Privacy
Privacy policy
This document is a ledger. Every entry opens with a claim about personal information, names the mechanism that produces the claim, and points at something a reader can inspect to test it. Assertions with nothing underneath them do not get an entry.
Effective 14 August 2026Version 2.0Privacy Act 1988 (Cth)
1The entity that owns these claims
A privacy policy is worth reading only if somebody identifiable is answerable for it. That is the first entry.
Claim
Responsibility for everything below rests with AGENTIX AI PTY LTD, ACN 695 748 693, ABN 24 695 748 693, whose home state is Queensland, Australia. In the entries that follow, "the company" means that entity and "you" means the individual reading this.
Mechanism
A single entity operates the domain agentixai.fyi, receives mail at the published address, and would operate the evaluation harness described elsewhere on this site. Correspondence is not handled by a trading arm, an agency or a support contractor standing between you and the company.
Evidence
The ACN record sits with the Australian Securities and Investments Commission. The ABN, the entity name and the GST status can be read at abr.business.gov.au without an account and without a charge. Documents are served at the registered office ASIC holds against ACN 695 748 693.
Reach
The ledger governs three things: this website, mail sent to the published address together with the replies to it, and the evaluation harness once it is released. Harness entries are written in the future tense and marked where they appear.
It governs nothing on a site you reach by following a link away from here, including the Australian registers, and nothing your own mail provider does with a message before that message arrives.
2The business of a similar name
Two companies carry almost the same name. Only one of them is answerable for this ledger.
Claim
No personal information belonging to a customer of the firm trading at agentixai.com or agentix.com has ever reached this company, and none could be produced in answer to a request about it.
Mechanism
Nothing is shared between the two: not ownership, not staff, not infrastructure, not a mail domain, not a commercial arrangement of any description. There is no route along which a record could travel from one to the other, in either direction.
Evidence
Mail meant for that firm and delivered here gets a single reply saying it landed at the wrong company, after which the message is deleted rather than filed. Nothing about the sender is retained beyond sending that reply, so a later question about the thread has an accurate answer: it no longer exists.
3The standard we are measured against
The governing instrument is the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles in Schedule 1 to that Act. A reference below to APP 6, or to any other numbered principle, means the corresponding principle in that Schedule.
Claim
All thirteen principles are treated as binding on this company in full, and requests are handled on that footing rather than on the footing of what a small business could get away with.
Mechanism
Section 6D of the Act lifts the principles off most businesses turning over $3 million or less in a year. This company's turnover sits under that figure, so a narrow reading would place it outside. That reading is not being taken. Several of the exceptions in section 6D would draw a business of this shape back inside as it grows, and in any event a turnover line says nothing about whether the information matters to the person it describes.
Evidence
APP 1.4 sets out what a compliant policy must contain: the kinds of information collected and held, how and why it is collected, held, used and disclosed, how an individual gets access and correction, how a complaint is made and handled, and whether information goes to overseas recipients and to which countries. Each of those has its own numbered entry in this ledger, so the list can be walked against the Schedule rather than hunted for inside paragraphs.
Also applying
- Spam Act 2003 (Cth), governing commercial electronic messages, which requires consent, an identified sender and a working unsubscribe.
- Do Not Call Register Act 2006 (Cth), governing unsolicited telemarketing calls.
- Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), whose guarantees survive anything written on this site.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, which has an entry of its own below.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which created a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added disclosure duties for certain automated decisions. Each of those has an entry below.
