Privacy Policy
Last updated: 2026-08-10
Overview
EYwALINK ("we", "us", "our") is committed to protecting your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). This policy explains how we collect, use, store, and protect your personal data when you interact with our website, engage our services, or communicate with us about AI solutions.
1. Information We Collect
Directly Provided
- Name and contact details (email address, phone number)
- Company name and job title (if provided)
- Project requirements and technical specifications
- Enquiry messages and communication history
Automatically Collected
- IP address and approximate geographic location
- Browser type and device information
- Pages visited and time spent on site (via self-hosted Plausible analytics)
- Referral source (UTM parameters, referring URL)
2. How We Use Your Information
- Respond to your enquiries and provide requested information
- Deliver consulting services under engagement agreements
- Send project updates, invoices, and relevant communications
- Improve our website and services through analytics
- Comply with legal obligations and regulatory requirements
3. Data Processing Roles
Under the Privacy Act 1988 (Cth), the roles EYwALINK and you play in data processing depend on the context:
Website Visitors and Prospects
- EYwALINK is the APP entity (controller). We determine the purposes and means of collecting, using, and storing your personal information submitted through our website or communications.
Client Engagements
- You are the APP entity (controller). You determine the purposes and means of processing your own data (including any personal data of your employees, customers, or other individuals).
- EYwALINK is the engaged entity (processor). We process personal data on your behalf, solely in accordance with your documented instructions as set out in the applicable Statement of Work (SOW) and Master Services Agreement (MSA).
- Where an engagement involves the processing of personal data, a Data Processing Agreement (DPA) is executed alongside the MSA. The DPA governs the specific obligations, security controls, sub-processor restrictions, and data subject rights procedures applicable to that engagement.
This role distinction is consistent with MSA Section 7 (Data Protection and Privacy) and the DPA for engagements processing personal data.
4. Data Storage & Security
Enquiry data is stored and encrypted at rest and backed up securely. Client engagement data is stored on client-controlled infrastructure wherever practicable. Where EYwALINK holds client data, it is encrypted at rest (AES-256) and in transit (TLS 1.3). Your personal information is never shared with third parties without your consent, except as required by law or as described in this policy.
5. Data Retention
- Website enquiries: 24 months after last contact
- Client engagement records: 7 years post-engagement (tax and statutory compliance)
- Client data processed during engagements: retained only for the engagement duration, then returned or destroyed within 14 days
- Analytics data: Aggregated only, anonymised after 14 days
Where a law or regulatory obligation requires a longer retention period, we retain the data for the minimum period required. Upon expiry of the retention period, data is securely destroyed using NIST 800-88 compliant methods.
6. Your Rights
Under the APPs, you have the right to:
- Access your personal data held by us
- Request correction of inaccurate information
- Request deletion of your data (subject to retention obligations)
- Opt out of marketing communications at any time
- Lodge a complaint with the Office of the Australian Information Commissioner
APP 12 — Access Request Procedure
- Submit a written request to privacy@eywalink.org with sufficient identification.
- We will respond within 30 days, providing access or a written explanation for any lawful refusal (e.g., serious threat to life, privacy prejudice, legal privilege).
- No fee applies for access requests under the APPs.
APP 13 — Correction Request Procedure
- Submit a correction request to privacy@eywalink.org specifying the data and the proposed correction.
- We will take reasonable steps to correct the data within 14 days and notify you of the outcome.
- Where we have disclosed the inaccurate data to third parties, we will take reasonable steps to notify those recipients of the correction.
For client engagements, your data handling rights are further detailed in the Data Processing Agreement (DPA) executed under our Master Services Agreement. To exercise any of these rights, email privacy@eywalink.org.
7. Cookies & Analytics
Our website uses self-hosted Plausible Analytics, a cookieless analytics tool. It does not use cookies, does not collect personal data, and cannot identify individual visitors. Only aggregated, anonymised usage statistics (page views, referral sources, approximate geographic region) are collected. We do not use Google Analytics, Facebook Pixel, or any third-party tracking cookies. No personally identifiable data is sent to external services.
8. Client Engagement Data
When you engage EYwALINK's services under a signed Master Services Agreement (MSA), the following principles apply:
- Data ownership: You retain full ownership and control of all your data. EYwALINK processes your data solely as a service provider acting on your instructions (see MSA Section 7).
