Privacy Policy

How we collect, use, disclose and protect personal information — written to the Australian Privacy Principles and the GDPR.

Version 1.1 · Effective 9 August 2026 · Applies to numaya.ai, www.numaya.ai and dev.numaya.ai

1. Who we are

Numaya AI ("we", "us", "our") is a trading name of Rizvi Group of Companies, ABN 11 622 778 947, an Australian business. We are the entity responsible for personal information collected through this website — the "APP entity" under the Privacy Act 1988 (Cth) and the "controller" under the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Contact us about anything on this page at [email protected]. If you are in the EEA or the UK and would like to raise a matter under the GDPR, use the same address and mark your message "GDPR request" — it is routed to the person who handles privacy requests.

This policy covers the public website and the internal sales portal at /sales and /admin. It does not cover the separate products we build for clients: when we process personal information inside a client's system we generally do so as a processor on that client's instructions, under the contract with them, and that client's own privacy policy applies.

2. The short version

  • You can browse this entire site, and get a full indicative price from the quote flow, without telling us who you are.
  • We only create a record about you when you deliberately give us a way to reply — an email address or a phone number. A submission with neither is rejected by the server, not stored.
  • If you leave us contact details, expect a human to use them: one of our sales team may email or call you to talk through what you need before we quote it. Tell us to stop and we stop.
  • Analytics load only after you accept. Nothing is sent before that, and you can change your mind below at any time.
  • We do not sell personal information, and we do not share it for advertising.
  • Free-text you type about your project may be sent to an AI provider to help us size the work. Your name, email and phone are never sent to that provider.

3. Dealing with us anonymously (APP 2)

You have the option of not identifying yourself, or of using a pseudonym, when you deal with us — and the site is built that way. The quote and audit flow computes and shows you a price without any contact details. We ask for a name only where we have promised to ring a human back.

We cannot deal with you anonymously where it is impracticable — for example, we cannot send you a written proposal, reply to an enquiry, or give you access to the sales portal without knowing who you are.

4. What we collect, and where it comes from

We collect personal information directly from you wherever it is reasonable and practicable to do so (APP 3.6). The technical information below is collected automatically by the server or, for analytics, only after your consent.

4.1 Information you give us

Collected through the quote/audit flow, the contact form, call bookings and the exit-intent save prompt.
FieldRequired?Why we ask
Email addressOne of email or phoneTo send your quote, acknowledgement and scoped proposal
Phone numberOne of email or phoneAlternative to email; required if you ask for a call. May be used by our sales team to discuss your enquiry — see section 12
NameOnly for a booked callSo the person calling you knows who they asked for
CompanyOptionalTo scope the work and group enquiries from one organisation
Project description, tech stackOptional free textTo size and price the work — see section 6
Scope answers (users, pages, integrations, support level, complexity)OptionalTo compute the indicative price
Preferred day, time window and time zoneOnly for a booked callTo call you when you asked to be called
Marketing consentOptional, opt-inTo send occasional updates — see section 12

Please do not put sensitive information (health, biometric, racial or ethnic origin, political, religious or philosophical beliefs, trade union membership, sexual orientation, criminal record), government identifiers, credentials, or other people's personal details into the free-text fields. We do not need it, we do not ask for it, and we will delete it if you send it.

4.2 Information collected automatically

  • Request data. Your IP address, user agent, requested URL and timestamps are processed by our web server and appear in operational logs. IP is also used for anti-abuse rate limiting and is passed to Cloudflare Turnstile when a form is verified.
  • Attribution. If you arrive with utm_* parameters or from an external referrer, the first-touch source, medium, campaign, term, content, referring URL and landing path are stored in your browser and attached to an enquiry if you later submit one.
  • Tracked links. If you click a numaya.ai/r/… link from one of our sales emails, we record the click time, referrer, user agent and IP address against that link.
  • Analytics. Only after you accept: Google Analytics 4 page views and a small set of interaction events (starting/submitting the audit flow, generating or downloading a quote, booking a call, CTA clicks, form errors, outbound research-repository clicks). IP anonymisation is enabled.

4.3 Staff and contractor accounts

For the internal sales portal we hold a work email address, display name, role, account status and either a hashed password or a Microsoft Entra ID sign-in, plus the tracked links each person creates. This is employment/engagement-related administration, not website visitor data.

4.4 Unsolicited information (APP 4)

If we receive personal information we did not ask for and could not have collected under APP 3, we destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

5. Why we use it, and our legal basis

Under the Australian Privacy Principles we use personal information for the primary purpose it was collected, and for related secondary purposes you would reasonably expect (APP 6). Under the GDPR every purpose also needs a lawful basis — set out in the right-hand column.