4Inventory of what is held
An inventory is the only honest way to answer the question "what do you have on me". This is the whole of it.
| Record | Fields in it | Why it exists | Clock |
|---|---|---|---|
| General correspondence | Sender address, any name given, message body, mail headers, timestamps | Answering the message, and knowing what was said last time | 24 months from the final message in the thread |
| Access, correction and deletion files | The above, plus the identity check performed and the decision reached | Satisfying APPs 12 and 13, and showing afterwards how a request was handled | 7 years from closure |
| Complaint files | The above, plus the outcome and any regulator reference number | Answering the complaint, and answering a regulator about the same complaint | 7 years from closure |
| Security reports | Reporter address, the report, reproduction steps, credit preference | Repairing the fault and crediting the person who found it | 7 years from closure |
| Web server request logs | IP address, timestamp, path requested, response code, user agent, bytes served | Serving the pages and defending the domain against abuse | Held by the hosting provider on its own cycle; no copy is exported or kept by the company |
Claim
The table above is complete. A category of personal information absent from it is a category this company does not gather.
Mechanism
There is no submission box anywhere on the domain, no account system, no login, no measurement script and no advertising tag. Absent those, a category has no route by which it could arrive without somebody deliberately adding one, and adding one would mean editing this table first.
Evidence
Read the page source, or open the network panel of any browser and load every page on this domain in turn. The requests you will see are for the markup, one stylesheet, one small navigation script, whichever images that particular page carries, and the typeface files named in the cookie notice. Nothing else is fetched, so nothing else has anywhere to report to.
5Material carried inside an evaluation run
This entry covers material that arrives inside an evaluation run: a repository, the prompts driving it, and whatever the agent reads or writes while the run is under way. It is published so that a prospective customer reads the handling rules while deciding, rather than after committing.
Claim
Material submitted for evaluation is processed for the run it was submitted for, and for no other purpose.
Mechanism
A run happens inside a disposable container built from a recorded image. The submitted repository, prompts and configuration are mounted into that container, the agent acts, the finishing state is diffed against the image, and the container is destroyed. Personal information can enter a run incidentally, carried in by an author name on a commit, an address inside a test fixture, or a customer identifier inside a sample log. From the moment such material arrives it is treated as personal information under this ledger, exactly as correspondence is.
Evidence
Each run produces a record listing the image hash, the transcript hashes, the end state diff and the software versions involved. That record is what a customer reads to establish precisely what the run read and precisely what it wrote, without having to rely on a summary of it.
Boundary
Submitted material is not used to train or tune any model, is not shown to another customer, and does not appear in any published figure from which a person or a codebase could be identified. Where a run reaches a live third-party service instead of staying inside its container, the record marks that run unsealed, because from that point the company can no longer account for everything the run touched.
6Purposes, and the limits on them
Claim
Personal information is collected only where it is reasonably necessary for a function this company actually performs, which is the test APP 3 imposes.
Mechanism
The functions are these, and there are no others:
- Reading and answering correspondence sent to the published address.
- Handling requests for access, correction and deletion.
- Investigating and answering privacy complaints.
- Repairing security faults that somebody has reported.
- Serving this website and defending the domain against abuse.
- Running evaluations a customer has commissioned, once the harness is released.
Evidence
Every row of the inventory maps onto one of those six functions. A row mapping onto none of them would have no purpose justifying its existence and no basis for the clock attached to it, which is the test to apply should a new row ever appear in that table.
Secondary use
APP 6 permits a related secondary use where a person would reasonably expect it. Exactly one is made here: a closed complaint file is kept so that the same complaint can be answered again if a regulator asks about it. Sensitive information within the meaning of APP 3.3, meaning health, racial or ethnic origin, political or religious affiliation, sexual orientation, criminal record, biometric or genetic material, is never sought, and no record described above has a field waiting to receive it.
7Notice at the point of collection
Claim
Everything APP 5.2 requires you to be told is visible at the moment of collection, rather than discovered afterwards.
Mechanism
There is exactly one collection point on this site: the published mail address. The page carrying that address names the company behind it, states why a message is kept, states how long it is kept for, gives the escalation route to the regulator, and links to this ledger. All of that sits above the point at which anybody decides to write.
Evidence
Open the contact page and read the identity table at its foot before sending anything. The retention figures printed there are the figures in the inventory above, and they were published before the first message arrived rather than fitted around it later.
