Privacy Policy – Aiven Technologies
Welcome to Aiven Technologies. We are a dedicated AI development company in Perth Australia that builds intelligent software solutions for businesses across a wide range of industries. When you visit our website, reach out through a contact form, or work with us on a project, you trust us with certain personal details. That trust is something we take seriously.
This Privacy Policy spells out how we collect, store, use, and share your personal information. It also walks you through your rights under Australian law and the steps you can take if something does not sit right with you. We have written this policy in plain, everyday language so there are no grey areas or buried surprises.
Everything here aligns with the Privacy Act 1988 (Cth), the thirteen Australian Privacy Principles (APPs), the Notifiable Data Breaches (NDB) scheme, and, where applicable, the EU General Data Protection Regulation (GDPR) for our international clients.
The data we collect in our privacy policy?
We only gather personal information that is genuinely needed for the services we provide. Here is a breakdown of what that looks like in practice:
Information you give us directly:
- Full name, job title, and company name
- Email address, phone number, and postal address
- Details you share through enquiry forms, project briefs, or email conversations
- Payment and billing information (processed through secure third-party gateways we never store your card numbers on our servers)
Information collected automatically when you visit our website:
- Your IP address and general geographic location
- Browser type, device information, and operating system
- Pages you viewed, time spent on each page, and referring URLs
- Cookie data and similar tracking identifiers (see the Cookie section below for full details)
Information from third-party sources:
- Publicly available business data such as LinkedIn profiles or company directories
- Referral details if a mutual contact introduces you to us
- Analytics platforms like Google Analytics that provide aggregate visitor behaviour data
We do not go out of our way to collect sensitive information such as health records, racial background, religious beliefs, or political opinions. If a project ever requires handling that type of data, we will seek your explicit consent first and put extra safeguards in place.
How We Use Your Information
Every piece of personal data we collect serves a clear, defined purpose. As an AI development company in Perth Australia working on projects that often involve complex data pipelines, we are acutely aware of the responsibility that comes with handling information. Here is what we use your data for:
- Responding to your enquiries: When you fill out a form, send us an email, or call our office, we use your contact details to get back to you promptly.
- Delivering our services: Project management, software development, testing, deployment, and ongoing support all require us to keep records of who we are working with and what has been agreed upon.
- Invoicing and payments: Your billing details help us generate invoices, process payments, and maintain accurate financial records as required by Australian taxation law.
- Improving our website: Analytics data helps us understand which pages are useful, where visitors drop off, and how we can make the browsing experience smoother.
- Marketing communications: If you opt in, we may send you newsletters, case studies, or product updates. You can unsubscribe at any time (see the section on electronic communications below).
- Legal compliance: Certain records must be kept to comply with Australian corporate, taxation, and privacy legislation.
We will never use your information for a purpose that is completely unrelated to the ones listed above without telling you first and getting your agreement.
Our Legal Grounds for Processing Your Data
Under Australian law, we rely on the following lawful bases:
- Consent: You gave us clear permission to collect and use your data for a specific purpose. You can withdraw this consent at any time.
- Contractual necessity: We need your information to fulfil a contract or complete a project you have engaged us for.
- Legitimate interest: Certain processing activities, such as website analytics or fraud prevention, are reasonably necessary for running our business without overriding your privacy rights.
- Legal obligation: Some data must be retained to meet requirements under Australian law, including the Corporations Act 2001, the Income Tax Assessment Act, and the Privacy Act 1988.
For our clients based in the European Union, we also honour the GDPR’s lawful basis requirements and will always be transparent about which basis applies to each processing activity.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to give you a better browsing experience. Here is the breakdown:
Essential cookies: These keep the site functioning. They handle things like session management and security. You cannot opt out of these because the site simply would not work without them.
Analytics cookies: We use tools like Google Analytics to understand how people navigate our site. These cookies track page views, session duration, and general traffic patterns. The data is aggregated and does not personally identify you.
Marketing cookies: If we run advertising campaigns, these cookies help measure their effectiveness. They may also allow third parties to show you relevant ads on other platforms.
You have choices when it comes to cookies:
- Adjust your browser settings to block or delete cookies at any time.
- Use our cookie consent banner to select which categories you are comfortable with.
- For visitors from the EU, we apply opt-in consent for all non-essential cookies in line with the ePrivacy Directive and GDPR.
Keep in mind that disabling certain cookies may reduce the functionality of our website.
Who Do We Share Your Data With?
We do not sell, rent, or trade your personal information. Full stop. However, running a modern technology business means working with trusted partners. Here are the categories of third parties who may receive your data:
- Cloud infrastructure providers: We host data on secure platforms such as Amazon Web Services (AWS) and Google Cloud Platform. Servers may be located in Australia, the United States, or the European Union.
- Payment processors: Secure, PCI-DSS compliant gateways handle all financial transactions on our behalf.
- Analytics and marketing platforms: Google Analytics, email marketing tools, and CRM systems help us manage communications and measure website performance.
