Westringia is an OpenAI Select Partner.

What the partnership means →
Westringia Labs

Legal

Privacy policy

How we handle personal information, written so you can actually read it.

The short version

We collect very little. If you email us, ring us or fill in a form, we keep what you send so we can reply. If you hire us, we see whatever is inside the systems we work on, and we treat that as yours.

Some of the AI services we build on run overseas. We say which ones, below, and we stay responsible for what happens to your information after it leaves. We do not sell anything to anyone.

Who we are

This policy applies to Westringia Labs, based in Sydney, New South Wales. You can reach us at hello@westringia.com or on 02 8531 8610.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. oaic.gov.au ↗

What we collect, and why

When you contact us. Your name, email address, phone number, business name, and whatever you choose to tell us about your situation. We use it to reply and to work out whether we can help. We keep it so that if you come back in six months we remember the conversation.

When you hire us. Contact and billing details for the people we deal with. During a project we usually get access to systems that hold information about your staff and your customers. We only look at what the job needs, we work under your instructions, and we do not use it for anything else.

When you visit this website. This site is a set of static pages. It runs no analytics, sets no cookies of its own, and does not track you between visits. Our hosting provider keeps standard server logs, which include IP addresses, for security and troubleshooting.

When you ask us to read your website. The contact page can read up to three pages of a website you name – pages anyone can see. It writes a short first look from them. The read runs only after you give an email address and tick the consent box, and both are kept with the read as a lead in our own system, so the person who replies has it in front of them. It is kept as enquiry information (see below), used for replying to you and nothing else, and deleted whenever you ask. We record the exact consent sentence you agreed to, and we store a scrambled form of your network address rather than the address itself.

We do not buy contact lists, and we do not collect sensitive information such as health, biometric or political information unless a specific project requires it and we have agreed that in writing first.

Where your information goes

Building AI systems means using services that may process information outside Australia. Under Australian Privacy Principle 8 we have to take reasonable steps to make sure an overseas recipient handles your information the way the APPs require. oaic.gov.au ↗

There is a part of that law worth knowing about, because most privacy policies skip it. Under section 16C, if an overseas provider mishandles information we sent them, that is treated as our breach, even if we took reasonable steps beforehand. We cannot contract our way out of it. So our approach is to keep processing inside Australia where the service supports it, and to be specific with you about the cases where it does not.

Who processes information for us

Providers we may use. Where a row says "to be confirmed" we have not yet settled on a provider, and this table is updated when we do.
Provider What it does Where it processes
Website hosting Serves these pages and keeps server logs To be confirmed
Email Sends and receives our email, including your enquiry To be confirmed
AI model providers Runs the models inside systems we build. Named in the statement of work for each project, along with the region each one runs in. Australia where supported, otherwise overseas

On a client project, the providers we use are named in the statement of work before the work starts, so you know the list before you agree to it. Where a provider offers terms that exclude training on customer content, we use those terms. We do not put your information into publicly available chatbots. The Office of the Australian Information Commissioner recommends against exactly that, and we agree with it. oaic.gov.au ↗

Decisions made by computers

From 10 December 2026, Australian privacy law requires an organisation to say in its privacy policy when a computer program makes a decision about someone, or does something substantially and directly related to making one, where that decision could significantly affect their rights or interests and personal information is used to do it. OAIC, APP 1 guidelines ↗

We do not make any such decisions about you. We do not score you, rank you, or use software to decide whether to work with you. A person reads every enquiry.

If that ever changes, we will list here what kinds of personal information go into the program, which decisions are made entirely by it, and which ones it substantially helps a person make.

This obligation applies to our clients too, and it catches more than AI. Credit scoring tools and software that sorts job applicants count as well. Working out which of your systems are covered is part of any build we do, and we will do it on its own if you just want it sorted.

Keeping it safe, and getting rid of it

We use separate credentials for each client, we turn on multi-factor authentication where a service supports it, and we limit access to the people doing the work. Under APP 11 we have to take reasonable steps to protect personal information and to destroy or de-identify it when it is no longer needed. oaic.gov.au ↗

We keep enquiry information for two years after our last contact. Project records we keep for seven years, because tax and corporations law require it. Access to a client's systems is handed back or switched off at the end of the engagement, and we ask you to confirm it has been revoked at your end too.

We do not hold an independent security certification such as ISO 27001 or SOC 2. We would rather say that plainly than imply otherwise.

Marketing

We do not run marketing campaigns, and there is no mailing list on this site. If we ever send something, it will be to people who asked for it, it will say who it is from, and it will have a working unsubscribe link.

Seeing what we hold, and correcting it

You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Email hello@westringia.com. We will reply within 30 days. There is no charge. If we cannot give you something, we will tell you why in writing.

If the information sits inside a client's system and we are handling it on their behalf, we will point you to them, because it is their record rather than ours.

If you are our client

When we handle personal information on your behalf, you remain the organisation responsible to your own customers for it. We act on your instructions. If a system we build for you makes decisions about people, the disclosure obligation described above is yours, and we will help you work out what it covers and write it down.

Complaints

Tell us first. Email hello@westringia.com with what happened and we will look into it and respond within 30 days.

If you are not satisfied with our answer, you can take it to the Office of the Australian Information Commissioner. They can be reached on 1300 363 992, and their complaints process is set out on their website. oaic.gov.au ↗ You do not need our permission to complain to them.

Changes

If we change this policy we will change the date below. If a change matters to someone we are working with, we will tell them directly rather than expect them to notice.

Last updated 8 August 2026.