Version: 2.0 | Effective Date: 2 September 2026 | Last Updated: 24 September 2026
Version 1.x, effective 1 March 2026, was replaced by this version.
Difinity Pty Ltd (ABN 82 686 692 759)
This Privacy Policy explains how Difinity Pty Ltd ("Difinity", "we", "us" or "our") handles personal information through difinity.ai, the Difinity.ai governed chat and agent platform, the chat and agent workspace at chat.difinity.ai, Hub, the Platform API, Flow, the tool gateway, our public tools, and related support and business communications (together, the "Services").
This Policy applies when Difinity handles personal information as a controller or business for its own purposes. When a customer determines why and how Customer Data is processed through the Platform, Difinity generally acts as that customer's processor or service provider. The Data Processing Agreement governs that processing.
This Policy is intended to address the Australian Privacy Act 1988 (Cth) and, where they apply, the EU GDPR, UK GDPR, Canadian privacy law, United States state privacy laws and applicable privacy laws in the Middle East. Local law may give you additional rights.
1. Who is responsible
The entity responsible for this Policy is:
- Legal entity: Difinity Pty Ltd
- ABN: 82 686 692 759
- Registered office: Sydney, NSW, Australia
- Privacy enquiries: privacy@difinity.ai
- Legal enquiries: legal@difinity.ai
1.1 EU and UK representatives
Difinity has not yet appointed a representative in the European Union or the United Kingdom. Contact privacy@difinity.ai for any request.
1.2 Privacy contact
Difinity has not identified a statutory Data Protection Officer in this Policy. Contact privacy@difinity.ai to exercise a privacy right or ask about our handling of personal information.
2. Our roles
Difinity acts as a controller or business for account administration, authentication administration, billing, security, support, our website, public tools, marketing and our own business records.
Difinity acts as a processor, service provider or sub-processor when it handles Customer Data on a customer's documented instructions to provide the Platform. If the customer is itself a processor, Difinity acts as its sub-processor. The customer remains responsible for its own legal basis, notices, instructions, connected-system authority and configuration. Difinity remains responsible for the duties that apply to it.
A connected model provider or business system may instead be in a direct relationship with the customer. This is the case when a customer supplies its own provider key or appoints a connector destination. The DPA and Sub-processors page explain the distinction.
3. Personal information we handle
What we handle depends on the Services a person or customer uses.
3.1 Account and authentication information
This can include name, business email address, organisation, role, telephone number if provided, account and organisation identifiers, permissions, login timestamps, authentication identifiers, session and refresh-token data, and security events. Supabase Auth provides authentication. This Policy does not say that Difinity stores a password chosen by a person.
3.2 Platform configuration and administration
This can include organisation settings, people and groups, agent identities and instructions, policies, use cases, model settings, connector and MCP server configuration, enabled tools, scopes, permissions, approval requirements, credential references and administration activity.
A credential reference identifies a stored credential without revealing it. Provider keys and connector credentials are write-only through customer-facing interfaces, and no stored credential is returned through those interfaces. The tool gateway may hold the credential needed to carry out a customer-authorised action.
3.3 Conversations, agents and governed runs
Customer Data can include:
- conversation messages and transcripts;
- attachments, including file bytes, file names, types, sizes, extracted text, ownership and expiry metadata;
- prompts, responses and agent instructions;
- model and tool arguments, results and error information;
- proposed and completed actions in connected systems;
- policy decisions, personal-information control results and refusal reasons;
- approvals, including who was permitted to decide and the decision made;
- run status, timing, model and provider metadata, usage and cost data; and
- the separate append-only Run Trail, which records available evidence about a governed run.
The Platform API stores conversations, messages, configuration, approvals, Run Trails, usage and related records. Flow applies configured controls and runs model and agent work. The tool gateway holds connector credentials, decides whether a proposed action may proceed and acts on the connected system. Tool results are not stored. The tool gateway keeps a digest of a tool result; the Run Trail records a reference to the gateway's record.
