Legal
Privacy policy
Last updated 4 July 2026
Who we are
This policy is issued by Neurastruct Pty Ltd (ABN 84 699 674 649) (“Neurastruct,” “we,” “us,” or “our”), an Australian private company based in Melbourne, Australia (P.O. Box 52, Chelsea VIC 3196), accessible at neurastruct.com.au. The Neurastruct business and brand are owned by Harcle Holdings Pty Ltd; Neurastruct Pty Ltd operates the website and services at neurastruct.com.au under licence and is the entity responsible for handling your personal information under this policy.
We are an AI and software consultancy for Australian small and medium businesses. Our services evolve and we onboard new services from time to time as required, but they currently include (without limitation) AI workflow design and automation; custom software and SaaS builds; websites, online bookings, social content, ecommerce and brand identity; and managed hosting and maintenance.
This policy explains what personal information we collect, how we use it, the third-party services we rely on, and your choices. We handle personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
What we collect
We collect personal information only to the extent it is reasonably necessary to operate our website, respond to enquiries, and deliver the services you request.
1. Consultation bookings (via Cal.com)
When you book a consultation through our website, our calendar provider Cal.com collects your name, email address, and any free-text answers you provide to intake questions (such as “what would you like to build?”). Cal.com’s own privacy policy applies to that processing — see cal.com/privacy.
2. Direct correspondence
If you email us at privacy@neurastruct.com.au, we collect the contents of your message and any contact details you provide.
3. Usage and technical data
Our hosting provider (Vercel) records standard request metadata — IP address, user agent, timestamp, and requested URL — for security and abuse-prevention. We also use Vercel Web Analytics and Speed Insights for cookie-free aggregate analytics (pageviews, referrers, event counts, and page-performance metrics), without cookies, session recording, or ad tracking.
An IP address may be personal information where an individual is reasonably identifiable, so we treat request-log data accordingly; only the cookie-free Vercel Web Analytics and Speed Insights data is genuinely aggregate and anonymous.
We give a short collection notice at the point of collection — for example on our booking and contact forms — so you know who is collecting your information and why at the time you provide it.
How we use your information
- To respond to your booking, enquiry, or correspondence.
- To deliver the consultation or services you have requested.
- To maintain the security and integrity of our website and infrastructure.
- To comply with our legal obligations.
We do not sell, rent, or trade your personal information. We do not use your personal information to train AI models — public or otherwise.
Third-party services we use
We use the following providers to run our website, respond to enquiries, and deliver our services. Where a provider is located overseas, your personal information may be disclosed to, or processed in, a country outside Australia. Some providers are used only for specific customer projects, as noted.
- Cal.com (United States) — handles the name, email, and intake free-text you enter when booking a consultation; used for scheduling and booking notifications.
- Resend (United States) — handles your email address and message content; used to send transactional and enquiry-related email on our behalf.
- Sentry (United States) — handles application error and diagnostic data, which may include limited technical request details; used for error monitoring and reliability.
- Vercel (hosting in Sydney, Australia; Vercel Inc. is US-based) — handles standard request metadata (IP address, user agent, timestamp, requested URL) and cookie-free analytics; used for website hosting, content delivery, and analytics.
- VentraIP (Australia) — handles the email and message content forwarded to our mailbox, and our domain records; used for domain registration and email hosting.
- Amazon Web Services — AWS (Sydney,
ap-southeast-2, Australia) — hosts our primary datastore and, by default, user internal business data for the projects we build; used for production infrastructure. - Anthropic (United States) — where a project or feature uses AI, handles the specific data sent for that AI processing; used as a large language model provider, applied and disclosed on a per-project basis.
- Render (United States) — handles application and runtime data for certain projects hosted there; used for cloud application hosting.
- Supabase (region selected per project — Sydney where feasible; provider is US-headquartered) — handles database and backend data for certain projects; used as a managed database and backend.
- Stripe (United States and globally) — handles payment and billing information for paid or ecommerce features; card data is handled directly by Stripe. Used for payment processing.
- Cloudflare (global network; Cloudflare, Inc. is US-based) — handles request metadata routed through its network; used for content delivery, DNS, and security/DDoS protection on certain projects.
Each provider handles only the specific, limited information described for its function. Their respective privacy policies apply to the processing they carry out.
Where your data lives and data residency
Personal information you submit through our website — such as consultation bookings and messages — is handled by the providers listed above; some are located overseas, as indicated. Our own primary datastore is hosted on Amazon Web Services in Sydney (ap-southeast-2), onshore in Australia.
Your internal business data — the operational data inside the projects we build and run for you — is held in AWS Sydney (ap-southeast-2) by default, so it stays in Australia. Where a project cannot use AWS Sydney because of technical or product constraints, any deviation — and the service and region involved — is set out in the terms and conditions for that specific service, product, or custom engagement, and accepted by you before the work proceeds.
By default, personal information submitted through our website and enquiry forms is not passed to any third-party large language model (LLM) provider. Where a specific project or feature uses AI processing that may be performed by an overseas provider (such as Anthropic in the United States), we tell you and identify the country involved for that engagement.
Retention
We retain consultation enquiry data only as long as necessary to respond to your enquiry and any reasonable follow-up. Email correspondence is retained in accordance with normal business record-keeping practice.
Server logs are typically retained for 30 days for security purposes.
Security
We protect personal information using technical and organisational safeguards, including TLS 1.3 in transit, AES-256 at rest, role-scoped database access, and tenant-isolated infrastructure. We periodically review our security posture and update controls as risks evolve.
No system is perfectly secure. If you believe your personal information has been compromised, please email us immediately at privacy@neurastruct.com.au.
Your rights under the Australian Privacy Principles
We offer the following as a matter of good practice, consistent with the APPs. You have the right to:
- Access — request a copy of the personal information we hold about you (APP 12).
- Correct — request that we correct inaccurate or incomplete information (APP 13).
- Anonymity — interact with us anonymously where lawful and practical (APP 2).
- Complain — lodge a complaint about how we handle your personal information (see below).
To exercise any of these rights, email privacy@neurastruct.com.au. We will respond within a reasonable period — typically within 30 days. Where we are unable to grant access or correction, we will explain why and, for a refused correction, note your request on the relevant record if you ask us to.
Cookies
This website does not currently set first-party tracking cookies. The Cal.com booking modal may set its own cookies as required for booking functionality. See cal.com/privacy for details.
Children
This site is not directed to children, and we do not knowingly collect personal information from a child who does not have the capacity to consent. If you believe we have collected such information, please contact us and we will delete it.
International users
Neurastruct is operated from Australia. If you access this site from outside Australia, you understand that your information will be processed in Australia, and by the overseas providers listed above, under the applicable laws.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated via the website or, where appropriate, by direct email.
This policy is incorporated into our Terms of service by reference.
Contact and complaints
For general privacy enquiries, access requests, or correction requests:
- Email: privacy@neurastruct.com.au
- Postal: Neurastruct Pty Ltd, P.O. Box 52, Chelsea VIC 3196, Australia
To lodge a formal privacy complaint, email complaints@neurastruct.com.au. We will acknowledge complaints within 7 business days and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner: oaic.gov.au.
This policy was prepared in good faith with reference to the Australian Privacy Principles. It is provided for transparency and is not a substitute for legal advice. Neurastruct Pty Ltd will update this document as our processing practices evolve.