Legal & CompliancePrivacy Policy
How AI Squad and AI Squad Bot collect, use, and protect your personal information in accordance with Australian Privacy Law and Meta Platform Terms.
Last updated: May 2026Century IT Consultants Pty LtdABN 66 606 592 063Meta App ID: 1330780349073247
Section 01
About This Policy
This Privacy Policy describes how Century IT Consultants Pty Ltd (ACN 606 592 063 / ABN 66 606 592 063), trading as AI Squad ("we", "us", "our"), collects, uses, stores, and manages personal information across all of our products and services, including:
- AI Squad website — aisquad.com.au
- AI Squad Bot — our Meta-integrated Instagram automation app (Meta App ID: 1330780349073247)
- AI Squad Consult — our pre-meeting intake and booking system
- AutoBills — our automated invoice processing system
- Recovery Squad — our data recovery service at recoverysquad.com.au
- All related automation workflows, voice agents, and client-facing tools
This policy is publicly accessible at aisquad.com.au/privacy-policy without login or registration at any time. By using our services, you agree to the terms of this policy.
Section 02
Data We Collect
We collect personal information only where it is necessary to deliver our services.
| Data Type | Source | Context |
|---|
| Name & email address | Contact forms, booking system | Website enquiries, consultation bookings |
| Phone number | Contact forms, AI voice agent interactions | Sales calls, support, voice agent testing |
| Business information | Intake forms, consultations | AI audit tool, strategy consulting |
| Instagram username & user ID | Instagram Graph API | AI Squad Bot comment detection |
| Instagram comment content | instagram_manage_comments | Trigger keyword detection (@aisquad posts) |
| Instagram DM thread data | instagram_business_manage_messages | Sending automated DM responses |
| Invoice & financial data | AutoBills email processing | Automated invoice management via Xero |
| Call recordings & transcripts | AI voice agent platform | Service delivery, quality improvement |
| Usage & analytics data | Website cookies, server logs | Performance monitoring, UX improvement |
We do not collect sensitive information such as health data, financial account credentials, government identifiers, or biometric data unless explicitly required and consented to.
Section 03
How We Use Data
- Delivering AI consulting, automation, and voice agent services to clients
- Responding to enquiries and booking consultation appointments
- Operating AI Squad Bot to detect trigger comments and send information via Instagram DM
- Processing invoices and managing accounts via AutoBills and Xero
- Improving our AI models, workflows, and service quality
- Communicating service updates, reports, and project deliverables
- Complying with legal obligations and platform terms (including Meta Platform Terms)
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Section 04
AI Squad Bot (Instagram Automation)
AI Squad Bot is a server-to-server automation application connected to the @aisquad Instagram business account. It operates using a permanent system user token. There is no end-user login flow.
How it works:
- A user comments with a trigger keyword (e.g. "Info") on an @aisquad Instagram post
- The bot reads the comment using instagram_manage_comments and detects the keyword
- The bot authenticates the @aisquad business account using instagram_business_basic
- A single personalised Direct Message is sent to the commenter via instagram_business_manage_messages
- The interaction is logged in our CRM for legitimate business follow-up
- No further automated messages are sent to the same user
Meta Permissions used: instagram_basic, instagram_business_basic, instagram_manage_comments, instagram_business_manage_messages. All permissions are used strictly in accordance with Meta's Platform Terms and Developer Policies.
Section 05
Data Processors & Service Providers
| Processor | Purpose | Data Type | Location |
|---|
| OpenAI | AI message generation | Comment content, message text | United States |
| Anthropic (Claude) | AI response generation, audit reports | Business information, query data | United States |
| n8n | Workflow automation infrastructure | Workflow execution data | Germany / Cloud |
| Google Workspace | CRM logging, email, Drive storage | Lead data, emails, documents | Australia / United States |
| Xero | Accounting and invoice processing | Financial and business data | Australia / New Zealand |
| Cal.com | Appointment booking | Name, email, booking details | United States |
| Retell AI / Vapi | AI voice agent infrastructure | Call recordings, transcripts | United States |
| Vercel | Website hosting | Usage and access logs | United States |
| Telegram | Internal alert notifications | Lead alert summaries | Germany |
The entity responsible for all Platform Data shared by Meta is Century IT Consultants Pty Ltd (ACN 606 592 063), located in Melbourne, Victoria, Australia.
Section 06
Data Retention
- Instagram interaction data — 90 days from collection, then securely deleted
- Client consultation data — duration of client relationship plus 7 years (Australian tax law)
- Invoice and financial data — 7 years (ATO requirements)
- Call recordings — 90 days unless required for ongoing service delivery
- Website analytics — 26 months in aggregated, anonymised form
- Email correspondence — 3 years or duration of business relationship
Section 07
Legal Basis & Compliance
- Australian Privacy Act 1988 and the Australian Privacy Principles (APPs)
- Meta Platform Terms and Developer Policies
- General Data Protection Regulation (GDPR) where applicable to EEA users
- Spam Act 2003 (Australia) — all commercial electronic messages comply with consent requirements
We have a data minimisation policy ensuring we collect and disclose only the minimum personal information necessary. We have not provided user data to public authorities in response to national security requests in the past 12 months.
Section 08
Your Rights
- Access — Request a copy of the personal data we hold about you
- Correction — Request correction of inaccurate or incomplete data
- Deletion — Request that we delete your personal data
- Objection — Object to the processing of your data in certain circumstances
- Portability — Request your data in a portable, machine-readable format
- Restriction — Request restricted processing in certain circumstances
- Withdrawal of consent — Withdraw consent at any time where processing is consent-based
To exercise any of these rights, contact us using the details in Section 13. We will respond within 30 days. You may also lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Section 09
Security
- Encrypted data transmission via HTTPS/TLS across all integrations and services
- Access controls limiting data access to authorised personnel only
- Secure credential management using industry-standard practices
- Use of reputable cloud infrastructure providers with SOC 2 compliance
- Regular review of data handling practices and processor agreements
In the event of a data breach likely to result in serious harm, we will notify affected individuals and the OAIC as required by the Notifiable Data Breaches (NDB) scheme.
Section 10
Cookies & Tracking
- Essential cookies — Required for the website to function correctly
- Analytics cookies — Used to understand how visitors interact with our website
- Preference cookies — Used to remember your settings and preferences
You can control cookie settings through your browser preferences. We do not use cookies for targeted advertising.
Section 11
Third-Party Links
Our website and communications may contain links to third-party websites and platforms including Meta, Google, Cal.com, LinkedIn, and others. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Section 12
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. Continued use of our services after changes are posted constitutes your acceptance of the updated policy.