How we collect, use and protect your personal information
Boby Pty Ltd (ABN 22 643 102 167) understands that protecting your personal information is important. This Privacy Policy sets out our commitment to protecting the privacy of personal information provided to us, or collected by us, when interacting with you.
This Privacy Policy takes into account the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as the New Zealand Privacy Act 2020 and the Information Privacy Principles. Individuals located in the EU or UK may have additional rights under the GDPR and UK GDPR — these are set out in Appendix 1.
Our Platform is intended for persons aged 18 years and over. We do not knowingly collect or retain personal information of persons under 18 years of age. If we become aware that a person under 18 has provided us with personal information, we will take steps to delete that information as soon as practicable. If you believe a person under 18 has provided us with their personal information, please contact us at info@getboby.ai.
Personal information is information or an opinion, whether true or not and whether recorded in a material form or not, about an individual who is identified or reasonably identifiable.
The types of personal information we may collect about you include:
Your name, age, profession and photographic identification.
Your telephone number, address and email address.
Bank account and payment card details, processed through our third-party payment processor. We do not have direct access to or storage of your financial data.
Government-issued identification details collected as part of our onboarding process to comply with our due diligence obligations and anti-money laundering laws. Where you provide security services or operate as a security firm, this includes your security licence number, licence status and expiry date, ABN, GST registration status, professional qualifications, insurance details and other credentials required to provide security services through our Platform.
Details about payments to and from you and details of products and services purchased through our Platform.
When you access our websites, platforms or emails: your IP address, login data, browser session and geo-location data, statistics on page views and sessions, device and network information, acquisition sources, search queries and browsing behaviour, access and use of our website (including through the use of cookies or tracking pixels), and communications with our website.
Your username and password, profile picture, purchases or orders made with us, content you post and share through our Platform, information shared with our social media platforms, support requests, and all information, knowledge, preferences, documents and data you input into your AI-powered digital twin assistant (Digital Twin Data), which may include personal information, professional information, preferences, communications, and any other content you choose to store in your digital twin.
Information you provide when participating in interactive features, including surveys, contests, promotions, activities or events.
Your preferences in receiving marketing from us and third parties, and your communication preferences.
Where you are a worker of ours or applying for a role with us: your professional history, previous positions and professional experience, and whether you hold required authorisations or licences.
Sensitive information is a sub-set of personal information given a higher level of protection. It includes information relating to racial or ethnic origin, political opinions, religion, trade union memberships, philosophical beliefs, sexual orientation or practices, criminal records, health information or biometric information.
The types of sensitive information we may collect include:
We only collect sensitive information where it is reasonably necessary for our functions and activities, and with your consent or as otherwise permitted by law.
We collect personal information in a variety of ways, including:
We have set out below the purposes for which we collect, hold, use and disclose your personal information.
| Purpose | Types of Personal Information |
|---|---|
| To enable you to access and use our Platform, including to provide you with a login | Identity Data, Contact Data |
| To assess whether to take you on as a new client | Identity Data, Contact Data, Background Verification Data |
| To work with you as a customer or supplier of our business | Identity Data, Contact Data |
| To contact and communicate with you about our business, support requests and enquiries | Identity Data, Contact Data, Profile Data |
| For internal record keeping, administrative, invoicing and billing purposes | Identity Data, Contact Data, Financial Data, Transaction Data |
| For analytics, market research and business development, including to operate and improve our business | Profile Data, Technical and Usage Data |
| For advertising and marketing, including to send you promotional information we consider may be of interest to you | Identity Data, Contact Data, Technical and Usage Data, Profile Data, Marketing and Communications Data |
| To run promotions, competitions and offer additional benefits to you | Identity Data, Contact Data, Profile Data, Interaction Data, Marketing and Communications Data |
| To consider your employment application | Identity Data, Contact Data, Professional Data |
| To power and improve your digital twin assistant using AI technologies | Profile Data (Digital Twin Data), Technical and Usage Data |
| To verify your identity and comply with security licensing obligations | Identity Data, Background Verification Data |
| To comply with our legal obligations or as otherwise required or authorised by law | Any relevant personal information |
We only collect, hold, use and disclose sensitive information for the following purposes:
We will only disclose personal information (excluding sensitive information) to third parties where it is necessary as part of our business, where we have your consent, or where permitted by law. This includes disclosure to:
We will only disclose sensitive information with your consent or where permitted by law. Sensitive information may be disclosed to our employees and contractors, IT service providers, professional advisors, and courts or regulatory authorities as required by law.
