Privacy Policy

How The Autonomous Collective Pty Ltd handles personal information.

Last updated: 10 September 2026

This policy explains how The Autonomous Collective Pty Ltd (TAC, we, us) handles personal information in connection with our website and TAC AWS Foundations service.

About this Policy

Our service includes customer onboarding, support, Atlassian Jira Service Management forms, our Forge applications and related deployment integrations. Personal information means information about an identified or reasonably identifiable individual.

This policy covers information about website visitors, people making enquiries and nominated customer users and contacts. It describes our handling of that information, including when we use other providers to deliver the service.

Collecting and Using Personal Information

Information You Provide

We collect information you or your organisation provide when making an enquiry, requesting support or configuring the service. This includes names, organisation details, roles, email addresses, telephone numbers and the contents of requests. AWS account configuration can also include nominated billing, operations and security contacts and business address details.

Our Forge applications use relevant Atlassian user identifiers, organisation membership and service-request information to associate requests with the appropriate customer. Information can come from you, your organisation or the Atlassian records used to deliver the service.

Please provide only information needed for your request. Do not include passwords, access keys or unrelated personal information in enquiry or support messages.

Website Information and External Services

Our website uses AWS hosting and content delivery, Google Fonts and jsDelivr resources. The Contact page also loads an Atlassian enquiry widget. Your browser connects to these providers when loading their resources, which exposes connection information such as your IP address and browser request details to them.

Website and service providers can generate operational logs. Embedded services may use cookies or similar storage under their own arrangements. You can control cookies through your browser, although this can affect embedded functionality.

How We Use Information

We use this information to respond to enquiries, onboard customers, identify nominated users, process service requests, configure AWS accounts, deliver and support TAC AWS Foundations, and maintain service security. We do not use customer service configuration or nominated AWS contact details for unrelated advertising.

Providers and Deployment Records

We use Atlassian Jira Service Management and Forge for requests and workflows, GitHub for configuration and deployment changes, and AWS for provisioning and infrastructure. Information needed for these activities is handled through these providers. Nominated AWS contact details are supplied to AWS when configuring the relevant accounts.

Information can be recorded in service requests, application storage, configuration files, change history, deployment state and operational records. Updating a contact or configuration file does not necessarily remove earlier copies from history or backups.

Storage, Access and Overseas Handling

We take reasonable steps to protect personal information, including access controls and secure storage appropriate to the systems used. Access is limited to authorised people and providers who need it for service delivery, support or other purposes described in this policy. No storage or transmission method is completely secure.

We use the AWS Sydney region (ap-southeast-2) for customer deployment backend storage and configure Atlassian data residency in Australia. These settings do not mean that every part of provider processing occurs in Australia. Authentication, support and other provider services may involve processing outside Australia.

We consider provider processing arrangements when selecting and using services and take reasonable steps to protect information handled on our behalf.

Retention and Deletion

We retain personal information for as long as it is reasonably needed for the purposes described in this policy, including applicable legal obligations and resolving disputes. We review information when the service ends and take reasonable steps to delete or de-identify information that is no longer needed.

Deletion can involve service requests, configuration history, deployment records and backups. Where a copy must be retained, we restrict its use and review the reason and period for keeping it. We coordinate changes to customer-controlled AWS contacts and infrastructure records with the customer so that deletion does not disrupt resources they still need.

Access, Correction and Deletion Requests

You can contact us to request access to or correction of your personal information, or ask us to delete it. We may need to verify your identity and authority before acting on a request.

We aim to respond within 30 calendar days of receiving your request. This is a response target, not a guarantee that every historical or backup copy will be deleted within that period. If further time is needed, or information must be retained, we will explain why and the next steps. We will explain any limitations on the action we can take.

Other Disclosures

We may disclose information where required or authorised by law, to protect legal rights or service security, or with your consent. If ownership of the business changes, we will consider the protection of personal information in the transfer and notify affected people of material changes to its handling.

External websites and providers have their own privacy policies. Review those policies when using their services. This does not remove our responsibility for information we handle or arrange to be handled on our behalf.

Changes to this Privacy Policy

We review this policy as our information handling changes. We publish updates on this page and revise the date above. We will take reasonable steps to bring material changes affecting existing customers to their attention.

Contact Us and Privacy Complaints

To make a privacy request or complaint, use our Contact Us page or call +61 7 3184 4300. Please say that your enquiry concerns privacy.

You can also write to The Autonomous Collective Pty Ltd, P.O. Box 769, Hamilton Central QLD 4007.

We will investigate privacy complaints and aim to respond within 30 calendar days. If further time is needed, we will let you know. If you remain dissatisfied, you can contact the Office of the Australian Information Commissioner for information about available complaint options.

Questions about privacy or data handling?

Contact TAC