Legal
Privacy policy
Personal information behaves like evidence. It is worth something only when its provenance is known, and it becomes a liability the moment it is held without a reason. This document is the handling standard that follows from treating it that way.
Effective 14 August 2026Version 2.0Privacy Act 1988 (Cth)30 clauses
1The standard this document sets
ARCUS AI PTY LTD keeps a record of the people who deal with it. That record is small, and this document is the standard it is held to. It states what may be entered into the record at all, on whose authority each item was entered, whose hands it may pass through afterwards, how long it survives, how it is destroyed, and what a person named in it may compel us to do.
The register is deliberate. An evidence handling procedure asks four questions of any item it holds, and those questions transfer intact to personal information: where did this come from, who has touched it since, is it still needed, and can its handling be reconstructed after the fact. A policy that cannot answer those four about its own record is a description of good intentions rather than a control.
The standard applies to arcusai.fyi, to correspondence sent to the address published on this site, and to the evaluation tooling supplied under the same name. Clauses governing the tooling rather than the website say so in their opening line, so that a reader can tell at a glance which part of the record any clause is about.
2The custodian of the record
The custodian is ARCUS AI PTY LTD, an Australian proprietary company in New South Wales, ACN 697 547 505, ABN 82 697 547 505. Arcus is a trading name of that company and there is no second entity standing behind the brand. Under the Privacy Act the company is an APP entity, and the obligations in this document bind it in that capacity.
Custody is not delegated. The company answers for the record even where a supplier physically holds part of it, and the clause on chain of custody names every function that does. Where this document says we, it means the company named above, acting through whoever is doing the work that day.
Everything owed under this standard is claimed at [email protected]. That single address carries requests, objections, corrections and complaints alike, and the clause at the end sets out what to put in the subject line so that a request is recognised as one on arrival.
3The governing instrument
The instrument is the Privacy Act 1988 (Cth) and, within it, the thirteen Australian Privacy Principles set out in Schedule 1. Those principles are the operative text. This document is subordinate to them: where a clause here reads more narrowly than the principle it implements, the principle governs and the clause is to be read as an undertaking to do more, never as a licence to do less.
The Office of the Australian Information Commissioner administers the Act, issues the guidance the principles are read against, and hears complaints from individuals about how an entity handled their information. A separate statutory cause of action for serious invasion of privacy was inserted into the Act by the Privacy and Other Legislation Amendment Act 2024 (Cth) and is pursued in the courts. It is available to you independently of anything written here, and no clause in this document affects it.
Two other statutes touch this record at the edges. The Spam Act 2003 (Cth) governs commercial electronic messages and is dealt with under the marketing clause. The Corporations Act 2001 (Cth) obliges the company to display its name and ACN on public documents, which is why both appear in the footer of every page.
4What is admitted to the record
Three classes of item are admitted, and the table is exhaustive. There is no second inventory kept elsewhere and no category held back under a general heading such as technical data.
| Class of item | Contents | Authority for admitting it | Physically held by | Disposal |
|---|---|---|---|---|
| Correspondence | Whatever name you sign, the address the message came from, its subject and body, any attachment, and the replies that follow in the same thread | APP 3.2: reasonably necessary in order to answer a person who wrote to us | The mail provider, plus the company mailbox | Two years after the exchange closes |
| Request logs | The network address a request came from, the moment it arrived, the path asked for, the status returned, the size of the response, the declared browser string and any referring page | APP 3.2: reasonably necessary to serve pages and to absorb automated abuse at the edge | The hosting and delivery provider | On the provider's own cycle, presently under thirty days |
| Verification material | Only what a particular request makes necessary, and only where a right is asserted over the record. Usually nothing beyond a reply from the address already on file | APP 3.2, read with APP 12.5 and APP 13, which require an entity to be satisfied of identity before releasing or altering a record | The company mailbox, briefly | Destroyed within seven days of the check |
Anything outside those three classes has no field to sit in. There is no account system on this website, no form that submits anywhere, no newsletter, no comment facility, no advertising identifier and no measurement product observing your visit. A reader who wanted to test that claim rather than accept it can open the network panel of a browser and watch what a page actually requests, which takes about a minute and settles the question better than a paragraph of assurance.
