Skip to main content
Agentix AI

Privacy

Privacy policy

What this company holds today, what an evaluation run would carry if the harness ships, how long anything is kept, and how to make us delete it.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1Who we are and what this covers

AGENTIX AI PTY LTD (ACN 695 748 693, ABN 24 695 748 693) is an Australian proprietary company registered in Queensland. It is building an evaluation harness for autonomous software agents. In this document "we", "us" and "our" mean that company, and "you" means the person reading it.

What this policy covers

  • This website at agentixai.fyi.
  • Email sent to our published address, and our replies to it.
  • The evaluation harness described on this site, if and when it is released. Those parts are written in the future tense on purpose and are marked where they appear.

What it does not cover

  • Any site you reach by following a link from ours, including the Australian registers.
  • Your own mail provider, which handles your message before it reaches us and has its own policy.
  • Any other company, including the separate business of a similar name dealt with in the next section.

Where things actually stand. No product has been released, so there are no users, no accounts and no customer data. The only personal information this company currently holds is correspondence sent to its published address. Everything in this policy about evaluation runs describes how the harness is being designed to behave, so that anybody considering it has something to read beforehand. The rights are not aspirational: access, correction, deletion and complaint all work today for the correspondence we do hold.

2The other company of a similar name

There is an established and entirely separate company trading under a very similar name at agentixai.com and at agentix.com. This is not that company.

  • There is no relationship between the two, no shared ownership, no shared personnel and no commercial arrangement of any kind.
  • Neither company endorses, controls or is responsible for the other.
  • We hold no personal information belonging to that company's customers, we have never received any, and we could not answer a request about it.

If you meant to reach them about an account, an invoice, a contract, a support matter or a privacy request, this is the wrong site and the wrong company. We cannot forward your message and we will not keep a copy of it beyond replying to say so.

AGENTIX AI PTY LTD was registered in Australia in 2026 under ACN 695 748 693. Anyone can confirm that in a minute at abr.business.gov.au, which is the point of publishing the number.

3The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, which is why this page exists

APP 1 requires an organisation to manage personal information in an open and transparent way, to take reasonable steps to implement practices and systems that ensure compliance, and to maintain a clearly expressed and up to date privacy policy that is available free of charge and in an appropriate form.

APP 1.4 sets out what that policy has to contain: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual may access and correct it, how to complain and how a complaint will be handled, whether information is likely to be disclosed to overseas recipients and to which countries. Each of those is a numbered section of this document rather than a sentence buried in a paragraph, because a policy that technically contains the information but hides it is not "clearly expressed".

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. AGENTIX AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

4What we collect

These tables are the whole list. A category that is not on them is not collected.

From this website

Personal information collected by agentixai.fyi
CategoryFieldsWhyKept
Request logsIP address, timestamp, path requested, user agent, response codeServing the page and blocking abusive traffic. Held by the hosting provider, not by usProvider cycle, presently under 30 days
Security cookieA strictly necessary cookie the hosting provider may setTelling automated traffic from human traffic. See the cookie noticeUp to 30 days
Font requestIP address and user agent, sent to Google's font servers by your browserLoading the two typefaces this site uses. We receive nothing from itNot held by us at all

There is no analytics on this site, no advertising, no tracking pixel, no session recording and no consent banner, because there is nothing here that would require consent.

From correspondence

Personal information collected when you write to us
CategoryFieldsWhyKept
Your messageWhatever you chose to put in itAnswering you24 months for ordinary correspondence
Mail metadataSending address, display name, timestamps, routing headers added by your provider and oursDelivery, and spam filtering24 months
Complaint threadThe correspondence, and our record of what we did about itEvidence of how a complaint was handled, which the Commissioner may ask for7 years
Security reportThe report, and any credit you asked forFixing the problem, and acknowledging you if you want that7 years

We do not enrich an address, look it up against any third party service, or add it to a list. Writing to us subscribes you to nothing.

What we never collect

  • Government related identifiers of any kind, dealt with in its own section below.
  • Payment card details. We have taken no money from anyone and have no payment processor.
  • Location beyond whatever a rough IP lookup would suggest, which we do not perform.
  • Special category information under Article 9 style regimes, such as health, race, religion, sexuality, political opinions or biometrics.
  • Anything about children, who are not the audience for a piece of engineering tooling.

5Material inside an evaluation run

This section describes a product that does not exist yet. It is published now so that the design commitments are on the record before the first customer, rather than written afterwards to describe whatever happened to get built.

An evaluation run is the harness executing somebody else's task in a sealed container. The material that flows through it belongs to the customer, not to us, and much of it is more sensitive than an ordinary support email: source code, prompts, internal file names, hostnames, and sometimes personal information sitting in a fixture or a test database that nobody thought about.

