Privacy Policy
Atashi.com.au Pty. Ltd. ACN 696 804 074
Effective date: [DATE] Last updated: [DATE]
This is a template draft prepared for internal review. A qualified Australian lawyer should review this document before it is published or relied upon in production.
1. Who we are
Atashi.com.au Pty. Ltd. (ACN 696 804 074) ("Atashi", "we", "us", "our") operates an AI workspace platform where users delegate tasks to specialist AI agents. Our registered office is in Sydney, New South Wales, Australia.
This Privacy Policy explains how we collect, use, store, disclose and protect your personal information in accordance with the Australian Privacy Principles ("APPs") under the Privacy Act 1988 (Cth) ("Privacy Act"). We treat compliance with the APPs as a baseline obligation regardless of whether we are technically required to do so by our size or revenue.
If you are located outside Australia, we extend equivalent rights to you, including rights of access, correction, deletion and data portability.
Contact: Privacy enquiries: privacy@atashi.com Postal: [ADDRESS — TO BE CONFIRMED]
2. What information we collect
We collect different categories of personal information depending on how you use the platform.
Account information. When you create an account, we collect your email address, display name (optional) and a password hash. We do not store your password in plain text. If you use guest mode, we assign a temporary session identifier that is discarded when the session ends.
Workspace information. When you use the platform, we process the content you create or provide, including text messages sent to agents, agent responses, conversation history, agent memory (long term context that persists across sessions), and any files you upload. This is the core data the platform needs to function — agents cannot remember your projects or hand off context without it.
API keys (BYOK). If you choose to bring your own API keys for third party model providers, we store those keys encrypted at rest using envelope encryption. We use your keys solely to route requests to the provider you selected. We do not log, read or share your keys outside the encryption and routing pipeline.
Telemetry and usage data. We collect page view events, feature usage events, error logs and performance metrics. This data helps us identify bugs, measure reliability and improve the product. We use Sentry for error tracking. Telemetry data may include your IP address, browser type, operating system and session timestamps.
Payment information. During the closed beta, we do not collect payment information. When we introduce paid tiers, payment processing will be handled by a third party payment processor. We will update this policy before that happens.
Information we do not intentionally collect. We do not ask for or intentionally collect sensitive information as defined under the Privacy Act (APP 3.3), including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records or biometric data. If you include such information in your conversations with agents, it will be processed as part of your workspace content, but we do not extract, categorise or use it for any secondary purpose.
3. How we collect your information
We collect information directly from you (APP 3.6) when you create an account, use the workspace, upload files, configure API keys or contact us. We do not purchase, scrape or otherwise acquire personal information from third party data brokers.
Telemetry data is collected automatically when you interact with the platform.
4. Why we collect your information
We collect and use your personal information for the following purposes (APP 6):
Primary purposes: Providing the AI workspace service, including routing your messages to agents, maintaining conversation history, preserving agent memory across sessions, processing uploaded files and returning agent responses.
Secondary purposes within reasonable expectations: Platform security and abuse prevention; error tracking and reliability monitoring; product improvement based on aggregated, de-identified usage patterns; communicating with you about your account or the service; complying with Australian law.
We will not use your personal information for a purpose you would not reasonably expect without first obtaining your consent.
5. How AI processing works
This section explains how your data moves through the platform. We believe you should understand this clearly before trusting us with your work.
When you send a message to an agent, your message (and relevant context from your conversation history and agent memory) is transmitted to one or more third party AI model providers for processing. The provider generates a response, which is returned to you through the platform.
We currently use the following AI model providers:
What this means in practice: Your prompts and the responses you receive pass through servers operated by these providers, which are located in the United States. Each provider has committed under their terms not to use your data for model training. However, they may retain your data temporarily for safety and abuse monitoring as described above. We cannot control their internal practices beyond our contractual arrangements with them.
Agent memory. Agents maintain long term memory — summaries and key facts derived from your conversations — that persists across sessions. This is what allows an agent to remember your projects and preferences. Memory is stored in our database, not with the AI providers. If you delete a conversation, the conversation messages are removed, but memory summaries derived from that conversation may persist until you explicitly delete them or request a full memory reset.
AI outputs. Responses generated by agents are probabilistic and may contain inaccuracies, biases or fabricated information ("hallucinations"). Agent outputs do not constitute professional advice of any kind. You should verify any output before relying on it.
