Privacy Policy
Effective 9 April 2026 · Last updated 3 August 2026
1. Who we are
Aijency is an Australian company. We provide an AI assistant, called an Aijent, that businesses put on their website. It answers questions, qualifies enquiries, books meetings, and passes requests to a human. Aijent Relay is a version of the same product for businesses that do not use a CRM.
In this policy, you means the business using Aijency, and visitor means someone who chats with an Aijent on your website. For visitor data, you are the data controller and we are your processor.
2. What we collect
From visitors, when they tell us. Name, email address, company, phone number, what they are looking for, and the full conversation.
From visitors, automatically. A random visitor identifier stored in their browser, a second copy of it set by the embed script, and a timestamp of when they last engaged so the widget does not keep prompting the same person. The address of the page the widget sits on, so the right Aijent answers. Their browser’s time zone, so meeting times are shown in local time. If a visitor clicks a link the Aijent gives them, we record that click and pass a reference to the conversation with them, so you can see which conversations led somewhere.
We do not collect IP addresses, browser fingerprints, referrers or browsing history, and we do not track anyone across other websites.
From you. Account details, and whatever you upload to your knowledge base. Website addresses you give us are sent to Firecrawl, which reads the pages so your Aijent can answer from them.
From systems you connect. Calendar availability, and contact records from your CRM where we need to check whether somebody already exists.
3. What we use it for
- Running your Aijent and answering visitors
- Qualifying enquiries against the criteria you set
- Booking meetings and sending calendar invitations
- Passing leads, notes and callback requests to your CRM or your team
- Billing you, and telling you about your usage
- Meeting our legal obligations
We do not sell personal information, we do not use visitor data for advertising, and we do not use data from Google or Microsoft Workspace APIs to train or improve any AI or machine learning model.
4. AI processing
Your Aijent’s replies are generated by Anthropic’s Claude. To produce a reply, the following is sent to Anthropic: the conversation so far, the relevant parts of your knowledge base, and, when a visitor is booking, the free times read from your connected calendar so the model can offer them.
Two other services see visitor data in the course of a conversation. Voyage AI receives the visitor’s question in order to find the right passage of your knowledge base. Kickbox receives a visitor’s email address to confirm it is real before a booking is made.
What is not sent to any AI service: the contents of your calendar events, your contact lists, or anything from your CRM beyond what is needed to avoid creating a duplicate record. Anthropic does not train on this data, by contract.
Our use of data from Google Workspace APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
5. Systems you connect, and what we ask for
When you connect one of these, you are asked to grant the permissions listed below.
Google Calendar and Google Meet — Read your free and busy times to offer a visitor a slot, and create the event with a Meet link once they choose one.
openiduserinfo.emailcalendar.eventscalendar.readonly
Microsoft Outlook and Microsoft Teams — Read your availability, create the calendar event, and generate a Teams link where Teams is your meeting provider.
Calendars.ReadWriteOnlineMeetings.ReadWriteoffline_access
Zoom — Create the Zoom meeting when a visitor books a time.
meeting:write:meeting
HubSpot — Create and update contacts, companies, deals and notes, and add one custom field to contacts and deals so records your Aijent created can be filtered in your own reports.
crm.objects.contacts.writecrm.objects.contacts.readcrm.objects.deals.writecrm.objects.companies.writecrm.objects.companies.readcrm.schemas.contacts.writecrm.schemas.deals.write
Salesforce — Create and update contacts, accounts, opportunities and tasks. Salesforce does not offer a narrower permission for this.
apirefresh_tokenoffline_access
Pipedrive — Find and create people, organisations, deals and activities.
contacts:fulldeals:fullactivities:fullsearch:read
Zoho CRM — Create and update leads, contacts, accounts, deals, notes, tasks and events, and read your field and user settings so records are filed correctly.
ZohoCRM.modules.leads.ALLZohoCRM.modules.contacts.ALLZohoCRM.modules.accounts.ALLZohoCRM.modules.deals.ALLZohoCRM.modules.notes.ALLZohoCRM.modules.tasks.ALLZohoCRM.modules.events.ALLZohoCRM.settings.fields.ALLZohoCRM.settings.modules.READZohoCRM.users.READ
Slack — List your channels so you can choose one, and post an alert there when a visitor asks to be contacted.
chat:writechat:write.publicchannels:read
You can disconnect any of these at any time from the Integrations page in your dashboard, or revoke access from the provider’s own settings.
6. Who else handles the data
The complete list of companies that process personal data on our behalf is published at sub-processors, with what reaches each one. How the data is protected is set out on the security page.
Stored data lives in Australia, in Sydney. Several of the companies in that list are in the United States and data does reach them while a conversation is happening.
7. How long we keep it
| Situation | What happens |
|---|---|
| Your account is active | Data is kept while you are a customer |
| You cancel | Everything is permanently deleted 45 days after cancellation, automatically |
| You ask us to delete sooner | Email us and we will action it, and confirm when it is done |
Deletion after cancellation is automatic and complete. It removes lead records, conversations, uploaded knowledge, connected account credentials and the login accounts themselves.
8. Your rights
Under the Australian Privacy Act, and under the GDPR where it applies, you can ask for a copy of your personal information, ask us to correct it, or ask us to delete it. Email info@aijency.ai. We will respond within 30 days.
If you are a visitor rather than one of our customers, your request usually belongs with the business whose website you were on, because they decide what happens to it. Send it to us anyway if that is easier and we will pass it on and tell you we have.
9. Contact
Aijency, Sydney, New South Wales, Australia. info@aijency.ai.