8Dealing with us under no name
Claim
APP 2 gives you the option of not identifying yourself, or of using a pseudonym, and that option is real here rather than nominal.
Mechanism
Reading anything on this domain requires no account and no identifier. Writing in requires an address capable of receiving a reply, and nothing beyond it. A message from a pseudonymous mailbox receives the same answer, on the same clock, as a message signed with a full legal name.
Boundary
A request for access, correction or deletion has to attach to a record, and where the only record is an email thread, control of the mailbox that produced that thread is the thing tying you to it. A request arriving from some other address is therefore asked to demonstrate the connection before records are handed over, since handing one person's correspondence to another would itself breach APP 6.
9Information that arrives unasked
Claim
Unsolicited personal information that this company would not have been permitted to collect is destroyed, not quietly absorbed into a file.
Mechanism
APP 4 requires a decision, within a reasonable period, about whether unsolicited material could lawfully have been collected in the first place. Where it could not, it is destroyed or de-identified. In practice that means an attachment full of a third party's data that had no business being sent: it comes out of the thread, and the sender is told that it came out.
Evidence
The removal is written into the thread it came from, so a later question about what became of that attachment has a dated answer rather than a shrug.
10Who else sees it, and where they sit
| Recipient | Role | What reaches them | Where |
|---|---|---|---|
| Hosting and content delivery provider | Serves the static pages of this site | Request metadata: IP address, path, user agent, response code | Infrastructure in more than one country |
| Mail provider | Carries and stores the published mailbox | Message content, headers, attachments | Infrastructure in more than one country |
| Typeface host | Serves the two families the pages request | The IP address making the request, and the browser making it | Global network |
| Professional advisers | Legal advice on a specific matter | Only the material that matter requires | Australia |
| Regulator, court or law enforcement | Where a law, warrant or order compels disclosure | Only what is compelled, and no more | Australia |
Claim
Personal information held by this company is not sold, rented, bartered or handed to anybody to use for ends of their own.
Mechanism
Disclosure occurs in three situations only: to a service provider in the table above, which processes on instruction and for no purpose of its own; to a professional adviser on a specific matter; and where a law or a court order compels it. There is no advertising relationship, no data broker, no affiliate arrangement and no analytics vendor, because no such party appears anywhere in the stack that serves this domain.
Evidence
The table names every category of recipient. A recipient outside it would be a departure from this ledger, and reportable to the Commissioner as exactly that. Where a compelled disclosure is made and the law permits us to say so, you are told.
11Marketing, and the Spam Act
Claim
Writing to this company subscribes you to nothing, and an address cannot join a list merely by having been used.
Mechanism
No mailing list exists in any system this company operates, so there is nothing for an address to be appended to. Replies stay inside the thread that prompted them. APP 7 restricts direct marketing by an organisation, and the Spam Act 2003 (Cth) requires consent, an identified sender and a functioning unsubscribe on any commercial electronic message.
Evidence
Should a list ever be started, it will be opt-in at the point of joining, identified in every message and unsubscribable in a single step, and this entry will be rewritten to say so, with a date on it, before the first message goes out. Until then the position is checkable the easy way: write in, and watch what does not arrive afterwards.
12Disclosure outside Australia
Claim
Where personal information crosses a border, responsibility for it does not stay behind at the border.
Mechanism
APP 8.1 requires reasonable steps before an overseas recipient is given personal information, to ensure that recipient handles it consistently with the principles. The providers serving this site and carrying its mailbox run distributed infrastructure, and processing realistically occurs in Australia, the United States, the European Union and Singapore. Before a provider is engaged, its published terms are read for a binding commitment to handling of that standard, and a provider unwilling to give one is not engaged.
Evidence
Section 16C of the Privacy Act makes this company answerable for an overseas recipient's mishandling as though the mishandling were its own. That provision is why the destinations are listed by name here rather than gestured at as global infrastructure: a named list can be checked against reality, and a gesture cannot.
