Awesomate.ai (“Awesomate”, “we”, “us”, or “our”) is committed to protecting personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, use our services, or otherwise interact with us. It applies to all of our services, including managed n8n hosting, the Buddzee data platform, and Vibe Coding application development.
By using our services, you consent to the practices described in this policy. If you do not agree with this policy, please do not use our services.
Awesomate operates in two capacities depending on the type of data involved:
As a data controller: We collect and manage personal information about our customers for account management, billing, communications, and service delivery (e.g., your name, email, payment details). We determine the purposes and means of processing this data, and this Privacy Policy governs that processing.
As a data processor: When you use our services — including n8n hosting, Buddzee, and Vibe Coding — we process data on your behalf according to your instructions. This may include your customers’ data, business records, and other information you choose to store or process through our platforms. In this capacity, you remain the data controller and are responsible for ensuring that your use of our services complies with applicable privacy laws. We process this data solely to deliver the services you have engaged us to provide and in accordance with any Data Processing Addendum (DPA) agreed between us.
This distinction is important: our obligations and your rights differ depending on whether Awesomate is acting as a controller or a processor. The remainder of this policy covers both roles, with specific sections noting where distinctions apply.
We may collect the following personal information directly from you:
When you visit our website or use our services, we may automatically collect:
Depending on which services you use, we may process data on your behalf, including:
This service data belongs to you. We do not access, use, or disclose it except as necessary to deliver the services you have requested, or as required by law.
We recognise that some clients use our services to process sensitive information as defined under the Privacy Act, which may include biometric data, health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records, or trade union membership.
When Awesomate processes sensitive information on your behalf as a data processor:
If your use case involves sensitive information — particularly in regulated industries such as government, healthcare, or financial services — we strongly recommend engaging with us to establish a Data Processing Addendum tailored to your compliance requirements.
We collect information from your interactions with us, including support tickets, contact form submissions, email correspondence, and feedback you provide.
We collect and use personal information for the following purposes:
Our Buddzee platform and related services use artificial intelligence and machine learning technologies to help you query and analyse your business data using natural language. Here is how AI is used within our services:
AI processing may involve third-party AI providers. Our current AI sub-processors and their data commitments are:
| Provider | Data Training | Data Retention | Governing Terms |
|---|---|---|---|
| Google (Gemini) | Your data is not used to train Google’s models | Data is processed transiently and not retained beyond request fulfilment | Google Cloud Data Governance |
| Anthropic (Claude) | Your data is not used to train Anthropic’s models when accessed via the API | Data may be retained for up to 30 days for trust and safety purposes | Anthropic API Data Usage Policy |
| OpenAI | Your data is not used to train OpenAI’s models when accessed via the API | Data may be retained for up to 30 days for abuse monitoring | OpenAI API Data Usage Policy |
All data transmitted to AI providers is encrypted in transit. We do not send personally identifiable information to AI providers unless it is contained within the data you have instructed us to process on your behalf.
We are committed to transparency about how AI is used in our services and will update this section as our use of AI evolves, in accordance with the automated decision-making transparency requirements under the Privacy Act.
We never sell your personal information.
We may share your information with the following categories of third parties, only to the extent necessary to deliver our services:
| Category | Provider | Purpose |
|---|---|---|
| Infrastructure hosting | OVHcloud | Dedicated server and database hosting |
| Offsite backup storage | Amazon Web Services (S3) | Encrypted database backups |
| Edge security | Cloudflare | DDoS protection, web application firewall, and secure traffic delivery |
| CRM and marketing | Ontraport | Contact management, forms, email |
| AI providers | OpenAI, Anthropic, Google | AI-powered features |
| Payment processing | Stripe, Eway | Secure payment transactions |
| Analytics | Cloudflare, Google Analytics | Website performance and usage insights |
We may also disclose personal information to professional advisors (legal, accounting), law enforcement or government agencies when required by law, or to a potential buyer in the event of a business sale or merger.
Your personal information may be transferred to and processed in countries outside of Australia. Specifically:
Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles your information in accordance with the APPs (APP 8). All our third-party providers are bound by data processing agreements that require appropriate security and privacy safeguards.
For clients in regulated industries, data residency requirements — including the jurisdiction of backups and disaster recovery — can be addressed as part of a Data Processing Addendum.
Awesomate’s infrastructure is designed to support varying levels of data isolation depending on client requirements.
Standard deployments: Client services are deployed within shared infrastructure groups with logical separation between accounts. Access controls ensure that each client can only access their own data.
Isolated deployments: For clients with enhanced security or compliance requirements — including government, healthcare, and financial services — we offer fully isolated infrastructure deployments. In an isolated deployment:
This isolation model applies to both our n8n hosting and application hosting services. Isolated deployments can be combined with regional hosting to meet both data sovereignty and data segregation requirements simultaneously.
Detailed technical specifications of our isolation architecture are available under NDA as part of our security documentation. To discuss isolated deployment options, contact us at hello@awesomate.ai.
We take the security of your data seriously. Our infrastructure is purpose-built for workloads that require the highest levels of security and compliance. Key security measures include:
Detailed technical specifications of our security architecture, including encryption protocols, network design, and access control implementation, are available under NDA as part of our security documentation for enterprise and government clients.
While we implement robust security measures, no system is completely immune to risk. We encourage you to use strong, unique passwords and keep your account credentials secure.
We retain personal information only as long as necessary for the purposes outlined in this policy:
Upon termination of services, we securely delete all service data, including backups, within the agreed timeframe. For clients requiring certified deletion, this can be arranged as part of a Data Processing Addendum.
Our website uses cookies and similar technologies to enhance your experience:
You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website.
Under the Australian Privacy Act, you have the right to:
To exercise any of these rights, contact us at hello@awesomate.ai. We will respond to your request within 30 days.
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:
For clients with a Data Processing Addendum, breach notification timelines may be further tightened in accordance with your contractual requirements.
We recognise that clients in regulated industries — including government, healthcare, defence, and financial services — have compliance requirements that go beyond what a standard privacy policy can address.
Our infrastructure is purpose-built for sensitive and regulated workloads, running on dedicated physical servers with no shared resources, a zero-public-exposure network architecture, encryption at every layer, and full auditability through Infrastructure as Code.
Our hosting provider holds internationally recognised certifications at the data centre level, including ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 1 Type 2, SOC 2, SOC 3, CSA STAR, HIPAA, and PCI DSS. Certification documentation is available upon request.
For regulated-industry clients, we offer:
To discuss enterprise or government requirements, contact us at hello@awesomate.ai.
Our services are designed for businesses and are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected information from a child, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email or by posting a prominent notice on our website. We encourage you to review this page periodically.
If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:
If you are not satisfied with our response to a privacy concern, you can contact the Office of the Australian Information Commissioner: