Privacy Policy

How we collect, use and protect your personal information

Last Updated: 22 January 2026

Boby Pty Ltd (ABN 22 643 102 167) understands that protecting your personal information is important. This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or collected by us, when interacting with you.

This Privacy Policy takes into account the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as the New Zealand Privacy Act 2020 and the Information Privacy Principles. Individuals located in the EU or UK may have additional rights under the GDPR and UK GDPR — these are set out in Appendix 1.

Our Platform is intended for persons aged 18 years and over. We do not knowingly collect or retain personal information of persons under 18 years of age. If we become aware that a person under 18 has provided us with personal information, we will take steps to delete that information as soon as practicable. If you believe a person under 18 has provided us with their personal information, please contact us at info@getboby.ai.

Contents

1

Information We Collect

Personal information is information or an opinion, whether true or not and whether recorded in a material form or not, about an individual who is identified or reasonably identifiable.

The types of personal information we may collect about you include:

Identity Data

Your name, age, profession and photographic identification.

Contact Data

Your telephone number, address and email address.

Financial Data

Bank account and payment card details, processed through our third-party payment processor. We do not have direct access to or storage of your financial data.

Background Verification Data

Government-issued identification details collected as part of our onboarding process to comply with our due diligence obligations and anti-money laundering laws. Where you provide security services or operate as a security firm, this includes your security licence number, licence status and expiry date, ABN, GST registration status, professional qualifications, insurance details and other credentials required to provide security services through our Platform.

Transaction Data

Details about payments to and from you and details of products and services purchased through our Platform.

Technical and Usage Data

When you access our websites, platforms or emails: your IP address, login data, browser session and geo-location data, statistics on page views and sessions, device and network information, acquisition sources, search queries and browsing behaviour, access and use of our website (including through the use of cookies or tracking pixels), and communications with our website.

Profile Data

Your username and password, profile picture, purchases or orders made with us, content you post and share through our Platform, information shared with our social media platforms, support requests, and all information, knowledge, preferences, documents and data you input into your AI-powered digital twin assistant (Digital Twin Data), which may include personal information, professional information, preferences, communications, and any other content you choose to store in your digital twin.

Interaction Data

Information you provide when participating in interactive features, including surveys, contests, promotions, activities or events.

Marketing and Communications Data

Your preferences in receiving marketing from us and third parties, and your communication preferences.

Professional Data

Where you are a worker of ours or applying for a role with us: your professional history, previous positions and professional experience, and whether you hold required authorisations or licences.

Sensitive Information

Sensitive information is a sub-set of personal information given a higher level of protection. It includes information relating to racial or ethnic origin, political opinions, religion, trade union memberships, philosophical beliefs, sexual orientation or practices, criminal records, health information or biometric information.

The types of sensitive information we may collect include:

  • Results of criminal records checks (where you apply for a role with us)
  • Professional registrations and associations (where applicable)
  • Identity verification data that may constitute biometric information, where required for security provider onboarding

We only collect sensitive information where it is reasonably necessary for our functions and activities, and with your consent or as otherwise permitted by law.

2

How We Collect Personal Information

We collect personal information in a variety of ways, including:

  • When you provide it directly to us, including face-to-face, over the phone, by email or online
  • When you complete a form, such as registering for events or newsletters, or responding to surveys
  • When you use any website or platform we operate (including from analytics providers, cookie providers or marketing providers)
  • From third parties, including identity verification services, security licence registries and payment processors
  • From publicly available sources
  • From single sign-on providers such as Apple, Facebook or Google, where you choose to connect your account
  • From your device's location services, where you have granted our mobile application permission to access location data
3

Why We Collect and Use Your Information

We have set out below the purposes for which we collect, hold, use and disclose your personal information.