Boundary
The countries named are the destinations known to the company at the effective date on this page. A change to that set is a change to this document, carrying its own version number and date, rather than a silent adjustment nobody announced.
13Government related identifiers
Claim
No government related identifier belonging to you is adopted, used or disclosed by this company as its own means of identifying you.
Mechanism
APP 9 restricts precisely that practice. No record described in the inventory carries a field for a tax file number, a Medicare number, a driver licence number or a passport number, and none of those is requested when a request has to be tied to a person.
Evidence
Identity for an access or deletion request is established through control of the mailbox the correspondence came from, which is why no document ever has to be photographed and sent in. The ACN and ABN printed throughout this site identify the company itself, published so a stranger can check it, and they identify nobody who writes in.
14Accuracy of what is recorded
Claim
Records are kept accurate, current and complete to the degree the purpose behind them requires, which is what APP 10 asks for.
Mechanism
Correspondence is stored as it arrived rather than as somebody's summary of it, so nothing is lost to paraphrase and no note about you exists that you have not already seen. Where a correction is accepted, the record is annotated with the correction and its date instead of being overwritten, so the sequence remains readable afterwards.
Evidence
A correction produces a written outcome naming what changed and when. Where a correction is declined, the reasons are written down as APP 13.5 requires, and a statement of your view can be attached to the record so that anybody reading it later reads both accounts together.
15Security of what is recorded
Claim
Reasonable steps are taken to protect held information against misuse, interference and loss, and against unauthorised access, modification or disclosure, as APP 11.1 requires.
Mechanism
- Every page on this domain is served over TLS, and a request arriving without it is redirected.
- The published mailbox is protected by multi-factor authentication, and access to it is confined to the people running the company.
- The site is static files. No database sits behind it, no administrative panel, and no server-side code accepting input, which removes the categories of flaw that most often expose a small company's records.
- Evaluation material, once the harness runs, exists inside a container for the life of that run and is destroyed with it, apart from the record the customer commissioned.
Evidence
The certificate is readable from the padlock in your address bar. The response headers this domain sends, including its content security policy, can be dumped with any HTTP client in one command, and they will show you which origins a page here is permitted to talk to at all.
Boundary
No transmission across a public network is perfectly secure, and a policy claiming otherwise would be describing an ambition rather than a mechanism. What the steps above do is narrow the ways a record here can go wrong. They do not abolish them, which is why the breach entry below exists and is specific about dates.
16Retention, and destruction after it
Claim
Nothing is retained on the reasoning that it might come in useful one day. Every record carries a period, and every period runs from a defined event.
Mechanism
APP 11.2 requires destruction or de-identification once information is no longer needed for any permitted purpose. The clocks are the ones printed in the inventory: 24 months from the last message in a general thread; 7 years from closure for a privacy request, a complaint file or a security report; the life of the run plus whatever the commissioning contract specifies for evaluation material; and the hosting provider's own cycle for request logs.
When a period expires the thread goes from the mailbox, and any working copy taken from it goes at the same time. Backup media age out on their own schedule, so a deleted item can survive in a backup for a short interval after deletion. It is not restored during that interval and it is not searchable.
Evidence
The seven year figure is not arbitrary. It sits at the outer edge of the periods within which a complaint or a claim about the same subject matter can still be brought, so a file outlives the dispute it might have to answer and then stops. The twenty-four month figure marks the point past which an ordinary enquiry thread has no remaining use to either side of it.
17Deleting what is held about you
Claim
Deletion of data held about you can be asked for at any time, and the request does not have to arrive with a reason attached to it. In practice what that means here is the correspondence in the mailbox, since correspondence is what this company holds.
Mechanism
Write to [email protected] with Delete my data at the front of the subject, from the address the correspondence came from. The thread comes out of the mailbox along with any working copy taken from it, inside the same thirty days that govern an access request.
Evidence
You receive written confirmation naming what was deleted and the date it went. Where something had to stay, the confirmation names that too, with the reason, rather than reporting a clean sweep that did not occur.
