Privacy Policy

Version 2.0 · Last updated 16 August 2026

ItemDetails
Legal entityChristopher Hoang Luu Nguyen trading as ETEC+ (Sole trader) — ABN 16 504 803 804
Websitesetecplus.ai (product) · etecplus.com.au (parent brand — all staff and email operate under it)
LocationETEC+ is an online business based in New South Wales, Australia.
Privacy contactsales@etecplus.com.au
Governing lawPrivacy Act 1988 (Cth) & Australian Privacy Principles · New South Wales, Australia

How to read this policy. This policy is the complete, formal statement of how ETEC+ handles personal information. It is intentionally detailed so that our practices and commitments are clear, transparent, and capable of being reviewed. Plain-language summaries appear where useful. If anything here conflicts with your written agreement with us, the terms of that agreement govern to the extent permitted by law.

1. Definitions

  • "ETEC+", "we", "us", "our" means the business operating under the name ETEC+, owned and operated by Christopher Hoang Luu Nguyen trading as ETEC+ (ABN 16 504 803 804).
  • "Service" means the ETEC+ AI Agent, your private workspace, and any related products, features, tools, or support we provide.
  • "Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in the Privacy Act 1988 (Cth).
  • "Customer Data" means all content, instructions, workflows, prompts, notes, files, and other data that you provide, upload, or create in your Workspace while using the Service, and any personal information contained within them.
  • "Workspace" means your private, customer-controlled area within the Service that holds your Customer Data.
  • "You / Customer" means the business or individual that purchases or uses the Service, and where the context requires, any authorised users associated with that business.
  • "Processing" means any operation performed on personal information, including collection, use, storage, disclosure, retention, and deletion.
  • "Connected tools" means the third-party apps, platforms, and services (for example email, calendar, CRM, and file storage) that you authorise the Service to connect to.

2. About ETEC+ and this policy

ETEC+ provides an AI agent service that answers questions, does research, creates content, and carries out tasks across the tools and channels you already use. This Privacy Policy explains how we handle personal information in connection with that service and our websites.

ETEC+ is one legal entity operating two domains: etecplus.com.au is the parent brand and primary business domain — all staff, email, and operations run under it — and etecplus.ai is where the ETEC+ AI Agent product is hosted. This policy applies to both.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply to us, and we operate from New South Wales, Australia. Where the Privacy Act does not apply to us in respect of a particular activity (for example, because the activity falls outside its coverage or an exemption applies), we nonetheless aim to apply the same high standards described in this policy.

By purchasing a plan, creating an account, or using the Service, you acknowledge that you have read and understood this policy and agree to the handling of information described in it. If you do not agree, you must not use the Service.

3. Who this policy applies to

  • Customers — businesses and individuals who purchase or use the Service;
  • Customer personnel — employees, contractors, and authorised users of a Customer;
  • Contacts of Customers — individuals whose personal information a Customer includes in their Customer Data (for example, the Customer's own clients, team members, or suppliers);
  • Website visitors — people who visit etecplus.ai or etecplus.com.au; and
  • Prospective customers — people who contact us, book a discovery session, or express interest in the Service.

4. What information we collect

Information you provide directly

  • Account details — name, business name, email address, phone number, and billing address when you create an account or purchase a plan.
  • Payment information — payment is processed securely by our payment provider (Stripe). We do not store full card numbers.
  • Workspace content (Customer Data) — instructions, workflows, prompts, notes, and files you add so your agent can perform the tasks you set.
  • Correspondence — when you contact us for support or book a discovery session.

Information collected through the Service

  • Connections you approve — when you connect an email, calendar, CRM, files, or other tool, the Service accesses that tool to carry out the tasks you authorise.
  • Agent activity — records of the tasks your agent performs, so it can learn your processes and so we can support you and resolve issues.
  • Technical data — IP address, device and browser type, and similar technical data when you visit our website or use the Service.

Interactive demo

Our public demo at /demo can be used without an account. It is a simulation: the responses are pre-built, no AI model is run, and no system of yours is contacted. We do keep a copy of the conversation you have with it — the messages you type and the responses shown — together with the industry you selected and the website you arrived from, so we can improve the demo and follow up if you ask us to. We do not store your IP address for this purpose. Demo conversations are deleted after 90 days unless you have asked us to contact you, in which case they are retained with your enquiry. Please do not enter confidential or sensitive information into the demo. Any files you attach in the demo stay in your browser and are never uploaded to us.