6. Who we share your information with
We disclose your personal information to the following categories of recipients (APP 6):
AI model providers (Google, Anthropic, OpenAI) — as described in section 5, to process your messages and generate responses.
Infrastructure providers:
Legal and regulatory bodies — if required by Australian law, court order or regulatory request.
We do not sell your personal information. We do not share it with advertisers. We do not disclose it to any party not listed above without your consent, unless required by law.
7. Cross border disclosure (APP 8)
Some of your personal information is disclosed to organisations located outside Australia, specifically in the United States (Google, Anthropic, OpenAI, Sentry). We take reasonable steps to ensure these recipients handle your information consistently with the APPs, primarily through data processing agreements that contractually require them to protect your data.
Under section 16C of the Privacy Act, we remain accountable for the handling of your personal information by overseas recipients to the extent required by law.
8. How we protect your information (APP 11)
We take reasonable technical and organisational steps to protect your personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Encryption at rest. All data stored in our database is encrypted at rest using AES-256 encryption. BYOK API keys receive an additional layer of envelope encryption with per tenant key isolation.
Encryption in transit. All data transmitted between your browser and our servers, and between our servers and third party providers, is encrypted using TLS 1.2 or higher.
Access controls. Database access is restricted through row level security policies that prevent any user from accessing another user's data. Administrative access is limited and logged.
Monitoring. We use error tracking and logging to detect and respond to anomalies. During the closed beta, the founding team operates the platform directly, which means incident response is best effort rather than governed by a formal SLA.
What we do not yet have. We are an early stage company in closed beta. We do not currently hold SOC 2, ISO 27001 or any formal security certification. We do not yet have a formal penetration testing programme. These are on our roadmap and we will update this policy as our security posture matures.
9. How long we keep your information
We retain your personal information for as long as your account is active or as needed to provide the service.
Account data: Retained while your account exists. Deleted within 30 days of account closure.
Conversations and files: Retained while your account exists. You can delete individual conversations at any time. Files are deleted when the associated conversation is deleted or when your account is closed.
Agent memory: Memory summaries persist across sessions. You can delete specific memories or request a full memory reset at any time through the platform or by contacting us.
BYOK API keys: Stored encrypted while active. Deleted immediately when you remove them or close your account.
Telemetry and error logs: Retained for up to 90 days, then purged or de-identified.
Third party retention: AI model providers retain your data temporarily as described in section 5 (Anthropic: up to 7 days; OpenAI: up to 30 days; Google: per their Cloud Data Processing Addendum).
10. Your rights
You have the following rights under the Privacy Act and we extend equivalent rights to all users regardless of location:
Access (APP 12). You may request access to the personal information we hold about you. We will respond within 30 days.
Correction (APP 13). You may request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Deletion. You may request deletion of your account and all associated data. We will process deletion requests within 30 days, subject to any legal retention obligations.
Data export. You may request an export of your workspace data (conversations, memory, uploaded files) in a machine readable format.
Withdraw consent. Where we rely on your consent for a specific use of your information, you may withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@atashi.com.
11. Children
Atashi is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected information from a person under 18, we will take steps to delete that information promptly.
12. Data breach notification
We are committed to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Take immediate steps to contain the breach and mitigate harm.
- Assess the breach within 30 days to determine whether it meets the threshold for notification.
- If the threshold is met, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
13. Automated decision making
The platform uses AI models to generate responses to your queries. These responses are outputs of statistical language models and should not be treated as decisions with legal or similarly significant effect. No automated decision is made about you (for example, about your creditworthiness, eligibility or access to services) based on AI model outputs.
If Australian law introduces specific transparency obligations for automated decision making (anticipated from December 2026), we will update this section accordingly.
14. Complaints
If you believe we have breached an Australian Privacy Principle, you may lodge a complaint with us by contacting privacy@atashi.com. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:
- Online: https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us
- Phone: 1300 363 992
- Email: oaicintake@oaic.gov.au
- Post: GPO Box 5288, Sydney NSW 2001
15. Changes to this policy
We may update this policy from time to time. When we make material changes, we will notify you by email or through the platform before the changes take effect. The "Last updated" date at the top of this page indicates when the most recent revision was published.
16. Contact us
Atashi.com.au Pty. Ltd. ACN 696 804 074 Sydney, New South Wales, Australia
Privacy enquiries: privacy@atashi.com