PurposeTypes of Personal Information
To enable you to access and use our Platform, including to provide you with a loginIdentity Data, Contact Data
To assess whether to take you on as a new clientIdentity Data, Contact Data, Background Verification Data
To work with you as a customer or supplier of our businessIdentity Data, Contact Data
To contact and communicate with you about our business, support requests and enquiriesIdentity Data, Contact Data, Profile Data
For internal record keeping, administrative, invoicing and billing purposesIdentity Data, Contact Data, Financial Data, Transaction Data
For analytics, market research and business development, including to operate and improve our businessProfile Data, Technical and Usage Data
For advertising and marketing, including to send you promotional information we consider may be of interest to youIdentity Data, Contact Data, Technical and Usage Data, Profile Data, Marketing and Communications Data
To run promotions, competitions and offer additional benefits to youIdentity Data, Contact Data, Profile Data, Interaction Data, Marketing and Communications Data
To consider your employment applicationIdentity Data, Contact Data, Professional Data
To power and improve your digital twin assistant using AI technologiesProfile Data (Digital Twin Data), Technical and Usage Data
To verify your identity and comply with security licensing obligationsIdentity Data, Background Verification Data
To comply with our legal obligations or as otherwise required or authorised by lawAny relevant personal information

Sensitive Information

We only collect, hold, use and disclose sensitive information for the following purposes:

  • Any purposes you have consented to
  • The primary purpose for which it was collected
  • Secondary purposes that are directly related to the primary purpose
  • To contact emergency services, or to speak with your family or support person, where we reasonably believe there is a serious risk to the life, health or safety of you or another person and it is impracticable for us to obtain your consent
  • Where otherwise required or authorised by law
4

Who We Disclose Personal Information To

We will only disclose personal information (excluding sensitive information) to third parties where it is necessary as part of our business, where we have your consent, or where permitted by law. This includes disclosure to:

  • Our employees, contractors and related entities
  • IT service providers, data storage, web-hosting and server providers (including Google Cloud Platform and Cloudflare, Inc.)
  • AI technology providers who power our digital twin feature (including Anthropic, PBC)
  • Marketing or advertising providers
  • Professional advisors, bankers, auditors, insurers and insurance brokers
  • Payment systems operators or processors
  • Our existing or potential agents or business partners
  • Identity verification and background check service providers
  • Security licence registries and regulatory bodies
  • In the event of a merger, acquisition or sale of assets: our advisers and any prospective purchaser's advisers, and as part of the transferred assets
  • Courts, tribunals and regulatory authorities, in the event of a failure to pay for goods or services
  • Courts, tribunals, regulatory authorities and law enforcement officers, as required or authorised by law
  • Third parties to collect and process data, such as analytics providers and cookies (see our Cookies Policy for more detail)
  • Any other third parties as required or permitted by law

Sensitive Information

We will only disclose sensitive information with your consent or where permitted by law. Sensitive information may be disclosed to our employees and contractors, IT service providers, professional advisors, and courts or regulatory authorities as required by law.

5

Overseas Disclosure

Australian Residents

We store your personal information primarily in Australia. Where we disclose your personal information to third parties, those third parties may store, transfer or access personal information outside of Australia, including in the following countries and regions:

  • United States of America — Anthropic, PBC (AI model processing), Cloudflare, Inc. (content delivery and network security)
  • United States of America and multiple global regions — Google Cloud Platform (cloud hosting and infrastructure)
  • Other countries — where our service providers operate or maintain infrastructure, including countries in the European Union and Asia-Pacific region

We will only disclose your personal information overseas in accordance with the Australian Privacy Principles. We take reasonable steps to ensure that overseas recipients handle your personal information in a manner consistent with those Principles.

New Zealand Residents

Where we disclose your personal information to third parties, those third parties may store, transfer or access personal information outside of New Zealand, which may not have equivalent data protection laws. Before disclosing any personal information to an overseas recipient, we will comply with Information Privacy Principle 12 and only disclose the information where we are satisfied that the recipient provides comparable safeguards, or where you have authorised the disclosure after being informed of the relevant risks.

6

How Long We Keep Your Information

We will only retain your personal information for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, tax, accounting or reporting requirements. When personal information is no longer needed for any purpose for which it may be used or disclosed, we will take reasonable steps to destroy or de-identify it.

The following table sets out our general retention periods by data type. Specific retention periods may vary depending on applicable legal obligations.