Information we do not intentionally collect

We do not knowingly or intentionally collect sensitive information (within the meaning of the Privacy Act) unless you choose to provide it as part of your Customer Data and it is necessary to provide the Service. We ask that you not include sensitive personal information in your Customer Data unless it is genuinely required for a task you set. See section 21.

5. How we use your information

We use your information only for the purposes of providing, maintaining, securing, and improving the Service for you, including to:

  • operate your AI agent and your private Workspace, and perform tasks you set up;
  • connect and manage the tools you approve;
  • provide customer support, troubleshooting, and resolve bugs or issues;
  • process payments and manage your subscription;
  • communicate with you about your account, the Service, and (with your consent) relevant updates;
  • analyse and improve the Service where carried out in a way that does not identify you (for example, aggregated and anonymised usage statistics); and
  • meet our legal, accounting, insurance, and security obligations.

7. How we do NOT use your information

This section records explicit prohibitions that apply to the Service:

  • No selling or renting. We do not sell, rent, trade, license, or otherwise commercially transfer your information to any third party for their own purposes. Ever.
  • No model training on your data. Your documents, emails, prompts, Workspace content, and customer data are not used to train, fine-tune, or improve any AI or machine-learning model.
  • No cross-customer mixing. Customer Data is not mixed across customers for any purpose. Each customer's Workspace is separate.
  • No promotional sharing. We do not use your business information or case material in marketing or testimonials without your prior written consent.
  • No secondary use. We do not use your information for any purpose other than those described in this policy, and we do not repurpose data collected for one purpose for an unrelated purpose without consent or a lawful basis.

Our commitment. Your data is used only to deliver the Service to you and to fix issues you ask us to fix. We do not train models on your data and we do not sell your data.

8. Data-processing roles (controller / processor)

  • You are the controller of your Customer Data. You decide what goes into your Workspace, what tasks your agent performs, and which tools it connects to.
  • ETEC+ acts as a processor in respect of Customer Data: we process it only on your instructions, for the purposes described in this policy, and in accordance with our agreement with you.
  • For the limited categories of information that relate to your own account with us (for example, your billing details and correspondence), ETEC+ acts as a controller and handles that information in accordance with this policy.
  • You authorise us to process Customer Data as described in this policy and to engage service providers to do so on our behalf, subject to the safeguards in sections 11 and 18.

9. Our obligations under the Australian Privacy Principles

The following table summarises how we address each of the Australian Privacy Principles. This is provided for transparency and ease of review.

APPPrincipleHow we address it
APP 1Open and transparent managementThis policy (open, current, and easy to access).
APP 2Anonymity and pseudonymityWhere practical, you may interact without identification; where required to provide the Service (e.g., account or billing), we collect identifying information.
APP 3Collection of solicited personal informationWe collect only information that is reasonably necessary for the functions and activities of the Service.
APP 4Dealing with unsolicited informationIf we receive unsolicited personal information, we will destroy or de-identify it where lawful and reasonable.
APP 5Notice of collectionThis policy notifies you of what we collect, why, and how to complain.
APP 6Use or disclosureWe use and disclose only for the primary purpose of providing the Service, or a permitted secondary purpose.
APP 7Direct marketingOnly with consent, with an opt-out (see section 25).
APP 8Cross-border disclosureSafeguards apply (see section 18).
APP 9Adoption, use or disclosure of government identifiersWe do not adopt government identifiers as our own.
APP 10Quality of personal informationWe take reasonable steps to ensure information is accurate, current, complete, and relevant.
APP 11Security of personal informationReasonable security safeguards (see section 12).
APP 12AccessYou may request access (see section 15).
APP 13CorrectionYou may request correction (see section 15).

10. Storage & data location

Service data (including Customer Data) is stored in secure cloud infrastructure operated by reputable providers that maintain industry-standard security practices. The providers we use are listed in section 11, and some of them operate data centres outside Australia — see section 18 for how cross-border disclosure is safeguarded.

Where a specific data-region is required for a particular engagement, we will discuss and accommodate this where available. If you request it, we will advise you of the relevant data-region details for your Workspace. Further details of the live infrastructure are available on request and in any data-processing agreement (DPA) we enter into for a specific engagement.