Boundary
A complaint file the Commissioner may still ask about is retained until its seven years expire, since destroying it would leave both sides unable to evidence what happened. That is the only category ordinarily held back against a deletion request, and where it applies the reply says so in the same breath as reporting the rest gone.
18Access and correction
Claim
You can obtain what is held about you, and have what is wrong put right, inside thirty days and without paying for either.
Mechanism
APP 12 governs access and APP 13 governs correction. Write with Privacy request at the front of the subject, from the address the material relates to. The reply carries the records themselves and not a description of them, because a description is the company marking its own homework.
Evidence
APP 12.4(b) fixes thirty days for an organisation's response. APP 12.9 requires written reasons and a complaint mechanism where access is refused, and APP 13.5 requires the same where correction is refused. A refusal issued here follows that shape, so it can be measured against the Schedule instead of against our assurance that it was fair.
Boundary
APP 12.3 lists the grounds for refusing access, among them an unreasonable impact on another person's privacy, material relating to anticipated legal proceedings, and information whose release would prejudice an investigation into unlawful activity. Where such a ground applies, the reply names it. Where the obstacle is simply a third party's presence in a document, the usual answer is to supply the document with that person's details removed rather than withhold the whole of it.
19Children and young people
Claim
Neither this website nor the harness is directed at children, and neither is built in a way that would attract them.
Mechanism
The subject matter is the evaluation of autonomous software, addressed to the engineers and buyers who commission that work. Nothing on the domain creates an account, builds a profile, offers a social feature, gamifies anything or carries advertising, so none of the surfaces that ordinarily draw a child in exists here to be drawn to.
Evidence
Where correspondence makes plain that the writer is under sixteen, the thread is answered briefly and then deleted rather than held for the ordinary twenty-four months, and a parent or guardian may exercise access, correction and deletion on the child's behalf. The Commissioner is developing a Children's Online Privacy Code under the Privacy and Other Legislation Amendment Act 2024 (Cth); once that Code is registered, this entry gets rewritten against it and dated accordingly.
20Automated decisions
Claim
No automated process operated by this company makes a decision about you carrying a legal effect, or anything similarly significant.
Mechanism
Correspondence is read and answered by a person. The harness produces verdicts about a software run: whether an assertion passed, whether a claim in an agent's closing message is supported by the diff. Those verdicts describe a machine and a piece of software. None of them scores, ranks or profiles a human being.
Evidence
The 2024 amendments require a privacy policy to disclose where automated decision-making materially affects individuals. This entry is where such a disclosure would live, and should the position ever change, the change appears here with a version number against it rather than buried inside a general clause somewhere else.
21Breaches and the notification scheme
Claim
A suspected eligible data breach is assessed within thirty days and notified wherever the statutory threshold is met.
Mechanism
Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, engages where unauthorised access to, unauthorised disclosure of, or loss of personal information is likely to result in serious harm and the risk cannot be remedied. On becoming aware of a suspected breach the company contains it first, then runs the assessment for which section 26WH allows thirty days, and records the date awareness began so that the clock can be audited afterwards by somebody else.
Evidence
Where the threshold is met, the statement section 26WK requires goes to the Commissioner and to each affected individual, carrying the company's identity and contact details, a description of what happened, the kinds of information involved, and the steps the recipient should take in response. Where notifying individuals directly is impracticable, section 26WL permits publication instead, and any such publication would appear on this website.
Posture
Where the threshold is genuinely arguable, the choice made here is to notify. A report that turns out to have been unnecessary costs this company some embarrassment. A breach kept quiet because the harm looked debatable costs somebody else their information, and the two are not comparable quantities.
22The statutory tort
Claim
The statutory tort for serious invasion of privacy is a right you hold against this company directly, and nothing published here tries to blunt it.
