Privacy notice
Privacy notice
How UY4X PTY LTD handles personal information across uy4x.com.au, agentds.ai and AgentDS. Written to be read: short sections, no surprises.
Part A · Websites, forms and everyone who contacts us
About this notice
This privacy notice is issued by UY4X PTY LTD (ABN 18 702 107 846, ACN 702 107 846) of Unit 1, 45 Alison Road, Wyong NSW 2259, Australia ("UY4X", "we", "us"). It covers uy4x.com.au, agentds.ai, our enquiry forms and the AgentDS software. Contact us about privacy at usman@uy4x.com.au.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). We do this voluntarily and in full, even where the small-business exemption might otherwise apply to us, because the businesses that use AgentDS are trusted with sensitive client information and expect the same standard from us.
Two roles: your information and your clients' information
We handle personal information in two different roles.
- For people who contact us, use our websites or hold an AgentDS account, we collect the information ourselves and decide how it is used. In this role we are the collector and are responsible to you directly.
- For the client records that an agency, law firm or other business enters into AgentDS, that business collects the information and decides how it is used. We hold and process it only on the business's instructions as its service provider. If you are a client of a business that uses AgentDS, that business is your first point of contact for access, correction and questions about your information, and we will help it respond.
Part B of this notice explains the second role in detail.
Information we collect from you
What we collect depends on how you deal with us.
- Contact, feedback and demo requests: your name, agency or business name, email address, the topic you choose, your message (up to 500 characters) and, if you ask for product news, your consent to receive it. We ask you not to include client names, visa details or documents.
- AI Strategy for SMEs and managed website or app enquiries: your name, email address, the service you are interested in and your message, plus your business name, phone number and budget range if you give them.
- Retail-agent expressions of interest: contact name, email address, business name, suburb or town and state or territory, plus business phone, business type, store count and a short message if you give them.
- Bank4X interest register: your name, email address, phone number and your consent to be told when account availability changes.
- ChatDS launch list: your name, email address and your consent to be notified when ChatDS is ready.
- AgentDS accounts: see Part B.
Every form has a required-fields minimum. If you would rather not use a form, you can email us directly. The sign-in and account pages for the 4X transfer service are a preview only; they create no account and collect nothing.
Technical information
When you use our websites, our hosting provider and application servers record the technical information web servers ordinarily record: your IP address, browser and device type, the pages requested, timestamps and error details. We use it to keep the sites running, to detect abuse (for example, form flooding) and to fix problems. We do not use it to build advertising profiles. Some form endpoints keep a short-lived, in-memory count of requests per network address to limit abuse; this is not stored.
How we use your information
We use the information you give us to:
- reply to your enquiry, feedback or demo request and, where you asked us to, arrange a walkthrough;
- tell you about Bank4X availability or the ChatDS launch, if you asked for that and only for that;
- send product news only if you ticked the newsletter box, and stop when you unsubscribe;
- run, secure and support the websites and AgentDS;
- meet our legal obligations, such as keeping tax records; and
- understand how our products are used so we can improve them (see the AgentDS service data section in Part B).
We do not sell personal information, and we do not use it for third-party advertising.
How enquiries reach us
Form submissions are not stored in a database. Each one is sent as an email through Resend, our transactional email provider, to usman@uy4x.com.au, with your email address as the reply-to address so we can answer you. A successful submission means the email provider accepted the message. It does not subscribe you to anything, and it never authorises use of client data for AI training.
Who we share information with
We share personal information only with the service providers we need to run our services, and only for that purpose:
- Google Cloud and Firebase (Google LLC): application database, file storage and sign-in accounts for AgentDS. Agency data and account data are stored in the Sydney region (australia-southeast1). Firebase Authentication may process sign-in credentials in Google's infrastructure outside Australia.
- Vercel Inc.: hosts the website and application code and serves it through a content delivery network. Requests pass through Vercel's servers, which are mainly in the United States; agency data is processed there in transit and is not stored there.
- Stripe Payments Australia Pty Ltd and Stripe, Inc.: payment processing, invoices and the customer portal for AgentDS subscriptions. Stripe holds card details; we never do.
- Resend, Inc.: sends our transactional email (enquiry deliveries and, when enabled, client messages from AgentDS) from the United States. Email-verification messages for AgentDS sign-in are sent by Firebase Authentication.
We may also share information with our professional advisers under confidentiality, and where the law requires or permits it, such as to respond to a lawful request from a regulator or court. We do not sell, rent or trade personal information, and we do not share it with advertisers.
Overseas disclosure
AgentDS agency data and account records are stored in Australia. The providers above process some information outside Australia: Vercel in the United States, Stripe in the United States and Australia, Resend in the United States, and Google's sign-in service in Google's global infrastructure. Each provider is bound by contractual terms that require it to protect the information and to use it only to provide its service to us. By using our services you acknowledge these disclosures. If you have concerns about a particular provider, contact us before using the service.
How we protect information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. In AgentDS today those steps include: separation of each agency's data enforced by database security rules; role-based visibility so staff see only the records their role allows; verified email addresses for every account; encryption in transit and at rest provided by Google Cloud; secret keys kept on the server and never in the browser; card details held only by Stripe; a change history on every record; and exports limited to the agency owner. We do not claim any security certification. No system is perfectly secure, and you should keep your own devices and email accounts secure too.
Data breaches
If we become aware of a data breach that involves personal information we hold, we will assess it without undue delay. Where an AgentDS agency's data is involved, we will tell the agency owner without undue delay and give them what they need to meet their own obligations. Where the Privacy Act requires it, we will notify the Office of the Australian Information Commissioner (OAIC) and the affected individuals.
How long we keep information
- Enquiries, feedback and interest-register emails: for as long as we need them to respond and to keep a record of our dealings with you. You can ask us to delete them at any time.
