How Venode Labs Pty Ltd handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, for venode.ai and related business contact.
Version 1.0.0 · In force from 10 July 2026 · Last updated 10 July 2026
Short version. venode.ai is a static marketing site. We do not run accounts, first-party analytics, advertising pixels or tracking cookies on the Site itself. If you email us, we receive what you send so we can reply. Hosting providers (currently Vercel and Cloudflare) process standard connection data to deliver pages. We do not sell personal information. You can ask for access, correction or deletion. Complaints go to us first, then to the Office of the Australian Information Commissioner if needed. The full Policy below is the operative document.
The organisation responsible for personal information described in this Policy is Venode Labs Pty Ltd, trading as Venode and Venode Labs (we, us, our), an Australian AI lab and services studio.
For the purposes of the Privacy Act 1988 (Cth), we are the entity that collects and holds personal information in connection with the Site and ordinary business contact. Where European Union, European Economic Area, United Kingdom or Swiss law applies to a particular interaction, we are the controller of that personal information unless an engagement agreement states that we act only as a processor on a client's documented instructions.
Privacy contact: privacy@venode.ai. The Privacy Officer for the organisation is reachable at that address.
Registered office details and Australian Business Number will be added to this Policy when ASIC registration particulars are finalised for public display. Until then, privacy notices and requests may be sent to the email addresses in clause 24.
This Policy applies to personal information we handle in connection with:
This Policy does not cover:
We design this Policy to be open and accurate about a low-collection marketing Site. If our collection practices change (for example if we add analytics, accounts or a contact form backend), we will update this Policy before or when that change goes live.
As at the version date above, the Site is a static marketing presence. In particular:
mailto: links to our email addresses rather than a server-side form that stores submissions in our database; andThat posture reduces, but does not eliminate, personal information processing. Connection metadata processed by infrastructure providers can still constitute personal information in some circumstances (for example IP address).
When you email us or otherwise contact us, we collect the personal information you include in that communication. Depending on what you send, that may include:
When you load the Site, our hosting and content-delivery providers process technical data that is ordinarily generated by web traffic, which may include:
We do not operate a separate first-party analytics product on the Site that profiles you across sessions. We may receive aggregate or operational metrics from providers (for example bandwidth and error rates) that are not tied to a marketing profile about you.
Through ordinary use of the Site we do not seek to collect:
Please do not email us sensitive information unless it is necessary for a professional Engagement and we have agreed a secure channel and purpose for that information.
We may receive limited personal information from third parties where relevant to an enquiry or Engagement, for example:
We do not buy personal information from data brokers for marketing lists.
We collect personal information in ways consistent with Australian Privacy Principle 3 (collection of solicited personal information) and Australian Privacy Principle 4 (dealing with unsolicited personal information):
If we receive unsolicited personal information and we could not have lawfully collected it under APP 3, we will destroy or de-identify it as soon as practicable where it is lawful and reasonable to do so, consistent with APP 4, unless an exception applies (for example the information is contained in a Commonwealth record, or we are required to retain it).
Wherever practicable we collect personal information by fair and lawful means and only what is reasonably necessary for our functions and activities (APP 3.1 and 3.2).
We collect, hold, use and disclose personal information for the following purposes, consistent with Australian Privacy Principle 6 (use or disclosure) unless another APP or law authorises a different handling:
| Purpose | Examples | APP / legal note |
|---|---|---|
| Respond to enquiries | Reply to emails, schedule calls, send proposals | Related to primary purpose of collection; APP 6.1 |
| Perform Engagements | Deliver Services, manage projects, support handovers | Primary purpose; contract performance |
| Operate and secure the Site | Hosting, TLS, abuse prevention, debugging outages | Related secondary purpose you would reasonably expect; APP 6.2(a) |
| Business administration | Invoicing, accounting, insurance, professional advice | Related secondary purpose; legal obligations |
| Legal and regulatory | Respond to court orders, regulators, establish legal claims | APP 6.2(b) to (e) as applicable; other law |
| Improve our offerings | Aggregate enquiry themes, internal quality review | De-identified where practicable; related purpose |
| Marketing (optional) | Occasional updates about Venode services you asked about | Spam Act consent rules; APP 7 for direct marketing |
We do not use personal information collected through ordinary Site contact to train foundation models for public release. If an Engagement involves model training or fine-tuning on client data, that will be scoped in Engagement Documents and is not implied by Site use alone.
We do not sell personal information. We do not share personal information with advertisers for their independent marketing. We do not rent or trade contact lists.