The starting position

We handle that material on the customer's instructions and for the customer's purposes. Australian law does not use the controller and processor split that European law does, but the distinction is still the honest way to describe the relationship, so this policy uses it as a description rather than as a legal claim.

Material inside an evaluation run, and how it is intended to be handled
MaterialWhose it isWhat we would do with itIntended retention
Container image and task definitionThe customer'sBuild the sealed starting state and hash itFor the life of the account, then deleted on request
Transcript of tool calls and model outputThe customer's, and possibly a third party's if the task touched oneRecord it, hash it, run reconciliation against itCustomer set, defaulting to 90 days
End state diffThe customer'sCompare against the sealed image and produce the deltaCustomer set, defaulting to 90 days
Personal information incidentally inside a fixtureSomebody else's entirelyNothing. It is not indexed, not extracted and not used for any purpose of oursDeleted with the run that contained it
Aggregate figures about the harness itselfOursUnderstanding whether the harness is working, for example the share of claims that resolve as unresolvableIndefinite, and carries no customer identifier

Commitments made in advance

  • Run material is never used to train a model, ours or anybody else's.
  • Run material is never used to improve the harness other than as counts that carry no content. Knowing that eleven per cent of claims were unresolvable is useful. Reading the claims to find out why, on a customer's data, is not something we would do without asking.
  • A customer can set a shorter retention than the default, including deletion at the end of every run.
  • Where a run would carry personal information belonging to people who are not the customer, we would say plainly that the customer should use synthetic fixtures, and the documentation would say it before the first run rather than after an incident.

What we would not be able to do

If a person whose information sat inside a customer's fixture asked us to delete it, we would not be able to identify them inside an opaque container, and the honest answer is that the request has to go to the customer who put it there. We would forward the request and say so, rather than claim a capability we do not have.

6Notice at the point of collection

Australian Privacy Principle 5 requires that we tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards: who we are, why we are collecting it, who we might give it to, that this policy exists, and what happens if you do not provide it.

Where that notice actually appears

  • Here. This document is linked from the footer of every page of this website.
  • In the collection tables above, which state the purpose and the retention for each category rather than describing them in general terms elsewhere.
  • In our reply, where you have sent us something we did not expect and would rather not hold. We say what we are doing with it.

The consequences of not providing information

There is only one thing you can decline to give us, because there is only one thing we ask for. If you write to us without a return address, we cannot answer you. Nothing else about this website depends on you providing anything, and there is no account to create.

7Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

You can read every page of this site without identifying yourself. There is no account, no sign in, no newsletter and no gate in front of anything.

You can also write to us from a pseudonymous address, and we will answer it on its merits. We do not require a real name, an employer, a job title or a reason for asking. A question about the design of the harness is exactly as answerable from an anonymous address as from a corporate one.

The single place the option genuinely narrows is a request to access or correct personal information. To answer one of those we have to be satisfied that you are the person the information is about, which in practice means replying to the address the correspondence came from. That is dealt with under access and correction below.

8Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

This happens most often when somebody sends us a bug report and includes a full screen recording, a diagnostic export, or a message thread containing other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.

9Use and disclosure

Australian Privacy Principle 6 governs what we may do with personal information once we hold it. Information collected for one purpose may be used for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.

What we use it for

  • Answering your message, and keeping enough of the thread that a follow up makes sense.
  • Dealing with a complaint, and keeping the record of how it was dealt with.
  • Fixing a security problem you reported, and crediting you if you asked to be credited.
  • Meeting a legal obligation, which for a company with no revenue is currently a short list.

What we do not do with it

  • We do not sell personal information. Not to a broker, not to an advertiser, not as part of an audience product, and not as an asset in isolation.
  • We do not build a profile of you, here or across anybody else's products.
  • We do not use your correspondence to market anything, because we do not market anything.
  • We do not train a model on your correspondence, and we do not paste it into a third party assistant to draft a reply.

Disclosure to law enforcement and courts

We may disclose personal information where the Act permits: where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists such as a serious threat to life, health or safety, or to an enforcement body where reasonably necessary for an enforcement related activity.

Where we make a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you that a request was made, we will tell you. We have received no such request to date, and this sentence is the mechanism by which you would notice if that stopped being true.

10Recipients and their locations

The complete list of everyone who receives personal information from us. It is short because the company is small and has no product.

