Privacy Policy
Last updated: April 2025
1. About This Policy
This Privacy Policy explains how Petrosi Group Pty Ltd trading as SafegateAI (ABN: 25 615 926 335) ("SafegateAI", "we", "us", "our") collects, holds, uses, discloses, and protects your personal information in accordance with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR) where applicable, and the UK Data Protection Act 2018.
This policy applies to all personal information collected through our website (safegateai.com.au), the SafegateAI SmartHub platform, workshops, consultations, and any other interaction with SafegateAI.
2. Information We Collect
We may collect the following categories of personal information:
2.1 Information You Provide
- Full name, email address, phone number, and job title
- Company name, ABN/ACN, industry sector, and business address
- Information submitted via contact forms, consultation requests, event registrations, and survey responses
- Payment and billing information (credit card details are processed by our PCI-DSS compliant payment providers and are not stored by SafegateAI)
- Communication records including emails, call logs, meeting notes, and support tickets
- Professional qualifications, training history, and AI readiness assessment results
2.2 Information Collected Automatically
- IP address, browser type and version, operating system, and device identifiers
- Pages visited, time spent on each page, referral source, and click patterns
- Cookies and similar tracking technologies (see our Cookie Policy)
- Log data from our SafegateAI SmartHub platform including usage patterns, feature interactions, and session duration
2.3 Information From Third Parties
- Publicly available business information from company registries and professional networks
- Referral information from business partners and professional contacts
- Analytics data from third-party platforms such as Google Analytics and LinkedIn
3. Legal Basis for Processing
We process your personal information on the following lawful bases:
- Contractual necessity: To perform our obligations under a service agreement or statement of work
- Legitimate interests: To operate, improve, and promote our services, provided these interests are not overridden by your rights
- Consent: Where you have given explicit consent, such as subscribing to marketing communications
- Legal obligation: To comply with applicable laws, regulations, court orders, or government requests
4. How We Use Your Information
We use your personal information for the following purposes:
- Delivering our AI managed services, governance, compliance, and consulting engagements
- Operating and improving the SafegateAI SmartHub platform, including shadow AI monitoring and ROI dashboards
- Conducting AI audit and risk assessments for your organisation
- Developing and delivering AI training workshops and custom learning courses
- Processing payments, generating invoices, and managing client accounts
- Communicating with you about service updates, scheduled maintenance, and new feature releases
- Sending marketing communications where you have opted in (you may unsubscribe at any time)
- Analysing website and platform usage to enhance performance and user experience
- Detecting, preventing, and responding to fraud, security threats, and unauthorised access
- Meeting our legal, regulatory, and compliance obligations including record-keeping requirements
5. Disclosure of Information
We may share your personal information with the following categories of recipients:
- Service providers: Trusted third parties who assist in delivering our services, including cloud infrastructure providers, payment processors, CRM systems, email platforms, and analytics providers. All service providers are contractually bound to protect your data.
- Professional advisors: Lawyers, accountants, auditors, and insurers as necessary for professional advice and compliance
- Business partners: Technology partners and resellers involved in delivering joint solutions, subject to appropriate data protection agreements
- Regulatory authorities: Government agencies, law enforcement, or regulators where required by law or to protect our legal rights
- Corporate transactions: In connection with a merger, acquisition, restructure, or sale of assets, your information may be transferred to the acquiring entity
We will never sell, rent, or trade your personal information to third parties for their independent marketing purposes.
6. International Data Transfers
SafegateAI operates offices in Australia (Sydney), the United Kingdom (London), and the United Arab Emirates (Dubai). Your personal information may be transferred to, stored, and processed in any of these jurisdictions.
Where we transfer data outside Australia, we take reasonable steps to ensure the recipient handles your information consistently with the APPs. For transfers from the UK/EU, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or rely on adequacy decisions where applicable.
7. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required by law. Our general retention periods are:
- Client records and service data: 7 years from the end of the engagement (in accordance with Australian tax and corporate law requirements)
- Marketing contact information: Until you withdraw consent or unsubscribe
- Website analytics data: 26 months from collection
- Platform usage logs: 12 months from generation
- Job application data: 12 months from the conclusion of the recruitment process
When personal information is no longer required, we securely destroy or de-identify it in accordance with our data destruction procedures.
8. Data Security
We implement robust technical and organisational measures to protect your personal information from unauthorised access, modification, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Multi-factor authentication and role-based access controls
- Regular vulnerability assessments and penetration testing
- Employee security awareness training and confidentiality agreements
- Incident response and data breach notification procedures
- SOC 2-aligned cloud infrastructure and hosting environments
While we take all reasonable steps to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
9. Data Breach Notification
In the event of a data breach that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required under the Notifiable Data Breaches (NDB) scheme. For breaches affecting UK/EU individuals, we will also notify the relevant supervisory authority within 72 hours where required by the GDPR.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request erasure of your personal information where there is no compelling reason for continued processing
- Restriction: Request that we restrict the processing of your information in certain circumstances
- Data portability: Request a copy of your data in a structured, commonly used, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing purposes
- Withdraw consent: Where processing is based on consent, you may withdraw that consent at any time
To exercise any of these rights, please contact us at info@safegate.ai. We will respond to your request within 30 days (or sooner where required by applicable law).
11. Children's Privacy
Our services are directed at businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected such information, we will take steps to delete it promptly.
12. Complaints
If you believe we have breached the APPs or GDPR, you may lodge a complaint with us by contacting info@safegate.ai. We will investigate and respond within 30 days.
If you are not satisfied with our response, you may escalate your complaint to:
- Australia: Office of the Australian Information Commissioner (OAIC), www.oaic.gov.au
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated policy on our website with a revised "Last updated" date. We encourage you to review this policy periodically. Material changes will be communicated via email or a prominent notice on our website.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Privacy Officer
Petrosi Group Pty Ltd t/a SafegateAI
ABN: 25 615 926 335
Level 35, International Towers One
100 Barangaroo Ave, Barangaroo NSW 2000
Australia
Email: info@safegate.ai
Tel: +61 2 8359 8379