Privacy Policy
Last updated 18 July 2026
Jamie Clerk Pty Ltd (ABN 67 698 745 881) (trading as Jamie Clerk; we, us or our) is committed to protecting Your privacy. This Privacy Policy explains how we collect, hold, use, and disclose personal information in connection with the Jamie Clerk service (the Service), and how You can exercise the rights You have under the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).
In this Policy, Customer means a business that subscribes to the Service, and End Customer means a customer or prospective customer of a Customer who interacts with the Service (for example, a person who sends a message to the Jamie chat widget on a Customer's website). Customer Data means any data, content, messages, documents or contacts that a Customer or its End Customers upload to, or generate within, the Service.
This Policy applies to personal information we handle in connection with the Service — for example, information about Customers and team members who sign up for the Service, visitors to jamieclerk.ai and our mobile app, and personal information contained in Customer Data (for example, conversations between Jamie and an End Customer of one of our Customers).
For most personal information contained in Customer Data, our Customer is the entity primarily responsible under the APPs — the Customer's own privacy policy applies to its End Customers, and we process that information as the Customer's service provider in accordance with our Terms & Conditions and any Data Processing Addendum. Because we also decide important matters about how Customer Data is handled (including the Sub-processors we use, the security model we apply, retention windows, and any use of de-identified or aggregated information derived from Customer Data for our own product-improvement purposes), we are an APP entity in our own right for those decisions, and the APPs apply to us independently for those uses.
1. The kinds of personal information we collect
We collect the following categories of personal information:
Account information: name, business name, email address, phone number, role, and password (stored hashed) of users who sign up for the Service.
Business profile information: information about Your business that You or our onboarding agent provide or that we extract from Your public website to pre-fill Your knowledge base, business hours, services offered, frequently asked questions and similar configuration.
Conversation and Customer Data: information sent to, generated within, or processed through the Service by You or Your End Customers — for example, messages, contact details, documents, configuration, attachments, and operational metrics derived from those interactions. This data is handled on behalf of our customers as described in the introduction.
Payment information: billing address and a token reference to Your stored payment method. Card numbers are collected and stored by our third-party payment gateway and not by us.
Usage and device information: IP address, browser type, device identifiers, pages viewed, features used, error reports and similar telemetry, collected through cookies and analytics on our website and within the Service.
Support information: the content of any support requests You send us and our responses.
We do not knowingly collect sensitive information as defined in the Privacy Act (which includes health information, racial or ethnic origin, political opinions, membership of a political, professional or trade association, religious beliefs, philosophical beliefs, sexual orientation or practices, criminal record, biometric information and genetic information) about Customers or their team members in the ordinary course of providing the Service. See section 4A below for the special position that applies where End Customers may share sensitive information with a Customer through the Service.
2. How we collect personal information
We collect personal information directly from You when You sign up for and use the Service, contact us, or engage with our website or mobile app. We also collect information automatically through cookies and similar technologies when You visit jamieclerk.ai, use our mobile app, or otherwise use the Service.
In some cases we receive information from third parties: for example, our onboarding agent will visit Your public website to extract publicly available business information; OAuth providers (such as Google) will share basic profile information when You choose to sign in with them; and our analytics, advertising, and error-monitoring providers may share aggregated information about Your interactions with our website.
Where it is reasonable and practicable to do so, we collect personal information directly from the individual concerned. Where information is collected from a third party, we take reasonable steps to confirm that the source has appropriate authority to provide it.
3. Why we collect, hold, use, and disclose personal information
We use personal information to:
(a) provide and operate the Service, including authenticating users, generating Jamie Output, scoring confidence, flagging conversations for human review, and producing operational metrics for Your dashboard;
(b) onboard Your business, including auto-extracting publicly available information from Your website to pre-fill the knowledge base;
(c) bill You and process payments;
(d) provide customer support and respond to enquiries;
(e) maintain the security, integrity, and reliability of the Service, including preventing fraud and abuse;
(f) improve the Service, including evaluating model performance and developing new features, using de-identified and aggregated signals;
(g) communicate with You about the Service, including service announcements, security notices, and (where You have not opted out) information about features and offers in accordance with section 8;
(h) comply with our legal obligations and respond to lawful requests from authorities.
