Privacy policy
Gigabuddy is a place for your work, your people and your buddies (our AI agents). To do that job we have to hold some of your information. This policy says what we collect, why, who else touches it, and what you can do about it. We’re an Australian company and follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We also give everyone the rights in the EU and UK General Data Protection Regulation (GDPR), wherever you live.
The short version
- We collect what we need to run and improve Gigabuddy.
- We don’t sell your personal information, and we don’t show ads.
- We don’t train generative AI on your content, and our AI providers don’t either.
- What we store depends on the features you use. Messages, files, pages and call transcripts are stored because keeping them for you is the point.
- If you connect apps like GitHub or Xero, we also hold data from them. What depends on what you connect.
- Australia is our primary region for storing data.
- You can see, correct, export or delete your data. Email privacy@gigabuddy.com.
1. Who we are
“Gigabuddy”, “we” and “us” mean Gigabuddy Operations Pty Ltd (ABN 44 657 005 117), a company based in Melbourne, Australia. We run gigabuddy.com, the Gigabuddy apps (web, desktop and mobile), our APIs and our buddies. Our parent company, Gigabuddy Pty Ltd (ABN 37 657 004 281), may also handle your information, under this policy. For GDPR purposes we are the controller of your account and usage information.
When a club (a workspace, team or business on Gigabuddy) puts information into Gigabuddy, that club decides what goes in and who can see it. For that content we act on the club’s behalf (a “processor” under GDPR). If you have a question about content a club holds about you, ask the club first. We’ll help them answer you.
That means the club’s owners control what’s posted in the club, including what you post there. Depending on their role and settings they can see, export or delete it. If you leave a club or delete your account, what you posted in the club stays with the club unless the club deletes it. If you use Gigabuddy on your own, your own space is yours to control.
2. What we collect
Gigabuddy stores what you put into it. That’s the service: your messages, files and pages are there the next time you or your team look. So what we hold depends on which features you and your club use.
Everyone
- Account details: your name, email address, profile picture, and the sign-in identity you use (for example Google, Apple or GitHub).
- Membership: which clubs and rooms you belong to, and your role in them.
- Billing, if your club pays: the billing contact, plan, invoices and payment history. Card details go straight to our payment provider, Stripe. We never see or store full card numbers.
Depending on the features you use
- Messages and rooms: messages, replies, reactions and mentions, stored so the room keeps its history.
- Files: anything you upload, including documents, images, audio and video, stored so you and the people you share them with can open them later. We may process files so you and your buddies can search and use them, for example by transcribing a recording or reading the text in a document. We keep what that produces (such as a transcript) with the file.
- Pages, tasks and activities: what you write, with its edit history and comments.
- Calls: if a room turns on transcription, the text of what each person says, attributed to them, saved in the room. Audio is sent to a transcription provider to make the text. We don’t keep call audio unless a call is recorded, and you’ll know when it is.
- Dictation: where your device can, it turns speech into text on the device itself. In a web browser, dictation may use the browser’s own speech service (in Chrome this sends audio to Google). We keep the text you choose to send, not the audio.
- Buddies: your conversations with buddies, what they did for you, and notes a buddy keeps about how to work with you (for example your preferences), so it can remember them next time.
- Actions and automations: what ran, when, who started it, and its inputs and results, so you can see what happened and fix it.
- Waitlist sign-ups: your email address, the page you signed up from, your browser’s user agent and the time.
- Support: what you tell us when you contact us.
Apps and services you connect
When you or your club installs an app or connects another service, we hold data from that service. What we hold depends on what you connect and the permissions you approve when you connect it.
You’re shown what an app or service can access before you connect it. Where you see that depends on how it connects: in Gigabuddy, or on the other service’s own sign-in and consent screen (for example when you connect GitHub or Xero, they list what Gigabuddy is asking for).
For example:
- GitHub: repositories, issues, pull requests, comments and the people who made them.
- Xero: invoices, bills, contacts, accounts and bank transactions.
- HubSpot: contacts, companies, deals and notes.
- Shopify: products, orders and customers.
- Slack or Google: the messages, calendar events or files you give access to.
