Skip to main content
Neurastruct

Legal

Privacy policy

Last updated 29 September 2026

Who we are

This policy is issued by Neurastruct Pty Ltd (ABN 84 699 674 649) (“Neurastruct,” “we,” “us,” or “our”), an Australian private company based in Melbourne, Australia (P.O. Box 52, Chelsea VIC 3196), accessible at neurastruct.com.au. The Neurastruct business and brand are owned by Harcle Holdings Pty Ltd; Neurastruct Pty Ltd operates the website and services at neurastruct.com.au under licence and is the entity responsible for handling your personal information under this policy.

We are an AI and software consultancy for Australian small and medium businesses. Our services evolve and we onboard new services from time to time as required, but they currently include (without limitation) AI workflow design and automation; custom software and SaaS builds; websites, online bookings, social content, ecommerce and brand identity; and managed hosting and maintenance.

This policy explains what personal information we collect, how we use it, the third-party services we rely on, and your choices. We handle personal information consistently with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Neurastruct complies with the Australian Privacy Principles voluntarily, whether or not the small-business exemption applies.

What we collect

We collect personal information only to the extent it is reasonably necessary to operate our website, respond to enquiries, and deliver the services you request.

1. Consultation bookings (via zCal)

When you book a consultation through our website, our calendar provider zCal collects your name, email address, and any free-text answers you provide to intake questions (such as “what would you like to build?”). zCal’s own privacy policy applies to that processing — see zcal.co/privacy.

2. Direct correspondence

If you email us at privacy@neurastruct.com.au, we collect the contents of your message and any contact details you provide.

3. Usage and technical data

Our hosting provider (Vercel) records standard request metadata — IP address, user agent, timestamp, and requested URL — for security and abuse-prevention. We also use Vercel Web Analytics and Speed Insights for cookie-free aggregate analytics (pageviews, referrers, event counts, and page-performance metrics), without cookies, session recording, or ad tracking.

Separately, we run the Google Ads tag (gtag.js) across this website for advertising measurement — attributing enquiries to the ads and campaigns that produced them — and to build remarketing audiences. Unlike the Vercel analytics above, it does set a first-party cookie, described under Cookies below. It does not run on our gated sandbox demo environment.

An IP address may be personal information where an individual is reasonably identifiable, so we treat request-log data accordingly; only the cookie-free Vercel Web Analytics and Speed Insights data is genuinely aggregate and anonymous.

4. Our social media pages

We operate company pages on social media platforms — currently LinkedIn, Facebook, Instagram and X — and we publish our own marketing content to some of them. We do not send your personal information to those platforms, and this website carries no social media tracking pixel of any kind: no LinkedIn Insight Tag, and no Meta pixel. The links to our pages in the site footer are ordinary links; following one takes you to that platform, where that platform’s own privacy policy applies.

We do not collect personal information about people who view, react to or comment on those posts. Where we measure how our own content performed, we receive aggregate counts only — such as how many impressions, reactions or comments one of our posts received, and our own follower numbers — never the identity of anyone who engaged. We read and reply to comments on the platforms themselves, and we do not copy that activity into our own systems.

5. Client invoicing (via Xero)

When you engage Neurastruct, we record your business name, your contact details, and the details of the work and payments, so that we can issue tax invoices and keep our accounts. We keep these records in Xero, our accounting software. Xero’s own privacy notice applies to that processing — see xero.com/au/legal/privacy.

If you pay us on a payment plan, Stripe also holds your billing details, the card or bank account you pay with, and the plan’s invoices. We keep a copy of the plan and its invoices in our own systems, but we never see your full card or account number.

We give a short collection notice at the point of collection — for example on our booking and contact forms — so you know who is collecting your information and why at the time you provide it.

How we use your information

  • To respond to your booking, enquiry, or correspondence.
  • To deliver the consultation or services you have requested.
  • To maintain the security and integrity of our website and infrastructure.
  • To comply with our legal obligations.

We do not sell, rent, or trade your personal information. We do not use your personal information to train AI models — public or otherwise.