Mechanism
The Privacy and Other Legislation Amendment Act 2024 (Cth) introduced a cause of action covering intrusion upon seclusion and misuse of information, available where a person in your position had a reasonable expectation of privacy, where the invasion was serious, and where it was intentional or reckless. It runs alongside the complaint route to the Commissioner rather than replacing it.
Evidence
Read the site terms beside this page. Neither document contains a waiver of the tort, an agreement not to sue, a compulsory arbitration clause or a foreign forum selection, and the liability entry over there is expressly subject to rights that cannot be excluded.
23What this site stores in your browser
Claim
These pages ask your browser to retain nothing that would let this company recognise you on a later visit.
Mechanism
The site is static markup and one stylesheet, plus a short script whose entire job is opening the navigation on a narrow screen. No cookie is written under this domain, no value is placed into local or session storage, and no measurement or advertising tag is loaded. The pages do request typeface files from Google's font hosts, which is a request to a third party and is described in full in the notice below.
Evidence
Visit every page on this domain, then open the storage panel of your browser's developer tools and look under this origin. The cookie notice sets out what to look at, what the typeface request carries with it, and how to prevent that request if you would rather it did not happen.
24Complaints, and where they escalate
Claim
A privacy complaint made to this company produces a decision on the merits, and an escalation route that runs without our cooperation.
Mechanism
Write with Privacy complaint at the front of the subject. Receipt is confirmed within five business days. Within thirty days you get an outcome naming what was examined, what was found, what changed as a result, and what did not change together with the reason it did not.
Evidence
The Office of the Australian Information Commissioner accepts privacy complaints against this company independently of anything we think about them:
- Online at oaic.gov.au
- By post to GPO Box 5218, Sydney NSW 2001
- By telephone on 1300 363 992
Lodging a complaint costs nothing, needs no representative and needs no consent from this company. In the ordinary course the Commissioner looks for the matter to have been raised with us first, with thirty days allowed to elapse before the complaint is brought.
25Readers outside Australia
Claim
The rights described in this ledger are extended to every reader, wherever that reader happens to be sitting.
Mechanism
This company is Australian, its records are governed by Australian law, and the principles in Schedule 1 are the ones every entry above is written against. None of those entries is conditioned on residence, so access, correction, deletion and complaint operate identically for a reader in Brisbane and a reader anywhere else on the map.
Evidence
Where the law where you live grants something the Australian principles do not, name it in your message. It gets answered on its own terms and against its own timetable, rather than met with an explanation of why a different statute governs over here.
26How this document changes
Claim
An amendment to this ledger is dated and numbered, never slipped in between one visit and the next.
Mechanism
The heading of this page carries the effective date and the version in force. An amendment that narrows a right, lengthens a retention period or widens a purpose is published on the site before it takes effect, and where the company holds an address for somebody the change affects, it goes there as well.
Evidence
The version number at the top of this page is the operative one. An earlier version can be requested by mail and will be sent as it stood, so that an argument about what the policy used to say gets settled from the text rather than from anybody's memory of it.
27Writing to us about any of it
One address carries the whole of it, and the subject lines that route a message are listed on the contact page.
- Registered name
- AGENTIX AI PTY LTD
- ACN
- 695 748 693
- ABN
- 24 695 748 693
- Home state
- Queensland, Australia
- Where to write
- [email protected]
- Access, correction, deletion
- Thirty days, at no charge, under APPs 12 and 13
- Complaints
- Receipt confirmed within five business days, outcome within thirty
- Regulator
- Office of the Australian Information Commissioner, oaic.gov.au, GPO Box 5218, Sydney NSW 2001, 1300 363 992
- Service of documents
- The registered office ASIC holds against ACN 695 748 693
The state of play at the effective date. The personal information this company holds is correspondence sent to its published address, nothing more. Entries describing evaluation runs set out how material that arrives with a run is handled, published ahead of any given run so a customer can read the rules while deciding. Your rights are on no such timetable: access, correction, deletion and complaint all operate today, against the correspondence that exists today.