Privacy Policy

Effective date: 15 May 2026 Applies to: refinedautonomy.ai, related product pages, and the services operated by Volency Pty Ltd (ACN 702 218 531, ABN 53 702 218 531), trading as Refined Autonomy

1. Who we are

Volency Pty Ltd (ACN 702 218 531, ABN 53 702 218 531), trading as Refined Autonomy (‘Refined’, ‘we’, ‘us’, ‘our’), operates the services we provide (the ‘Service’).

The Service uses a hybrid deployment model. Customer business data stays in the customer’s own environment. We process a narrower set of data to run authentication, governance records, support, billing, and service operations.

2. What this policy covers

This policy explains:

This policy covers:

This policy does not replace any signed contract. If your organisation has a separate order form, MSA, or DPA with us, those documents govern that commercial relationship as well.

3. Our privacy position

We designed the Service so customer business data stays with the customer wherever possible.

In the ordinary course, we do not host or process the customer’s business records, documents, messages, vault content, or agent outputs. Those stay in the customer’s own tenant or infrastructure.

We do process limited service data so the Service works. That usually includes:

4. What personal information we collect

The types of personal information we collect depend on how you interact with us.

A. Website and enquiry data

We may collect:

B. Account and service data

We may collect:

C. Governance and operational metadata

We may collect:

D. Billing and commercial data

We may collect:

5. What we generally do not collect

In the ordinary course, we do not collect or host the customer’s core business content inside Refined infrastructure. That includes:

If a customer asks us to help with a support issue that requires temporary access to business content, we treat that as a limited support event. We restrict access, log it, and remove any working copy when the support work ends.

6. How we collect personal information

We collect personal information when:

We may also receive personal information from:

7. Why we collect and use personal information

We collect and use personal information to:

Where we use anonymised or aggregated data for product improvement, we do not use it to identify you.

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

Depending on the context, we process personal information because:

If your organisation uses the Service for decisions about individuals, that organisation remains responsible for its own privacy notices, lawful basis, and automated decision-making obligations.

9. Hybrid deployment and data sovereignty

The Service does not follow a standard shared-data SaaS model.

The boundary works like this:

This structure reduces the amount of personal information we process directly. It does not remove the customer’s own privacy obligations for the data they control in their environment.

10. Disclosure of personal information

We may disclose personal information to:

We do not sell personal information.

We do not disclose customer business data as part of a general commercial data-sharing model because that data does not sit with us in the ordinary course.

11. Cross-border disclosure

We aim to keep Refined-hosted data for Australian customers in Australian infrastructure where practical, including our default Sydney-region posture.

Some service providers may process limited personal information outside Australia. This can happen, for example, in identity, support, or AI inference workflows if a customer enables those features or chooses a provider with offshore processing.

Where cross-border disclosure occurs, we use contractual and operational controls that fit the service. Enterprise customers can review the details in their contract documents, including the DPA where one applies.

12. Cookies and similar technologies

We use cookies and similar tools to:

You can control cookies through your browser settings. If you block essential cookies, parts of the website or service may not work properly.

13. Security

We use technical and organisational controls to protect personal information we hold. Those controls include access control, encryption in transit, monitoring, audit logging, and incident response processes.

No system is perfect. If we detect an eligible data breach, we will respond under our incident procedures and any legal obligations that apply.

14. Retention

We keep personal information only for as long as we need it for the reasons in this policy, including legal, accounting, security, dispute, and record-keeping purposes.

Retention periods vary by data type:

If we no longer need personal information, we delete it or de-identify it where reasonable.

15. Access, correction, and complaints

You can ask us to:

Email support@refinedautonomy.ai and mark the subject line ‘Privacy’. We may need to verify your identity before we act.

If you are an end user of a customer deployment, contact your organisation first for requests about customer business data held in that deployment. Your organisation controls that data environment.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

16. Direct marketing

We may send product, event, or company updates to people who asked for them or whose business role makes the contact reasonably expected.

You can opt out at any time by using the unsubscribe option in the message or by contacting us.

17. Children’s privacy

The Service is for business use. We do not design it for children.

18. Changes to this policy

We may update this policy from time to time. We will post the current version at refinedautonomy.ai. If a change is material, we will use a reasonable notice method for the context.

19. Contact

For privacy questions, requests, or complaints:

Volency Pty Ltd (trading as Refined Autonomy) Email: support@refinedautonomy.ai Subject line: ‘Privacy’