5Provenance: how each item arrives
Provenance is recorded because the answer to who supplied an item determines what may lawfully be done with it. APP 3.6 requires collection from the individual concerned unless that is unreasonable or impracticable, and the record here divides cleanly along that line.
- Supplied by you, knowingly. Correspondence, and anything you choose to put inside it. You control the whole of this class, including how much of your name it carries.
- Generated by machinery in the ordinary course. Request logs. Nobody types these and nobody chooses their contents. They come into existence because a server that answers a request writes down that it did.
- Supplied by somebody else about you. This happens when a correspondent names a third party in a message. Where that occurs and the person is identifiable, APP 5.2 requires reasonable steps to make them aware of the collection, and we take those steps unless doing so would itself disclose more than leaving it alone.
No item enters the record from a data broker, a list vendor, an enrichment service or a scrape. The company does not buy contact information, does not look up the employer behind a domain name, and does not append anything to a message from an outside source. An item without a traceable origin is treated as inadmissible and is deleted rather than kept on the chance it becomes useful.
6Categories excluded by construction
Some exclusions are worth stating because a reader cannot verify an absence from the outside. Each of these is a design constraint rather than a current preference, which means changing one requires an amendment under the clause at the end and cannot happen quietly.
- No behavioural profile is assembled. Pages are not correlated into a picture of what one reader looked at across a visit.
- No persistent identifier of any kind is issued to a visitor, so there is nothing that could be joined across sessions even in principle.
- No precise location is collected. A network address permits a coarse geographic inference and that inference is neither recorded nor acted on.
- No payment instrument is accepted anywhere on this site, so no card data, bank detail or billing address exists to be protected.
- No part of the record is used as training material for a machine learning model, whether operated by this company or by anybody else.
- No information is sold, rented, bartered or supplied to another party for that party's own purposes, and no arrangement of that kind is contemplated.
7Sensitive material and identity documents
Sensitive information is a defined class under section 6 of the Privacy Act. It covers health information, biometric material, and information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and membership of a professional or trade association. APP 3.3 sets a higher bar for it: an organisation may collect it only with the consent of the individual and only where it is reasonably necessary for a function the organisation actually performs.
This company does not seek sensitive information and has no function that needs it. One realistic route exists by which it could nonetheless arrive, and it is described here rather than left implicit, because a standard that only covers the easy case is not a standard.
Where an identity document could carry it
If you assert a right over the record and the ordinary check described in the next clause cannot settle who you are, we may have to ask for something better. A driver licence, a passport page or a similar document establishes identity well, and it also carries a photograph, a date of birth and sometimes material that falls squarely inside the sensitive class. Asking for one therefore has a cost, and the cost lands on you rather than on us.
The handling that follows from that is set out plainly. We ask for the minimum that would resolve the specific doubt, and we say what the doubt is rather than requesting documents as a reflex. We accept a copy with everything irrelevant blacked out, and a redacted copy is not treated as an inferior answer. We do not require certification, notarisation or an original. Sending the document is the act of consent for the purposes of APP 3.3, it is voluntary, and it can be refused without penalty to the underlying request.
Once the check is done, the copy is destroyed within seven days and what survives is a single line recording that identity was verified, on what date, and by what class of document. That line holds no image, no number and no content from the document itself. Consent to hold the copy may be withdrawn at any point before destruction, in which case it is destroyed at once; withdrawal cannot undo a check already completed, and this document does not pretend otherwise.
Where you would rather not send anything of the kind, say so. We will look for another route, and where no route exists that would let us release a record safely, we will tell you that in writing and explain exactly what stood in the way. A request is never abandoned in silence.
8Government related identifiers
APP 9 restricts what an organisation may do with an identifier assigned to a person by a government agency. A tax file number, a Medicare number, a passport number, a driver licence number and a Centrelink reference are all identifiers of that kind, and the restriction is deliberately strict.
No such identifier is adopted as this company's own way of referring to you, used as a key to organise the record, or disclosed to anybody. None is requested at any point. Where one is visible on a document supplied for verification, it may be obscured before the copy is stored, it is never transcribed into a system, and it disappears with the copy when the copy is destroyed.
