Scope
This policy explains how Avi Santoso Pty Ltd handles personal information connected with our websites, subdomains, sales pages, forms, checkouts, products, services, delivery, support, marketing, research, product development, and related business operations. It applies across the Avi Santoso business unless a specific product or service displays a separate privacy policy.
We handle personal information in line with this policy and any privacy law that applies to us. This policy describes categories of providers and technology because the specific services we use may change as the business develops.
Who handles your information
Avi Santoso Pty Ltd, ABN 48 691 842 074, is responsible for the websites, offers, products, services, and fulfilment covered by this policy. Our service providers may include website and cloud hosts, payment processors, email and delivery services, analytics services, advertising platforms, customer support tools, AI and data-processing services, software and integration providers, security services, contractors, and professional advisers.
Current examples include Vercel and Cloudflare for website hosting and security, Stripe for payment processing, and Resend for contact and transactional email. These examples are not a complete or permanent list. Each provider handles information under its own privacy terms and may use its own subprocessors.
Information we may collect
- Identity and business information, including your name, business name, role, contact details, and account details.
- Enquiry and support information, including the problem you describe, its effect on the business, what you have tried, and any later correspondence.
- Order information, including the product or service selected, amount, currency, payment status, receipt reference, refund status, and checkout time.
- Technical information, including IP address, browser type, device information, referring page, page requests, security logs, identifiers, and approximate location derived from an IP address.
- Website and campaign information, including pages viewed, links followed, forms or checkout steps viewed or completed, preferences, attribution data, and validation errors.
- Product and service information, including access records, downloads, feature use, licence records, project material, feedback, and information needed to deliver or improve the work.
Our websites do not collect or store full card details. The payment provider shown at checkout collects and processes the payment information required to complete a purchase.
How information is collected
We collect information directly from you through websites, forms, checkout, email, meetings, product use, support requests, and other business interactions. We may also receive information from payment providers, hosting and security services, analytics and advertising platforms, referral sources, public sources, integration partners, and other people or organisations involved in delivering a product or service.
Browser storage
Our websites, forms, and checkouts may store details such as your name, email address, business name, role, preferences, and checkout progress in cookies or local storage on your device. This can keep a session working, restore a form or checkout step, remember a choice, measure use, or protect the website from abuse. You can remove this information by clearing site data in your browser. People with access to the same browser profile may be able to see restored details.
How information is used
- Respond to enquiries and assess whether we can help.
- Process and record purchases, subscriptions, bookings, and service requests.
- Deliver product access, consulting, implementation work, and customer support.
- Operate accounts, integrations, websites, forms, and checkout processes.
- Handle refunds, disputes, fraud checks, tax, accounting, and legal obligations.
- Personalise, measure, test, and improve offers, products, services, and campaigns.
- Organise, classify, enrich, analyse, summarise, or transform information to support research, administration, product development, service delivery, and business decisions.
- Protect our systems, buyers, clients, and business from abuse, fraud, and security threats.
- Enforce product licences, contracts, and other legal rights.
- Send service messages about an enquiry, order, access, project, product update, policy change, or support request.
Automated and AI-assisted processing
We may use rules, software, AI systems, or other automated tools to route enquiries, organise records, analyse use, detect abuse, support decisions, create or review work, personalise communications, and help deliver products or services. A person may review or change an automated output where appropriate. If we arrange for an automated system to make a decision that could significantly affect a person's rights or interests, we will provide any additional information or notice required by applicable law.
Direct marketing
We may use contact, transaction, website, campaign, and preference information to send or measure marketing where you have consented or where applicable law otherwise permits. We may use email, advertising platforms, or other communication channels. You may unsubscribe using the link or method provided with the message. Service messages needed to respond to a request, complete a purchase, deliver access, or administer an existing product or service are not marketing messages.
Disclosure
We may disclose relevant information to providers that help us operate the business and deliver our offers. These may include payment processors, website and cloud hosts, security services, email and delivery providers, analytics and advertising platforms, customer relationship and support tools, AI and data-processing services, software and integration providers, contractors, professional advisers, and government or regulatory bodies.
We may also disclose information where required or authorised by law, to protect legal rights or safety, to investigate fraud or misuse, or as part of a genuine sale, restructure, financing, or transfer of all or part of the business. We do not sell full payment-card details.
Overseas processing
Our providers and their subprocessors may process or store information outside Australia. Likely locations include the United States and other countries where global cloud, payment, email, analytics, advertising, support, or software providers operate. Providers and processing locations can change. Privacy protections in those countries may differ from Australian law.
Cookies, analytics, and advertising
Our websites may use necessary cookies, local storage, analytics, conversion tracking, advertising pixels, session tools, or similar technologies to operate forms and checkout, remember preferences, measure use, attribute campaigns, improve offers, prevent fraud, and support security. Our providers may also use cookies, identifiers, or technical data under their own terms. Where consent is required for a technology, we will request it before using that technology.
Retention
Retention periods depend on the type of information, the service involved, provider settings, and our legal and operational needs. We keep enquiry, transaction, project, support, refund, fraud, licence, tax, and legal records only for as long as reasonably required for the purposes described above or by law. When information is no longer required, we may delete it or remove identifying details.
Security
We use reasonable administrative, technical, and service-provider controls to protect information. No internet transmission, browser storage, or online service is completely secure. You should use a secure device and avoid entering passwords, card numbers, access tokens, or other credentials into fields that do not request them.
Access and correction
You may ask whether we hold personal information about you and request access to or correction of that information. We may need to verify your identity and may refuse or limit a request where permitted by law. If we refuse a request, we will explain the reason where required.
Privacy complaints
You may make a privacy complaint through our contact form or by replying to a message or purchase receipt from us. Describe the concern and include enough information for us to identify the relevant interaction. We will review the complaint and aim to respond within 30 days. If applicable privacy law gives you a further complaint right, you may contact the Office of the Australian Information Commissioner after first giving us a reasonable opportunity to respond.
Children
Our offers are intended for adults and businesses. We do not knowingly seek personal information from children under 18.
Changes to this policy
We may update this policy when our business, websites, subdomains, products, services, providers, legal requirements, or data practices change. The effective date at the top identifies the current version. Material changes apply from the date the updated policy is published unless another date is stated.
Contact
For a privacy, access, correction, deletion, or complaint request, use our contact form or reply to a message or purchase receipt from us. Include enough information to identify the relevant interaction. Do not include card numbers, passwords, access tokens, or other credentials.