Privacy Policy
Effective date: 01 July 2026
Last updated: 01 July 2026
1. About NeptoLabs
NeptoLabs ("NeptoLabs", "we", "us" or "our") is a sole-trader business based in Western Australia that provides AI automation, workflow integration, consulting and related services, primarily to HVAC, plumbing and other trade businesses.
This Privacy Policy explains how we collect, hold, use and disclose personal information when you:
- visit www.neptolabs.com or www.neptolabs.com.au (together, the "Websites");
- contact us, request a proposal or become a client;
- use an automation, chatbot, integration, form or other service that we operate; or
- otherwise interact with us.
We aim to handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. Some small businesses may be exempt from the Privacy Act. However, we intend to follow the privacy practices described in this Policy regardless of whether an exemption applies.
In this Policy, "personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
This Policy should be read together with our Terms of Service at https://www.neptolabs.com/terms-of-service, which govern the services themselves. If there is a conflict between this Policy and a Service Order about how personal information is handled in a particular engagement, the Service Order prevails to the extent of the inconsistency.
2. Information we collect
Depending on how you interact with us, we may collect:
- name, email address and phone number;
- business name, ABN, trade type, company address and other business details;
- messages, enquiries, support requests and other correspondence;
- documents and files you or an authorised user upload, including images and PDF files;
- project requirements, workflow details, job information and service records;
- account, transaction, invoice and billing information. Payment card details are generally processed by our payment provider rather than stored directly by us;
- technical and usage information, such as IP address, browser type, device information, pages viewed, referring URL, timestamps, cookie identifiers and interaction logs; and
- information generated by or submitted through AI-enabled tools, automations, integrations and connected business systems.
Please do not provide sensitive information, or personal information about another person, unless it is necessary, lawful and you are authorised to do so. Uploaded images, documents, job notes and messages may contain personal or sensitive information. You are responsible for reviewing material before submitting it and for obtaining any notices, permissions or consents required from your customers, workers or other individuals.
3. How we collect information
We may collect information:
- directly from you through the Websites, email, telephone, meetings, forms, contracts and service interactions;
- from your employees, contractors, customers or authorised representatives;
- through software integrations, APIs, webhooks, connected accounts and automation platforms that you authorise;
- automatically through cookies, logs and similar technologies; and
- from service providers, referral partners and publicly available business sources where lawful and appropriate.
If you do not provide information we reasonably need, we may be unable to respond to your enquiry, provide a quote, configure an automation or deliver some or all of our services.
4. How we use information
We may collect, hold, use and disclose information to:
- respond to enquiries and provide proposals;
- set up, operate, monitor and improve our services, automations and integrations;
- provide customer support and troubleshoot technical issues;
- manage contracts, accounts, billing, payments and debt recovery;
- communicate service notices and, where permitted, marketing messages;
- protect our systems, investigate misuse and prevent fraud or security incidents;
- meet legal, regulatory, insurance, accounting and record-keeping obligations;
- analyse service performance and develop new features; and
- exercise or defend legal rights.
We may use information for another purpose where you have consented, where you would reasonably expect the use and it is related to the original purpose, or where otherwise authorised or required by law.
5. AI systems and service improvement
Our services may use artificial intelligence to process content, classify requests, draft responses, extract information, route work, support customer service or perform other agreed automations. AI-generated outputs may be inaccurate and should be reviewed by an appropriately qualified person before being relied on for business, safety, compliance, financial or technical decisions.
We may use de-identified, aggregated or non-personal business data to evaluate, improve and develop our services and AI-enabled workflows.
We will not use identifiable personal information, sensitive information, client confidential information, or the contents of client messages and uploaded files to train or fine-tune our own or a third party's general-purpose AI model unless:
- the relevant client and, where required, the affected individual has given specific and informed consent;
- the proposed use is documented, reasonably necessary and permitted by law; and
- appropriate safeguards, access controls, retention limits and opt-out or withdrawal arrangements are in place.
Where information is sent to an AI provider solely to deliver a contracted service, the provider may process that information on our behalf under its applicable service terms and data controls. Available controls and retention settings may vary by provider and product. We seek to use business or API offerings with appropriate privacy and security settings where reasonably practicable.
You may contact us to ask whether your information is used in an AI-enabled workflow or to withdraw a consent that applies to future AI training. Withdrawal will not affect processing that was lawful before withdrawal and may not remove information already incorporated into a model where removal is technically impracticable, unless applicable law requires otherwise. We will explain any material limitation when seeking consent.
6. Third-party providers and disclosures
We may disclose or provide access to information to service providers where reasonably necessary to operate our business or deliver services. Depending on the client solution, these providers may include:
- AI and cloud providers, including OpenAI, Anthropic, Google and Microsoft;
- communications providers, including Twilio;
- workflow and automation platforms, including n8n, Zapier and Make;
- payment providers, including Stripe;
- field-service and trade-business platforms, including ServiceM8, Simpro and AroFlo;
- hosting, analytics, security, accounting, professional advisory and support providers; and
- a purchaser, adviser or other party involved in a proposed or completed sale, merger or restructuring of our business.
We do not necessarily use every provider listed above for every client. Each provider handles information under its own terms, privacy policy, product configuration and data location arrangements. When a client directs us to connect a third-party account or platform, the client's agreement with that provider may also apply.