We store your personal information primarily in Australia. Where we disclose your personal information to third parties, those third parties may store, transfer or access personal information outside of Australia, including in the following countries and regions:
We will only disclose your personal information overseas in accordance with the Australian Privacy Principles. We take reasonable steps to ensure that overseas recipients handle your personal information in a manner consistent with those Principles.
Where we disclose your personal information to third parties, those third parties may store, transfer or access personal information outside of New Zealand, which may not have equivalent data protection laws. Before disclosing any personal information to an overseas recipient, we will comply with Information Privacy Principle 12 and only disclose the information where we are satisfied that the recipient provides comparable safeguards, or where you have authorised the disclosure after being informed of the relevant risks.
We will only retain your personal information for as long as reasonably necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, tax, accounting or reporting requirements. When personal information is no longer needed for any purpose for which it may be used or disclosed, we will take reasonable steps to destroy or de-identify it.
The following table sets out our general retention periods by data type. Specific retention periods may vary depending on applicable legal obligations.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account and Identity Data | Duration of Account plus 7 years | Legal and regulatory obligations |
| Financial and Transaction Data | 7 years after the relevant transaction | Tax and accounting obligations |
| Digital Twin Data | Duration of Account; deleted within 90 days of Account closure unless an authorised representative requests otherwise | Service provision and estate management |
| Background Verification Data | Duration of engagement plus 7 years | Regulatory compliance |
| Technical and Usage Data | Up to 2 years | Analytics and fraud prevention |
| Marketing and Communications Data | Until you withdraw consent or unsubscribe, plus 3 years | Record of consent |
| Employment Application Data (unsuccessful) | 12 months after decision | Legal obligations and future opportunities |
| AI Training Data (anonymised and aggregated) | Indefinite once fully anonymised | Model improvement; no longer constitutes personal information |
We may retain your personal information for longer than the periods set out above where there is a complaint, a dispute, or we have reason to believe litigation may occur in respect of our relationship with you.
We use artificial intelligence and machine learning technologies, including AI technologies provided by third parties, in our business operations and the provision of our Services. We will only use AI technologies when legally permitted and necessary for our business operations.
We may use AI technologies for the following purposes:
We use AI technologies to power your digital twin assistant. When you create a digital twin, you expressly consent to us using your Digital Twin Data (including any personal information contained within it) to train, improve and develop our AI models and the digital twin feature. This may include analysing usage patterns, improving AI response accuracy, developing new features, and creating anonymised aggregated data for research purposes.
Withdrawing Consent: You may withdraw your consent to the use of your Digital Twin Data for AI training purposes at any time by contacting us at info@getboby.ai with the subject line "AI Training Opt-Out". Upon withdrawal, we will cease using your Digital Twin Data for AI training from the date of your withdrawal. Your withdrawal will not affect the lawfulness of processing that occurred prior to withdrawal. Where data has already been incorporated into trained AI models in anonymised or aggregated form, it may not be technically feasible to remove it. We will notify you where this applies. Withdrawing AI training consent does not affect your ability to continue using your digital twin.
Where we use service providers who provide AI technologies to us, we take reasonable steps to ensure that such service providers handle your personal information in accordance with applicable privacy law, including through contractual obligations requiring the protection of personal information.
We treat information generated or inferred by AI technologies about individuals as personal information, and you maintain all rights over your personal information regardless of whether AI technologies are used in processing. When using AI technologies with your personal information:
Please read this Privacy Policy carefully. If you provide personal information to us, you understand we will collect, hold, use and disclose it in accordance with this Privacy Policy. You are not required to provide personal information to us, however, if you do not, it may affect our ability to provide you with our Services.