- Newsletter consent: until you unsubscribe.
- AgentDS account and agency data: while the agency account is active, then for 30 days after it ends so the owner can export, after which we delete it from live systems and from backups within a further 35 days.
- Billing and tax records: for the period the law requires, currently five years.
- De-identified, aggregated service data: may be kept indefinitely, because it does not identify anyone.
Cookies and browser storage
We use only what is strictly necessary. AgentDS keeps your sign-in session in your browser's storage (managed by Firebase Authentication) so you stay signed in, and some pages remember a preference such as a collapsed section or a chosen tab. Product walkthrough entries on the website stay in your browser and clear on reload. We do not use analytics, advertising or tracking cookies, and we do not load third-party trackers. If we introduce analytics in future, we will update this notice first and tell you what is collected.
Email and the Spam Act
Our email is transactional: replies to your enquiry, sign-in and verification emails, subscription receipts and notices about your account. We send marketing email only to people who have asked for it, for example by ticking the newsletter box on the contact form, and every marketing email includes a way to unsubscribe that takes effect promptly. We do not buy lists or send unsolicited commercial email. If you receive something from us you did not ask for, tell us at usman@uy4x.com.au.
Access and correction
You can ask to see the personal information we hold about you, or ask us to correct it, by emailing usman@uy4x.com.au. We may need to confirm your identity and, for agency information, your authority. We aim to respond within 30 days. If we refuse a request, we will tell you why in writing. If your information is in a business's AgentDS client records, please ask that business first; we will help it respond.
Complaints
If you think we have mishandled your personal information, email usman@uy4x.com.au with a description of the issue (please leave out identity documents and unnecessary client details). We will acknowledge your complaint, look into it and reply in writing, aiming to do so within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this notice
We update this notice when our practices change, for example when a new AgentDS feature changes how data is handled or when we add a service provider. The date at the top of this page is the date of the current version. For changes that matter to AgentDS agencies, we email the agency owner before the change takes effect.
Contact
UY4X PTY LTD, ABN 18 702 107 846, ACN 702 107 846. Unit 1, 45 Alison Road, Wyong NSW 2259, Australia. Email usman@uy4x.com.au.
Part B · AgentDS accounts and agency client data
AgentDS account information
When an agency owner opens an AgentDS account we collect the owner's name and verified business email address, the agency name, the firm type (migration agent, law firm or other) and, for other firms, a short description and website. When the owner invites staff we collect each person's name, email address and role. Sign-in accounts are created with Firebase Authentication; we never see your password.
For subscriptions we hold a Stripe customer reference, the plan and version of the terms you accepted, and invoice and subscription status. Card details are entered on Stripe-hosted pages and held by Stripe only.
We use account information to run your workspace, verify who can see what, manage your subscription, send you account and support email and meet our legal obligations.
Agency client data
Agencies enter their own client and business records into AgentDS: client names, dates of birth, email addresses and phone numbers, visa type and status, matters and applications, tasks, appointments, invoices and recorded payments, notes, prepared messages, workflow templates and document checklists. Document entries currently hold names, status and metadata only, because uploads are not yet enabled; the files themselves stay with the agency.
The agency owns this data and is responsible for collecting it lawfully and telling its clients how it is used. We hold it only on the agency's instructions and use it only to provide, secure, back up and support the service, as set out in the AgentDS service terms. We do not use identifiable client data for our own purposes, do not sell it, do not use it for advertising and do not train models on it.
Who can see agency data
Within an agency, visibility follows the roles the owner assigns: the owner sees everything; practitioners see clients, leads and appointments plus the applications, tasks, documents and notes assigned to them; reception sees clients, leads and appointments; and accounts staff see clients, invoices and payments. Paused staff see nothing. No other agency can see your records.
UY4X staff do not browse agency data. A UY4X administrator may look at a specific record only to fix a problem the agency has reported, to investigate a security issue or where the law requires, and only for as long as that takes.
Client email from AgentDS
When an agency sends a message to a client from AgentDS, the message is sent through Resend from a UY4X sender address on behalf of the agency, with the sending staff member's email address as the reply-to address and a footer naming the agency and the sender. The message and its delivery status are kept in the agency's outbox. Client email is currently restricted to testing: messages can be sent only to the sending staff member's own address. When it opens for clients, the agency remains responsible for having the client's agreement to be contacted.
Service data and product improvement
We collect service data so we can learn how agencies, law firms and other businesses use AgentDS and make it better: which features are used and how often, performance and diagnostic data, support conversations and feedback, and de-identified, aggregated statistics derived from the service. We use it to operate, secure, support and improve AgentDS and ChatDS, including to develop and improve features and models.
Service data used for improvement must not identify an agency, its staff or its clients; it is never derived from client records unless they have first been de-identified and aggregated so they cannot reasonably be linked back to a person or agency; and it is never used to reconstruct a client record. We keep de-identified, aggregated service data after an agency leaves, because it does not identify anyone. The full clause is section 9 of the AgentDS service terms.
Export and deletion
The agency owner can export the whole workspace at any time as a complete JSON Lines file. When an agency's subscription or trial ends, the workspace stays read-only for 30 days for export, then we delete the agency's data from live systems and from backups within a further 35 days, keeping only what the law requires (such as invoices) and de-identified service data. An owner can ask for earlier deletion at usman@uy4x.com.au.
If you are a client of an agency that uses AgentDS
Your migration agent, lawyer or adviser controls your records in AgentDS. To see or correct them, or to ask how they are used, contact that business first. If you cannot reach them, or you believe your information is being mishandled in AgentDS, email usman@uy4x.com.au and we will help, within the limits of our role as the agency's service provider.