1. About This Policy
Awesomate.ai (“Awesomate”, “we”, “us”, or “our”) is committed to protecting personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, use our services, or otherwise interact with us. It applies to all of our services, including managed n8n hosting, the Buddzee data platform, and Vibe Coding application development.
By using our services, you consent to the practices described in this policy. If you do not agree with this policy, please do not use our services.
2. Our Role: Data Controller and Data Processor
Awesomate operates in two capacities depending on the type of data involved:
As a data controller: We collect and manage personal information about our customers for account management, billing, communications, and service delivery (e.g., your name, email, payment details). We determine the purposes and means of processing this data, and this Privacy Policy governs that processing.
As a data processor: When you use our services — including n8n hosting, Buddzee, and Vibe Coding — we process data on your behalf according to your instructions. This may include your customers’ data, business records, and other information you choose to store or process through our platforms. In this capacity, you remain the data controller and are responsible for ensuring that your use of our services complies with applicable privacy laws. We process this data solely to deliver the services you have engaged us to provide and in accordance with any Data Processing Addendum (DPA) agreed between us.
This distinction is important: our obligations and your rights differ depending on whether Awesomate is acting as a controller or a processor. The remainder of this policy covers both roles, with specific sections noting where distinctions apply.
3. Information We Collect
Personal Information (Awesomate as Controller)
We may collect the following personal information directly from you:
- Name (first and last)
- Email address
- Phone or SMS number
- Company name and job title
- Billing and payment information
- Account login credentials
Usage and Technical Data
When you visit our website or use our services, we may automatically collect:
- IP address and approximate location
- Browser type and version
- Device type and operating system
- Pages visited, session duration, and navigation paths
- Referring website or source
Service Data (Awesomate as Processor)
Depending on which services you use, we may process data on your behalf, including:
- n8n Hosting: Workflow configurations, execution logs, and connected service credentials (encrypted at rest)
- Buddzee: Database connection details, query history, and generated reports
- Vibe Coding: Application specifications, design requirements, and project files
This service data belongs to you. We do not access, use, or disclose it except as necessary to deliver the services you have requested, or as required by law.
Sensitive Information
We recognise that some clients use our services to process sensitive information as defined under the Privacy Act, which may include biometric data, health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records, or trade union membership.
When Awesomate processes sensitive information on your behalf as a data processor:
- We do so only under your instruction and in accordance with any agreed Data Processing Addendum.
- We apply additional safeguards, including the option for fully isolated infrastructure deployments (see Section 9: Data Isolation).
- We do not collect, use, or disclose sensitive information for any purpose other than delivering the services you have engaged us to provide.
- We require explicit consent or lawful authority before processing sensitive information, in compliance with APP 3.3.
If your use case involves sensitive information — particularly in regulated industries such as government, healthcare, or financial services — we strongly recommend engaging with us to establish a Data Processing Addendum tailored to your compliance requirements.
Communication Data
We collect information from your interactions with us, including support tickets, contact form submissions, email correspondence, and feedback you provide.
4. How We Collect Information
- Directly from you — when you fill out forms on our website, register an account, contact us for support, or provide information during onboarding.
- Automatically — through cookies, analytics tools, and server logs when you visit our website or use our services.
- From third parties — from payment processors (transaction confirmations), referral partners, and publicly available business directories.
5. Why We Collect Information
We collect and use personal information for the following purposes:
- Service delivery — to set up, maintain, and support your account and the services you subscribe to.
- Payments and billing — to process transactions, send invoices, and manage subscriptions.
- Communication — to respond to enquiries, send service updates, and provide technical support.
- Marketing — to send promotional material with your consent. You can opt out at any time.
- Improvement — to analyse usage patterns, improve our services, and develop new features.
- Security — to detect, prevent, and respond to security incidents, fraud, and abuse.
- Legal compliance — to comply with applicable laws, regulations, and legal processes.
6. How We Use AI and Automated Systems
Our Buddzee platform and related services use artificial intelligence and machine learning technologies to help you query and analyse your business data using natural language. Here is how AI is used within our services:
- AI processes your data to generate insights, reports, and query results based on your instructions.
- AI does not make autonomous decisions that affect your rights or interests — it produces informational outputs that you choose how to act on.
- We do not use automated decision-making that produces legal effects or similarly significant effects on individuals without human oversight.
