on our pages offers a "Microsoft Teams" link that starts a chat with us in your own Teams. If you use it, Microsoft carries that conversation - your Teams display name, your work address and whatever you write or send us - the same way it carries any Teams chat. Nothing is sent to Microsoft unless you choose that channel yourself | Global (Microsoft infrastructure) |
| jsDelivr | Public CDN that serves the emoji images used in the chat window. It sees only that your browser asked for a picture. | Global edge |
We may also disclose personal information where the law requires it - for example to a court, a regulator, or a law-enforcement agency acting under proper authority - or where it is necessary to protect someone's safety or to establish or defend a legal claim. We may share it with our own professional advisers (accountant, lawyer, insurer) where they need it and are bound by confidentiality. If our business is ever sold or restructured, information may transfer to the new owner, who would remain bound by this policy or one at least as protective; if that ever happens we will say so on this page.
If we add or swap a provider, this table changes at the same time - see section 26.
09Overseas disclosure
As the table above shows, some of our providers are based overseas - primarily in the United States, and in the case of global CDN, telephony and messaging services, potentially in other countries where they operate infrastructure. That means personal information you give us may be accessed or stored outside Australia.
We choose providers that publish enforceable privacy and security commitments and we contract with them on their data-processing terms. But we tell you plainly, as APP 8 requires: once information is held overseas, Australian privacy law may not apply to it in the same way, and you may not be able to seek redress under the Privacy Act against that overseas recipient.
Where it matters most - the booking data and the CRM that holds your enquiry - we host in Sydney, Australia, and systems we build for clients are hosted onshore in Australia by default.
10Where it lives & how it is protected
- Everything is served over HTTPS; there is no unencrypted path to this site.
- Our site and CRM run in Google Cloud's australia-southeast1 (Sydney) region.
- Internal tools are behind authentication; access to the CRM that holds enquiry data is limited to the TwinMind team - today, the two founders.
- Credentials are held in a secret store, never in code or in the site itself.
- Access is limited to the people who need it to answer you or deliver the work.
- Backups are encrypted and replicated. Because of them, deleting something can take up to 35 days to disappear from every copy - see section 14.
No system is perfectly secure, and we will not pretend otherwise. If we suspect a data breach we assess it promptly - within 30 days at the outside, as the law requires - and if it is likely to cause you serious harm we will notify you and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.
11How long we keep it
- Enquiries and bookings - while we are in contact and for up to 7 years afterwards, which matches our Australian business record-keeping obligations.
- Assistant conversations - up to 12 months, then deleted. This is enforced by a scheduled job, not by memory: transcripts, uploaded files and session metadata past that age are erased automatically. The copy in your own browser lasts until you clear your browser storage.
- Call recordings, transcripts and summaries (section 06) - a call is part of the enquiry or client record it belongs to, so it is kept on that record's clock: up to 7 years, the same as the first line above, and not the 12-month rule that covers assistant chats. Ask us to delete a particular call and we will, unless we are required to keep it.
- Analytics data - retained by Google Analytics (event data set to 14 months) and Microsoft Clarity under its own limited retention.
- Server and security logs - typically 30-90 days. Counters that hold an IP address are purged automatically at 90 days.
- Demo dashboard visits (
dashboard.twinmind.au, section 02) - opening the public demo is recorded as one visit: the IP address, the approximate city and network it resolves to, the browser and device, the page you arrived from and which tabs you opened. It is kept for up to 90 days and then deleted automatically, on the same clock as the line above. This one is enforced by a scheduled sweep in the demo’s own code and by a test that fails the build if an older record survives. - The panel demo (
studio.twinmind.au, section 02) - nothing is kept. It writes no visit log, sets no cookie and has no database; the only thing it holds is a short-lived counter in memory that stops one address flooding the transcription limit, and that disappears when the process restarts. A voice clip you record there is passed straight to OpenAI for transcription and is not written to disk by us at any point. - Our own page and button click counters (section 03) - these clicks are kept for up to 12 months, then deleted by the same scheduled job that clears the assistant conversations.
- Client project records - for the life of the engagement and then as long as our agreement with that client and the law require.
When we no longer need personal information for any purpose set out above and are not required to keep it by law, we destroy it or de-identify it.
12Marketing & how we got your email
If we contacted you first, we want to be straightforward about it. We reach out to Australian businesses using publicly listed business contact details - a company website, a public business directory, or a professional profile - where the role and the business make our work plainly relevant. We do not buy consumer lists.