4. AI processing and the use of foundation models
The Service uses large language models (LLMs) to generate Jamie Output. Our current LLM Sub-processor is Google Vertex AI, which provides both the conversational model (Gemini) used to draft Jamie's replies and the embedding model used to index Your knowledge base so it can be retrieved at reply time. To produce a reply, we send the relevant portions of the conversation, the relevant portions of Your knowledge base, and our system instructions to Vertex AI; Vertex AI returns a response that we deliver back to the Service.
Inference requests on the conversational model are routed to Google's global Vertex AI endpoint, which means they may be processed in any region with available capacity — at the date of this Policy, predominantly in the United States. Embeddings of Your knowledge base are likewise computed on Google's global Vertex AI endpoint, which means they may be processed in any region with available capacity and carry no data-residency guarantee — at the date of this Policy, predominantly in the United States. The resulting numerical vectors are stored back in our Australian database alongside the rest of Customer Data. See section 7 for the full cross-border picture.
We do not allow Customer Data to be used to train foundation models. Data we send to Vertex AI is processed transiently to generate the requested response or vector, is not retained by Vertex AI beyond the operational window required for that response, and is not used to train or fine-tune general-purpose models, in accordance with the Google Cloud Data Processing Addendum that governs our use of Vertex AI. We may use de-identified and aggregated signals derived from interactions (for example, the distribution of confidence scores) to evaluate the performance of, and improve, our own product.
4A. Regulated industries and sensitive information
Some of our Customers operate in industries — including allied health, fitness, healthcare, and other regulated professions — where End Customers may, in the course of an enquiry, share sensitive information (as defined in the Privacy Act), most commonly health information.
The Customer is primarily responsible for that information under the APPs, including for ensuring that consent has been obtained from the End Customer under APP 3 before sensitive information is collected through the Service, and for handling that information in accordance with the APPs and any industry-specific privacy obligations (for example, those that apply to allied health professionals under State or Territory law). As set out in section 4(c) of our Terms & Conditions, certain high-risk data — including payment card numbers, government identifiers, passwords, and records sourced from the My Health Record system — must not be submitted through the Service at all.
We process that information as the Customer's service provider in accordance with our Terms & Conditions and any Data Processing Addendum, and we apply the same security and Sub-processor controls described in this Policy to all Customer Data regardless of whether it contains sensitive information. We also have our own APP obligations for the decisions we make about how Customer Data is handled, as described in the introduction to this Policy.
4B. Google user data and the Gmail integration
Where a Customer connects a Google account to the Service through the Gmail integration, we access Google user data on that Customer's behalf so Jamie can read incoming customer emails and, where Jamie's confidence in its reply meets the threshold the Customer has set and the reply passes automated safety checks, compose and send that reply on the Customer's behalf. Where Jamie is not confident, it does not send: it holds the drafted reply in the Jamie app for the Customer to review, edit, and send. This section describes our handling of that data and applies in addition to the rest of this Policy.
We request only the minimum Google OAuth scopes necessary to deliver the Gmail integration. The Customer can see at any time which scopes have actually been granted to the Service from myaccount.google.com/permissions in their Google account, and can revoke access from there or from the Service's integration settings.
Compliance with the Google API Services User Data Policy. Our use and transfer to any other app of information received from Google APIs adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Restrictions on use of Google user data. Consistent with the Limited Use requirements:
(a) we do not use Google user data for advertising purposes, including serving ads, retargeting, personalised advertising, or interest-based advertising;
(b) we do not sell Google user data, and we do not transfer it to any third party except (i) Sub-processors strictly necessary to deliver the Gmail integration features described above, (ii) where required by applicable law, (iii) as part of a merger, acquisition or sale of assets, after obtaining the Customer's explicit prior consent, or (iv) where the Customer has given express consent for a specific transfer;
(c) we do not use Google user data to develop, improve, or train generalised AI or machine learning models, including the foundation models offered by our LLM Sub-processor. Google user data is sent to the LLM Sub-processor solely to generate the specific reply the integration is requested to produce, and is subject to the no-training position described in section 4;
(d) humans do not read a Customer's Google user data, except where: (i) the Customer has given us specific, voluntary, opt-in consent to do so (for example, to debug an issue they have reported); (ii) it is necessary for security, including investigating abuse or addressing a security incident; (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated and is used for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.