Recipients, what they receive, and where they are
RecipientPurposeReceivesWhere
Cloudflare, Inc.Serving and protecting this websiteRequest logs including IP address, and the strictly necessary security cookieGlobal edge network, including Australian locations
Our email providerReceiving, sending and storing correspondenceWhatever you put in an email, and its metadataAustralia and the United States
Google LLCServing the two typefaces this site uses. Your browser makes this request directlyYour IP address and user agent, received by Google and not by usUnited States and Google regions
Our accountantStatutory accounts and tax obligationsCompany financial records. No correspondence, and no personal information about visitors to this siteAustralia

Who is not on this list

No data broker, no marketing platform, no customer data platform, no enrichment service, no identity graph, no analytics provider, no advertising network, no session recorder and no chat widget vendor. Adding any of them would mean changing this table first and announcing it under the changes section below.

If the company is sold

On a sale of the company or its assets, personal information may transfer to the buyer. Where we are lawfully able to, we will give notice on this website before a transfer completes, and the buyer is bound by this policy until it publishes its own, which cannot reduce your rights over information collected before the sale without your consent.

11Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime: consent, accurate identification of the sender, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.

Our position

We do not run a marketing list. No marketing message has ever been sent under this company name, there is no signup field anywhere on this site, and there is no product to announce.

If that changes it will be opt in. The consent will be recorded with a timestamp and the exact wording agreed to, the first message will say where the address came from, and the unsubscribe link will work in one click without asking you to sign in to anything.

Writing to us is not subscribing

Quietly turning a support thread into a mailing list is the most common way small companies build one, and it is a breach of the Spam Act rather than a growth tactic. Your address is used to answer you and for nothing else.

Unsolicited approaches to us

Marketing sent to our published address is deleted. We do not add senders to any list, we do not resell the fact that they contacted us, and we do not publish their messages.

12Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

How this maps onto the international transfer vocabulary

Readers who work with European or United Kingdom law will look for the language of international transfers, standard contractual clauses and transfer risk assessments. Australian law frames the same problem differently, as a cross border disclosure under APP 8 with accountability under section 16C, so this policy uses the Australian framing and this subsection connects the two.

Where a provider's published data processing terms incorporate the European Commission's standard contractual clauses, or the United Kingdom Addendum to them, those clauses govern that transfer as a matter of contract between us and that provider. We do not rely on them to satisfy APP 8. APP 8 is satisfied by taking reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, and section 16C keeps us answerable if the recipient does it anyway.

The countries in which personal information may be held or accessed are the ones named in the recipients table earlier in this policy: Australia, the United States, and the other locations in which a named provider operates infrastructure. There is no other international transfer, because there is no other recipient.

13Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

14Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

15Security, and what we do not hold

Australian Privacy Principle 11 requires reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it once it is no longer needed for any purpose for which it may be used or disclosed.

What reasonable steps mean for a company of this size

  • Transport encryption on everything. This website is served over HTTPS only, with HTTP redirected.
  • Encryption at rest for stored correspondence, provided by the mail platform.
  • Multi factor authentication on every account that can reach the mailbox, the domain registrar, the DNS zone or the hosting account.
  • A hardware backed second factor rather than SMS, because SMS is a phone company's idea of security rather than a security control.
  • Collecting less. The most dependable control available to a company this small is simply not holding the data, which is why the collection tables above are as short as they are.
  • A static website with no server side code, no database and no login. There is nothing here to inject into and no session to steal.

What is planned for the harness, and is not built

  • Per customer isolation at the container level, with no shared writable state between runs.
  • Outbound network denied by default inside a run, with any exception recorded in the run record and marked unsealed.
  • Run material encrypted at rest under a key that can be destroyed per customer, so deletion is not a database flag.
  • Administrative access to run material logged, with the log visible to the customer whose material it was.

Those are design intentions. None of them has been built, tested or reviewed by anyone outside the company, and reading them as a security posture would be a mistake.

AGENTIX AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment or any other independent security accreditation, and will not represent otherwise until one is genuinely held. No third party has conducted a penetration test. There is no security team, no chief information security officer and no bug bounty budget. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

16Retention

Australian Privacy Principle 11.2 requires destruction or de-identification once information is no longer needed for any permitted purpose, unless an Australian law requires us to keep it.