Every email we send identifies us, states why we are writing, and carries a working unsubscribe link, as the Spam Act 2003 (Cth) requires. One click is enough - there is no login, no "manage preferences" maze, and it takes effect immediately. Your address goes on a permanent stop list that every sending path in our system checks before it sends anything, so it applies across every campaign, not just the one you clicked. You can also reply "stop", email sergey@twinmind.au, or use the form below. We keep the minimum record needed to make sure we never contact you again by accident - that record is the whole point of the stop list.
13Your choices & opt-outs
- Do Not Track / Global Privacy Control - if your browser sends a DNT or GPC signal, this site loads neither Google Analytics nor Microsoft Clarity at all, and our own click counter (section 03) stays off as well. We honour it automatically; you do not have to ask. The one thing it does not switch off is the record that a link we emailed you was opened - that is part of our correspondence with you rather than tracking a stranger, and it stops the moment you tell us to stop contacting you.
- Google Analytics opt-out - install the Google Analytics Opt-out Browser Add-on.
- Microsoft Clarity opt-out - blocking third-party scripts or cookies in your browser, or sending DNT/GPC as above, stops Clarity loading.
- Cookies generally - delete or block them in your browser settings. The site still works.
- The assistant - simply do not open it. It sends nothing until you do. To clear the conversation stored on your device, clear this site's data in your browser.
- The microphone - both in the assistant and behind the booking form's Dictate button, permission is asked for and never assumed, nothing is captured until you press the button, typing is always an alternative, and access can be revoked at any time in your browser's site settings.
- Emails from us - use the unsubscribe link in any email, or the form below.
14Access, correction & complaints
Under the Australian Privacy Principles you can:
- Ask what we hold about you and get a copy of it.
- Ask us to correct it if it is wrong, out of date or incomplete.
- Ask us to delete it, where we are not required to keep it.
- Ask us to stop contacting you - and we will, permanently.
- Deal with us anonymously or under a pseudonym where that is lawful and practicable - for example, you can read every page and use the assistant without telling us who you are.
Use the form below, or email sergey@twinmind.au with the subject "Privacy request". We acknowledge within 48 hours and answer within 30 days. There is no charge. For anything beyond "stop contacting me" we may need to verify your identity first, so that we do not hand your information to somebody else - usually that just means replying from the address the information is held under.
The honest limits. Some things we may not be able to delete: records we are legally required to keep (invoices and tax records for 7 years), information needed to defend a legal claim, and the minimum record that keeps you on our do-not-contact list. Deletions can also take up to 35 days to age out of encrypted backups. If we refuse a request, we will tell you why in writing and how to complain.
If you are not happy with how we handled it, tell us and we will try to fix it. If you are still not satisfied, you can complain to the Office of the Australian Information Commissioner - oaic.gov.au, 1300 363 992.
15Make a privacy request
One form. No account, no phone call, no waiting for business hours. Tell us what you want and it starts happening the moment you press the button.
Prefer email? sergey@twinmind.au reaches a founder directly and starts the same 30-day clock. Acting for someone else - a client, an employee, a family member? Say so in the form and we will tell you what we need to confirm you are authorised.
16When we work inside your systems
Most of our work involves building automation that runs on a client's own data - invoices, customer records, payroll files, mailboxes. When that happens, the client is the entity responsible for that personal information and we handle it on their instructions, under a written agreement, not under this policy.
- We take the least access that does the job, and we ask for test or de-identified data whenever the work allows it.
- We do not use a client's data to train models, to build products for anyone else, or for our own marketing.
- Client systems we build are hosted in Australia by default, and we tell the client in writing whenever a component sends data offshore.
- Access is removed at the end of an engagement, and working copies are destroyed once they are no longer needed for support or warranty.
- Everyone who touches client data is bound by confidentiality.
If you are an individual whose information sits in a system we built for a business, that business is who to ask about it first - they control it. Contact us anyway if you cannot reach them and we will help route your request to the right place.
17Case studies, logos & testimonials
We publish what we build. Where a case study, screenshot, quote or logo would identify a client or a named person, we either get written permission first or de-identify the story - changed names, blurred figures, "a Brisbane distributor" instead of the business name. We never publish a client's actual customer data as an illustration; the numbers in our demos are synthetic.
If you gave us a testimonial or agreed to be named and you have changed your mind, tell us and we will take it down. That is not a negotiation.
18Applying for a job or pitching us
If you send us a CV, an application, or a partnership or supplier pitch - by email, LinkedIn, or through the assistant - we collect what you send: your name, contact details, work history, and anything else in the message.
- We use it only to consider you for that role or opportunity and to talk to you about it.