Across all of them, we hold:
- Connection details: which account is connected, by whom, and the access tokens that keep it working. Tokens are encrypted and used only for that connection.
- Data we fetch: some is read when a person or buddy asks for it and used for that request. Some is copied into Gigabuddy, for example to show it in a room, search it, or keep a record of what a buddy did.
- Events the service sends us: for example “a pull request was opened” or “an invoice was paid”, so Gigabuddy can react to them.
That data often includes information about other people, such as your customers or suppliers. The club that connects the service decides what to bring in and must have the right to share it with us. We handle it on the club’s behalf, and only to do what the club asks.
Disconnecting stops new data coming in. Data already copied into Gigabuddy stays in the club until it’s deleted, like any other content. You can also revoke access from the other service’s own settings.
Some apps in Gigabuddy are made by other developers. An installed app can use your club’s data only within the permissions it’s given. If it sends data to its developer’s own services, that developer’s privacy policy covers what they do with it.
Information collected automatically
- Usage and logs: which features you use, actions and buddies you run, errors, and request details such as IP address, browser and device type.
- Device information: for the mobile and desktop apps, your device model, operating system and a push notification token if you allow notifications.
- Presence: whether you’re online in a room, so others in the room can see it.
We don’t collect sensitive information (such as health, religion or political views) on purpose. If you put it into your content, we treat it as your content and protect it the same way.
3. How we use it
- To run Gigabuddy: sign you in, store and sync your content, run your actions and buddies.
- To connect to the services you’ve linked and act in them when you ask.
- To keep Gigabuddy secure: detect abuse, investigate incidents, and enforce our terms.
- To fix, improve and develop Gigabuddy, including new features.
- To understand how Gigabuddy is used, mostly through aggregated or de-identified information.
- To tell you about your account, security or changes to the service.
- To send you product news, only if you’ve asked for it. You can unsubscribe at any time.
- To meet our legal obligations.
- For other purposes we tell you about when we collect the information, or that you agree to.
We don’t sell personal information, share it for advertising, or build advertising profiles.
When our people look at your data
Most of Gigabuddy runs without anyone at Gigabuddy seeing your content. A small number of our people can access it when they need to:
- to help you, when you ask for support;
- to keep the service running and improve it, for example to fix a fault or recover lost data;
- to investigate security incidents, abuse or breaches of our terms;
- to meet a legal obligation, for example a court order or a request from a regulator.
They’re bound by confidentiality.
4. AI and buddies
Buddies are AI agents that work in your rooms. To answer a request, a buddy sends the relevant part of your content to an AI model provider. We use these providers under business terms that don’t let them train their models on your content, and that limit how long they keep it.
Training our own models
We don’t train generative AI models (models that write text or make images or speech) on your content.
We may use de-identified or aggregated information about how Gigabuddy is used to train our own models, so Gigabuddy works better for you: for example, to route your requests to the right buddy faster, or to spot what needs your attention first.
A club can ask us not to use its information this way by contacting privacy@gigabuddy.com.
AI can get things wrong. Buddies act with the permissions you and your club give them, and you can see what they did in the room.
5. Who we share it with
We share personal information in these cases:
- Other people in your club and rooms, according to the access you and your club set.
- Services you connect and apps you install, when you or a buddy asks Gigabuddy to act in them, and within the permissions they’re given.
- Our suppliers, who process data for us under contract and only on our instructions:
- cloud hosting, storage and sign-in;
- AI model providers;
- voice, calling and transcription services;
- email delivery;
- payments (Stripe);
- push notifications (Apple and Google).
- The law: when we must, for example to comply with a court order, or to protect someone from serious harm. If we’re asked for a club’s content, we’ll tell the club where we’re allowed to and it’s reasonable.
- Our related companies, such as Gigabuddy Pty Ltd, under this policy.
- With your agreement, or when you ask us to.
- A business change: if Gigabuddy is sold or merges, your information may move to the new owner, who must keep following this policy.
We’ll publish a list of the suppliers that handle personal data. Until then, email us and we’ll tell you who they are and where they process data.