Data TypeRetention PeriodReason
Account and Identity DataDuration of Account plus 7 yearsLegal and regulatory obligations
Financial and Transaction Data7 years after the relevant transactionTax and accounting obligations
Digital Twin DataDuration of Account; deleted within 90 days of Account closure unless an authorised representative requests otherwiseService provision and estate management
Background Verification DataDuration of engagement plus 7 yearsRegulatory compliance
Technical and Usage DataUp to 2 yearsAnalytics and fraud prevention
Marketing and Communications DataUntil you withdraw consent or unsubscribe, plus 3 yearsRecord of consent
Employment Application Data (unsuccessful)12 months after decisionLegal obligations and future opportunities
AI Training Data (anonymised and aggregated)Indefinite once fully anonymisedModel improvement; no longer constitutes personal information

We may retain your personal information for longer than the periods set out above where there is a complaint, a dispute, or we have reason to believe litigation may occur in respect of our relationship with you.

7

Use of Artificial Intelligence

Overview

We use artificial intelligence and machine learning technologies, including AI technologies provided by third parties, in our business operations and the provision of our Services. We will only use AI technologies when legally permitted and necessary for our business operations.

How We Use AI Technologies

We may use AI technologies for the following purposes:

  • To conduct analysis and processing of information
  • To generate and modify content
  • To improve and optimise our Services and operations
  • To automate certain processes and communications
  • To personalise your experience with our Services
  • For quality assurance purposes
  • To assist with customer support and queries
  • To power and improve your digital twin assistant

Digital Twin and AI Training

We use AI technologies to power your digital twin assistant. When you create a digital twin, you expressly consent to us using your Digital Twin Data (including any personal information contained within it) to train, improve and develop our AI models and the digital twin feature. This may include analysing usage patterns, improving AI response accuracy, developing new features, and creating anonymised aggregated data for research purposes.

Withdrawing Consent: You may withdraw your consent to the use of your Digital Twin Data for AI training purposes at any time by contacting us at info@getboby.ai with the subject line "AI Training Opt-Out". Upon withdrawal, we will cease using your Digital Twin Data for AI training from the date of your withdrawal. Your withdrawal will not affect the lawfulness of processing that occurred prior to withdrawal. Where data has already been incorporated into trained AI models in anonymised or aggregated form, it may not be technically feasible to remove it. We will notify you where this applies. Withdrawing AI training consent does not affect your ability to continue using your digital twin.

Data Protection and Security

Where we use service providers who provide AI technologies to us, we take reasonable steps to ensure that such service providers handle your personal information in accordance with applicable privacy law, including through contractual obligations requiring the protection of personal information.

Your Rights and Our Commitments

We treat information generated or inferred by AI technologies about individuals as personal information, and you maintain all rights over your personal information regardless of whether AI technologies are used in processing. When using AI technologies with your personal information:

  • Transparency and control: We will inform you when AI technologies are used to make decisions that may significantly affect you. We implement processes to verify the accuracy of AI-generated outputs and maintain human oversight of significant AI-generated decisions.
  • Security: We implement appropriate technical and organisational measures to ensure our use of AI technologies maintains the security and integrity of your personal information.
  • Risk mitigation: We regularly assess and document the risks associated with our use of AI technologies and implement appropriate mitigation measures.
8

Your Rights and Controlling Your Information

Your Choice

Please read this Privacy Policy carefully. If you provide personal information to us, you understand we will collect, hold, use and disclose it in accordance with this Privacy Policy. You are not required to provide personal information to us, however, if you do not, it may affect our ability to provide you with our Services.

Information from Third Parties

If we receive personal information about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal information about someone else, you represent and warrant that you have that person's consent to provide the personal information to us.

Access

You may request access to the personal information we hold about you. An administrative fee may be payable for the provision of such information. In some circumstances, we may be legally permitted to withhold access. If we cannot provide access, we will advise you as soon as reasonably possible and provide our reasons and any available complaint mechanism.

Correction

If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us. We will take reasonable steps to promptly correct any such information. If we cannot correct your information, we will advise you as soon as reasonably possible and provide our reasons and any available complaint mechanism.

Deletion

You may request that we delete personal information we hold about you. We will consider your request and, where we are not required or permitted by law to retain the information, we will take reasonable steps to delete or de-identify it. We will advise you of the outcome of your request and, where we are unable to delete information, we will explain why.

Restrict and Unsubscribe

To object to processing for direct marketing, or to unsubscribe from our email database, please contact us using the details below or use the opt-out facilities provided in the communication.

Complaints

If you wish to make a complaint, please contact us using the details below and provide full details of the complaint. We will promptly investigate and respond to you in writing, setting out the outcome of our investigation and the steps we will take in response.

