Privacy Policy

Effective 9 April 2026 · Last updated 3 August 2026

1. Who we are

Aijency is an Australian company. We provide an AI assistant, called an Aijent, that businesses put on their website. It answers questions, qualifies enquiries, books meetings, and passes requests to a human. Aijent Relay is a version of the same product for businesses that do not use a CRM.

In this policy, you means the business using Aijency, and visitor means someone who chats with an Aijent on your website. For visitor data, you are the data controller and we are your processor.

2. What we collect

From visitors, when they tell us. Name, email address, company, phone number, what they are looking for, and the full conversation.

From visitors, automatically. A random visitor identifier stored in their browser, a second copy of it set by the embed script, and a timestamp of when they last engaged so the widget does not keep prompting the same person. The address of the page the widget sits on, so the right Aijent answers. Their browser’s time zone, so meeting times are shown in local time. If a visitor clicks a link the Aijent gives them, we record that click and pass a reference to the conversation with them, so you can see which conversations led somewhere.

We do not collect IP addresses, browser fingerprints, referrers or browsing history, and we do not track anyone across other websites.

From you. Account details, and whatever you upload to your knowledge base. Website addresses you give us are sent to Firecrawl, which reads the pages so your Aijent can answer from them.

From systems you connect. Calendar availability, and contact records from your CRM where we need to check whether somebody already exists.

3. What we use it for

  • Running your Aijent and answering visitors
  • Qualifying enquiries against the criteria you set
  • Booking meetings and sending calendar invitations
  • Passing leads, notes and callback requests to your CRM or your team
  • Billing you, and telling you about your usage
  • Meeting our legal obligations

We do not sell personal information, we do not use visitor data for advertising, and we do not use data from Google or Microsoft Workspace APIs to train or improve any AI or machine learning model.

4. AI processing

Your Aijent’s replies are generated by Anthropic’s Claude. To produce a reply, the following is sent to Anthropic: the conversation so far, the relevant parts of your knowledge base, and, when a visitor is booking, the free times read from your connected calendar so the model can offer them.

Two other services see visitor data in the course of a conversation. Voyage AI receives the visitor’s question in order to find the right passage of your knowledge base. Kickbox receives a visitor’s email address to confirm it is real before a booking is made.

What is not sent to any AI service: the contents of your calendar events, your contact lists, or anything from your CRM beyond what is needed to avoid creating a duplicate record. Anthropic does not train on this data, by contract.

Our use of data from Google Workspace APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

5. Systems you connect, and what we ask for

When you connect one of these, you are asked to grant the permissions listed below.

Google Calendar and Google MeetRead your free and busy times to offer a visitor a slot, and create the event with a Meet link once they choose one.

  • openid
  • userinfo.email
  • calendar.events
  • calendar.readonly

Microsoft Outlook and Microsoft TeamsRead your availability, create the calendar event, and generate a Teams link where Teams is your meeting provider.

  • Calendars.ReadWrite
  • OnlineMeetings.ReadWrite
  • offline_access

ZoomCreate the Zoom meeting when a visitor books a time.

  • meeting:write:meeting

HubSpotCreate and update contacts, companies, deals and notes, and add one custom field to contacts and deals so records your Aijent created can be filtered in your own reports.

  • crm.objects.contacts.write
  • crm.objects.contacts.read
  • crm.objects.deals.write
  • crm.objects.companies.write
  • crm.objects.companies.read
  • crm.schemas.contacts.write
  • crm.schemas.deals.write

SalesforceCreate and update contacts, accounts, opportunities and tasks. Salesforce does not offer a narrower permission for this.

  • api
  • refresh_token
  • offline_access

PipedriveFind and create people, organisations, deals and activities.

  • contacts:full
  • deals:full
  • activities:full
  • search:read

Zoho CRMCreate and update leads, contacts, accounts, deals, notes, tasks and events, and read your field and user settings so records are filed correctly.

  • ZohoCRM.modules.leads.ALL
  • ZohoCRM.modules.contacts.ALL
  • ZohoCRM.modules.accounts.ALL
  • ZohoCRM.modules.deals.ALL
  • ZohoCRM.modules.notes.ALL
  • ZohoCRM.modules.tasks.ALL
  • ZohoCRM.modules.events.ALL
  • ZohoCRM.settings.fields.ALL
  • ZohoCRM.settings.modules.READ
  • ZohoCRM.users.READ

SlackList your channels so you can choose one, and post an alert there when a visitor asks to be contacted.

  • chat:write
  • chat:write.public
  • channels:read

You can disconnect any of these at any time from the Integrations page in your dashboard, or revoke access from the provider’s own settings.

6. Who else handles the data

The complete list of companies that process personal data on our behalf is published at sub-processors, with what reaches each one. How the data is protected is set out on the security page.

Stored data lives in Australia, in Sydney. Several of the companies in that list are in the United States and data does reach them while a conversation is happening.

7. How long we keep it

SituationWhat happens
Your account is activeData is kept while you are a customer
You cancelEverything is permanently deleted 45 days after cancellation, automatically
You ask us to delete soonerEmail us and we will action it, and confirm when it is done

Deletion after cancellation is automatic and complete. It removes lead records, conversations, uploaded knowledge, connected account credentials and the login accounts themselves.

8. Your rights

Under the Australian Privacy Act, and under the GDPR where it applies, you can ask for a copy of your personal information, ask us to correct it, or ask us to delete it. Email info@aijency.ai. We will respond within 30 days.

If you are a visitor rather than one of our customers, your request usually belongs with the business whose website you were on, because they decide what happens to it. Send it to us anyway if that is easier and we will pass it on and tell you we have.

9. Contact

Aijency, Sydney, New South Wales, Australia. info@aijency.ai.

Arch Aijency, ABN 27 129 394 163info@aijency.ai