Storage of Gmail data. Email content required to power the integration is stored as part of Customer Data, encrypted in transit (TLS) and at rest, and retained in line with section 9.
Disconnecting and deleting Gmail data. The Customer can disconnect the Gmail integration at any time from within the Service, and revoke our access from myaccount.google.com/permissions in their Google account. Once disconnected we revoke and delete Gmail OAuth refresh tokens immediately, stop syncing further Gmail data, and delete synced Gmail content in line with the deletion commitments in section 9. The Customer may also request deletion of specific Gmail data at any time by contacting us through the Service, and we will action the request as described in section 12.
4C. Meta messaging integrations (WhatsApp, Instagram, and Messenger)
These messaging integrations are being introduced to the Service and may not yet be enabled for every Customer. This section describes how the associated data will be handled once a Customer connects one of these channels.
Where a Customer connects a WhatsApp Business account, an Instagram professional account, or a Facebook Page (Messenger) to the Service, we access data from that channel on the Customer's behalf so Jamie can read incoming messages from the Customer's own customers (End Customers), draft replies, and — where the Customer has configured Jamie to do so — send replies on the Customer's behalf. These channels are provided through Meta Platforms, Inc. (Meta). This section describes our handling of that data and applies in addition to the rest of this Policy.
What we receive. Through these integrations we receive the content of messages an End Customer sends to the Customer's connected account, together with associated metadata — for example the End Customer's WhatsApp phone number and WhatsApp ID (wa_id), Instagram-scoped ID, or Messenger Page-scoped ID (PSID); any display name Meta provides; message timestamps and identifiers; and delivery, read and failure status events. We also store the identifiers and access tokens for the connected account (for example the WhatsApp phone number ID and WhatsApp Business Account ID, or the connected Page and Instagram account IDs) that are required to receive and send messages on the Customer's behalf.
Minimum permissions. We request only the Meta permissions necessary to deliver the messaging integration the Customer has enabled. The Customer connects each channel through Meta's own authorisation flow, can see which permissions have been granted, and can revoke our access at any time from the Customer's Meta Business settings or from the Service's integration settings.
Transparency. Jamie is an automated AI assistant. We do not impersonate a human; replies sent through these channels are sent on the Customer's behalf and are identified as coming from an automated assistant, consistent with Meta's policies.
Compliance with Meta's terms. Our access to, use of, and transfer of data received through these integrations adhere to Meta's Platform Terms and Developer Policies (developers.facebook.com/terms) and, for WhatsApp, the WhatsApp Business Terms, including any limitations those terms place on the use of platform data.
Restrictions on use of Meta data. Consistent with those terms:
(a) we do not use data received through these integrations for advertising purposes, including serving ads, retargeting, personalised advertising, or interest-based advertising;
(b) we do not sell this data, and we do not transfer it to any third party except (i) Sub-processors strictly necessary to deliver the messaging features described above, (ii) where required by applicable law, (iii) as part of a merger, acquisition or sale of assets, after obtaining the Customer's explicit prior consent, or (iv) where the Customer has directed or expressly consented to a specific transfer;
(c) we do not use this data to develop, improve, or train generalised AI or machine learning models, including the foundation models offered by our LLM Sub-processor. Message data is sent to the LLM Sub-processor solely to generate the specific reply the integration is requested to produce, and is subject to the no-training position described in section 4;
(d) humans do not read End Customer message content received through these integrations, except where: (i) the Customer has given us specific, voluntary, opt-in consent (for example, to debug an issue they have reported); (ii) it is necessary for security, including investigating abuse or addressing a security incident; (iii) it is necessary to comply with applicable law; or (iv) the data has been aggregated or de-identified and is used for internal operations consistent with applicable law.
Storage of messaging data. Messages and metadata received through these integrations are stored as part of Customer Data, encrypted in transit (TLS) and at rest, and retained in line with section 9.
Disconnecting and deleting messaging data. The Customer can disconnect any messaging channel at any time from within the Service, and can revoke our access from the Customer's Meta Business settings. Once disconnected we revoke and delete the associated Meta access tokens immediately, stop receiving further messages on that channel, and delete synced message content in line with the deletion commitments in section 9. The Customer, or an End Customer, may also request deletion of specific data at any time — the Customer through the Service, and an End Customer either through the Customer or via our public web form at https://jamieclerk.ai/delete-account — and we will action the request as described in section 12. Where Meta notifies us that an End Customer has revoked permission or requested deletion of their data, we honour that request and delete the corresponding data.