For the avoidance of doubt, using the Service does not require that your Customer Data be transferred out of your control. Access to your Connected tools is made using the permissions you approve, and every connection can be revoked by you at any time.

11. Sub-processors & third-party service providers

To provide the Service, we engage third-party service providers (sub-processors) to perform functions such as cloud hosting, computing infrastructure, storage, payment processing, and support tooling. The current sub-processors and AI model providers used to deliver the Service are:

ProviderRoleData handled
Agent37Agent compute platform — runs each agent's isolated environment and AI gatewayWorkspace content and agent activity, to operate your agents
Anthropic / OpenAI / GoogleAI model providers accessed via the Agent37 platform (the model is selectable per agent)Prompts and task content, to generate responses
OpenAIKnowledge-base search (text embeddings of files you upload)Knowledge-file content, for retrieval only
SupabaseDatabase, authentication, and file storage for the applicationAccount details and Workspace records
StripePayment processingBilling details — we never see full card numbers
ResendTransactional email delivery (for example, account and billing notices)Email address and message content
VercelWebsite and application hostingTechnical data (requests, logs)
ComposioOAuth connectivity to your Connected tools, via the Agent37 platformConnection credentials and the tool data your tasks require

Before engaging any sub-processor that may handle Personal Information, we take reasonable steps to:

  • require that they process Personal Information only on our documented instructions;
  • require that they maintain appropriate security safeguards;
  • where reasonably practicable, contractually bind them to comply with obligations that protect your information consistently with this policy; and
  • maintain a list of the sub-processors and AI model providers used for your Workspace, which we will provide to you on request together with applicable data-region details.

We configure the Service so that sub-processors and AI model providers do not use your data to train models and do not sell your data. A current sub-processor list is available from our privacy contact (section 30).

12. Security safeguards

We take reasonable steps to protect Personal Information from misuse, interference, loss, and unauthorised access, modification, or disclosure, as required by the Australian Privacy Principles. Our security measures include:

  • encryption of data in transit (TLS) and at rest;
  • access controls so that ETEC+ personnel can access Customer Data only where necessary to operate, support, or secure the Service;
  • a server-side authorisation boundary — platform keys and database credentials never reach the browser;
  • least-privilege permissions on Connected tools, so the Service uses only the access required to perform the tasks you approve;
  • authentication controls on accounts and administrative access;
  • secure handling of credentials and connection permissions;
  • incident-response procedures, including assessment, containment, and notification in accordance with the Notifiable Data Breaches scheme (section 24);
  • staff obligations to protect confidential and personal information; and
  • ongoing review of security practices appropriate to the nature and scale of the Service.

We do not currently hold SOC 2 or ISO 27001 certifications, which are not legally required to operate this type of service within Australia. We instead apply reasonable, industry-standard controls appropriate to the Service and take our obligations under the Privacy Act seriously. A summary of our security controls and architecture is available on request as part of a procurement or security review, and if a specific certification is a contractual requirement of your engagement, please contact us to discuss.

No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. You are responsible for protecting your own login credentials and for the security of the tools you choose to connect.

13. Data retention & deletion

We retain information only for as long as is necessary to provide the Service and meet our legal obligations.

  • Active subscription: your Workspace content and agent data are retained while your subscription is active, to provide the Service.
  • Unpaid or missed payment: if a subscription payment is not received, a grace period begins — 7 days unless your plan states a different period — and we notify you before the deadline. If payment is not received within that period, the subscription is cancelled and we proceed with removal of your Service data, subject to any legal obligation requiring us to retain a specific record.
  • Free trials: trial agents run until their stated expiry time, after which the agent is stopped and may be removed unless converted to a paid plan (conversion preserves your Workspace content).
  • On your request: you may request deletion of your data (including your Workspace) at any time, and we will delete it as described in section 15.
  • Legal or accounting records: certain records (for example, billing and tax records) may be retained for the period required by the Income Tax Assessment Act 1997 (Cth) (generally five years) or other applicable law, solely to meet legal obligations. These records do not include your Workspace content.
  • Log and technical data: routine technical logs are retained only for as long as needed for security and operational purposes, and are not used to identify you where they can be anonymised.

Deletion requests are actioned promptly. Once deleted, data that is not otherwise required to be retained by law is permanently removed from the Service and, where reasonably practicable, from back-up media on the schedule that applies to those backups.