Retention schedule, with a reason for every row
CategoryPeriodReason
Ordinary correspondence24 monthsLong enough to recognise a recurring question and to pick up a thread somebody restarts a year later
Complaint correspondence and our record of handling it7 yearsMatches the general limitation period, and the Commissioner may ask how a complaint was dealt with
Security reports7 yearsA reported weakness can recur, and the history of what was fixed matters
Website request logsUnder 30 daysThe hosting provider's cycle. We do not export or extend them
Evaluation run material, when the harness existsCustomer set, defaulting to 90 daysLong enough to re-read a disputed result, short enough that a breach cannot expose years of somebody else's code
Aggregate figures about the harnessIndefiniteThey carry no identifier and cannot be traced back to a customer or a person
Financial and tax records7 yearsRequired by Australian tax and corporations law once there is anything to record

Destruction means removal from live systems and expiry from backups on the ordinary rotation, complete within 35 days. De-identification means removing every identifier and any field from which one could be reconstructed, and it is only claimed where re-identification is genuinely impractical rather than merely inconvenient.

17Deleting what we hold about you

There is no account to delete, because there is no product to have an account for. What exists is correspondence.

How to have it deleted

You can ask us to delete your data at any time, for any reason or for none. Email contact@agentixai.fyi from the address the correspondence came from, with "Delete my data" in the subject line. That is the whole process. No form, no identity documents and no explanation required.

When the harness exists there will also be an in product route for a customer to delete an account and every run attached to it, and the commitment made here now is that the in product route will delete the same things on the same timetable as the email route rather than merely hiding them from a list.

What deletion does

Effect of a deletion request
DataOn deletionReason
Ordinary correspondenceDeleted within 30 days, usually the same weekWe have no reason to keep it against your wishes
Complaint correspondenceRetained for 7 years, and we tell you that rather than deleting quietlyEvidence of how a complaint was handled. Keeping it protects both sides
Security reportRetained, with your identifying details removed on requestThe technical substance of a weakness has to survive, your name does not
BackupsOverwritten on the ordinary rotation within 35 daysWe do not restore deleted records from a backup afterwards
Website request logsNot deletable on requestThey sit with the hosting provider, are not searchable by us, and expire inside 30 days anyway

We confirm in writing when it is done. We do not mark a record deleted and keep it, and where something is retained under a row above we say which row and why.

18Access and correction

Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.

How to ask

Email contact@agentixai.fyi with "Privacy request" in the subject line and say what you want. Given the shape of this company, the honest answer to most access requests will be a copy of a correspondence thread, and we would rather send it than negotiate about it.

Verifying who you are

We have to be satisfied you are the person the information is about, or an authorised representative. In practice that means replying to the address the information is attached to. We will not ask you to send identity documents, because collecting a licence or a passport to answer a privacy request creates a worse privacy problem than the one it solves.

Timing and cost

We respond within 30 days. Access is free, correction is free, and making a request is free. If producing something in an unusual format imposed a genuine cost we would tell you the charge before doing the work, and it would not be excessive. That has not happened and is unlikely to.

When we can refuse

The grounds in the Act are narrower than most people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.

If we refuse in whole or in part, you get written reasons, the specific ground relied on, and how to complain. Where part of the information can be given, or given in another form that meets your need, we offer that instead of a flat refusal.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we correct it. If we had disclosed it to somebody else and you ask us to notify them of the correction, we take reasonable steps to do so unless that is impracticable or unlawful.

If we refuse to correct, you may require us to attach a statement to the record saying that you consider it inaccurate, and we must take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is frequently overlooked and it is worth knowing you have it.

19Children and young people

This site is a technical description of engineering tooling for people who run software agents. It is not directed at children, it is not designed to appeal to children, and there is nothing on it that a child would have a reason to use.

The Australian position

The Privacy Act does not fix an age at which a person can consent for themselves. The Commissioner's guidance is that capacity should be assessed individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless something suggests otherwise. We apply that presumption.

The Privacy and Other Legislation Amendment Act 2024 provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force, and we will update this policy then rather than guess at its terms now.

In practice

  • We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
  • There is no account, no profile, no chat, no user generated content and no advertising anywhere on this site.
  • If a child has written to us, a parent or guardian can have the correspondence deleted by writing to contact@agentixai.fyi. We will not demand proof of a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm when it is done.

20Automated decisions, including the ones the product makes

The Privacy and Other Legislation Amendment Act 2024 inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of decisions made. That requirement commences on 10 December 2026. This section is published in advance of that date.

About you

We make no automated decision that significantly affects your rights or interests. Nothing we operate decides whether you get credit, a job, a service, a benefit, a price or a legal entitlement. Your correspondence is read by a person and answered by a person.

About the harness, which is a machine that produces verdicts

This deserves more than a denial, because the product is an automated assessment engine and it would be evasive to describe it as anything else.

  • The subject of a verdict is a software agent's run, not a person. The harness scores what a machine did inside a container.
  • A verdict is not a decision about anybody's rights. It is evidence handed back to the customer, who decides what to do with it.
  • Where a run's transcript happens to contain personal information, that information is not an input to any verdict about that person, and no profile is built from it.
  • Every verdict is published with the evidence it rests on, so it can be checked and contested rather than accepted.