Third-party services we use

We use the following providers to run our website, respond to enquiries, and deliver our services. Where a provider is located overseas, your personal information may be disclosed to, or processed in, a country outside Australia. Specifically: the AI chat assistant on this website uses a model provided by Anthropic, and its inference runs in the United States; our transactional email is sent through Resend, which runs on Amazon Web Services in Tokyo, Japan, and handles delivery and bounces; our /sandbox demo runs on AWS Bedrock in Sydney, Australia; if you choose to make a live image in the demo, a short scene description and a line from the post are sent to AWS Bedrock in the United States (Oregon) to create it; our accounting records, including the invoices we issue to clients, are kept in Xero, which may process them in Australia, New Zealand and the United States; if you pay us on a payment plan, your billing details and the plan’s invoices are also held by Stripe, which may process them in the United States and other countries; and your internal business data — the operational data inside the projects we build and run for you — is hosted in AWS Sydney (ap-southeast-2) by default, so it stays in Australia. Some providers are used only for specific customer projects, as noted.

  • zCal (United States) — handles the name, email, and intake free-text you enter when booking a consultation; used for scheduling and booking notifications.
  • Google (United States) — handles the pageview and advertising-identifier data collected by the Google Ads tag on this website; used for advertising measurement, conversion attribution, and remarketing audiences.
  • Resend (United States; our sending region is Tokyo, Japan) — handles your email address and message content; the internal notification email for every enquiry form also includes your IP address, and, where you submit the chat assistant’s callback or contact form, a short excerpt of your recent chat messages, so whoever picks it up has context; used to send transactional and enquiry-related email on our behalf.
  • Sentry (United States) — handles application error and diagnostic data, which may include limited technical request details; used for error monitoring and reliability.
  • Vercel (hosting in Sydney, Australia; Vercel Inc. is US-based) — handles standard request metadata (IP address, user agent, timestamp, requested URL) and cookie-free analytics; used for website hosting, content delivery, and analytics.
  • Microsoft 365 (data stored in Australia; Microsoft is US-based) — handles the email and message content sent to and from our mailbox, including the internal notification email for each enquiry, and our calendar; used for our business email and calendar.
  • VentraIP (Australia) — handles our domain records, and holds the email our old mailbox received before 28 September 2026 until that mailbox is closed; used for domain registration and DNS hosting.
  • Alltel (Australia) — handles the phone number and call details (such as the time and length of the call) of calls to our 1300 number, which it connects to us; used for our business phone line.
  • Amazon Web Services — AWS (Sydney, ap-southeast-2, Australia, and Oregon, United States, for optional live sandbox images) — provides the cloud infrastructure our database provider (Neon, below) runs on, and, by default, hosts user internal business data for the projects we build; used for production infrastructure.
  • Neon (Sydney, ap-southeast-2, on Amazon Web Services infrastructure) — hosts our primary database, including this website’s own operational data; used as our managed Postgres database provider.
  • Anthropic (United States) — handles the text of messages you send through the AI chat assistant on this website, and, where a client project or feature uses AI, the specific data sent for that processing; used as a large language model provider, applied and disclosed on a per-project or per-feature basis.
  • Render (United States) — handles application and runtime data for certain projects hosted there; used for cloud application hosting.
  • Supabase (region selected per project — Sydney where feasible; provider is US-headquartered) — handles database and backend data for certain projects; used as a managed database and backend.
  • Stripe (United States and globally) — handles card and bank payments and invoices for clients who pay us on a payment plan, and payment information for client projects that take payments. Card and bank details go directly to Stripe; we never see your full card or account number. Used for payment processing and invoicing.
  • Xero (Australia, New Zealand and the United States; Xero is headquartered in New Zealand) — handles our clients’ business names, contact details, and the invoices and payment records we keep for them; used for accounting and invoicing.
  • Cloudflare (global network; Cloudflare, Inc. is US-based) — handles request metadata routed through its network; used for content delivery, DNS, and security/DDoS protection on certain projects.

Each provider handles only the specific, limited information described for its function. Their respective privacy policies apply to the processing they carry out.

Where your data lives and data residency

Personal information you submit through our website — such as consultation bookings and messages — is handled by the providers listed above; some are located overseas, as indicated. Our own primary datastore is provided by Neon, running on Amazon Web Services infrastructure in Sydney (ap-southeast-2), onshore in Australia.