The company's own registration numbers, the ACN and the ABN, identify the business rather than a person and sit outside APP 9 entirely. They are published on every page of this site on purpose, so that anyone reading can confirm at the source who they are dealing with.
9Dealing with us without being named
APP 2 gives you the option of not identifying yourself, or of using a pseudonym, unless identification is impracticable or the law requires otherwise. That option is real here and is not hedged into uselessness.
Reading anything on this site requires no identification and offers none. A question about the measures, the boundary or the reasoning can be sent from an address that carries no part of your name, answered on its merits, and closed without anybody establishing who wrote it. We will not ask. A mailbox that only opens for people willing to identify themselves gets a poorer class of correspondence, and the most useful message this company could receive is one telling it that its premise is wrong.
The exception is narrow and follows from the nature of the request rather than from preference. Where you ask to inspect, correct or destroy a record about a specific person, we have to be satisfied you are that person, because releasing a record to the wrong hands is the failure this whole standard exists to prevent. The next clause sets out how that is done proportionately.
10Notice at the moment of collection
APP 5 requires that a person be told certain things at or before the time their information is collected, or as soon as practicable afterwards. This document is that notice, and it is published in advance so that the telling happens before the collecting rather than in a reply to somebody who asked.
Read as a notice, it discloses the identity and contact details of the collecting entity in clause 2, the purposes in clause 12, the consequences of not supplying information in clauses 9 and 11, the recipients in clause 14, the overseas position in clause 15, and the access, correction and complaint routes in clauses 19, 20 and 27. Nothing required by APP 5.2 is held back for a separate document available on request.
Where information about you is collected from someone else, the notice obligation still runs. In that case we tell you what was collected and from whom, at the point we become aware that you are identifiable, unless telling you would disclose more about a third party than staying silent would.
11Authenticating whoever asserts a right
Every right in this document is a right to make something happen to a record about a particular person, which means each one is only as safe as the check that precedes it. The standard applied is proportionate: the strength of the check rises with the harm a mistake would do.
| What is asked for | What ordinarily satisfies us | Why the bar sits there |
|---|---|---|
| A general question about this standard | Nothing. Ask anonymously if you prefer | Answering it discloses nothing about anybody |
| Correction of a detail we hold about you | A reply from the address the record is filed under | An error introduced by an impostor is visible and reversible |
| A copy of everything held about you | A reply from that address, plus confirmation of a detail already inside the record | Release cannot be undone once it has happened |
| Destruction of the record | The same, and a confirmation step in a separate message | Destruction is irreversible in both directions |
| Anything above, where control of the address itself is in doubt | A document, handled under clause 7 | A compromised mailbox defeats every check built on that mailbox |
Someone acting for you must produce written authority, and we will confirm the arrangement with you directly before anything is released to them. A verification, once done, is written into the file as a dated line: who was satisfied, on what basis, and for which request. That line is part of the exhibit and is destroyed alongside it, so the audit trail never outlives the thing it audits.
12Purposes the record may serve
APP 6 confines use and disclosure to the purpose for which information was collected, unless a secondary purpose falls within your reasonable expectations and is related to the first, or unless another exception in the principle applies.
The primary purpose of correspondence is answering it, together with whatever exchange follows and any record of an obligation that arises out of it. The primary purpose of request logs is delivering pages and keeping the site standing under automated traffic. Those are the whole of it.
Three secondary purposes are treated as within reasonable expectation and are listed so that reasonable expectation is not a phrase doing silent work. First, keeping a complaint file that shows how a complaint was handled, since a complaint handled without a record cannot be reviewed by anyone. Second, taking advice about a dispute that has actually arisen. Third, complying with a demand that carries legal force, which is disclosed to you unless the demand itself prohibits that, in which case the prohibition is noted in the file and the disclosure is made as soon as it lifts.
Beyond those, nothing. The record is not mined for patterns, not aggregated into a picture of who reads this site, not used to decide anything about you, and not made available to another party for that party's own ends.
13Direct marketing and the Spam Act
APP 7 restricts the use of personal information for direct marketing, and the Spam Act 2003 (Cth) governs commercial electronic messages separately, requiring consent, accurate identification of the sender and a working way out.
