The Artificial Organisation
Log inBook a discovery callBook a call
Back to home
Privacy Policy

What we collect, what we do with it, and what we never do.

TAO holds a lot of what makes your business yours. This policy says, in plain English, what we collect, how we use it, where it lives, how long we keep it and what you can ask of us. Last updated 27 August 2026.

Who we are

The Artificial Organisation (TAO) builds and runs TAO for client businesses from Sydney and Singapore. For anything in this policy, write to support@theartificialorganisation.com.

What we collect

Only what is needed to talk to you, build your TAO, and run it.

  • When you enquire or book a call: your name, work email, business name, and what you tell us about the business.
  • When your team is set up: each person’s name, work email, role and sign-in details, plus the security records that go with an account (two-factor state, sessions, audit entries).
  • When you connect a system: the data that system holds and you have authorised, such as email, calendar, contacts, quotes, invoices, jobs and messages.
  • When you use TAO: what was drafted, approved, sent and changed, and who did it, so that the audit trail is complete.
  • When you contact support: the messages and any material you send us.

What we do with it

We use your information to build and run your TAO, and for nothing else.

  • To connect the systems you already use and keep them in sync, both ways.
  • To let Andy read your record so it can draft, propose and notice the way you would.
  • To learn how your business does things into your company brain, which is yours alone.
  • To provide support, keep the service secure, and meet our legal obligations.
  • We do not sell your information. We do not use it for advertising. We never use it to train models for anyone else.

Connected systems, including Google

A connection is only ever made by you or your administrator, and only for modules you can see. Each system’s own terms continue to apply, and you can see and revoke every permission inside TAO.

  • TAO’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Google user data is used only to provide or improve user-facing TAO features, never to develop or train generalised models, and is not transferred to others except as needed to provide those features, for security, or where the law requires it.
  • People at TAO read your connected data only when you ask for support, when it is needed to investigate a security problem, or where the law requires it.

Andy, and decisions made with it

Andy drafts. A person approves. Andy does not send a message or change a record without that approval, and every action is on the audit trail with who approved it.

  • You can ask what Andy read and which inputs produced a draft.
  • You can have any Andy-influenced step reviewed by a person before it happens.
  • You can turn automated steps off for your business at any time.

Where it lives and how it is protected

Every client sits on their own isolated database. Sign-in credentials and system tokens are stored encrypted and never shown in the browser. Every account uses two-factor sign-in. Every action is logged. SOC 2 is in progress; we say in progress, not certified, until it is complete.

How long we keep it

For as long as we are building or running your TAO. When an engagement ends we hand your data back in a usable form and delete our copy after a short wind-down period, keeping only the records the law or a security investigation requires. Disconnecting a system stops future sync as soon as the disconnect is processed.

What you can ask of us

Write to support@theartificialorganisation.com and we will act promptly. Where the law where you are gives you more than this list, the law wins.

  • A copy of the personal information we hold about you.
  • A correction where something is wrong or incomplete.
  • Deletion, subject to the records we must keep.
  • An export of your business record in a structured format.
  • To object to a specific use, including automated steps.
  • To complain to a regulator: the Office of the Australian Information Commissioner in Australia, or the Personal Data Protection Commission in Singapore.

Who else touches the data

A short list of providers, each limited to what their job needs. Clients get advance notice of changes and a reasonable window to object.

  • VercelHosting and delivery of this website.
  • DigitalOceanApplication hosting and the isolated per-client databases.
  • Model providers, via OpenRouterLanguage-model inference for Andy’s drafts and answers. Your data is never used to train their models.
  • Transactional email providerSign-in codes, invitations and notifications.
  • Error and uptime monitoringKeeping the service healthy. Limited to technical diagnostics.

Changes and contact

We will update this page when something material changes and note the date at the top. Questions, requests and complaints: support@theartificialorganisation.com. The contractual detail behind this policy is in our Data Processing Agreement.

One conversation about how your business works.

Half an hour with the people who would build it. Then a proposal for exactly what TAO should take off your plate.