5. Sub-processors and sharing of personal information
We do not sell personal information, and we do not disclose personal information to third parties for the purpose of those third parties marketing their own products or services to You.
Sub-processors that process personal information on our behalf. To deliver the Service we engage Sub-processors who process personal information strictly on our instructions and under contractual obligations of confidentiality and security. Personal information is encrypted in transit and at rest. Where a Sub-processor must operate on personal information to deliver its service — for example, when our LLM Sub-processor generates a reply from the conversation text, or when our error-monitoring Sub-processor receives a stack trace — the data is decrypted only as needed to perform that operation and is not used for any other purpose. Sub-processor personnel do not access personal information except where strictly necessary to provide, secure or debug the service. The information remains accessible to You and Your authorised users when accessing it through the Service. Our current Sub-processors include:
Google Cloud Platform — hosting, databases, storage and serverless infrastructure (Australia);
Firebase (Google) — authentication, serverless functions and notifications;
Google Vertex AI — large language model inference and embedding generation. Conversational-model inference and embedding generation are both served from Google's global Vertex AI endpoint and may run in any region with available capacity, predominantly in the United States;
Cloudflare — bot protection (Turnstile) and edge content delivery for the chat widget, on Cloudflare's globally distributed network;
Resend — transactional email delivery for service notifications and escalations (United States);
Sentry — application error monitoring (United States);
a third-party payment gateway — billing address and tokenised payment method storage;
analytics and transactional-communication providers — product telemetry and service-related notifications.
Law enforcement, regulators and courts. We share personal information with law enforcement, regulators or courts where required by law or where we reasonably believe disclosure is necessary to investigate or prevent fraud, harm or breach of our Terms & Conditions.
Corporate transactions. In the event of a merger, acquisition, or sale of substantially all of our assets, we may share personal information with the other party to the transaction, subject to confidentiality protections.
Professional advisers. We may share personal information with our professional advisers, such as lawyers and accountants, where reasonably necessary and subject to confidentiality, and with third parties to whom You direct us to share information.
6. Direct marketing
We may send You electronic marketing messages — by email and, where You have provided a mobile number, by SMS — about features and offers that we believe will interest You. We will only send marketing messages where we have Your express or inferred consent, in accordance with the Spam Act 2003 (Cth), and every marketing message will include an easy way to opt out (for example, an unsubscribe link, or replying STOP to an SMS). You can also contact us through the Service at any time to be removed from our marketing list. Opting out of marketing does not affect service-related communications, which we may continue to send to operate the Service.
We do not send our own marketing messages to End Customers. Any marketing or transactional message sent through the Service to an End Customer is sent on behalf of the Customer, in accordance with the configuration the Customer has set and the requirements of section 6 of our Terms & Conditions.
7. Cross-border disclosure of personal information
The primary, durable record of Customer Data — including conversations between Jamie and Your End Customers, contact records, the business knowledge base, and operational metadata — is stored in Australia.
Some processing of personal information takes place outside Australia, in the following countries:
United States — Google Vertex AI processing on its global endpoint (the conversational model that generates Jamie's replies and the embedding model that indexes Your knowledge base for retrieval, both processed transiently and not retained, and predominantly served from the United States), Resend (transactional email delivery), and Sentry (application error monitoring);
Cloudflare's globally distributed network — bot protection and edge content delivery for the chat widget, including in-transit handling of message bodies.
Before disclosing personal information overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the APPs, primarily through contractual safeguards (for example, the Google Cloud Data Processing Addendum, and equivalent Sub-processor agreements with Resend, Sentry and Cloudflare). By using the Service, You acknowledge that personal information may be processed outside Australia as described in this Policy.
Under section 16C of the Privacy Act, where we disclose personal information to an overseas recipient, we remain accountable for any breach of the APPs by that recipient as if the breach were our own.
8. How we keep personal information secure
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include encryption in transit (TLS) and at rest, role-based access controls, audit logging, vulnerability monitoring, and reviews of our Sub-processors' security postures.