There is no mailing list attached to this site and no facility to join one. Writing to the company subscribes you to nothing; the reply you get is a reply to your message and is not the first instalment of anything. An address that arrives in the mailbox is used to answer that thread and is not added to a broader distribution.
Were a list ever to exist, four conditions are fixed now, while there is no commercial reason to soften them. Joining would require a deliberate act by you and would never follow from having written to us. Every message would identify the sending company and its ACN. Every message would carry an unsubscribe route that works in a single step and is honoured within five working days. Choosing to leave would remove the address from the list rather than moving it to a quieter one.
14Chain of custody
A chain of custody is the list of every party that has held an item and the reason each of them held it. Ours is short, and it is listed by function rather than by brand, because a supplier can be replaced and the constraint on the class of supplier is the part that must survive the replacement.
| Function | What it touches | Why it is in the chain | Constraint it is held to |
|---|---|---|---|
| Hosting and content delivery | Request logs, and the pages themselves | Something has to answer a request for a page and absorb hostile traffic before it reaches the origin | Processes only on our instructions, retains logs briefly on its own cycle, has no licence to use them for its own purposes |
| Mail transport and storage | Correspondence, including any attachment | A mailbox has to exist somewhere and be reachable from the public network | Transports and stores only; content is not scanned for advertising and is not used to build a profile |
| Domain registration and name service | Nothing about you | Resolving the name to an address is what makes the site reachable | Holds company registration details rather than visitor information |
| Professional advisers | Only what a live dispute makes relevant | Advice on a matter that has already arisen sometimes requires the underlying material | Engaged case by case, bound by professional duties of confidence, given the narrowest extract that answers the question |
| A court, regulator or authority acting under power | Whatever the instrument compels | Compulsion is not consent and is not refused | Scope checked against the instrument, nothing volunteered beyond it, and you are told unless the instrument forbids it |
Nobody else is in the chain. Adding a function to that table is a material change to this standard and is written into the table before the arrangement begins, not disclosed afterwards in a revision note.
15Custody outside Australia
APP 8 governs what happens when personal information leaves the country. Before disclosing to an overseas recipient, an entity must take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and section 16C of the Act then makes the disclosing entity accountable for an act of that recipient which would have breached the principles had it been done here.
The suppliers in the chain of custody operate infrastructure in more than one country, as nearly all infrastructure of this kind does. Where any part of the record is stored, replicated or processed outside Australia, that is a cross-border disclosure and this clause governs it. The company does not assert that everything stays onshore, because that assertion would require a guarantee no small purchaser of commodity infrastructure is in a position to give.
What follows from that is the position on accountability. The company does not rely on the exception in APP 8.2(b), under which an entity that obtains a person's informed consent to an overseas disclosure is released from responsibility for what the recipient then does. Consent obtained that way transfers the risk from the party that chose the supplier to the party that had no say in the choice, and this company keeps the accountability instead. If a supplier mishandles part of the record abroad, the answer to who is responsible is the company named in clause 2.
If the countries in which the record can sit matter to your own compliance position, ask. The answer will name the suppliers and what each is understood to do, in writing, and it will distinguish what has been confirmed from what has been inferred from a supplier's published documentation.
16Securing the exhibit
APP 11.1 requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. What counts as reasonable is scaled to the entity and to the sensitivity of what it holds; the measures below are what a company of this size holding a record of this kind can actually maintain, which is the only kind worth writing down.
- Every page is served over an encrypted connection, and requests arriving unencrypted are upgraded rather than answered.
- The site is a collection of files with no database behind it, no administrative interface exposed to the network, and no code path that writes anything a visitor submits.
- The mailbox requires more than a password to open, and the number of people who can open it is the smallest number that allows correspondence to be answered.
- Copies are not taken onto removable media or personal devices, and material is not moved into a third party tool for convenience.
- Verification material is quarantined from ordinary correspondence and is destroyed on the schedule in clause 18 rather than when somebody remembers.
- Disposal at the end of a retention period is a scheduled act with a dated entry, not an accumulation left to run.
One limit belongs here rather than in a footnote. Mail between independent providers is generally protected in transit today, but that protection depends on both ends and is not something this company can promise on behalf of yours. If what you need to send is genuinely sensitive, send a message saying so first and we will agree a better route before you send the substance. The obligation to protect what has arrived is ours absolutely; the journey is shared, and pretending otherwise would be the wrong kind of reassurance.