Your internal business data — the operational data inside the projects we build and run for you — is held in AWS Sydney (ap-southeast-2) by default, so it stays in Australia. Where a project cannot use AWS Sydney because of technical or product constraints, any deviation — and the service and region involved — is set out in the terms and conditions for that specific service, product, or custom engagement, and accepted by you before the work proceeds.

This website includes an AI chat assistant, labelled as AI in its interface. Messages you type into it are sent to Anthropic (United States) for processing. If you use the chat assistant’s own callback or contact form, your name, email, and phone number follow the same path as our other enquiry forms — direct to our database and to Resend — and are not sent to Anthropic; the internal notification email that generates does include a short excerpt of your recent chat messages, so whoever picks it up has context. Anything typed into the chat conversation itself, including any contact details a visitor chooses to include in a message, is chat text, and is processed by Anthropic like the rest of that conversation.

Outside the chat assistant, personal information submitted through our website and enquiry forms is not passed to any third-party large language model (LLM) provider by default. Where a specific client project or feature uses AI processing that may be performed by an overseas provider (such as Anthropic in the United States), we tell you and identify the country involved for that engagement.

Retention

We retain consultation enquiry data only as long as necessary to respond to your enquiry and any reasonable follow-up. Email correspondence is retained in accordance with normal business record-keeping practice.

We keep enquiry and consultation records for 24 months and chat conversations for 90 days after their last activity, after which they are deleted automatically. Encrypted backups are kept for 400 days.

Copies of emails our sandbox sends you are kept for 90 days, then deleted automatically.

Sample data you work with in the sandbox demos, including anything you paste or upload into them, is deleted when you exit the sandbox, and automatically within 24 hours.

Server logs are typically retained for 30 days for security purposes.

We keep invoices and other accounting records for 7 years, as Australian company law requires.

Chat conversations with our AI assistant — the messages exchanged — are retained for quality review, so we can check the assistant is describing our services accurately, and to support any enquiry you submit through it.

Security

We protect personal information using technical and organisational safeguards, including TLS 1.3 in transit, AES-256 at rest, role-scoped database access, and tenant-isolated infrastructure. We periodically review our security posture and update controls as risks evolve.

No system is perfectly secure. If you believe your personal information has been compromised, please email us immediately at privacy@neurastruct.com.au.

Your rights under the Australian Privacy Principles

We offer the following as a matter of good practice, consistent with the APPs. You have the right to:

  • Access — request a copy of the personal information we hold about you (APP 12).
  • Correct — request that we correct inaccurate or incomplete information (APP 13).
  • Anonymity — interact with us anonymously where lawful and practical (APP 2).
  • Complain — lodge a complaint about how we handle your personal information (see below).

To exercise any of these rights, email privacy@neurastruct.com.au. We will respond within a reasonable period — typically within 30 days. Where we are unable to grant access or correction, we will explain why and, for a refused correction, note your request on the relevant record if you ask us to.

Cookies

This website sets one first-party advertising cookie, _gcl_au, placed by the Google Ads tag. It records that a visit arrived from a Google ad so an enquiry can be attributed to the campaign that produced it, and it expires by itself. We set no other first-party tracking cookies: Vercel Web Analytics and Speed Insights remain cookie-free, our AI chat assistant sets no cookies or browser storage of its own, and the gated sandbox demo carries no advertising tag — or chat assistant — at all. The zCal booking embed on our booking page may set its own cookies as required for booking functionality. See zcal.co/privacy and policies.google.com for details.

Children

This site is not directed to children, and we do not knowingly collect personal information from a child who does not have the capacity to consent. If you believe we have collected such information, please contact us and we will delete it.

International users

Neurastruct is operated from Australia. If you access this site from outside Australia, you understand that your information will be processed in Australia, and by the overseas providers listed above, under the applicable laws.

Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be communicated via the website or, where appropriate, by direct email.

This policy is incorporated into our Terms of service by reference.

Contact and complaints

For general privacy enquiries, access requests, or correction requests:

To lodge a formal privacy complaint, email complaints@neurastruct.com.au. We will acknowledge complaints within 7 business days and aim to resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner: oaic.gov.au.

This policy was prepared in good faith with reference to the Australian Privacy Principles. It is provided for transparency and is not a substitute for legal advice. Neurastruct Pty Ltd will update this document as our processing practices evolve.