If you are in the European Economic Area, the United Kingdom or Switzerland, and those laws apply to our handling of your personal information, we rely on one or more of the following bases under the GDPR or UK GDPR as relevant:
Where we rely on legitimate interests, you may object under applicable law (see clause 14). Australian law remains the primary framework for our Australian operations; overseas rights apply to the extent those laws bind us.
As at the version date:
You can configure your browser to refuse cookies or clear stored data. Blocking all cookies may affect unrelated sites you visit; it should not prevent reading this static Site.
If we later introduce non-essential cookies or similar technologies that require consent under applicable law, we will update this Policy and implement an appropriate notice or consent mechanism before those technologies go live on the Site.
We use service providers to operate the Site and run the business. Providers that may process personal information on our behalf or as independent infrastructure operators include:
| Provider | Role | Typical data | Primary region(s) |
|---|---|---|---|
| Vercel Inc | Static site hosting and edge delivery | Request logs, IP, user-agent, URLs | United States and global edge |
| Cloudflare, Inc | DNS, CDN, security edge (where configured) | Request metadata, security events | Global edge network |
| Email and workspace providers | Business email and documents | Message content and metadata you send or receive | Depends on provider configuration (often AU or US) |
| Professional advisers | Legal, accounting, insurance | Information necessary for advice under confidence | Australia (typically) |
| Subcontractors on Engagements | Delivery assistance under our direction | Only what is needed for assigned work | As scoped per Engagement |
Provider names and regions can change as our stack changes. Material changes to categories of overseas recipients will be reflected in an updated Policy.
We may also disclose personal information:
We do not disclose personal information for third-party direct marketing.
Some providers listed above store or process information outside Australia, including in the United States and on global edge networks. When we disclose personal information to an overseas recipient, we take steps consistent with Australian Privacy Principle 8, which may include:
By using the Site or contacting us, you acknowledge that infrastructure providers may process connection data and message-routing data in overseas locations as part of delivering global web and email services. Where APP 8.1 applies and consent is the basis we rely on for a particular disclosure, your continued use of the Site and voluntary submission of information constitutes that consent for the disclosures described in this Policy. You may contact us to discuss alternatives where practicable (for example offline delivery of documents).
We remain accountable under the Privacy Act for personal information we disclose overseas in the circumstances set out in APP 8, except where an exception in APP 8 applies.
We retain personal information only for as long as needed for the purpose we collected it, and for any longer period required or authorised by law (APP 11.2).
| Category | Typical retention |
|---|---|
| Casual Site enquiries with no Engagement | Up to 24 months after last meaningful contact, then delete or de-identify, unless a longer period is needed for a dispute or legal hold |
| Engagement correspondence and project records | For the life of the Engagement plus at least 7 years (tax, limitation periods, professional records), unless Engagement Documents set a different period |
| Invoices and financial records | At least 5 to 7 years as required by tax and corporations record-keeping laws |
| Infrastructure logs held by providers | Per provider default rotation (often days to weeks); we do not independently archive full request logs from the static Site |
| Marketing suppression / unsubscribe records | As long as needed to honour the opt-out |
| Security incident records | As long as needed to investigate, remediate and meet legal duties |
When retention ends, we destroy or de-identify personal information where it is lawful and reasonable to do so. Residual copies may remain in encrypted backups until those backups rotate.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, consistent with Australian Privacy Principle 11. Those steps are proportionate to the volume and sensitivity of what we hold and include:
No method of transmission or storage is perfectly secure. Email in particular is not a perfect confidentiality channel. For highly sensitive Client Materials we may require a more controlled transfer method under the Engagement.
If you believe your personal information has been compromised in connection with us, contact security@venode.ai and privacy@venode.ai promptly.
We comply with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). If we have reasonable grounds to believe an eligible data breach has occurred (unauthorised access, disclosure, or loss of personal information that is likely to result in serious harm to an individual, and we have not been able to prevent the likely risk of serious harm with remedial action), we will:
Where an Engagement Document or overseas law imposes a shorter notification timeline to a client acting as controller, we will also meet that contractual timeline to the extent it is stricter than Australian law for that notification channel.
Under the Australian Privacy Principles and the Privacy Act 1988 (Cth), you have rights that include the following. Additional rights may apply under the GDPR, UK GDPR or other law if those laws cover the relevant processing.
We will respond to verified privacy requests within a reasonable period, and in any event within 30 days where APP 12 or APP 13 applies, unless a longer period is permitted. We may need to verify your identity before acting on a request. We may refuse a request where the Privacy Act or another law allows or requires refusal, and if we refuse we will give written reasons and information about complaint options, except where the law prevents us from doing so.