17Accuracy, and why messages are annotated
APP 10 requires reasonable steps to ensure that information collected is accurate, current and complete, and that information used or disclosed is accurate, current, complete and relevant to the purpose at hand.
For facts about you the obligation is straightforward. If the name or the address on file is wrong, it gets fixed. For correspondence the position needs stating carefully, because the record is not a database of facts but a record of what was said. A message you sent in March is accurate as a record of that message even if what it asserted turned out to be mistaken.
So a correction to correspondence is applied by annotation. Your correction is attached to the thread, dated, and travels with it wherever the thread goes afterwards, while the original text stays as it was. Editing history to make it read better is exactly what an evidence standard exists to prevent, and it would leave the file less trustworthy rather than more. Where you would rather the original were gone altogether, that is a destruction request under clause 21 and it is treated as one.
18Retention schedule and disposal
APP 11.2 requires that personal information be destroyed or de-identified once it is no longer needed for any purpose for which it may be used or disclosed, subject to any law requiring it to be kept. Retention without a stated period is retention forever by default, so each class of item carries an explicit clock.
| Class of item | Clock starts | Period | Why that long, and not longer |
|---|---|---|---|
| Ordinary correspondence | The last message in an exchange | Two years, then destroyed at the next scheduled disposal | Long enough that a person returning to an old thread is not met by amnesia; short enough that a dormant mailbox is not an archive |
| Verification material | Completion of the check | Seven days | The document has done its work the moment the check is recorded, and every day it survives after that is pure exposure |
| The verification line itself | Filed with its request | Destroyed with the file it belongs to | An audit trail that outlives the record it audits becomes a record in its own right |
| Complaint files | Closure of the complaint | Five years | A complaint may be reviewed externally well after it is closed, and the file is the evidence that it was handled properly |
| Request logs | Arrival of the request | The provider's cycle, presently under thirty days | They exist to keep the site standing, which is a question about the present week |
| Anything under a legal hold | Notice of the obligation | Until the obligation ends, then destroyed | A hold suspends the schedule for the specific material it covers and for nothing else |
Disposal means the item is deleted from live systems and the deletion is recorded as having happened. Copies inside a supplier's routine backup persist until that supplier's own cycle overwrites them, which is a limit of using ordinary infrastructure rather than a reservation of rights. Material in a backup is not returned to service, is not searched, and is not consulted in the ordinary course; if it were ever restored for a technical reason, anything already destroyed under this schedule would be destroyed again before the system was used.
19Inspecting the record
APP 12 entitles you to ask what personal information the company holds about you and to be given access to it. The right belongs to you by statute; nothing here grants it and nothing here may narrow it.
Send the request to the published address with Inspect the record in the subject line. Once the check in clause 11 is satisfied, you receive the whole of what is held about you: the correspondence in full, the verification line if there is one, and a plain description of what the hosting provider's logs would contain for a visit, since those sit with the provider on a short cycle rather than in a form the company can search by person.
APP 12.4 requires a response within a reasonable period. This company treats thirty days from a verified request as the outer edge of reasonable and works well inside it; where something will take longer, you are told before the thirty days elapse and told why. Making a request costs nothing. APP 12.8 would permit a charge for giving access provided it is not excessive, and none is levied.
APP 12.3 lists the grounds on which access may be refused, including where giving it would unreasonably affect another person's privacy or reveal a third party's confidential information. If a ground is relied on, you are told in writing which one, what has been withheld in general terms, what you can still have, and where to take the disagreement. Refusal in silence is not available under this standard.
20Correcting the record
APP 13 obliges the company to correct personal information it holds where the information is inaccurate, out of date, incomplete, irrelevant or misleading, whether you ask or we notice it ourselves.
Use Correct the record in the subject line and say what is wrong and what it should say. Corrections are made within thirty days and are free. Where the incorrect information was previously disclosed to somebody else, APP 13.2 entitles you to ask that they be told of the correction, and that notice is sent unless it is impracticable or unlawful to send it.