3.4 Billing and credits
This can include the billing contact, Stripe customer and transaction identifiers, invoice information, Credits ledger entries, Usage Events, provider-cost records, taxes, payment status and related account records. Invoices are issued monthly through Stripe. Credits are a prepaid ledger for eligible model and tool work funded by Difinity, with usage settled shortly after each run.
3.5 Website, public tools and marketing
When a person visits difinity.ai, requests a demo, subscribes, or uses a public tool, we can handle information they enter, such as name, business contact details, organisation, role, answers and free-text responses. We also handle the generated result, report or PDF, delivery status, consent choices and related communications.
Our public tools use Amazon Web Services, including DynamoDB, S3, Bedrock and SES, to receive answers, generate and store results, and deliver requested reports. Detailed contact and answer summaries may be written to HubSpot as CRM contacts and sales notes. The Cookie Policy explains optional analytics and marketing technologies.
3.6 Communications and support
This can include contact details, the contents of an enquiry or support request, attachments, investigation notes, the organisation concerned and actions taken to respond.
3.7 Website device and event information
Before Analytics consent, PostHog captures no analytics event and stores nothing on the device. On each page load, the Site makes one request through its proxy to PostHog Cloud EU for the project configuration that shapes the page. The request does not repeat while that page stays open. It has no body and no visitor identifier beyond the public project token. As with any web request through the proxy, PostHog Cloud EU receives the IP address, page URL and browser details. No feature-flag evaluation request or analytics event is sent before consent. We rely on our legitimate interests in loading the Site's feature configuration for this request.
After Analytics consent, PostHog can receive event-level information such as the page path, referring information, screen dimensions, user agent, clicks, scroll depth, page exits and engagement timing. Click and copy events send the full page URL, including any query string. A click event can also send the element's ID, classes, selector and page section. A click event can include up to 50 characters of text from the clicked interface element. A copy event records that text was copied, the length of that text and whether it looked like code. It never includes the copied text itself. PostHog can also receive a replay of configured page interactions. PostHog uses local and session storage described in the Cookie Policy, not a PostHog cookie. Rejecting or withdrawing Analytics consent stops capture, clears PostHog local and session storage, and removes difinity_has_visited. PostHog data is processed through PostHog Cloud EU in the European Union (Frankfurt).
Google Analytics, when enabled, loads only after Analytics consent is given. Meta Pixel, when enabled, loads only after Marketing consent is given. Apollo loads after Marketing consent is given. The Cookie Policy identifies their browser technologies, destinations and retention.
4. Why we handle personal information
We handle personal information to:
- provide, administer and secure the Services;
- authenticate people and manage organisations, roles and permissions;
- follow customer instructions for conversations, agents, policies, approvals and connected-system actions;
- detect and respond to misuse, fraud, security events and service failures;
- calculate usage, maintain the Credits ledger, invoice and keep financial records;
- answer enquiries, provide support and administer customer relationships;
- generate and deliver a public-tool result requested by a person;
- send marketing where permitted and manage consent, opt-out and suppression records;
- understand and improve our website and Services where the applicable legal basis permits; and
- comply with law and establish, exercise or defend legal claims.
Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk, and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification.
Difinity may use data that has been irreversibly anonymised so that a person or customer cannot reasonably be identified. We do not treat replaced, pseudonymised or merely aggregated data as irreversibly anonymised. We do not use Customer content to train a general model or publish a Customer-derived benchmark without the customer's prior written agreement.
5. Legal bases and privacy grounds
Where EU or UK law applies, our legal basis depends on the activity:
- Contract: account administration, requested Services, billing, transactional messages and support needed to perform a contract or take requested pre-contract steps.
- Consent: optional Analytics and Marketing technologies, marketing subscriptions and another activity where we ask for consent. Consent can be withdrawn at any time.
