APP 1 · Open management of personal information
Privacy Policy
boobookIT · www.boobookit.com.au · Last updated 21 July 2026
Who we are
boobookIT is an Australian AI services business based in Melbourne, Victoria. We deploy AI agents that handle conversational support, workflow automation, document processing, analytics, HR and marketing tasks for Australian organisations. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and how our AI practice follows OAIC guidance.
Questions or requests about your data: call 1800 557 179.
What we collect, and why
- Enquiry details - name, work email, company, optional phone number and message, collected only when you submit our contact form with your active consent. Used solely to respond to your enquiry.
- Marketing consent - a separate, optional opt-in. We never send marketing without express consent (Spam Act 2003), every message identifies us and carries a working unsubscribe, and opt-outs are processed within 5 business days.
- Analytics - only if you opt in via the cookie banner (see Cookies below). IP addresses are anonymised before storage.
We collect the minimum needed (APP 3), and we do not collect sensitive information through this website.
AI-specific commitments
- No training on your data. Personal information and client business data are never used to train AI models - ours or third parties'.
- No silent prompt logging. User-submitted content and prompt history are not logged or stored without explicit, active consent. Where you consent, retention is limited to the period you set.
- Automated decisions are transparent. Agent actions are logged with their reasoning. Decisions that meaningfully affect a person are identified as automated, are reviewable, and always have a human appeal path.
- Data sovereignty by default. Agent processing runs in Australian-region infrastructure. Data leaves Australia only under a documented, client-approved exception.
Cross-border disclosure (APP 8)
Our engineering team operates from Colombo, Sri Lanka. Development and testing use no production customer data. Where any overseas disclosure of personal information is required to deliver a service, we take reasonable steps to ensure the overseas recipient complies with the APPs - including contractual data-protection clauses - and we tell you before it happens. Australian-hosted processing remains the default for all client workloads.
Security & retention (APP 11)
Personal information is encrypted in transit (HTTPS/TLS) and at rest, with access restricted to staff who need it to respond to you. We keep enquiry details only as long as needed for the purpose you gave them, then destroy or de-identify them. If we hold marketing consent, it lasts until you withdraw it.
Access, correction & complaints
You can ask us what personal information we hold about you, ask us to correct it, or withdraw any consent - call 1800 557 179. We respond within 30 days. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.