If we decline to correct something, APP 13.4 entitles you to have a statement of your own associated with the record, so that anyone who reads it afterwards reads your position alongside ours. That statement is attached in a form that cannot be missed by a later reader. APP 13.5 requires written reasons for the refusal and notice of the complaint routes available, and both are given without being asked for. The annotation practice in clause 17 applies to correspondence for the reason set out there.
21Destruction on request
A request for deletion of data held about you is treated as a request to destroy the whole exhibit rather than to hide it from a search. Put Destroy the record in the subject line. After the check in clause 11, which for destruction includes a confirmation step in a separate message, everything held about you is removed from live systems and you are told when it is done.
Two things can survive a destruction request, and both are stated in advance rather than produced as a surprise afterwards. Material subject to a legal hold or an obligation that binds the company independently stays until that obligation ends, and you are told that it applies and in general terms why. A single dated line recording that a destruction occurred also stays, because a disposal schedule with no evidence of disposal cannot be audited by anyone; that line records the act and holds nothing about its contents.
Supplier backups are covered by the paragraph at the end of clause 18. Nothing else is retained, no shadow copy is kept for analytics, and no de-identified residue is derived from a record on its way out.
22Personal information inside a query set
This clause governs the evaluation tooling rather than the website, and it is stated here so that the constraint sits in a published document rather than in a commercial negotiation.
A result list is joined to a set of relevance judgements using identifiers. A run records which documents came back for a question, in what order, with what score, against which configuration. Document text is not transmitted, has no field to occupy, and is needed by none of the measures, all of which are computed from identifiers and ranks.
Two places where personal information could nonetheless appear are worth naming. Questions taken from a live system frequently contain personal information, because that is what people type into search boxes. Question text is therefore optional and the join runs on a question identifier, so a customer can evaluate a pipeline without the text ever leaving their environment. A corpus, meanwhile, very often contains scanned identity documents, medical correspondence and other sensitive material; since document contents stay where they are, that material sits outside the boundary by construction rather than by promise.
Where a customer chooses to send question text, the customer remains the entity responsible for what that text contains, and a written arrangement says so before any data moves. If document text were ever required to cross the boundary, that would be a material change to this standard, disclosed under clause 29 before it took effect rather than noticed afterwards by a reader comparing versions.
23Children and young people
This site is addressed to people who run software systems at work. Nothing on it is directed at a child, nothing is designed to appeal to one, and no information is sought about anybody under eighteen.
The Privacy Act sets no fixed age at which a person can consent for themselves. Capacity is assessed individually, and the Commissioner's guidance treats a young person of about fifteen or older as ordinarily capable of consenting unless something suggests otherwise. Where a young person plainly could not understand what they were agreeing to, we deal with a parent or guardian instead, and where capacity is genuinely unclear we take the more protective reading.
A young person holds the same rights over the record as anyone else, and clauses 19 through 21 apply to them without a different process. If information about a child reaches this record without a proper basis, it is destroyed rather than retained, and it is not put to any use in the interval before destruction.
24Automated decisions
Nothing about you is decided by a machine here. There is no scoring, no ranking of correspondents, no automated refusal and no profile that grows as you read. Replies are written by a person who has read what you sent.
One automated step touches correspondence and is disclosed because it can affect you. Incoming mail passes through the provider's filtering, which occasionally misfiles a legitimate message. If a reply does not arrive inside the period stated for that kind of request, the most likely explanation is that filter rather than a decision to ignore you. Send it again, or send a short note saying a message went astray, and it will be looked for.
Amendments to the Privacy Act have introduced a transparency obligation about substantially automated decisions that significantly affect individuals. Nothing this company does falls inside that description at present. Were that to change, this clause would name the decision, say what information feeds it and describe how to have a person look at the outcome, before the process began rather than after.
25Breach of custody
The Notifiable Data Breaches scheme sits in Part IIIC of the Act. An eligible data breach occurs where there is unauthorised access to or disclosure of personal information, or a loss of it, and a reasonable person would conclude that serious harm to an affected individual is likely to result.
Where there are reasonable grounds to suspect an eligible data breach, section 26WH requires an assessment to be carried out expeditiously and, in any case, within thirty days. Where reasonable grounds to believe one has occurred exist, section 26WL requires a statement to the Commissioner and notification to the individuals at risk as soon as practicable.