- Legitimate interests: service security, fraud prevention, necessary business administration, responding to business enquiries, loading the Site's feature configuration before an Analytics choice and improving the Services where those interests are not overridden by a person's rights.
- Legal obligation: tax, accounting, regulatory, sanctions, security-notification and lawful-request duties.
- Legal claims: establishing, exercising or defending a legal claim where applicable law permits.
Under the Australian Privacy Act, we collect personal information that is reasonably necessary for our functions or activities by lawful and fair means. We collect sensitive information only with consent or where an exception applies. Under PIPEDA and substantially similar Canadian laws, we obtain meaningful consent where required. United States and Middle East privacy grounds apply according to the relevant law and activity.
6. Personal-information controls
Personal-information controls depend on customer configuration and the workflow. A policy may detect and replace supported values, block a request, use a detect-only mode or permit the data. Detection is not guaranteed to identify every personal value.
Where detection and replacement are configured, AWS Bedrock using Qwen currently processes the original content as the personal-information detector. The generation model works on replacement values. The redaction map remains within the Difinity processor and sub-processor boundary while needed for the run, including while an approval is pending.
A tool result is checked before the generation model reads it. If the check fails, the result is withheld and the run is refused rather than sending unchecked content onward. The Run Trail records the kind of personal value and its replacement, never the original value.
For a permitted external action, real values are restored as the last step before the action leaves the tool gateway. If policy requires an Approval, the person sees and approves the restored action that will run. These controls are detection and replacement, not deletion or anonymisation.
7. Who receives personal information
We do not sell personal information for money. We disclose it only for the purposes described here, on a customer's instruction, with a person's direction or consent, or where law permits or requires it.
7.1 Services sub-processors
The current Sub-processors page gives the applicable legal entity, purpose, data, region and transfer details. The Services can use:
- Amazon Web Services Australia Pty Ltd, including AWS Bedrock, for infrastructure and configured model or detector processing;
- Supabase Pte. Ltd. for authentication;
- Stripe Payments Australia Pty Ltd for billing; and
- OpenAI OpCo, LLC; Anthropic, PBC; Google Australia Pty Ltd; or SpaceXAI (formerly xAI), conditionally, when Difinity funds the model call.
When a customer uses its own model-provider key, that provider is the customer's own provider relationship rather than a Difinity sub-processor for that call.
7.2 Customer-authorised destinations
An agent can act through connectors or customer-configured MCP servers. Personal information in an action or tool call may be sent to the business system or provider authorised by the customer. The customer chooses the destination, account, tool and scope. The tool gateway holds the applicable credential and acts; the agent does not hold the credential or connect directly.
7.3 Website and business vendors
Website and business vendors are separate from the Services sub-processors listed at Sub-processors and are not covered by the DPA merely because they support Difinity's controller activity. They include:
- Amazon Web Services for public tools, report generation, storage and email delivery;
- HubSpot for CRM and sales operations;
- PostHog for one project-configuration request per page load before consent and for consented analytics, processed through PostHog Cloud EU in the European Union (Frankfurt);
- Google LLC for Google Analytics when enabled and consented, with processing in the United States and other countries where Google operates under its Data Processing Terms;
- ZenLeads, Inc. d/b/a Apollo.io for consented visitor attribution, with processing in the United States and other countries described in the Apollo Privacy Policy; and
- Meta Platforms Ireland Limited for Meta Pixel when enabled and consented, including transfers described in the Meta Platforms Privacy Policy and Meta Platforms Business Tools Terms.
7.4 Difinity staff access
Authorised Difinity staff use a separate, role-gated administration surface. They can administer organisations and people, billing, credits and plans, and view aggregate usage counts. They have no access through that surface to conversations, transcripts, run trails, agent definitions, prompts or uploaded files, and they do not sign in as one of an organisation's people.
Every staff action on an organisation is recorded in an immutable privileged-access log that identifies the staff member and organisation. The application cannot update or delete these entries. The log is available to authorised Difinity staff and is not currently visible through customer-facing interfaces. Staff access remains subject to confidentiality and purpose limits.