If we ever built something that made an automated determination about a person, for example scoring an individual developer's work across runs, this section is where it would be described, and it would be described before the processing started rather than after somebody noticed. We would also expect to be told plainly that it was a bad idea, and we would rather hear it early.

21Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to contact@agentixai.fyi with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

22The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

23Cookies on this website

This website sets no cookies of its own. There is no analytics, no advertising, no tracking pixel and no session recording, and therefore no consent banner, because a banner asking permission for nothing trains people to dismiss a control that matters elsewhere.

A strictly necessary security cookie may be set by the hosting provider to tell automated traffic from human traffic. Two typefaces are requested from Google's font servers, which reveals your IP address and user agent to Google rather than to us.

The full reasoning, the exact cookie names and how to block them are in the cookie notice.

24Mobile applications and app store declarations

AGENTIX AI PTY LTD publishes no mobile application. There is nothing on the App Store, nothing on Google Play, nothing on any other store and no listing under any other name.

Two consequences are worth stating in full, because both are things a careful reader checks and an omission would look like an evasion.

App Tracking Transparency

Apple's App Tracking Transparency framework governs an application that asks permission to track a user across other companies' apps and websites. We have no application, so there is no prompt, no Identifier for Advertisers in any system of ours, and no tracking across anybody's products. If an application were ever released, our position would be that tracking of that kind has nothing to do with an evaluation harness and would not be requested.

Google Play Data Safety

The Data Safety section of a Play listing declares what an application collects and shares. We have no listing, so there is no declaration, and therefore no possibility of a mismatch between a store declaration and this policy. Where a store declaration ever exists it will be written from this document rather than assembled separately, and any divergence between the two should be reported to contact@agentixai.fyi as a defect.

Why this section exists at all

Plenty of privacy policies for companies with no application still carry app store paragraphs, copied in from a template and left in place. That is a small signal that nobody read the document, and it makes every other paragraph harder to trust. This section says the true thing instead.

25Complaints

Step one: tell us

Email contact@agentixai.fyi with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

26If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to contact@agentixai.fyi and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. Personalised advertising is off unless you turn it on, which places us outside the sharing definition by default. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

The lawful bases, for readers who need to see them

Australian law does not work through lawful bases, so the Australian Privacy Principles are the operative framework for everything above. For a reader in a jurisdiction that does use them, the lawful bases for the only processing this company currently performs are set out below, with the legitimate interest named rather than left as a category.

Lawful bases under the GDPR and the UK GDPR, where either applies to you
ProcessingLawful basisThe interest, named
Reading and answering your emailArticle 6(1)(b) where you are asking about a possible agreement, otherwise Article 6(1)(f)Replying to a person who wrote to us, which is the thing they asked for
Keeping a complaint record for seven yearsArticle 6(1)(f), and Article 6(1)(c) where a regulator requires the recordBeing able to show how a complaint was handled if what happened is later disputed
Server logs and the strictly necessary security cookieArticle 6(1)(f)Keeping the website available and defending it from abusive traffic
Everything elseNot applicableThere is no marketing, no analytics, no profiling, no advertising and no automated decision making about people

We rely on no consent at present, which means there is no consent for you to withdraw and no dark pattern available to us for obtaining one.

Where to complain if you are not in Australia

In the United Kingdom, the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk. In the European Economic Area, the supervisory authority of the member state where you live, where you work, or where the matter arose. In New Zealand, the Office of the Privacy Commissioner. You do not need our agreement to approach any of them, and none of them charges you a fee.

27Changes to this policy

We may change this policy. When we do, the effective date and the version number in the header of this page change with it.

Where a change materially reduces your rights, or materially expands what we collect, we give notice before it takes effect: a note at the top of this page for at least 30 days, and a direct email to anyone with an open thread who would be affected. We will not make a material change effective retrospectively.

Previous versions are not published as separate pages, but they are kept. If you want to know what this document said on a particular date, ask and we will send you that version.

The change most likely to arrive first is the one that turns the future tense sections about evaluation runs into present tense. When that happens the section will be rewritten to describe what was actually built, including anything that ended up weaker than the commitment written here, because a policy that quietly drops an unmet promise is worse than one that never made it.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.

28How to contact us

All privacy matters reach one address.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of an account and its dataDelete my account30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: contact@agentixai.fyi

Entity: AGENTIX AI PTY LTD, ACN 695 748 693, ABN 24 695 748 693, registered in Australia, Queensland.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 695 748 693 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.