6. Where your data is stored
We store data with Google Cloud. Australia (Sydney and Melbourne) is our primary region, and a new club’s data is stored there unless the club chooses otherwise. Where we offer other regions, a club can choose where its content (messages, files, pages, transcripts and the rest) is stored.
A club’s members can be anywhere in the world. The club’s content stays in the club’s region, wherever its members are. If you’re in more than one club, each club’s content lives in that club’s region. Your account details are stored in our primary region, Australia, and our sign-in service also processes them (see below).
We’re moving to this setup now. Until the move finishes, some data is still stored in the United States (Iowa).
Some things are processed outside your club’s region wherever it is:
- AI model requests, and voice and transcription, go to our suppliers (section 5). Their processing may happen in the United States or other countries.
- Sign-in, email delivery and push notifications are handled by global services.
- When you connect another service, data you send it is stored wherever that service keeps it.
Before we send personal information overseas we take reasonable steps to make sure it’s protected to the standard of the Australian Privacy Principles. For information from the EU, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum), or an adequacy decision such as the EU–US Data Privacy Framework where the supplier is certified.
7. How long we keep it
- Content (messages, files, pages, transcripts, buddy notes and so on): for as long as the club exists, unless someone deletes it sooner.
- Closed clubs: when a club is closed, its owners get a short period to change their mind or export its content (currently 30 days). Then we delete it.
- Your account: when you delete your account, we delete your account details, usually within 30 days. What you posted in a club stays with the club (section 1).
- Backups: deleted data can stay in backups until they expire (currently about 14 weeks).
- Billing records: as long as tax and company law requires, usually 7 years.
- Application logs: about 30 days.
- Security and audit logs: up to about 13 months.
- Waitlist: until we invite you, or you ask us to remove you.
We may keep something longer if the law requires it, or while we need it to resolve a dispute or investigate abuse.
8. Security
Data is encrypted in transit and at rest. Access tokens and secrets are held in a dedicated secret store. Access inside Gigabuddy is checked on every request, and only the people who need it can reach production systems. We keep backups so we can recover from failures. No system is perfectly secure, but we work to protect your information and to improve over time.
If a data breach is likely to cause you serious harm, we’ll tell you and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, and the relevant EU or UK authority where GDPR requires it.
9. Your rights
Wherever you live, you can ask us to do the things below. If your country’s privacy law gives you more rights, you have those too.
- give you access to the personal information we hold about you;
- correct it if it’s wrong, out of date or incomplete;
- delete it;
- give you a copy in a portable, machine-readable format;
- restrict or stop using it, including objecting to uses based on our legitimate interests;
- stop sending you marketing;
- withdraw a consent you’ve given, without affecting what we did before.
Email privacy@gigabuddy.com. We may need to confirm it’s you. We’ll reply within 30 days, and there’s no charge. If we can’t do what you ask (for example because the law requires us to keep something), we’ll tell you why.
You can also deal with us without giving your name for general questions, but we can’t give you an account that way.
10. Legal bases (GDPR)
If GDPR applies to you, we rely on these legal bases:
- Contract: to provide Gigabuddy to you, including your account, content, buddies and connections.
- Legitimate interests: to keep Gigabuddy secure, prevent abuse, and fix and improve the service, including building and improving our models with de-identified or aggregated information. We balance these against your rights, and you can object.
- Consent: for the waitlist, marketing email and push notifications. You can withdraw it at any time.
- Legal obligation: where the law requires us to keep or disclose information.
11. Cookies and local storage
We use cookies and your browser’s local storage only to keep you signed in, remember your settings, and keep the app working offline. This website remembers in local storage that you’ve joined the waitlist. We don’t use advertising cookies or cross-site tracking.
12. Children
Gigabuddy isn’t meant for children under 16, and we don’t knowingly collect their personal information. If you think a child has given us their information, contact us and we’ll delete it.
13. Changes to this policy
We’ll update this page when our practices change and change the date at the top. If a change is significant, we’ll tell you by email or in the app before it takes effect.
14. Contact and complaints
For any privacy question, request or complaint, email privacy@gigabuddy.com. We’ll acknowledge it promptly and aim to resolve it within 30 days.
If you’re not happy with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992. If you’re in the EU or UK, you can also complain to your local data protection authority.