Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Last updated: 16 July 2026
1. Introduction
JOURN3Y Pty Ltd ("JOURN3Y", "we", "us", or "our") is committed to protecting your privacy and handling personal information responsibly. This Privacy Policy explains how we collect, hold, use, and disclose personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs).
This policy applies to personal information we collect through our website, in the course of providing AI consulting and implementation services, and through our general business dealings with clients, prospects, and other individuals.
2. Open and Transparent Management of Personal Information (APP 1)
We are committed to managing personal information in an open and transparent way. This policy sets out how we do that, and we take reasonable steps to implement practices, procedures, and systems that ensure compliance with the APPs and enable us to deal with related enquiries and complaints.
If you have questions about how we handle personal information, you can contact our Privacy Officer at any time using the details in Section 19.
3. Personal Information We Collect (APP 3)
We collect personal information that is reasonably necessary for our business functions and activities, including:
- Contact details (name, email address, phone number, company name)
- Professional information (job title, industry, business requirements)
- Communication records (enquiries, support requests, feedback)
- Technical information (IP address, browser type, device information)
- Website usage data (pages visited, time spent, interactions)
We only collect sensitive information (as defined under the Privacy Act) where you have consented, or where collection is otherwise permitted by law. We do not seek to collect sensitive information as part of our standard business operations.
4. How We Collect Personal Information (APP 3)
Where reasonable and practicable, we collect personal information directly from you, including through:
- Contact forms and enquiry submissions on our website
- Email communications and phone conversations
- Newsletter subscriptions and marketing communications
- Cookies and similar tracking technologies (see Section 14)
- Third-party integrations and analytics services
Where personal information is collected as part of delivering services to a client organisation (for example, where we implement or configure a client's software environment), that information is provided to us by the client or generated through our use of client-authorised systems, and is handled in accordance with our contractual obligations to that client as well as this policy.
5. Unsolicited Personal Information (APP 4)
If we receive personal information we did not solicit, we will assess whether we could have lawfully collected it under APP 3. If not, and the information is not contained in a Commonwealth record, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
6. Notification of Collection (APP 5)
Where we collect personal information about an individual, we take reasonable steps to notify the individual (or otherwise ensure they are aware) of matters including: our identity and contact details, the fact and circumstances of collection, the purposes of collection, the consequences if the information is not collected, our usual disclosure practices, and how to access, correct, or complain about the handling of their information. This policy, along with any specific notices provided at the point of collection, is intended to satisfy that requirement.
7. How We Use Personal Information (APP 6)
We use personal information for the primary purpose for which it was collected, and for related secondary purposes you would reasonably expect, including:
- Responding to enquiries and providing customer support
- Delivering our AI consulting and implementation services
- Sending marketing communications, where you have consented or as otherwise permitted by law
- Improving our website and services
- Complying with our legal and regulatory obligations
- Protecting our business interests and preventing fraud
We will not use personal information for a purpose unrelated to why it was collected without your consent, unless permitted or required by law.
8. Direct Marketing (APP 7)
We may send you direct marketing communications where you have consented, where you would reasonably expect to receive such communications, or as otherwise permitted under the Privacy Act or the Spam Act 2003 (Cth). Every marketing communication includes a simple way to opt out, and we will action opt-out requests promptly. You can also opt out at any time by contacting us using the details in Section 19.
9. Disclosure of Personal Information (APP 6, APP 8)
We may disclose personal information to:
- Service providers who assist us in operating our business, such as hosting, analytics, and email service providers, bound by contractual obligations to protect that information
- Business partners, where necessary to deliver our services or with your consent
- Legal and regulatory authorities, where required or authorised by law, or to protect our legal rights
- A prospective buyer or successor, in the event of a merger, acquisition, or sale of business assets, subject to appropriate confidentiality protections
We do not sell, rent, or trade personal information to third parties for their own marketing purposes.
10. Government Related Identifiers (APP 9)
We do not adopt, use, or disclose government related identifiers (such as tax file numbers or Medicare numbers) as our own identifiers for individuals, except where required or authorised by law.
11. Data Quality (APP 10)
We take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, up to date, and complete, having regard to the purpose of the use or disclosure. You can help us do this by keeping us informed of any changes to your contact or other details.
12. Data Security (APP 11)
We implement appropriate technical and organisational measures to protect personal information against misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include:
- Encryption of data at rest and in transit
- Access controls limiting information access to personnel who need it to perform their role
- Multi-factor authentication and endpoint security across company devices
- Regular review of security practices
Where personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, and we are not required by law to retain it, we take reasonable steps to destroy or de-identify it securely.
Data Breach Response
We maintain a process for identifying, containing, and responding to data breaches involving personal information, consistent with our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act. If we become aware of a data breach that we reasonably believe is likely to result in serious harm to any individual, we will:
- Contain the breach and assess its scope and impact as quickly as possible
- Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the NDB scheme
- Where the breach relates to personal information handled in the course of a client engagement, notify the affected client without undue delay, consistent with our contractual commitments
- Take reasonable steps to remediate the breach and prevent recurrence
13. Access to and Correction of Personal Information (APP 12, APP 13)
You have the right to:
- Access the personal information we hold about you
- Correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading
- Request deletion of your personal information, subject to our legal and record-keeping obligations
- Opt out of marketing communications at any time
- Complain about how we have handled your personal information
To exercise any of these rights, contact our Privacy Officer using the details in Section 19. We will respond within a reasonable period, and will not charge you for making a request. If we refuse to give access or make a correction, we will provide written reasons and information about how to complain.
14. Cookies and Tracking
Our website uses cookies and similar technologies to improve user experience and analyse website performance. You can control cookie settings through your browser preferences, though some website functionality may be affected if cookies are disabled.
15. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites and encourage you to review their privacy policies before providing any personal information.
16. Cross-Border Disclosure of Personal Information (APP 8)
Some of our service providers, including those supporting the software platforms we implement on behalf of clients, may store or process personal information overseas. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that recipient does not breach the APPs in relation to that information, including through contractual protections. Where required by the Privacy Act, we remain accountable for personal information handled by overseas recipients on our behalf.
17. Children's Privacy
Our services are not directed to children under 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will take reasonable steps to delete it.
18. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The updated version will be posted on our website with a revised "last updated" date. We encourage you to review this policy periodically.
19. Complaints and Contact
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to make a complaint about how we have handled your personal information, please contact our Privacy Officer:
JOURN3Y Pty Ltd
Attention: Privacy Officer
Email: info@journ3y.com.au
Address: Sydney, NSW 2000, Australia
We will acknowledge complaints promptly and aim to resolve them within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.