- We keep unsuccessful applications for up to 12 months in case something suitable comes up, then delete them. Tell us not to and we will delete it straight away.
- We do not run automated screening that decides your application on its own - a person reads it.
- If a role ever requires a background or reference check, we ask for your consent first and tell you what will be checked.
19Payments & billing
We invoice clients directly and are paid by bank transfer. Invoices carry the ordinary billing details: business name, ABN, contact name, email, amounts and dates. We keep them for 7 years because Australian tax law says so.
We do not collect or store credit-card numbers. If we ever add card or online payment, it will be through a PCI-compliant payment processor that handles the card details directly - we would receive only the confirmation and the last four digits - and this section will say who that processor is before the first payment goes through it.
20Automated decisions & AI
We build AI systems for a living, so we will be precise about what runs against your information here.
- On this website, AI generates assistant replies and transcribes speech. It does not decide anything about you.
- In our CRM, a model reads incoming enquiries to sort and prioritise them - a scoring aid that decides who we call first, nothing more. A human reads every real enquiry.
- We do not use automated decision-making that produces a legal effect for you or similarly significantly affects you - no automated credit, eligibility, pricing or employment decisions.
- You can always reach a human. Reply to any email, ask in the chat, or call us; nothing here traps you in a bot.
If that ever changes - if we introduce a decision that materially affects you and is made by a computer - we will say so here, explain what the system does and what it uses, and give you a way to ask for a human review. Australian privacy law is moving in that direction and we intend to be ahead of it, not behind.
21Information we did not ask for
Sometimes people send us things we never asked for - a spreadsheet of their customers to "show the problem", a CV attached to a sales email, sensitive details typed into a chat box. As APP 4 requires, we check whether we could have collected it lawfully ourselves. If we could not, and it is not in a record we must keep by law, we destroy or de-identify it as soon as practicable - and we will tell you we have done so if you ask.
So: if you have accidentally sent us something you should not have, just tell us. Deleting it is the easy case, not the awkward one.
22De-identified & aggregated data
We use aggregate numbers to run the business and to write about our work - "37% of enquiries come from wholesale distributors", "the average reconciliation run dropped from 6 hours to 20 minutes". Aggregated and de-identified information is no longer personal information, and we may keep and use it indefinitely, including after you have asked us to delete your personal information.
The line we hold: we do not publish or share anything aggregated that could reasonably be re-identified back to you or your business, and we do not attempt to re-identify data we have de-identified.
23Visitors from outside Australia
This site is aimed at Australian businesses, and we run it under Australian law. You are welcome to read it from anywhere, and a few things are worth saying plainly.
- Everyone, everywhere - the DNT/GPC switch in section 13 turns off both analytics tools for your browser, and the request form works no matter where you are.
- EU / UK visitors - we do not target the EU or the UK and we do not monitor visitors there. If the GDPR or UK GDPR nevertheless applies to something we do with your information, our lawful bases would be: your consent for the microphone and the assistant, performance of a contract or steps at your request for booking and delivering work, and our legitimate interests in running, securing and measuring a business website. You may ask for access, correction, erasure, restriction, portability, or object to processing - use the same form; we do not charge and we do not discriminate for asking.
- California / US visitors - we do not sell or share personal information, and we do not process it for cross-context behavioural advertising. There is no financial incentive attached to your data.
- Whatever your location, information you give us will be handled in Australia and in the countries listed in section 09.
24Other sites we link to
We link out to third-party sites - LinkedIn, our providers' documentation, articles worth reading. Once you follow a link, that site's own privacy policy applies and we have no control over what it does. We do not embed third-party social widgets, trackers or "like" buttons that would report your visit back to them from our pages.
25Children
This site is for businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
26Changes to this policy
We will update this page when what we do changes - a new provider, a new feature, a new obligation. The "last updated" date and version at the top always reflect the current text.
This is not a promise we keep by remembering: our build refuses to ship a change to the site's tracking, booking, assistant or call code unless this page has been reviewed in the same commit, and an automated test checks that the retention periods written above still match what our systems actually enforce. If a change materially affects information you have already given us, we will make that clear rather than quietly editing the page - and where it matters, we will tell the people affected directly.
27Contact us
Questions, requests or complaints about privacy - talk to a founder, not a ticket queue:
- Email · sergey@twinmind.au
- Privacy request · the form in section 15 - fastest, and it starts working immediately
- Phone · 1800 86-85-86
- Post · TwinMind, Brisbane, Queensland, Australia - email us and we will give you a postal address for anything you need to send physically
- ABN · 83 665 668 690