If we receive personal information about you from a third party, we will protect it as set out in this Privacy Policy. If you are a third party providing personal information about someone else, you represent and warrant that you have that person's consent to provide the personal information to us.
You may request access to the personal information we hold about you. An administrative fee may be payable for the provision of such information. In some circumstances, we may be legally permitted to withhold access. If we cannot provide access, we will advise you as soon as reasonably possible and provide our reasons and any available complaint mechanism.
If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us. We will take reasonable steps to promptly correct any such information. If we cannot correct your information, we will advise you as soon as reasonably possible and provide our reasons and any available complaint mechanism.
You may request that we delete personal information we hold about you. We will consider your request and, where we are not required or permitted by law to retain the information, we will take reasonable steps to delete or de-identify it. We will advise you of the outcome of your request and, where we are unable to delete information, we will explain why.
To object to processing for direct marketing, or to unsubscribe from our email database, please contact us using the details below or use the opt-out facilities provided in the communication.
If you wish to make a complaint, please contact us using the details below and provide full details of the complaint. We will promptly investigate and respond to you in writing, setting out the outcome of our investigation and the steps we will take in response.
If you are not satisfied with our response, you may contact:
We are committed to ensuring that the personal information we collect is secure. We have put in place suitable physical, electronic and managerial procedures to safeguard and secure personal information and protect it from misuse, interference, loss and unauthorised access, modification and disclosure.
Our security measures include:
While we are committed to security, we cannot guarantee the security of information transmitted to or by us over the internet. The transmission and exchange of information is carried out at your own risk.
We are committed to complying with our obligations under the Privacy Act 1988 (Cth) and the Notifiable Data Breaches (NDB) scheme. In the event of an eligible data breach that is likely to result in serious harm to one or more individuals:
If you become aware of any actual or suspected security breach affecting your Account or personal information on our Platform, please notify us immediately at info@getboby.ai.
We may enable you to post reviews, comments, photos and other user-generated content. Any content you choose to submit will be accessible by anyone, including third parties not associated with us. We have no control over how others may use or misuse information you make publicly available. We are not responsible for the privacy, security or accuracy of any user-generated content you choose to post, or for the use or misuse of that information by any third party.
We use cookies, tracking pixels and similar technologies on our website and in our emails. For full details of the cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please see our Cookies Policy.
We use Google Analytics Advertising Features. We and third-party vendors may use first-party cookies (such as the Google Analytics cookie) or other identifiers, and third-party cookies (such as Google advertising cookies) together. These may collect Technical and Usage Data about you. You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on.
We may use tools provided by Meta, such as the Meta Pixel and Conversions API. These allow us to measure ad performance and deliver relevant ads on Meta platforms based on your activity on our website. You can manage these preferences through Meta's settings and by adjusting your Off-Facebook Activity settings.
You can block cookies by activating the setting on your browser that allows you to refuse all or some cookies. You can block tracking pixels using ad-blocking or privacy-focused browser extensions. However, if you block all cookies (including essential cookies) you may not be able to access all or parts of our website.
Our website may contain links to other websites. We do not control those websites and we are not responsible for the protection and privacy of any personal information you provide while visiting them. Those websites are not governed by this Privacy Policy. We recommend you read the privacy policy of any third-party website you visit.
If you connect your account with us using a single sign-on service (such as Apple, Facebook or Google), we will collect your personal information from that provider in accordance with the privacy settings you have chosen with them.
The personal information we may receive includes your name, ID, username, handle, profile picture, gender, age, language, list of friends or follows, and any other personal information you choose to share.
We use the personal information received from the single sign-on provider to create a profile for you on our Platform and to provide you with our Services, including personalising your experience and enabling communication with you.
Where we have accessed your personal information through your Facebook account, you have the right to request the deletion of that personal information. To submit a deletion request, please email us at info@getboby.ai and specify which personal information you would like deleted. If we deny your request, we will explain why.