AI Data Protection Commitments
AI processing may involve third-party AI providers. Our current AI sub-processors and their data commitments are:
All data transmitted to AI providers is encrypted in transit. We do not send personally identifiable information to AI providers unless it is contained within the data you have instructed us to process on your behalf.
We are committed to transparency about how AI is used in our services and will update this section as our use of AI evolves, in accordance with the automated decision-making transparency requirements under the Privacy Act.
7. Who We Share Information With
We never sell your personal information.
We may share your information with the following categories of third parties, only to the extent necessary to deliver our services:
We may also disclose personal information to professional advisors (legal, accounting), law enforcement or government agencies when required by law, or to a potential buyer in the event of a business sale or merger.
8. International Data Transfers
Your personal information may be transferred to and processed in countries outside of Australia. Specifically:
- United States — our default hosting infrastructure is located in the US. AI API providers (OpenAI, Anthropic, Google) also process data in the US.
- Australian hosting — for clients with data sovereignty requirements, we can deploy fully isolated infrastructure within Australian-region data centres. Contact us to discuss Australian-hosted deployment options.
- Other regions — we can deploy infrastructure across North America, Asia Pacific, or Europe depending on your compliance requirements. All inter-datacenter traffic travels over private network infrastructure and never traverses the public internet.
Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles your information in accordance with the APPs (APP 8). All our third-party providers are bound by data processing agreements that require appropriate security and privacy safeguards.
For clients in regulated industries, data residency requirements — including the jurisdiction of backups and disaster recovery — can be addressed as part of a Data Processing Addendum.
9. Data Isolation
Awesomate’s infrastructure is designed to support varying levels of data isolation depending on client requirements.
Standard deployments: Client services are deployed within shared infrastructure groups with logical separation between accounts. Access controls ensure that each client can only access their own data.
Isolated deployments: For clients with enhanced security or compliance requirements — including government, healthcare, and financial services — we offer fully isolated infrastructure deployments. In an isolated deployment:
- Your services run on dedicated infrastructure components (database, caching, web server, and search services) that are not shared with any other client.
- No other client is deployed within your infrastructure group.
- Network-level segmentation enforced at the firewall layer ensures that traffic between isolated environments is prohibited by default. This isolation is not dependent on application-level controls.
- All traffic within your deployment is encrypted at the network layer.
This isolation model applies to both our n8n hosting and application hosting services. Isolated deployments can be combined with regional hosting to meet both data sovereignty and data segregation requirements simultaneously.
Detailed technical specifications of our isolation architecture are available under NDA as part of our security documentation. To discuss isolated deployment options, contact us at [email protected].
10. Data Security
We take the security of your data seriously. Our infrastructure is purpose-built for workloads that require the highest levels of security and compliance. Key security measures include:
- Dedicated infrastructure — our private cloud runs on dedicated physical servers exclusively allocated to Awesomate. We do not share compute, network, or storage resources with any third party at the physical infrastructure level.
- No public exposure — no server in our infrastructure has a public IP address. All user traffic enters through a secure, outbound-initiated tunnel. There are no open inbound ports.
- Encryption in transit — all traffic between services within our infrastructure is encrypted at the network layer. External traffic is encrypted via TLS. Backup transfers to offsite storage use TLS with certificate verification enforced.
- Encryption at rest — encryption at rest is available for all persistent volumes. Secrets such as API keys and database credentials are encrypted and never stored in plaintext.
- High-availability firewalling — all traffic is governed by a redundant firewall pair with instant failover. There is no single point of failure in the network security layer.
- Mandatory VPN for administration — all administrative access to production infrastructure requires an authenticated VPN connection. No management interface is accessible from the public internet.
- Automated credential rotation — administrative credentials are automatically rotated on a scheduled basis across all infrastructure.
- Database redundancy — production databases run as multi-replica clusters distributed across separate physical servers with automatic failover. No single hardware failure causes data loss or service interruption.
- Multi-layered backup strategy — frequent automated snapshots provide rapid on-host recovery, supplemented by daily encrypted offsite backups with multi-day retention.
- Full-stack monitoring — real-time monitoring and alerting across all infrastructure components, with network flow analysis for detecting anomalous traffic and supporting forensic investigation.
- Infrastructure as Code — every configuration across the entire infrastructure is version-controlled and auditable. Every change has an author, timestamp, and review history. The complete infrastructure can be rebuilt from scratch in a disaster recovery scenario.
