Privacy policy
Use what the job needs. Keep the boundary visible.
This policy explains how My SideKick Business Pty Ltd handles personal information across its website, enquiries and customer services.
Who we are
MySidekick is operated by My SideKick Business Pty Ltd.
My SideKick Business Pty Ltd (ABN 75 701 962 745, ACN 701 962 745) is responsible for this policy. This policy applies to personal information we control. A customer may remain responsible for personal information in its own systems, with our responsibilities also governed by the written customer agreement.
1. What we collect
Depending on how you deal with us, we may collect your name, business contact details, role, organisation, enquiry and correspondence, commercial and billing records, service requests, approvals and information needed to configure or support an agreed customer service. Our website host may also create technical and security logs such as IP address, browser, requested page and timestamp.
2. How we collect it
We collect information directly from you or an authorised contact, through monitored email and business conversations, from a customer that has authorised us to perform agreed work, and from approved systems used to deliver or support that work. The Day-1 website does not operate a public enquiry form, public webhook, self-service checkout or automated CRM persistence.
3. Why we use it
We use personal information to respond to enquiries, assess fit, prepare and administer quotes and agreements, deliver and support agreed services, maintain security and operational evidence, manage billing and records, meet legal obligations, and improve our service. An enquiry is not a marketing subscription. We do not send marketing communications without an appropriate basis and an available opt-out.
4. What not to send
Do not send passwords, API keys, access tokens, confidential documents, health information or other sensitive personal information to a public or general email address. If an agreed service genuinely requires protected information, we will identify an approved collection and access method first.
5. Disclosure and service providers
We disclose personal information only where reasonably required for an agreed purpose: to authorised staff and contractors; to website, email, document, automation and other service providers supporting our operations; to customer-approved providers used for an agreed service; to advisers; or where required or authorised by law. The Day-1 public website uses WP Engine for WordPress hosting and Google Workspace for monitored email. Customer integrations are selected and authorised separately; the website does not authorise them.
6. Overseas handling
Some providers operate global infrastructure or support and may process personal information outside Australia, including in the United States. The countries and providers used for a customer service can depend on the agreed systems and their configuration. We assess and record the relevant deployment facts during customer scoping and can provide current information on request.
7. Security and access boundaries
We use role-based access, approved credential stores, bounded workflow authority, evidence and change controls, and provider security features appropriate to the service. No online or storage system can be guaranteed completely secure. An enquiry does not authorise access to a customer system or a live deployment.
8. Retention
We keep personal information only for as long as reasonably needed for the purpose for which it was collected, to operate an agreed service, meet legal and financial record-keeping obligations, resolve disputes and maintain necessary evidence. Retention depends on the record and service. We delete, de-identify or securely dispose of information when it is no longer required, subject to law and legitimate operational needs.
9. Access, correction and complaints
You may ask to access or correct personal information we hold about you, or raise a privacy complaint, by emailing privacy@mysidekicks.au. We may need to verify your identity and authority before acting. We will respond within a reasonable period and explain if an exception applies. If a complaint is not resolved, you may contact the Office of the Australian Information Commissioner.
10. Automated activity
The Day-1 website does not make operational decisions about visitors or automatically write enquiries to a CRM. AI-enabled preparation or automation used in a customer service remains subject to the agreed purpose, system access, human authority, testing and release boundaries.
11. Cookies and analytics
MySidekick has not added advertising pixels or marketing analytics to the Day-1 website. WordPress and the hosting provider may use essential technical mechanisms and maintain access, security and performance logs. If we later add optional analytics or marketing technologies, we will update this policy and implement any required notice or choice before use.
12. Changes
We may update this policy when our services, providers or legal obligations change. The current version and effective date will be published on this page.