7.5 Law, safety and corporate transactions
We may disclose personal information when legally required, to protect rights and safety, investigate misuse or security incidents, or establish and defend legal claims. Personal information may also transfer as part of a merger, financing, acquisition, reorganisation or sale, subject to applicable notice and protection requirements.
8. Where information is processed
Difinity is headquartered in Sydney, Australia. Difinity offers Platform hosting in AWS regions in Australia (Sydney), European Union (Frankfurt) and United States. The hosting region for an organisation is agreed in the applicable Order Form.
Supabase authentication data is processed in the same region as the organisation's hosting region: Australia (Sydney), European Union (Frankfurt) or United States. Services sub-processor destinations are listed at Sub-processors. Website and business data is processed in the vendor destinations identified in Section 7.3 and the Cookie Policy. A connected system or customer-appointed provider processes data in the location chosen for that relationship.
For restricted transfers of Customer Data from the EEA, the DPA uses the EU Standard Contractual Clauses, Module 2, where required. For restricted transfers from the UK it uses the applicable UK Addendum or International Data Transfer Agreement. We use transfer assessments and supplementary safeguards where required. We address overseas disclosures under Australian Privacy Principle 8 and use the contractual or statutory mechanism required by applicable Canadian, United States or Middle East law.
9. How long we keep information
We keep personal information only for the period stated below, for the agreed customer configuration, or for as long as an objective legal or operational need applies.
| Category | Retention period or criterion |
|---|---|
| Chat attachments | 28 days. |
| Parked agent-run state awaiting completion | 7 days. |
| Database backups | 7 days. |
| Run Trails | Kept on a rolling 12-month window during the Subscription Term; after termination, the organisation can export them for 90 days, then they are deleted. |
| Transcripts and archived conversations | Kept on a rolling 12-month window during the Subscription Term; after termination, the organisation can export them for 90 days, then they are deleted. Archiving a conversation does not delete it. |
| Connector credentials | Until the connection is revoked, then the stored connector credential is destroyed. |
| Customer model-provider keys | Where an organisation's own provider keys are enabled for it, until the customer deletes or replaces the key or the account is closed, subject to backup ageing and legal obligations. |
| Account and authentication records | While the account is active, then while needed for security, disputes or legal obligations. |
| Billing and tax records | For the period required by applicable tax, accounting and corporate law. |
| Public-tool answers, results, PDFs and delivery records | Kept for 90 days, then deleted. |
| PostHog analytics events and session recordings | Kept for 12 months. Browser storage is kept until consent is withdrawn or the person clears browser storage; no fixed expiry is set. |
| Google Analytics data, when enabled | Browser identifiers follow the periods in the Cookie Policy. Event data used in Explorations is kept for 2 months by default and can be configured for 14 months. |
| Apollo visitor-attribution data | Apollo sets no published fixed period. It keeps information as set by the vendor under the Apollo Privacy Policy. Apollo's browser identifier persists until the person clears browser storage. |
| Meta Pixel data, when enabled | Browser identifiers are kept as set by Meta Platforms under its Meta Platforms Cookie Policy. Meta Platforms may retain Event Data for up to 2 years under its Meta Platforms Business Tools Terms. |
| Marketing contacts, consent and suppression records | While subscribed or engaged, then while needed to honour an opt-out, show consent history or meet a legal obligation. |
| Support and business correspondence | While needed to answer the matter, administer the relationship, resolve a dispute or meet a legal obligation. |
When we are a processor, an export of Customer Data containing personal information is available on request for 30 days after termination. That personal information is deleted within 90 days after that period, and database backups age out within a further 7 days. Connector credentials are destroyed at revocation. The Run Trail is anonymised by destroying the redaction map and is retained for 12 months on a rolling basis during the Subscription Term, with a 90-day export window after termination before deletion. Legal holds and mandatory recordkeeping are excepted. The DPA governs the process.