What notification looks like here
A notice from this company will say what happened and when it was discovered, which classes of information were involved, what has been done to contain it, what you can usefully do yourself, and how to reach a person about it rather than a form. It will go out as soon as the facts are established well enough to be useful, without waiting for the question of fault to be settled, and a later notice will correct anything the first one got wrong.
Where a breach originates with a supplier in the chain of custody, the notification obligation is still the company's, and clause 15 explains why that responsibility is not passed along with the data.
26Storage on your own device
Whatever a website writes onto your own machine is part of the honest account of what visiting it involves, and it is set out in full in the cookie notice rather than summarised twice with a risk of the two summaries drifting apart.
The essentials, so that this clause stands on its own: no storage is written by any code belonging to this site, the only items that can appear are set by the delivery provider to keep the service reachable, there is no measurement or advertising technology anywhere on these pages, and consequently there is no banner asking you to agree to something.
Where storage of that kind collects information about an identifiable person, it is personal information and this standard governs it in the ordinary way, alongside the principles named throughout this document.
27Objection and external review
If you think this standard has been breached, the first step is to say so directly, with Privacy complaint in the subject line. Describe what occurred and the outcome you are seeking. You will get a written answer that addresses the substance, and where the complaint is upheld it will say what has been changed as a result.
The Act gives you an external route that does not depend on our agreement or on our cooperation, and it is set out here in full because a complaint route buried in a final paragraph is a complaint route designed not to be used.
GPO Box 5218, Sydney NSW 2001. Telephone 1300 363 992. Online at oaic.gov.au.
The Commissioner ordinarily expects an individual to raise the matter with the entity first and to allow it a reasonable opportunity to respond, which is why the direct route is listed above. Complaining costs nothing, the process is designed to be used by people without professional help, and taking a matter to the Commissioner does not affect the statutory cause of action mentioned in clause 3 or any other legal remedy available to you.
28Readers outside Australia
This site is published from Australia and this standard is written to Australian law. It is read from elsewhere, and the practical position for a reader abroad is worth stating rather than leaving to inference.
Where the General Data Protection Regulation, the United Kingdom's data protection regime or a comparable law applies to you, the rights it gives you are exercised through the same address and the same subject lines used throughout this document. A request is not turned away because of where the person making it lives, and the response times promised here apply regardless of origin.
The company does not claim an establishment or a representative in any other jurisdiction, and it does not hold itself out as certified under any transfer framework. What it undertakes is to handle a request on its merits, to apply whichever standard is more protective where two of them differ, and to say plainly if a right you assert has no counterpart in Australian law rather than answering as though it did.
29Amendment of this standard
This standard carries a version number and an effective date, both at the head of the page. Any change moves both, and there is no unversioned editing of the text in place.
A material change is one that would alter what may be collected, who may hold it, where it may travel, how long it survives or what you may demand. Changes of that kind are published before they take effect, with a short note saying which clause moved and why, so that a reader can see the movement rather than having to detect it. A correction to wording that changes no obligation is made without ceremony and still moves the version.
Superseded versions are retained and supplied on request. If you need to know what this document said on a particular date, ask for that date rather than working from a paraphrase or from an archive that may have missed a revision.
30Where to send anything under this document
Everything in this standard is claimed at one address: [email protected]. It is read by a person. The subject lines below are a convenience rather than a condition, and a request written in your own words is treated exactly the same way.
| Subject line | What it invokes | Clause | Time to a substantive answer |
|---|---|---|---|
| Inspect the record | Access to everything held about you | 19 | Thirty days at the outside |
| Correct the record | Correction, or a statement attached to it | 20 | Thirty days at the outside |
| Destroy the record | Destruction of what is held | 21 | Thirty days at the outside |
| Privacy complaint | An objection to how information was handled | 27 | Thirty days, then the external route |
| Privacy question | Anything about this document, including from someone who is not in the record | Any | Five working days |
ARCUS AI PTY LTD, ACN 697 547 505, ABN 82 697 547 505, an Australian proprietary company in New South Wales. The registered office recorded at the Australian Securities and Investments Commission is the address that carries legal effect for the service of documents. This standard covers arcusai.fyi and the correspondence sent to the address above.