- Professional advisors: Accountants, lawyers, and auditors may access certain information in the course of providing their services to us.
- Government and regulatory bodies: We will disclose information if required by law, a court order, or a lawful request from a regulatory authority such as the Australian Information Commissioner.
Every third-party provider we work with is bound by contractual obligations to handle your data securely and only for the purposes we specify.
Keeping Your Data Safe
Data security is not an afterthought for us it is woven into how we build and operate everything. Here is what we do to protect your information:
- All data in transit is encrypted using TLS 1.2 or higher.
- Data at rest is encrypted on our cloud servers.
- Access to personal information is restricted to team members who genuinely need it for their role.
- We conduct regular security reviews, vulnerability assessments, and penetration testing.
- Staff complete annual privacy and security awareness training.
- We maintain documented incident response and disaster recovery procedures.
No system is completely immune to risk, but we are committed to keeping our defences as strong as practically possible.
How Long Do We Keep Your Data?
We only hold onto personal information for as long as it is needed. Once the purpose has been fulfilled and there is no legal reason to retain it, we securely destroy or de-identify the data. Here are some general timeframes:
- Client project records: Retained for seven years after project completion to comply with Australian taxation and corporate law requirements.
- Enquiry and contact form data: Retained for two years unless the enquiry leads to a client relationship.
- Website analytics data: Aggregated and anonymised data may be kept indefinitely; identifiable data is deleted within 26 months.
- Marketing consent records: Kept for as long as you remain subscribed, plus two years after unsubscription for compliance evidence.
If you ask us to delete your data, we will do so promptly unless we are legally required to keep it.
Your Privacy Rights
You have real, enforceable rights when it comes to your personal data. Here is what you are entitled to:
- Access: You can ask us for a copy of the personal information we hold about you. We will respond within a reasonable timeframe, and in most cases there will be no charge.
- Correction: If any of your information is inaccurate, out of date, or incomplete, let us know and we will fix it.
- Deletion: You can request that we delete your personal information, subject to any legal obligations that require us to keep certain records.
- Restrict processing: In certain circumstances, you can ask us to limit how we use your data while a concern is being resolved.
- Data portability: For our EU-based clients, you can request your data in a commonly used, machine-readable format so you can transfer it to another provider.
- Object to processing: You can object to us processing your data for direct marketing purposes, and we will stop.
- Withdraw consent: Where we rely on your consent, you can pull it back at any time without affecting the lawfulness of anything we did before you withdrew it.
To exercise any of these rights, email us at: reach@aiventechnologies.com. We will verify your identity before processing your request and aim to respond within 30 days.
Electronic Communications and the Spam Act
We play by the rules set out in the Spam Act 2003 (Cth). That means:
- We will never send you commercial electronic messages without your consent (express or inferred).
- Every marketing email we send clearly identifies Aiven Technologies as the sender and includes our accurate contact details.
- Every marketing email contains a working unsubscribe link. Once you unsubscribe, we honour it no tricks, no delays, no “are you sure?” loops.
- We process unsubscribe requests within five business days.
If you believe you have received an unsolicited message from us, please let us know immediately and we will investigate.
Automated Decision-Making and AI Transparency
Given our line of work, we think it is important to be upfront about how artificial intelligence features on our own operations. As part of our commitment to Australia’s AI Ethics Principles and the incoming Automated Decision-Making transparency obligations under the Privacy Act (effective 10 December 2026), here is what you should know:
- We do not currently use fully automated systems to make decisions that significantly affect your rights or interests without human oversight.
- Any AI tools used internally (for example, lead scoring or analytics) are supplementary and always subject to human review.
- If this changes in the future, we will update this policy and notify affected individuals before any significant automated decision-making is introduced.
Responsible AI practices sit at the core of who we are. We follow the six essential practices outlined in Australia’s Guidance for AI Adoption (AI6) framework and align our work with international standards such as ISO/IEC 42001.
Children’s Privacy
Our services are designed for businesses and professionals. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have inadvertently gathered data from a child, we will delete it promptly.
Third-Party Links
Our website may contain links to external sites that we do not control. Once you leave our site, this Privacy Policy no longer applies. We encourage you to review the privacy policies of any third-party websites before sharing your personal details.
How to Make a Complaint
If you feel that we have not handled your personal information properly, we want to hear about it. Here is the process:
- Contact us first:
Email at: reach@aiventechnologies.com with the details of your concern. We will acknowledge your complaint within five business days and aim to resolve it within 30 days. - Escalate if needed: If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
Get in Touch
If you have any questions about this Privacy Policy or how we handle your data, do not hesitate to reach out:
Address: Unit 14, 69–71 King George St Victoria Park WA 6100, Australia
Email: reach@aiventechnologies.com
Website: www.aiventechnologies.com
This Privacy Policy is provided for informational purposes and does not constitute legal advice. We recommend consulting a qualified Australian solicitor for specific legal guidance.