We may also disclose information where required or authorised by law, to respond to lawful requests, to protect a person's safety, or to establish, exercise or defend legal claims.
We do not sell personal information.
7. Overseas processing and storage
Some providers may store or process information outside Australia, including in the United States and other countries in which they or their subcontractors operate. The exact locations may vary according to the provider, product, client configuration and data-routing options.
Where required by applicable privacy law, we will take reasonable steps before disclosing personal information overseas and will consider the provider's contractual, privacy and security safeguards. Overseas recipients may be subject to privacy laws that differ from Australian law.
Contact us if you require information about the likely countries relevant to a particular service configuration.
8. Data retention and deletion
We generally retain personal information for the period reasonably necessary to provide services, manage our relationship, resolve disputes and meet legal, tax, accounting, insurance and security obligations.
As a default operational period, we may retain client and user records containing personal information for up to five years after the relevant interaction or the end of the client relationship. Some records may be retained for a shorter period, commonly three years. We may retain information for longer where required or permitted by law, necessary for legal claims, subject to a preservation request, or contained in secure backups that are scheduled for deletion in the ordinary course.
When information is no longer required, we take reasonable steps to delete it securely or de-identify it. De-identified information that can no longer reasonably identify an individual may be retained for analytics, service improvement and AI development.
A client may request earlier deletion of personal information. We will action a valid request where reasonably practicable and legally permitted, but may retain information where we have a lawful need or obligation to do so. Deletion from backups may occur through the normal backup rotation cycle.
9. Security
We use reasonable administrative, technical and physical safeguards appropriate to the nature of the information and the risks involved. These may include encryption in transit and, where supported by the relevant system, encryption at rest; access controls; authentication; least-privilege permissions; logging; backups; software updates; provider risk review; and incident-response processes.
No internet transmission, cloud platform or storage system is completely secure. We cannot guarantee absolute security. If you believe information has been accessed, disclosed or lost without authorisation, contact us immediately using the details below.
Where applicable, we will assess suspected data breaches and comply with the Notifiable Data Breaches scheme and other legal notification requirements.
10. Cookies and similar technologies
The Websites and our service providers may use cookies, pixels, local storage and similar technologies to:
- keep the Websites functioning and secure;
- remember settings and preferences;
- understand website traffic and usage;
- measure performance and diagnose errors; and
- support communications or marketing where permitted.
Cookies may be session cookies, which expire when you close your browser, or persistent cookies, which remain until they expire or are deleted. Some cookies are set by third parties that provide hosting, analytics, embedded content or other functionality.
You can control or delete cookies through your browser settings. Blocking certain cookies may affect Website functionality. Where required, we will request consent before using non-essential cookies. You can also use any cookie settings tool made available on the Websites.
11. Direct marketing
We may send service updates or marketing communications where permitted by law. You can opt out of marketing emails by using the unsubscribe link or contacting us. We may still send non-marketing messages needed to manage an active service, account, transaction or legal obligation.
12. Access, correction and deletion requests
Subject to applicable law, you may ask us to:
- confirm whether we hold personal information about you;
- provide access to that information;
- correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
- delete personal information we no longer need or are not legally required to retain;
- withdraw a consent for future processing; or
- explain how your information is used in an AI-enabled service.
To protect privacy and security, we may need to verify your identity and authority before acting on a request. We will respond within a reasonable period. If we cannot fulfil a request, we will explain why where required by law.
13. Client responsibilities
Our business clients may provide us with personal information about their customers, employees, contractors and other individuals. Unless agreed otherwise in writing, the client is responsible for:
- having a lawful basis to collect and provide that information;
- giving required privacy notices and obtaining required consents;
- limiting information to what is necessary for the service;
- configuring connected systems and user permissions appropriately; and
- responding to privacy requests relating to information the client controls.
For some services, NeptoLabs acts primarily as a service provider processing information on the client's instructions. The client remains responsible for its own privacy policy and compliance obligations.
14. Complaints
If you have a privacy concern or complaint, contact us using the details below and include enough information for us to investigate. We will acknowledge the complaint and aim to respond within 30 days.
If you are not satisfied with our response and the Privacy Act 1988 (Cth) applies, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.
15. Third-party links
The Websites and our services may link to third-party websites or services. We are not responsible for the privacy practices of third parties acting independently of us. Review their privacy policies before providing information.
16. Changes to this Policy
We may update this Privacy Policy to reflect changes to our services, providers, practices or legal obligations. The current version will be published on the Websites with its effective date. If a change materially affects how we use information already collected, we will take reasonable steps to provide notice and obtain consent where required.
17. Contact us
Privacy contact: Sandeep Dudhraj / NeptoLabs
Business structure: Sole trader
ABN: 59182383443
Email: sandeep.dudhraj@neptolabs.com
Phone: +61 426163951
Postal address: 149 Manning Rd, Bentley, WA, 6102, Australia
Reference guidance
This template was informed by the following Australian regulatory guidance:
- Office of the Australian Information Commissioner, Australian Privacy Principles
- Office of the Australian Information Commissioner, Small business
- Office of the Australian Information Commissioner, Guidance on privacy and the use of commercially available AI products
- Office of the Australian Information Commissioner, Guidance on privacy and developing and training generative AI models
- Office of the Australian Information Commissioner, Sending personal information overseas