Email privacy@venode.ai with:
We do not charge for ordinary access or correction requests. If a request is manifestly unfounded or excessive, we may refuse it or charge a reasonable fee where the Privacy Act permits.
If you are concerned about how we have handled personal information, contact privacy@venode.ai with a description of the issue. We will acknowledge the complaint within five Business Days where practicable and aim to resolve it within 30 days. Complex matters may take longer; we will tell you if more time is needed.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:
EEA residents may also have the right to lodge a complaint with their local supervisory authority. UK residents may contact the Information Commissioner's Office at ico.org.uk.
Australian Privacy Principle 7 and the Spam Act 2003 (Cth) regulate direct marketing and commercial electronic messages.
Sensitive information under the Privacy Act includes information or an opinion about racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information used for automated biometric verification or identification, and biometric templates.
We do not seek sensitive information through the Site. We will only collect sensitive information if it is reasonably necessary for one of our functions, and with consent, or where another exception in APP 3.3 or the Privacy Act applies (for example required or authorised by law, or a permitted health situation).
If you send us sensitive information unsolicited, we will handle it under APP 4 and limit further use to what is lawful and necessary.
The Site is aimed at business audiences. We do not knowingly market to children or knowingly collect personal information from children under 15 for marketing purposes. If you believe a child has provided personal information to us, contact privacy@venode.ai and we will take reasonable steps to delete it where appropriate.
Paid Engagements are with adults or organisations capable of contracting (see our Terms of Service).
We do not use automated decision-making on the Site that produces legal or similarly significant effects about you without human involvement. Infrastructure providers may use automated systems for bot detection, rate limiting and security scoring of network traffic. Those systems protect the Site; they do not decide whether we enter a contract with you. Engagement decisions are made by humans.
When you become a client, we may process additional personal information and business data, including employee details in Client Materials, system logs from integrations we build, and credentials you provide for implementation.
For that processing:
The Site links to third-party platforms (including X at x.com/venodeLabs, Instagram at instagram.com/venode.ai, and GitHub at github.com/venode-labs). If you follow those links, the third party may collect information under its own privacy notice. We do not control that collection.
If you interact with us on a social platform, that platform's terms and privacy notice apply to the interaction on their service. We may receive limited public profile information available through the platform when you message or mention us.
We may update this Policy from time to time to reflect legal, technical or business changes. The version number and date at the top of this page show the current version. Material changes will be indicated by updating that date. Where we have your email address in an active business relationship and a change materially reduces your rights, we will take reasonable steps to notify you.
Earlier versions may be available on request to privacy@venode.ai.
Privacy questions, access, correction, deletion and complaints: privacy@venode.ai
Security incidents and vulnerability reports: security@venode.ai
Legal correspondence: legal@venode.ai
General enquiries: hello@venode.ai
Support: support@venode.ai
For transparency, the table below maps core Australian Privacy Principles to where this Policy addresses them. It is a navigation aid, not a limitation of our obligations.
| APP | Topic | Where addressed |
|---|---|---|
| APP 1 | Open and transparent management | This Policy generally; clauses 1, 16, 24 |
| APP 2 | Anonymity and pseudonymity | Clause 14 |
| APP 3 | Collection of solicited personal information | Clauses 4, 5, 6, 18 |
| APP 4 | Dealing with unsolicited personal information | Clause 5 |
| APP 5 | Notification of collection | This Policy as collection notice for Site and contact channels |
| APP 6 | Use or disclosure | Clauses 6, 9, 21 |
| APP 7 | Direct marketing | Clause 17 |
| APP 8 | Cross-border disclosure | Clauses 9, 10 |
| APP 9 | Government related identifiers | Clause 4.3 (we do not seek them via the Site) |
| APP 10 | Quality of personal information | Clauses 14, 15 |
| APP 11 | Security of personal information | Clauses 11, 12, 13 |
| APP 12 | Access to personal information | Clauses 14, 15 |
| APP 13 | Correction of personal information | Clauses 14, 15 |
This Policy is governed by the Privacy Act 1988 (Cth), the Australian Privacy Principles, and where applicable the GDPR and the UK GDPR. Where a mandatory provision of those laws gives you more rights than this Policy describes, the law prevails to the extent of the inconsistency. This Policy is an operational document prepared for Venode Labs Pty Ltd under Australian law; it is not a substitute for advice from a qualified Australian privacy lawyer on your specific situation. Related terms: Terms of Service.