Purpose, and the GDPR Art 6 basis we rely on for it.
What we doGDPR lawful basis
Reply to your enquiry, produce a quote, prepare a proposal, book and hold a callArt 6(1)(b) — steps at your request before entering a contract
A member of our sales team contacting you by email or phone to scope the work (a discovery conversation) — see section 12Art 6(1)(b) — steps at your request before entering a contract; Art 6(1)(f) where the enquiry did not itself ask for contact
Recording that you opened or clicked a link in an email we sent you, and mirroring that onto your record in our CRMArt 6(1)(f) — legitimate interests in knowing whether our follow-up reached you
Deliver and administer a project you have engaged us forArt 6(1)(b) — performance of a contract
Rate limiting, bot/captcha verification, security monitoring and operational loggingArt 6(1)(f) — legitimate interests in keeping the service available and secure
Deduplicating and completing a single enquiry across several stepsArt 6(1)(f) — legitimate interests in accurate records and in not contacting you three times
First-touch marketing attribution attached to an enquiry you submitArt 6(1)(f) — legitimate interests in understanding which channels work
Sizing and summarising an enquiry with AI assistanceArt 6(1)(f) — legitimate interests in responding quickly and accurately
Analytics and measurementArt 6(1)(a) — your consent, which you can withdraw
Sending marketing updatesArt 6(1)(a) — your consent (opt-in), withdrawable at any time
Meeting tax, accounting, contractual and other legal obligationsArt 6(1)(c) — legal obligation; Art 6(1)(f) for records of legal claims

Where we rely on legitimate interests we have weighed those interests against your rights and freedoms. You can object to that processing — see section 13.

Giving us your details is never a statutory requirement. It is simply necessary if you want a reply: if you do not provide an email address or a phone number, we cannot respond to you, and the enquiry is not stored.

6. AI processing, and automated decisions

We use a large language model to help scope and price enquiries, and to write a one-sentence summary of an enquiry for the person who will action it. Being an AI company, we think you are entitled to know exactly what that means.

  • What is sent: your free-text project description, the tech stack you typed, your scope selections and your requested follow-up method.
  • What is never sent: your name, email address, phone number, company name, IP address, or any identifier that links the text back to you.
  • Who processes it: Z.AI (Zhipu AI), whose service is operated from China. Input is truncated to 800 characters. See section 9 on overseas disclosure before you decide what to type.
  • What we do with the output: it pre-fills fields you have not yet answered and never overwrites an answer you have already given, and it adds a summary line to the internal record. If the AI call fails, everything still works from our published rate card.

No solely automated decisions. The price the site shows you is indicative only. No decision that produces a legal or similarly significant effect for you is made solely by automated means — every proposal, price and engagement decision is reviewed by a person before it is acted on. That means Art 22 GDPR is not engaged; you can still ask us how a given estimate was reached.

7. Cookies and local storage

We use a small number of strictly necessary cookies, and store a few preferences in your browser's local storage. Nothing here is used for advertising or cross-site tracking. Local-storage items never leave your device unless stated.

Everything this site stores in your browser.
NameTypePurposeLifetimeBasis
numaya-consentLocal storageRemembers your analytics choice so we stop askingUntil clearedStrictly necessary
numaya-themeLocal storageYour dark/light theme preferenceUntil clearedStrictly necessary
numaya-attributionLocal storageFirst-touch campaign source, attached only if you submit an enquiryUntil clearedLegitimate interests
numaya-audit-draftLocal storageSaves your in-progress answers so you can come back to themUntil clearedStrictly necessary
numaya_sessionCookie (httpOnly)Signed sign-in session for staff using the sales portalSessionStrictly necessary
numaya_sso_txnCookie (httpOnly)Protects a Microsoft sign-in round trip against tampering10 minutesStrictly necessary
auth_*Local storageMirrors a signed-in staff member's role/name for the UI onlyUntil sign-outStrictly necessary
Cloudflare (e.g. __cf_bm, Turnstile)CookieBot detection and form verificationUp to 30 minutesStrictly necessary
_ga, _ga_*CookieGoogle Analytics 4 measurementUp to 2 yearsYour consent only

8. Who we disclose personal information to

We do not sell personal information, we do not trade or rent it, and we do not disclose it for another organisation's direct marketing. We use the following service providers, each bound to use the information only to provide their service to us.