If you are not satisfied with our response, you may contact:

  • Australian residents: The Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au
  • New Zealand residents: The Office of the New Zealand Privacy Commissioner at www.privacy.org.nz
  • EU and UK residents: The relevant Data Protection Authority in your jurisdiction (see Appendix 1)
9

Storage and Security

We are committed to ensuring that the personal information we collect is secure. We have put in place suitable physical, electronic and managerial procedures to safeguard and secure personal information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.

Our security measures include:

  • Encryption of data in transit using TLS
  • Access controls limiting personal information to authorised personnel only
  • Regular security monitoring and testing
  • Contractual security obligations on third-party service providers
  • Staff training on privacy and data security obligations

While we are committed to security, we cannot guarantee the security of information transmitted to or by us over the internet. The transmission and exchange of information is carried out at your own risk.

10

Data Breaches

We are committed to complying with our obligations under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme. In the event of an eligible data breach that is likely to result in serious harm to one or more individuals:

  • We will notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and no later than 30 days after we become aware of the breach
  • We will notify all affected individuals whose personal information was involved in the breach
  • We will take all reasonable steps to contain the breach and mitigate any resulting harm
  • Notification to affected individuals will be provided directly where contact details are known, or via a prominent notice on our Platform where direct notification is not practicable

If you become aware of any actual or suspected security breach affecting your Account or personal information on our Platform, please notify us immediately at info@getboby.ai.

11

User-Generated Content

We may enable you to post reviews, comments, photos and other user-generated content. Any content you choose to submit will be accessible by anyone, including third parties not associated with us. We have no control over how others may use or misuse information you make publicly available. We are not responsible for the privacy, security or accuracy of any user-generated content you choose to post, or for the use or misuse of that information by any third party.

12

Cookies and Analytics

We use cookies, tracking pixels and similar technologies on our website and in our emails. For full details of the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please see our Cookies Policy.

Google Analytics

We use Google Analytics Advertising Features. We and third-party vendors may use first-party cookies (such as the Google Analytics cookie) or other identifiers, and third-party cookies (such as Google advertising cookies) together. These may collect Technical and Usage Data about you. You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.

Facebook / Meta Analytics

We may use tools provided by Meta, such as the Meta Pixel and Conversions API. These allow us to measure ad performance and deliver relevant ads on Meta platforms based on your activity on our website. You can manage these preferences through Meta's settings and by adjusting your Off-Facebook Activity settings.

Managing Cookies

You can block cookies by activating the setting on your browser that allows you to refuse all or some cookies. You can block tracking pixels using ad-blocking or privacy-focused browser extensions. However, if you block all cookies (including essential cookies) you may not be able to access all or parts of our website.

14

Single Sign-On Accounts

If you connect your account with us using a single sign-on service (such as Apple, Facebook or Google), we will collect your personal information from that provider in accordance with the privacy settings you have chosen with them.

The personal information we may receive includes your name, ID, username, handle, profile picture, gender, age, language, list of friends or follows, and any other personal information you choose to share.

We use the personal information received from the single sign-on provider to create a profile for you on our Platform and to provide you with our Services, including personalising your experience and enabling communication with you.

Where we have accessed your personal information through your Facebook account, you have the right to request the deletion of that personal information. To submit a deletion request, please email us at info@getboby.ai and specify which personal information you would like deleted. If we deny your request, we will explain why.

15

Location Services

We collect your precise or approximate location via our mobile application for the following purposes:

  • For security and safety, including to enable location-based security reporting
  • To prevent and detect fraud
  • To match Members with Security Providers in their area
  • As permitted by law

We collect location data when you use our mobile application and have granted us permission to do so. If you do not want us to use your location data, you should turn off location services in your account settings or in your mobile device settings. If you do not provide geolocation data to us, it may affect our ability to provide certain location-based features of our Services.

16

Do Not Track

Some browsers include a "Do Not Track" feature that signals to websites that you do not want to have your online activity tracked. Our website does not currently respond to Do Not Track signals, as there is no universally accepted standard for how websites should respond to such signals. We will continue to monitor developments in this area.

You can manage your privacy preferences and limit tracking through your browser settings and by reviewing our Cookies Policy.