14. Backup, integrity & disaster recovery

We maintain reasonable backup practices to protect against accidental loss or corruption, and periodic restoration checks where appropriate. These practices are designed to protect the integrity and availability of Customer Data while you are using the Service. We do not use your data to train models and we do not sell your data (section 7). If you delete data in accordance with this policy, we take reasonable steps to ensure it is not restored from backup unless legally required.

15. Your rights (access, correction, deletion & more)

Under the Australian Privacy Principles (in particular APP 12 and APP 13), and consistent with this policy, you have the following rights:

  • Access. Request a copy of personal information we hold about you.
  • Correction. Ask us to correct personal information that is inaccurate, incomplete, out of date, or misleading.
  • Deletion. Delete your Workspace at any time to remove your data. We action deletion requests promptly and permanently remove the data you asked us to delete, unless we are required to retain a specific record by law.
  • Export. While your subscription is active, access and export your files, knowledge-base documents, workflows, and prompts through the dashboard — or ask us for reasonable export assistance, including when you are leaving.
  • Objection / restriction. Where we process information on a basis that depends on consent or our legitimate interests, you may withdraw consent or raise an objection, and we will consider it in accordance with applicable law.
  • Complaint. Lodge a complaint about our handling of your information, which we will acknowledge and investigate (section 26).

These rights are subject to any exceptions or limitations in the Privacy Act. We may need to verify your identity before acting on a request, and we may decline a request, or charge a reasonable fee, only where permitted by law.

16. How to exercise your rights

To exercise any of these rights, contact our privacy officer using the details in section 30. We will respond within a reasonable timeframe and in accordance with the Privacy Act. If we cannot identify you to our reasonable satisfaction, we may request further information. We will not discriminate against you for exercising your rights.

17. Disclosure & sharing

We share information only where necessary to provide the Service, and only to the extent needed, including with:

  • service providers and sub-processors who help us operate the Service (listed in section 11), under strict confidentiality and data-security obligations;
  • Connected tools, to perform the tasks you (or your authorised users) approve — for example, when your agent sends an email or updates a record on your behalf;
  • professional advisers (such as legal, accounting, or insurance advisers) where needed;
  • authorities or parties where we are required or permitted by law to disclose information, such as under a court order or in response to a lawful request; and
  • a successor in the event of a change of control, merger, or acquisition, as described in section 27.

We do not disclose your personal information to third parties for their own marketing purposes, and we do not sell your information.

18. Cross-border disclosure of personal information

Some of the service and infrastructure providers described in this policy, and some AI model providers, operate data centres or otherwise process data in countries outside Australia (including the United States). Where Personal Information is disclosed to an overseas recipient, we take reasonable steps to ensure that recipient handles the information in a manner consistent with the Australian Privacy Principles, and we comply with APP 8 (Cross-border disclosure of personal information). This includes, where appropriate, contractual safeguards that require the recipient to handle the information in accordance with the APPs.

Where your data is shared with a third-party AI model provider strictly to provide the Service to you, we configure the Service so that your data is not used to train models and is not sold. A current overseas-processing and AI-model-provider summary, including applicable data-region details, is available on request.

19. Third-party connected tools & apps

The Service connects to third-party tools and platforms that you approve (such as Gmail, Microsoft 365, Google Drive, calendar, CRM, and file storage). Each Connected tool has its own terms and privacy policy, and is an independent controller of the information you share with it.

Connections are made using secure OAuth authorisation, and the exact permissions (scopes) requested for each tool are displayed by the provider at the moment you connect it, before any access is granted. A current list of the permissions used for each connected app is available on request.

You are responsible for reviewing the terms and privacy practices of any Connected tool before connecting it, and for ensuring that connecting it does not breach any agreement you have with the provider of that tool. ETEC+ is not responsible for the practices of Connected tools. By connecting a tool, you consent to the access required to perform the tasks you approve, and you may revoke or disconnect any tool at any time.

20. Your responsibilities (data you submit about others)

If you upload, submit, or process personal information of other people (for example, your own customers, staff, or suppliers) through the Service, you are responsible for ensuring you have a lawful basis to do so. This includes:

  • obtaining any consents or providing any notices required by privacy law before you include third parties' personal information in Customer Data;
  • informing those individuals about how their information will be used, if required;
  • complying with the Privacy Act and any other applicable privacy law in respect of that information; and
  • using the Service in a way that does not breach any requirement of those laws.