Recipients, what they receive, and where they process it.
RecipientRoleWhat they receiveLocation
Twenty CRMOur customer record systemYour full enquiry: contact details, project description, scope and priceSelf-hosted on our own servers in Australia
CloudflareCDN, network tunnel, Turnstile anti-botRequest metadata, IP address, captcha tokenGlobal network, including the United States
Mailjet (Sinch)Transactional emailYour email address and name, and the content of the acknowledgement and internal notificationEuropean Union (France)
Z.AI (Zhipu AI)Scope and price assistance, enquiry summaryProject free text and scope answers only — no contact detailsChina
Google (Analytics 4)Website measurementPage views and interaction events, with IP anonymisation — only if you consentUnited States and other Google locations
Microsoft (Entra ID)Staff single sign-onStaff work identity only — no visitor dataMicrosoft cloud regions

We may also disclose personal information to our professional advisers, or where we are required or authorised by law — for example, in response to a court order, a lawful request from a regulator, or to establish or defend a legal claim. If our business is restructured or transferred, information may pass to the acquiring entity, subject to this policy.

9. Overseas disclosure (APP 8 and GDPR Chapter V)

Our own systems — the website, database, CRM and backups — run on infrastructure we operate in Australia. The recipients in section 8 are the only routine overseas disclosures, and the likely countries are those listed there: the United States, France (EU), China, and the Microsoft and Google regions used by those services.

APP 8.1: before disclosing to an overseas recipient we take steps that are reasonable in the circumstances to ensure they do not breach the Australian Privacy Principles — including contractual terms, using named, established providers, and minimising what is sent (the AI provider, for instance, receives no contact details at all).

Please note this specifically: the AI scope assistance is processed in China, a country whose privacy laws differ materially from Australia's and which has no EU adequacy decision. Australian privacy law may not be enforceable there, and you may not be able to seek redress under it. That is why the request excludes your identity, and why we ask you not to include personal or confidential information in the project description. If you would rather no free text left Australia at all, email us your requirements instead of using the on-site flow.

For EEA and UK visitors: transfers out of the EEA/UK are made under an Art 45 adequacy decision where one covers the destination, and otherwise under the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) together with a transfer risk assessment, per Arts 46 and 49. You can request a copy of the safeguards that apply to a particular transfer by emailing us.

10. How we protect it (APP 11, GDPR Art 32)

  • All traffic is served over HTTPS; the site is reached through a Cloudflare tunnel rather than an exposed origin.
  • Staff passwords are stored as salted scrypt hashes, never in plain text, and sessions are HMAC-signed httpOnly cookies. Staff sign-in prefers Microsoft SSO with the company directory.
  • Credentials and API keys are held in a secrets manager and injected at process start — never written into the repository or onto disk. Access is per-environment, so a development workload cannot read production secrets.
  • Integration keys are least-privilege: the CRM key used by the website can create records but cannot delete them.
  • Forms are protected by captcha verification and per-IP rate limiting; free-text sent to the AI provider is length-capped and explicitly treated as untrusted input.
  • Databases are backed up nightly with a 14-day retention window, and infrastructure is monitored with alerting.
  • Access to the CRM and the sales portal is restricted to authorised personnel.

No method of transmission or storage is perfectly secure. We take reasonable steps appropriate to the risk, but we cannot guarantee absolute security.

11. How long we keep it

We keep personal information only as long as we need it for the purposes in section 5, or as long as the law requires. When neither applies we destroy it or de-identify it (APP 11.2, GDPR Art 5(1)(e)).

Default retention periods.
RecordKept for
Enquiries that did not become an engagement24 months from your last contact with us
Client records and project correspondence7 years after the engagement ends (tax and business records)
Enquiry deduplication index12 months
Tracked-link click records12 months
Server and application logsUp to 30 days
Staff portal accountsDuration of engagement, then 12 months
Analytics data held by GooglePer the property's retention setting, currently 14 months
Backups14 days, after which deletions propagate out of backup
Anything stored in your browserOn your device until you clear it

12. Sales contact and direct marketing (APP 7 and the Spam Act)

12.1 A salesperson may contact you

We are a services business, so an enquiry is the start of a conversation with a person, not just an automated reply. If you give us an email address or a phone number, a member of our sales team may use it to contact you about your enquiry — typically a short discovery conversation to understand what you actually need before we put a scoped price on it. That may be by email, by phone, or on a video call you accept.

We may also reach out where you started the quote or audit flow, left contact details, and did not come back to finish — so you get the proposal you were evidently after. If you asked us to call at a particular day, time and time zone, we use exactly those details for that purpose.