We collect your precise or approximate location via our mobile application for the following purposes:
We collect location data when you use our mobile application and have granted us permission to do so. If you do not want us to use your location data, you should turn off location services in your account settings or in your mobile device settings. If you do not provide geolocation data to us, it may affect our ability to provide certain location-based features of our Services.
Some browsers include a "Do Not Track" feature that signals to websites that you do not want to have your online activity tracked. Our website does not currently respond to Do Not Track signals, as there is no universally accepted standard for how websites should respond to such signals. We will continue to monitor developments in this area.
You can manage your privacy preferences and limit tracking through your browser settings and by reviewing our Cookies Policy.
We may, at any time and at our discretion, update this Privacy Policy by publishing the amended version on our website. We recommend you check our website regularly to ensure you are aware of our current Privacy Policy. Where changes are material, we will notify you by email or by a prominent notice on our Platform.
Under the General Data Protection Regulation 2016/679 (GDPR) and, for UK residents, the UK GDPR and Data Protection Act 2018, individuals located in the EU and UK have additional rights in respect of their personal information (referred to as personal data under the GDPR). This Appendix sets out those additional rights and information about how we process the personal data of individuals in the EU and UK.
We collect and process personal information only where we have a legal basis to do so. The table below sets out our processing purposes and the legal basis we rely on for each.
| Purpose | Type of Data | Legal Basis |
|---|---|---|
| To enable you to access and use our Platform | Identity Data, Contact Data | Performance of a contract with you |
| To assess whether to take you on as a new client | Identity Data, Contact Data, Background Verification Data | Performance of a contract; legal obligation; legitimate interests (preventing fraudulent or unlawful activity) |
| To work with you as a customer or supplier | Identity Data, Contact Data | Performance of a contract with you |
| To contact and communicate with you about our business and support requests | Identity Data, Contact Data, Profile Data | Performance of a contract with you |
| For internal record keeping, administrative and billing purposes | Identity Data, Contact Data, Financial Data, Transaction Data | Performance of a contract; legal obligation; legitimate interests (recovering debts and notifying you of changes) |
| For analytics, market research and business development | Profile Data, Technical and Usage Data | Legitimate interests (keeping our Platform updated and relevant and improving our business) |
| For advertising and marketing | Identity Data, Contact Data, Technical and Usage Data, Profile Data, Marketing and Communications Data | Legitimate interests (developing and growing our business); or consent where required |
| To run promotions and competitions | Identity Data, Contact Data, Profile Data, Interaction Data, Marketing and Communications Data | Legitimate interests (facilitating engagement with our business) |
| To consider employment applications | Identity Data, Contact Data, Professional Data | Legitimate interests (considering your application) |
| To power your digital twin using AI technologies | Profile Data (Digital Twin Data) | Consent; performance of a contract with you |
| To comply with legal obligations | Any relevant personal information | Legal obligation |
If you have consented to our use of your data for a specific purpose, you have the right to withdraw that consent at any time, though this will not affect processing that has already taken place. Where we are relying on legitimate interests, you have the right to object to that use, though in some cases this may mean we can no longer provide our Services to you.
Where we transfer your personal information outside of the EU or UK, we will do so using appropriate safeguards in accordance with applicable data protection laws. This includes only transferring to countries deemed adequate by applicable authorities, or including standard contractual clauses in agreements with overseas recipients.
We will only retain your personal information for as long as reasonably necessary to fulfil the purposes we collected it for, including satisfying legal, regulatory, tax, accounting or reporting requirements. Please see Section 6 of this Privacy Policy for our general retention periods. We may retain information longer in the event of a complaint or anticipated litigation.
In addition to the rights set out in Section 8 of this Privacy Policy, individuals in the EU and UK have the following additional rights:
If you are not satisfied with how we handle your personal information, you have the right to make a complaint to the relevant Data Protection Authority in your jurisdiction. We would appreciate the opportunity to address your concerns first, so please contact us in the first instance using the details below.