ETEC+ is not liable for your failure to meet these responsibilities, including where your use of the Service breaches a third party's privacy rights.

21. Sensitive information

We do not require and do not seek sensitive information (within the meaning of the Privacy Act, including information about health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal record). If you choose to include sensitive information in Customer Data as part of a task you set up, you confirm that you have a lawful basis to do so and you consent to our handling of it strictly to provide the Service. We handle any such information in accordance with the Privacy Act, including APP 3.

22. Cookies, analytics & technical data

Our website and application use only the cookies and similar technologies needed to operate the Service — for example, to keep you signed in and remember your preferences. We do not use advertising trackers, and we do not build profiles about you from your use of our website. You can control cookies through your browser settings; disabling essential cookies may prevent sign-in from working.

23. Children

Our Service is directed to, and intended for use by, businesses and adults. We do not knowingly collect personal information from children. If you believe a child has provided personal information, please contact us and we will delete it.

24. Notifiable data breaches

The Privacy Act's Notifiable Data Breaches (NDB) scheme requires us to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. If we become aware of a breach involving your personal information that triggers this threshold, we will:

  • take reasonable steps to assess and contain the breach;
  • notify the OAIC and affected individuals where required; and
  • keep you informed, where you are our customer, in accordance with any agreement and the NDB scheme.

We take a disciplined approach to incident assessment so that potential breaches are identified and responded to promptly.

25. Direct marketing

We may send service-related communications (for example, about your account, subscription, or support) which are necessary for the Service and are not "direct marketing" for the purposes of the Privacy Act. If we send marketing communications, we will only do so with your consent, and you can opt out at any time using the unsubscribe link or by contacting us.

26. Complaints & dispute resolution

If you have a complaint about how we handle your personal information, please follow this process:

  • Contact us using the details in section 30. We will acknowledge your complaint promptly and investigate it, providing a response within a reasonable timeframe.
  • Escalation. If you are not satisfied with our response, you may escalate within ETEC+ to the proprietor.
  • OAIC. If the matter is not resolved to your satisfaction, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

We do not charge you to make a complaint and will not treat you adversely for making one.

27. Data on termination, insolvency or change of ownership

  • Termination: on cancellation or termination (including for non-payment after the grace period in section 13), you are responsible for exporting any Customer Data you wish to keep before access ends. After the applicable period, we remove Service data subject to any legal retention requirement.
  • Exports: while your subscription is active, you may export your workflows, prompts, and Customer Data. If you need a bulk export or reasonable assistance when leaving, contact us.
  • Change of control / insolvency: in the event of a merger, acquisition, restructuring, or insolvency, we will take reasonable steps to ensure that Customer Data continues to be handled in accordance with this policy. If ETEC+ is acquired, your data may be transferred to the successor, who remains bound by the commitments in this policy (including the prohibitions in section 7).

28. Limitation, disclaimers & relationship to other documents

  • This policy forms part of, and must be read together with, our Terms & Conditions and any data-processing agreement (DPA) entered into for a specific engagement.
  • Where this policy and the Terms conflict, the Terms govern to the extent permitted by law, except that nothing reduces your rights under the Privacy Act.
  • Nothing in this policy excludes, restricts, or modifies any right or remedy you may have under the Australian Consumer Law or other law that cannot be excluded. Our liability is limited to the maximum extent permitted by law and as described in our Terms & Conditions.
  • This policy describes our privacy practices. It is not, by itself, a substitute for legal advice about your own obligations, which you should obtain where appropriate.

29. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. We will update the version number and "Last updated" date at the top of this page. Where changes are significant, we will take reasonable steps to notify you, such as by email or a notice on our website. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

30. Contact

For privacy questions, requests, or complaints, please contact our privacy officer:

  • Email: sales@etecplus.com.au
  • Websites: etecplus.ai (product) · etecplus.com.au (parent brand)
  • Postal address: ETEC+ is an online business based in New South Wales, Australia.

We will respond within a reasonable timeframe. If you are not satisfied with our response, you may complain to the OAIC at oaic.gov.au or by calling 1300 363 992.

© 2026 ETEC+ · ABN 16 504 803 804. All rights reserved.