No system is perfectly secure, and we cannot guarantee the security of personal information transmitted to or from us. You play an important role in security too: keep Your account password confidential, enable multi-factor authentication where offered, and contact us immediately if You suspect a compromise.
9. How long we keep personal information
We keep personal information only for as long as is necessary for the purposes for which it was collected, or as required by law. Account information is kept while Your account is active and for a reasonable period after closure to handle billing and dispute resolution. Customer Data is retained in line with the Customer's configuration and our Terms & Conditions. For 30 days after termination of the Agreement, we retain Customer Data and make it available for export. After that period, Customer Data is permanently deleted and cannot be recovered, except for any de-identified or aggregated information (which may be retained indefinitely) and any information we are required by law to retain. You can also request deletion of Customer Data at any time by contacting us through the Service, in which case we will action the request as described in section 12.
10. Cookies and similar technologies
We use cookies and similar technologies to operate jamieclerk.ai, our mobile app and the Service, remember Your preferences, authenticate Your session, measure performance, and improve features. You can control cookies through Your browser settings; disabling cookies may break parts of the Service.
11. Children
The Service is intended for businesses and is not directed to children under 18, consistent with the minimum age of 18 required to use the Service under our Terms & Conditions. We do not knowingly collect personal information from children. If You believe a child has provided us with personal information, contact us through the Service and we will take reasonable steps to delete it.
12. Your rights — access, correction, and deletion
Under the APPs You have the right to request access to the personal information we hold about You, and to ask us to correct it if it is inaccurate, incomplete, out-of-date, irrelevant, or misleading. You may also ask us to delete personal information, subject to our legal obligations and where retention is necessary for a permitted purpose.
To make a request, contact us through the Service. We will respond within a reasonable period (and in any case within 30 days) and will not charge You to access or correct Your personal information. If we cannot give You access (for example, where doing so would unreasonably impact another person's privacy) we will explain why in writing.
Deleting Your account. You can permanently delete Your account from within the Service at any time by going to Settings → Account → Delete my account. When You confirm, Your login is removed immediately and the Jamie widget on Your website is disabled immediately. All of Your business data — conversations, contacts, documents, FAQs, skills, and business settings — is retained for 30 days so You have a chance to contact us if You change Your mind, and is then permanently deleted from our systems. To recover Your business within the 30-day window, email from the address You used to sign up. After 30 days the data is permanently gone and we cannot restore it. (Note: information we are required by law to retain — for example, billing records — is retained for the period required by law.)
If You can no longer sign in (for example, because You uninstalled the app) You can still request deletion through our public web form at https://jamieclerk.ai/delete-account. Our team verifies ownership of the email address before processing.
Reporting a Jamie reply. If the Service produces a Jamie reply that You believe is wrong, misleading, or off-brand, You can flag it from within the conversation view by tapping the Report affordance on the message. Our team reviews flagged replies and uses them to improve the Service.
13. Notifiable Data Breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware that there are reasonable grounds to suspect that there may have been an eligible data breach involving personal information, we will take all reasonable steps to complete an assessment of whether the suspected breach is an eligible data breach within 30 days, and sooner where practicable, as required by the scheme.
If we determine that an eligible data breach has occurred — that is, a breach that is likely to result in serious harm to any affected individual — we will, as soon as practicable, notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals (or otherwise publish a statement in accordance with the scheme), and will work with affected Customers to coordinate any notifications they are required to make.
14. Complaints
If You believe we have breached the APPs, please contact us through the Service with a description of the issue. We will investigate and respond within a reasonable period (and in any case within 30 days).
If You are not satisfied with our response, You may complain to the Office of the Australian Information Commissioner (OAIC): by phone on 1300 363 992, by post to GPO Box 5288, Sydney NSW 2001, or online at www.oaic.gov.au.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The current version is always available at jamieclerk.ai/privacy and within the Service. Where a change is material, we will notify You by email or in-product notice before the change takes effect.
16. Contact us
For privacy-related questions, requests, or complaints, please contact us through the Service.
The APP entity responsible for the Service is Jamie Clerk Pty Ltd (ABN 67 698 745 881).
© 2026 Jamie Clerk Pty Ltd. All rights reserved.