The Platform has no self-service conversation-delete feature. A person can still request erasure where applicable; the outcome depends on the controller's instructions, legal exceptions and the separate lifecycle of the Transcript and Run Trail.
10. Your privacy rights
Rights depend on your location, our role and the reason for processing. Contact privacy@difinity.ai. We may need information to verify identity and authority. If Difinity handles the relevant data only for a customer, we will usually refer the request to that customer and assist as required by the DPA.
10.1 Australia
You may request access to and correction of personal information under Australian Privacy Principles 12 and 13. You may complain to us about our handling of personal information. If the complaint is not resolved, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
10.2 EEA and United Kingdom
Where the EU GDPR or UK GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent and protection from a decision based solely on automated processing that produces legal or similarly significant effects. You may complain to your local supervisory authority.
10.3 United States
Residents of California and other states with comprehensive privacy laws may have rights to know or access, correct, delete, obtain a portable copy, opt out of specified sale, sharing, targeted advertising or profiling, limit specified use of sensitive information, appeal a decision, and receive equal service. The precise rights and exceptions depend on the applicable law. We do not discriminate against a person for exercising a privacy right.
10.4 Canada and the Middle East
Where applicable Canadian law applies, you may request access and correction, challenge compliance and withdraw consent subject to legal or contractual limits. Where UAE, DIFC, ADGM or Saudi law applies, you may have rights to access, correction, erasure, restriction, objection, portability and complaint, subject to the relevant statute.
10.5 Marketing and cookies
Use the unsubscribe link in a marketing email to stop that marketing. Use Cookie settings on the Site to change Analytics or Marketing consent. Withdrawing consent does not affect processing that was lawful before withdrawal.
We respond within the period required by applicable law. Some rights are subject to exceptions, and we will explain a refusal where the law requires it.
11. Security
We use technical and organisational measures intended to protect personal information from unauthorised access, use, change, disclosure and loss. Measures for Customer Data are described in the DPA. They include scoped identity and role controls, write-only credential handling, secrets storage, service-to-service boundaries, configured personal-information checks and separation between the Transcript and Run Trail.
No transmission or storage method is completely secure. Contact security@difinity.ai or legal@difinity.ai if you believe personal information or an account is at risk.
12. Automated processing and agent actions
The Platform performs several distinct kinds of automated processing. A configured policy can permit, refuse or route work. A model generates output. An agent may propose an action in a connected customer system, and the tool gateway decides whether it may proceed and carries out a permitted action.
Human approval is configurable and is not applied to every action. Where policy requires approval, only the person the agent is acting for may approve the proposed action. The customer determines the purpose of its deployment and whether a workflow could produce a legal or similarly significant effect. The customer must select an appropriate legal basis, notices and safeguards. Difinity remains responsible for faithfully implementing documented instructions and its own processor or controller duties.
13. Children
The Services are not directed to children under 18, and we do not knowingly collect their personal information through our own website. Customers must not configure the Platform to process children's information unless the processing is lawful, documented and covered by the agreement with Difinity. Contact privacy@difinity.ai if you believe a child has provided information to us directly.
14. Third-party links
The Site and Services may link to third-party websites or services. Their privacy practices are governed by their own notices unless the DPA states otherwise for a Services sub-processor.
15. Changes to this policy
We may update this Policy when our Services, practices or legal duties change. We will post the new version and Last Updated date and provide any additional notice required by law or contract. Earlier versions should be requested from legal@difinity.ai.
16. Contact and complaints
Contact:
- Privacy enquiries and rights: privacy@difinity.ai
- Legal enquiries: legal@difinity.ai
- Postal address: Difinity Pty Ltd, Sydney, NSW, Australia
We will acknowledge and investigate a privacy complaint and respond within the period required by applicable law. You may also complain to the regulator with jurisdiction over your complaint.
© 2026 Difinity Pty Ltd. All rights reserved.