17

Changes to This Policy

We may, at any time and at our discretion, update this Privacy Policy by publishing the amended version on our website. We recommend you check our website regularly to ensure you are aware of our current Privacy Policy. Where changes are material, we will notify you by email or by a prominent notice on our Platform.

Appendix 1

Additional Rights and Information for Individuals Located in the EU or UK

A

EU and UK Additional Rights

Under the General Data Protection Regulation 2016/679 (GDPR) and, for UK residents, the UK GDPR and Data Protection Act 2018, individuals located in the EU and UK have additional rights in respect of their personal information (referred to as personal data under the GDPR). This Appendix sets out those additional rights and information about how we process the personal data of individuals in the EU and UK.

Purposes and Legal Bases for Processing

We collect and process personal information only where we have a legal basis to do so. The table below sets out our processing purposes and the legal basis we rely on for each.

PurposeType of DataLegal Basis
To enable you to access and use our PlatformIdentity Data, Contact DataPerformance of a contract with you
To assess whether to take you on as a new clientIdentity Data, Contact Data, Background Verification DataPerformance of a contract; legal obligation; legitimate interests (preventing fraudulent or unlawful activity)
To work with you as a customer or supplierIdentity Data, Contact DataPerformance of a contract with you
To contact and communicate with you about our business and support requestsIdentity Data, Contact Data, Profile DataPerformance of a contract with you
For internal record keeping, administrative and billing purposesIdentity Data, Contact Data, Financial Data, Transaction DataPerformance of a contract; legal obligation; legitimate interests (recovering debts and notifying you of changes)
For analytics, market research and business developmentProfile Data, Technical and Usage DataLegitimate interests (keeping our Platform updated and relevant and improving our business)
For advertising and marketingIdentity Data, Contact Data, Technical and Usage Data, Profile Data, Marketing and Communications DataLegitimate interests (developing and growing our business); or consent where required
To run promotions and competitionsIdentity Data, Contact Data, Profile Data, Interaction Data, Marketing and Communications DataLegitimate interests (facilitating engagement with our business)
To consider employment applicationsIdentity Data, Contact Data, Professional DataLegitimate interests (considering your application)
To power your digital twin using AI technologiesProfile Data (Digital Twin Data)Consent; performance of a contract with you
To comply with legal obligationsAny relevant personal informationLegal obligation

If you have consented to our use of your data for a specific purpose, you have the right to withdraw that consent at any time, though this will not affect processing that has already taken place. Where we are relying on legitimate interests, you have the right to object to that use, though in some cases this may mean we can no longer provide our Services to you.

Data Transfers

Where we transfer your personal information outside of the EU or UK, we will do so using appropriate safeguards in accordance with applicable data protection laws. This includes only transferring to countries deemed adequate by applicable authorities, or including standard contractual clauses in agreements with overseas recipients.

Data Retention

We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying legal, regulatory, tax, accounting or reporting requirements. Please see Section 6 of this Privacy Policy for our general retention periods. We may retain information longer in the event of a complaint or anticipated litigation.

Your Additional Rights

In addition to the rights set out in Section 8 of this Privacy Policy, individuals in the EU and UK have the following additional rights:

  • Right of access: To request details of the personal information we hold about you and how we process it (commonly known as a data subject access request)
  • Right to rectification: To have inaccurate or incomplete personal information corrected
  • Right to erasure: To request deletion of your personal information in certain circumstances
  • Right to restriction: To restrict our processing of your personal information in certain circumstances
  • Right to data portability: To receive your personal information in a structured, machine-readable format and transfer it to another organisation
  • Right to object: To object to processing based on legitimate interests or for direct marketing purposes
  • Rights related to automated decision-making: To not be subject to a decision based solely on automated processing (including profiling) that produces a legal or similarly significant effect on you, without appropriate human oversight

If you are not satisfied with how we handle your personal information, you have the right to make a complaint to the relevant Data Protection Authority in your jurisdiction. We would appreciate the opportunity to address your concerns first, so please contact us in the first instance using the details below.

Privacy Officer

Boby Pty Ltd (ABN 22 643 102 167)

Email: info@getboby.ai

For privacy complaints, access requests or any questions about this Privacy Policy, please contact our Privacy Officer at the email above. We aim to respond to all privacy enquiries within 30 days.