This policy explains what personal information bynoon collects, why we collect it, where it goes, how we keep it safe and what you can do about it. It is written to meet the Australian Privacy Principles in the Privacy Act 1988 (Cth), and in plain language rather than legal boilerplate, because you should actually be able to read it.
who we are
bynoon is an AI automation and web development business operated by Joshua McCann (ABN 49 142 909 894), based in New South Wales, Australia. In this policy "we", "us", "our" and "bynoon" mean that business. We are the entity responsible for the personal information described here.
Privacy questions, access requests and complaints all go to the same place: josh@bynoon.ai.
what we collect
We only collect what you give us, or what we need to deliver the work. We do not buy contact lists and we do not scrape personal information.
when you enquire
- your name
- your business name
- your email address and phone number
- your suburb, on the social media management enquiry form
- what you want to automate or build, and which service you are interested in
- whether you ticked the box to receive marketing emails
- the page you submitted from, the date and time, and the country your request came from
when you become a client
- billing details, business address and ABN
- the contact details of staff we need to work with
- access to the systems you ask us to automate, such as your CRM, inbox, phone system or calendar
- records of the work, including quotes, invoices, scopes and correspondence
Working inside your systems means we may come into contact with personal information about your customers. We treat that as yours, not ours. We only handle it to do the job you engaged us for, we do not use it for anything else, and it is covered by the confidentiality obligations in our terms of service.
when you pay us
Payments are processed by third party payment providers. Your card number, CVC and full card details are entered directly with that provider and are never sent to us, seen by us or stored on our systems. What we receive back is the fact a payment succeeded or failed, the amount, the date and a masked reference such as the last four digits.
sensitive information
We do not seek sensitive information as defined by the Privacy Act, which includes health, biometric, racial, political, religious and sexual orientation information. If your business handles that kind of information and the work requires us to be near it, for example a clinic automating patient bookings, we will agree the handling rules with you in writing before we begin, and we will only ever access the minimum needed.
automated decision making and AI
We should be upfront about this, because it is the business we are in. From 10 December 2026 Australian privacy law requires businesses to disclose where computer programs make, or substantially help make, decisions that significantly affect someone.
On this website, our automated systems use your enquiry details to:
- route your enquiry to the right person and create your contact record
- send you an acknowledgement and notify us to call you
- add you to a marketing list, but only if you ticked the consent box
None of that makes a decision that significantly affects your rights. No automated system decides whether we will work with you, what we charge you, or refuses you a service. A person reads every enquiry and a person decides.
In work we build for clients, we may build systems that use AI to draft replies, qualify enquiries or schedule work. Where a system we build could make a decision that significantly affects an individual, we design a human review step into it and we tell the client they need to disclose it in their own privacy policy. If you are ever dealt with by one of our systems and want a human instead, email us and you will get one.
what we do not collect
This website has no analytics, no advertising pixels and no tracking cookies. We do not follow you around the internet and we do not build a profile on you. If you never fill in a form, we never receive anything about you at all.
dealing with us anonymously
You can browse this entire website without identifying yourself. You can also call or email to ask general questions without giving your real name. We do need real details to quote, contract, invoice or do the work, because we cannot deliver a service to an anonymous person.
why we collect it
- to reply to your enquiry and talk to you about working together
- to prepare quotes and proposals, and to book and prepare for calls
- to deliver, support and improve the services you engage us for
- to invoice you and collect payment
- to meet our tax, accounting and other legal obligations
- to send marketing emails, but only if you gave us consent
marketing and consent
Ticking the marketing box is entirely optional. If you leave it unticked we will still reply to your enquiry and still work with you, we just will not add you to the mailing list. We never make marketing consent a condition of doing business.
Every marketing email carries a working unsubscribe link and we act on it immediately, as required by the Spam Act 2003 (Cth). You can also email josh@bynoon.ai and ask to be removed.
Replies to your own enquiry, quotes, invoices, and messages about work in progress are not marketing. You will keep receiving those while we are dealing with each other, whether or not you opted in.
who we share it with
We do not sell your personal information, we do not trade in personal information, and we do not share it with anyone for their own marketing. We do use service providers to run the business. They act on our instructions and are not permitted to use your information for their own purposes.
- Cloudflare, which hosts this website and stores enquiry submissions
- GoHighLevel, our CRM, where your contact record lives
- Google Workspace, for email, documents, calendars and our internal lead log
- Microsoft 365, for email
- Telegram, which notifies us that a new enquiry has arrived
- Payment providers, who process your payments and hold your card details, not us
- Our accountant and professional advisers, where needed
- AI and automation providers, where a tool we run uses them to process content
We may also disclose personal information where the law requires it, for example to a court, a regulator or a law enforcement agency acting within its powers.
overseas disclosure
Several providers above are based overseas, mainly in the United States, or store data on servers outside Australia. By dealing with us you accept that your information may be stored and processed overseas, where privacy laws differ from Australian law and where we cannot guarantee the overseas recipient will handle it in a way that meets the Australian Privacy Principles. We choose established providers that publish their own security and privacy commitments, and we only send them what they need.
how long we keep it
- Enquiries that go nowhere: kept while we are in contact and for a reasonable period after, so we have context if you come back to us.
- Client records: kept for the life of the engagement.
- Financial records: kept for at least five years after the transaction, because Australian tax law requires it.
- Access credentials: revoked and deleted at the end of an engagement.
When we no longer need information and are not required to keep it, we delete it or de-identify it.
how we keep it safe
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. In practice that means encrypted connections, access controlled accounts, multi factor authentication where the provider supports it, secrets stored in encrypted secret managers rather than in code or documents, and access limited to the people who need it.
No system is perfectly secure and we will not pretend otherwise. What we can promise is that we only keep what we actually need, and that we tell you the truth if something goes wrong.
if there is a data breach
If a data breach occurs that is likely to result in serious harm, we will contain and assess it, notify affected individuals, and notify the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved and what you should do about it.
your rights
You can ask us to:
- tell you what personal information we hold about you and give you a copy
- correct anything inaccurate, out of date, incomplete or misleading
- delete information we are not required to keep
- stop sending you marketing
- explain how an automated system we run has handled your information
Email josh@bynoon.ai. We will confirm who you are, respond within 30 days, and we do not charge for it. If we refuse a request we will tell you why in writing and how to complain about it.
complaints
If you think we have mishandled your personal information, tell us first at josh@bynoon.ai. We will acknowledge it promptly and give you a written answer within 30 days.
If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or in writing to GPO Box 5288, Sydney NSW 2001.
cookies
We do not set tracking or advertising cookies. Any storage this site uses is strictly functional, for example remembering that you already submitted a form during your visit. Third party services we link to, such as our social profiles, set their own cookies under their own policies once you go there.
children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, tell us and we will delete it.
changes to this policy
If we change how we handle personal information we will update this page and change the date at the top. Where a change is significant and you are on our list, we will tell you directly. Australian privacy law is changing, including the removal of the small business exemption from 10 December 2026, and we will keep this policy current as those obligations take effect.
contact
bynoon
Joshua McCann, ABN 49 142 909 894
New South Wales, Australia
josh@bynoon.ai