- Purpose limitation: Your data is used only for the purposes specified in the applicable Statement of Work (SOW).
- No model training: We do not use client data to train our own AI models, benchmarks, or tools.
- Infrastructure: Where possible, data is processed on your own infrastructure (air-gapped, network-isolated, or your cloud environment). No data leaves your infrastructure unless the SOW explicitly requires it.
- Destruction: Upon engagement completion, we return or securely destroy all your data within 14 days.
- DPA: For engagements involving personal data, a Data Processing Agreement (DPA) is executed alongside the MSA, detailing our APP compliance obligations, security controls, sub-processor restrictions, and audit rights.
- Sub-processors: EYwALINK will not engage any sub-processor without prior written consent from the client, except for essential infrastructure providers disclosed in the DPA.
9. AI Model Data Handling
EYwALINK's services involve AI models. Our approach to AI data handling:
- Training data: Data used to fine-tune models for a client belongs exclusively to that client. It is processed in isolated compute environments with no cross-engagement data leakage.
- Inference data: Data submitted to AI models during use (prompts, queries, context) is processed in real-time and not persisted unless explicitly required by the engagement. For self-hosted models on client infrastructure, no inference data is transmitted to EYwALINK.
- Vector stores: Embeddings and vector indices created from client data are stored on client-controlled infrastructure and subject to the same security controls as the underlying data.
- Model weights: Fine-tuned model weights produced during an engagement belong to the client. EYwALINK does not retain model weights after delivery.
- Synthetic data: Synthetic data generated during an engagement is treated as personal data if it can be linked back to an identifiable individual, and handled accordingly.
10. Model Provenance
EYwALINK uses open-source AI models for client engagements. All foundational models are sourced from publicly available, licence-compliant repositories. We use inference runtimes such as Ollama and vLLM, and model frameworks such as LangGraph, all under open-source licences. We do not use proprietary or commercially licensed AI models (e.g., OpenAI, Anthropic, Google) for client data processing. A Software Bill of Materials (SBOM) listing all model sources and licences is provided with each engagement deliverable.
11. Cross-Border Data Transfers
EYwALINK primarily processes data within Australian infrastructure. Data is not transferred outside Australia unless explicitly required by a client engagement and authorised under our DPA.
Under APP 8 (cross-border disclosure of personal information), EYwALINK takes the following steps before any cross-border transfer:
- We take such steps as are reasonable to ensure the recipient does not breach the APPs in relation to the personal information; or we ensure you have consented to the disclosure;
- We ensure the destination jurisdiction provides an adequate level of data protection, or we put in place appropriate contractual safeguards (e.g., Standard Contractual Clauses where applicable, or equivalent contractual obligations binding the recipient to APP-equivalent standards);
- Client provides written authorisation specifying the destination jurisdiction, the categories of data, and the purpose of the transfer;
- The transfer is documented in the applicable SOW and DPA, including the recipient's identity, data handling obligations, and the client's right to audit.
For engagements involving cross-border collaboration (e.g., with APAC partners), the DPA includes specific provisions for APP 8 compliance, including mandatory data localization where the client requires it.
12. Notifiable Data Breaches
EYwALINK is subject to the Notifiable Data Breaches (NDB) Scheme under the Privacy Act 1988 (Cth). Where we become aware of an eligible data breach — access or disclosure of personal information that is likely to result in serious harm to any individual — we will:
- Assess the breach as soon as practically and reasonably possible;
- Notify affected individuals without unreasonable delay, including what happened, what data was involved, and what we are doing in response;
- Notify the Office of the Australian Information Commissioner (OAIC) concurrently with notifying affected individuals;
- For client engagements where the breached data belongs to the client, notify the client immediately and cooperate fully with the client's own notification obligations.
Our incident response procedures are documented in our internal security policies and are available for review under the DPA for engagements processing personal data.
Governing Law
This Privacy Policy is governed by the laws of Victoria, Australia. In the event of any inconsistency between this policy and our Master Services Agreement or Data Processing Agreement, the following hierarchy applies:
- The DPA governs for data protection and privacy matters under that specific engagement;
- The MSA governs for general engagement terms, including Section 7 (Data Protection and Privacy);
- This Privacy Policy governs for website visitors and prospects not under an engagement.
Contact
For privacy-related enquiries or to exercise your data rights, contact privacy@eywalink.org. For general enquiries, contact info@eywalink.org.