Legal
Privacy Policy
Last updated: 26 May 2026
1. Introduction
This privacy policy explains how Ditto ("we", "us", "our") collects, uses, stores, and protects personal information in connection with our AI automation services and website. We are committed to complying with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using our services or visiting our website, you acknowledge that you have read and understood this policy.
2. Information We Collect
We collect the following categories of information:
Contact information: name, business email address, phone number, and company name provided through our contact form or during discovery calls.
Business data: workflow descriptions, system configurations, and operational information shared during the scoping and implementation process.
Platform usage data: interaction logs, feature usage patterns, and session metadata generated when your team uses a Ditto system.
Technical data: IP addresses, browser type, device information, and referral URLs collected automatically when you visit our website.
Advertising identifiers: Meta click ID and UTM parameters collected when you arrive via an advertisement.
We do not collect sensitive information as defined under the Privacy Act unless explicitly required for a specific engagement and agreed upon in writing.
3. How We Use Your Information
We use collected information for the following purposes:
To respond to enquiries and communicate about our services.
To scope, design, build, and manage AI automation systems for your business.
To generate your personalised automation report and send it via email.
To measure the effectiveness of our advertising.
To operate and improve our platform and services.
To generate anonymised, aggregated analytics that help us improve system performance.
To comply with legal obligations and enforce our agreements.
We will not use your information for purposes materially different from those described here without your consent.
4. AI Data Processing
Ditto systems process business data through AI models to deliver automation services such as document classification, proposal drafting and reporting. Our approach to AI data processing follows these principles:
Pull, process, discard: client data is retrieved from connected platforms, processed by the AI system, and discarded after the task is complete. No client data is persisted beyond the active processing session.
No model training: your data is never used to train, fine tune, adapt, or enhance any AI model, machine learning model, large language model, or predictive analytics tool.
Human governance: every consequential action generated by AI requires explicit human approval before it is executed.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share information with the following parties:
Meta (Facebook): hashed email and event data for advertising measurement via the Conversions API.
Supabase: database hosting (data stored in Australia).
Google: Analytics and Drive (for report storage).
Anthropic: AI processing for report generation (no personal data retained).
Web3Forms: contact form processing.
Professional advisors: legal, accounting, and insurance professionals as required for business operations.
Law enforcement: where we are required to do so by law or court order.
We require all third party service providers to maintain appropriate security measures and to process personal information only as instructed by us.
6. Data Security
We implement technical and organisational measures to protect your information, including:
Encryption in transit (TLS 1.2+) and at rest for all data.
Multi factor authentication and role based access controls for all platform access.
Full audit logging of every action taken within the system.
Regular security assessments and vulnerability testing.
While we take reasonable steps to protect your information, no method of electronic transmission or storage is completely secure.
7. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this policy:
Contact form submissions: retained for 12 months after the last communication, then deleted.
Automation report data: retained for the duration of your engagement plus 90 days for transition purposes.
Website analytics: anonymised and aggregated data retained indefinitely. Identifiable data retained for 12 months.
You may request deletion of your personal information at any time by contacting us.
8. Your Rights
Under the Australian Privacy Act 1988, you have the right to:
Access the personal information we hold about you.
Request correction of inaccurate or incomplete information.
Request deletion of your personal information where we are not required by law to retain it.
Withdraw consent for any processing based on your consent.
Opt out of marketing communications at any time.
Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
To exercise any of these rights, contact us at hello@ditto.vip. We will respond to your request within 30 days.
9. Cookies and Tracking
Our website uses cookies and similar technologies:
Essential cookies: required for website functionality such as session management. These cannot be disabled.
Analytics: we use analytics to understand website usage patterns.
Advertising: we use the Meta Pixel for advertising measurement. You can manage cookie preferences through your browser settings.
10. Third Party Services
Our website and platform may contain links to third party services. We are not responsible for the privacy practices of these services. We encourage you to review the privacy policies of any third party service before providing your information.
11. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. The updated policy will be posted on our website with the effective date clearly indicated. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this privacy policy or wish to exercise your rights, contact us:
Email: hello@ditto.vip
Location: Australia
To lodge a privacy complaint with the OAIC, visit www.oaic.gov.au.
This policy is effective as of 26 May 2026.
If you have questions about this policy, please contact us.