- Firewall audit logs — retained for 30 days, covering all accepted and rejected traffic across network boundaries.
Detailed technical specifications of our security architecture, including encryption protocols, network design, and access control implementation, are available under NDA as part of our security documentation for enterprise and government clients.
While we implement robust security measures, no system is completely immune to risk. We encourage you to use strong, unique passwords and keep your account credentials secure.
11. Data Retention
We retain personal information only as long as necessary for the purposes outlined in this policy:
- Active accounts — data is retained for the duration of your service.
- After cancellation — your data remains available for export for 30 days after service termination, then is securely deleted. Extended retention periods can be agreed contractually for enterprise and government clients.
- Billing records — retained for 7 years to comply with Australian tax and financial reporting requirements.
- Server logs — retained for 90 days, then automatically purged.
- Firewall audit logs — retained for 30 days.
- Automated snapshots and backups — retained on a rolling basis in accordance with our backup schedule. All backups are included in the data deletion process upon service termination.
- Marketing data — retained until you withdraw consent or unsubscribe.
Upon termination of services, we securely delete all service data, including backups, within the agreed timeframe. For clients requiring certified deletion, this can be arranged as part of a Data Processing Addendum.
12. Cookies and Tracking
Our website uses cookies and similar technologies to enhance your experience:
- Essential cookies — required for the website to function (session management, authentication). These cannot be disabled.
- Analytics cookies — help us understand how visitors use our website so we can improve it.
- Marketing cookies — used with your consent to deliver relevant content and track campaign effectiveness (including Ontraport tracking and UTM parameters).
You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website.
13. Your Rights
Under the Australian Privacy Act, you have the right to:
- Access your personal information that we hold about you.
- Correct any inaccurate, incomplete, or out-of-date information.
- Request deletion of your personal information, subject to our legal obligations to retain certain records.
- Data portability — request an export of your data in a standard, machine-readable format.
- Withdraw consent for marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.
- Complain to us about how we handle your personal information. If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
14. Notifiable Data Breaches
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
- Conduct an initial assessment within 24 hours of becoming aware of the breach.
- Take immediate steps to contain the breach and mitigate any harm.
- Notify affected clients within 72 hours of confirming that the breach meets the notification threshold.
- Notify the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme.
- Provide clear information about what happened, what data was affected, and what steps individuals can take to protect themselves.
For clients with a Data Processing Addendum, breach notification timelines may be further tightened in accordance with your contractual requirements.
15. Enterprise and Government Clients
We recognise that clients in regulated industries — including government, healthcare, defence, and financial services — have compliance requirements that go beyond what a standard privacy policy can address.
Our infrastructure is purpose-built for sensitive and regulated workloads, running on dedicated physical servers with no shared resources, a zero-public-exposure network architecture, encryption at every layer, and full auditability through Infrastructure as Code.
Our hosting provider holds internationally recognised certifications at the data centre level, including ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 1 Type 2, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS. Certification documentation is available upon request.
For regulated-industry clients, we offer:
- Data Processing Addendum (DPA) — a contractual agreement covering data handling obligations, permitted use, sub-processor management, audit rights, breach notification timelines, and data deletion procedures.
- Fully isolated infrastructure — dedicated compute, database, caching, and networking with firewall-enforced separation and no resource sharing (see Section 9).
- Regional data hosting — deployment within Australian or other specified jurisdictions, with all data including backups remaining within the agreed region.
- Security documentation — detailed infrastructure architecture, data flow diagrams, network design, encryption specifications, and security control documentation available under NDA.
- Audit support — cooperation with your security assessments, penetration testing (by arrangement), and compliance audits.
- Government framework alignment — our technical controls align with major government and enterprise security frameworks covering access control, audit and accountability, configuration management, identification and authentication, incident response, system and communications protection, system integrity, and contingency planning.
To discuss enterprise or government requirements, contact us at [email protected].
16. Children’s Privacy
Our services are designed for businesses and are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child, we will take steps to delete it promptly.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or by posting a prominent notice on our website. We encourage you to review this page periodically.
18. Contact Us
If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:
- Email: [email protected]
- Website: awesomate.ai/contact
If you are not satisfied with our response to a privacy concern, you can contact the Office of the Australian Information Commissioner:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