To prepare for that conversation, the person contacting you can see the enquiry you submitted: your project description, scope answers, indicative price, company, and how you found us. Notes they take about the conversation are added to your record in our CRM. Links we send you from the CRM are tracked — clicking one tells us that our follow-up reached you, and records the click time, referrer, user agent and IP address against that link (see section 4.2).

You can stop this at any time, and it costs you nothing to do so: reply to any message asking us not to contact you, tell the person on the call, or email [email protected]. We will record the request against your file and stop. In the EEA and the UK this is your Art 21 right to object; we do not require a reason where the contact is for marketing, and we will honour it either way. If you would rather we never called at all, leave the phone field empty — an email address alone is enough for us to send you a proposal.

Australian unsolicited-call rules: if you register an Australian number on the Do Not Call Register we will respect it, except where you have consented to being called — which is what asking us for a call back is. Withdraw that consent using any of the routes above.

12.2 Marketing email

We send marketing email only where you have opted in, or where you gave us your address in the course of an enquiry and would reasonably expect follow-up about the work you asked about. Every marketing message carries a working unsubscribe link and identifies us, as the Spam Act 2003 (Cth) requires.

You can opt out at any time — use the unsubscribe link, or email [email protected] and we will action it promptly and confirm. Opting out of marketing does not stop transactional messages about work you have actually engaged us for. We do not use or disclose your information for anyone else's direct marketing, and we do not use it for political purposes.

13. Your rights and choices

13.1 Everyone

  • Access (APP 12). Ask for a copy of the personal information we hold about you. We normally respond within 30 days and do not charge for making a request; if a charge for giving access applies it will be reasonable, not excessive, and we will tell you before we incur it.
  • Correction (APP 13). Ask us to correct anything inaccurate, out of date, incomplete, irrelevant or misleading. If we decide not to correct something, we will tell you why in writing and you can ask us to attach a statement noting your view.
  • Deletion. Ask us to delete your enquiry and contact record. We will do so unless we are required to keep it (for example, tax records for a completed engagement, or information needed for a legal claim).
  • Withdraw consent. Change your analytics choice in section 7, or unsubscribe from marketing at any time.

13.2 Additional rights in the EEA and the UK

If the GDPR or UK GDPR applies to you, you also have the right to:

  • restrict processing (Art 18) while a dispute about accuracy or legitimate interests is resolved;
  • data portability (Art 20) — receive the information you gave us in a structured, machine-readable format, or have it sent to another controller;
  • object to processing based on legitimate interests (Art 21), including profiling — and to object to direct marketing at any time, which we will always honour;
  • erasure (Art 17) and rectification (Art 16), as above;
  • not be subject to a solely automated decision with legal or similarly significant effect (Art 22) — we do not make any, see section 6;
  • lodge a complaint with a supervisory authority (Art 77) — see section 16.

13.3 How to make a request

Email [email protected] and tell us what you want. We will verify your identity in proportion to the sensitivity of the request — usually by confirming control of the email address on the record — because we should not hand your information to someone else. We respond within 30 days, and within one month for GDPR requests (extendable by two further months for complex requests, in which case we will tell you within the first month and explain why). Exercising any of these rights is free, and doing so will never be held against you.

14. Data breaches

We maintain a data breach response plan. If an eligible data breach occurs — one likely to result in serious harm — we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, as the Notifiable Data Breaches scheme requires. Where the GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware, and affected individuals without undue delay where the risk to their rights and freedoms is high (Arts 33 and 34).

15. Children

This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

16. Complaints

Tell us first: email [email protected] with "Privacy complaint" in the subject. We will acknowledge within 5 business days, investigate, and give you a written response — normally within 30 days.

If you are not satisfied with our response, you can escalate:

  • Australia — Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001; 1300 363 992; oaic.gov.au.
  • EEA — the supervisory authority in your country of residence, place of work, or where the alleged infringement took place (GDPR Art 77).
  • United Kingdom — Information Commissioner's Office, ico.org.uk.

17. Changes to this policy

We update this policy when what we do changes. The version and effective date at the top always reflect the current text. If a change materially affects how we handle information we already hold about you, we will tell you directly before it takes effect where we have a way to reach you. Continuing to use the site after a change means the updated policy applies to that use.

18. Contact us

Numaya AI — a trading name of Rizvi Group of Companies, ABN 11 622 778 947, Australia.
Email: [email protected]

You can also reach us through the contact page.