Last updated: 1 April 2026
This Data Processing Agreement ("DPA") sets out how AI Lab Australia Pty Ltd (ABN 29 689 971 364) processes personal information on behalf of clients using the SydClaw platform, in compliance with the Privacy Act 1988 (Cth) and the Privacy and Other Legislation Amendment Act 2024.
| Category | Retention |
|---|---|
| Contact information | Duration + 60 days |
| Communication content | Duration + 60 days |
| Financial data | Duration + 7 years |
| Safety records | Duration + 7 years |
| Authentication data | Duration only |
Before any data is sent to external AI model providers (Anthropic, OpenAI), all personally identifiable information is tokenised using 17+ detection patterns. No PII is transmitted in plaintext. Token mappings are stored encrypted in the client's isolated database.
All data is stored and processed in Australia (AWS ap-southeast-2, Sydney). No client data is stored outside Australia unless explicitly agreed in writing.
| Processor | Purpose | Data Sent |
|---|---|---|
| Supabase (AWS) | Database | All data (encrypted) |
| Vercel | Hosting | Session data |
| Anthropic | AI inference | Tokenised only |
| OpenAI | AI fallback | Tokenised only |
| Stripe | Billing | Billing data only |
At rest: AES-256-GCM with per-organisation keys. In transit: TLS 1.3. Credentials: AES-256-GCM with scrypt-derived keys. Backups: Supabase managed encryption.
Client notified within 24 hours. OAIC notified within 72 hours if required under the Notifiable Data Breaches scheme.
Privacy enquiries: info@ailabaustralia.com
AI Lab Australia Pty Ltd | ABN 29 689 971 364 | Sydney, Australia