Privacy policy
Last updated 28 July 2026
This policy explains what personal information Tanto AI collects, why we collect it, who we share it with, how long we keep it and the choices you have. It applies to this website and our services.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What we collect
We only collect what we need to have a conversation with you and to deliver work you've asked for.
- When you book a call: your name, email address, and anything you choose to write in the booking questions, typically your company, role, and a description of the work taking up your week. Your chosen appointment time is shared with our calendar.
- When you email us: your email address and whatever you put in the message.
- During an engagement: information about how your business works: workflows, systems, and how your team spends its time. This may incidentally include personal information about your staff or your clients. See Business information we may access during an engagement below.
- When you visit this website: our hosting provider records standard server information such as IP address, browser type and pages requested. We use this only for security and reliability.
We do not collect sensitive information (such as health or financial details), and we ask that you don't send it to us.
Cookies and tracking
This website sets no cookies and does not track you. There is no analytics software, no advertising pixel, and no third-party tracker on any page. The only script on the site operates the mobile navigation menu.
Our pages load typefaces from Google Fonts, which means your IP address is sent to Google when a page loads. Google's handling of that data is covered by the Google Privacy Policy.
How we use it
- To respond to your enquiry and hold the call you booked.
- To prepare and deliver the written follow-up we've offered you.
- To scope, quote and carry out coaching or build work.
- To send you material you've specifically asked for, such as our playbooks.
- To meet our legal and record-keeping obligations.
We do not sell personal information, and we do not share it for anyone else's marketing.
Who we share it with
We use a small number of service providers to run the business. They only receive what they need, and only to provide the service to us:
- Cal.com, our booking system, which collects your name, email and booking answers when you schedule a call.
- Our email and calendar providers, to correspond with you and hold the appointment.
- Our website host, which serves this site and keeps standard server logs.
Some of these providers store data outside Australia, including in the United States and the European Union. By making an enquiry you consent to that disclosure. Where we can, we choose providers with recognised security and privacy standards, but overseas providers are subject to the laws of the countries they operate in, which may differ from Australian law.
We may also disclose information where we're required to by law.
Business information we may access during an engagement
Diagnostics and builds involve looking closely at how your business operates. We may see client-confidential material, staff information, and commercially sensitive detail during that work.
- We treat everything we see during an engagement as confidential.
- Systems we build run on your accounts, with your data, under your control. We don't move your data into our own systems to do the work.
- Any access we're given to your systems is for the duration of the engagement. At handover, access is returned to you and ours is removed.
- We keep only what we need to deliver and document the work.
- Where you need a confidentiality agreement on your own terms, we'll sign one.
If your firm has specific obligations to its own clients or regulators, tell us early and we'll work to them.
How we store and protect it
Information is held in cloud services protected by access controls and multi-factor authentication. We limit who can see it to the people doing the work.
No system is perfectly secure. We take reasonable steps to protect personal information from misuse, loss and unauthorised access, and if a data breach occurs that is likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner as required.
How long we keep it
Enquiries that don't become engagements are deleted within 24 months. Records relating to work we've done are kept for seven years to meet tax and legal obligations, then deleted. You can ask us to delete your information sooner, subject to those obligations.
Email we send you
We'll only add you to our playbook list if you ask us to. Every email we send identifies us and includes a working unsubscribe link, and we act on unsubscribes promptly, as required by the Spam Act 2003 (Cth). Unsubscribing has no effect on work we're doing for you.
Accessing or correcting your information
You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email hello@tantoai.co and we'll respond within 30 days. There's no charge for this.
Complaints
If you think we've mishandled your personal information, tell us first at hello@tantoai.co and we'll investigate and respond within 30 days.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this policy
We'll update this page when our practices change, and the date at the top will change with it. If we start using website analytics or any other tracking, we'll say so here before we turn it on.
Contact
Tanto AI
New South Wales, Australia
hello@tantoai.co