Policy

Privacy Policy

SCA-POL-003 · Version v1.0 · Effective 2 September 2026. The current version always lives at this address and carries a version number and a date.

Who we are

Scáil is the trading identity of Lagantyne Pty Ltd, ACN 612 682 434, ABN 63 612 682 434, a proprietary limited company registered in Australia and operating from Western Australia. The company's registered business name is Scail Masters. In this policy, "we", "us" and "Scáil" all mean Lagantyne Pty Ltd.

We help businesses adopt AI by mapping how they already work and building systems around it. That work means we handle information belonging to our clients, and sometimes information about the people who work for them. This policy explains what we do with it.

1. Our position on the Privacy Act

We want to be straight with you about this, because most privacy policies are not.

The Privacy Act 1988 (Cth) does not currently bind every Australian business. There is a long-standing exemption for businesses with an annual turnover of $3 million or less. On turnover, Lagantyne Pty Ltd falls within that exemption.

We have chosen to comply with the Australian Privacy Principles anyway, and to hold ourselves to this policy as though the Act applied to us.

We have done that for three reasons. Our clients are entitled to the same standard of care whether or not a threshold says we owe it. Several of our clients work for government agencies and universities that are themselves bound by privacy law, and a supplier who is not is a problem for them. And an advisory practice that tells clients how to handle information responsibly has no business claiming an exemption from doing so.

Two things follow that you should understand.

This is a commitment, not a registration. We have not formally opted in to the Privacy Act. That means the Office of the Australian Information Commissioner does not regulate us, and the Notifiable Data Breaches scheme does not bind us as a matter of law. We will nonetheless notify you of any data breach affecting your information, and we will do it on the same timeframe the scheme requires.

Some privacy law binds us regardless of the exemption. Since 10 June 2025 there has been a statutory right to sue for a serious invasion of privacy, and it reaches businesses that the Privacy Act itself does not. The exemption is narrower than it looks, and we do not treat it as protection.

2. What we collect, and when

When you contact us through our website

Our enquiry form asks for your name and surname, your email address, and a description of the problem you want help with. You can also give us your company name, your company web address, and email addresses for other people you want included in the conversation.

The problem description is a free-text box, and people often use it to describe how their business works today. That sometimes includes information about their staff. We treat anything you write there as confidential from the moment it arrives.

If you give us other people's email addresses, please only add people who are expecting to hear from us. The form asks you to do this at the point you fill it in. We have no way to tell those people we hold their address until we contact them, and we would rather you asked them first.

When you become a client

We collect what the work requires and no more. In practice that means the names, roles and business contact details of the people we will be working with, and whatever business information is needed to do the job.

Working on your systems means we see your information. Where we connect to your email, your documents or your files, we see what is in them. That is the nature of the work. We do not use it for anyone else, and section 4 sets out exactly where it ends up.

What we do not collect

We do not track you. Our website sets no cookies. There is no analytics, no advertising pixel, no session recording and no behavioural profiling of any kind. We do not know who visits scail.au, how many times, or what they looked at.

Our website loads its typeface from Google Fonts, which means your browser contacts a Google server and Google sees your IP address when the page loads.

3. Why we collect it

Only for these purposes:

We do not sell information, we do not rent it, and we do not trade it. We do not use your information to market to you unless you have asked us to, and if you ever do, every message will carry a working unsubscribe link.

4. Where your information actually lives

Your information sits in three places: your own systems, our storage, and the services listed in section 5. They are governed differently, and only one of them is ours.

Your own systems

Most client work happens inside your email, document and file systems, using access you grant us. That information stays under your control, and your agreement with your own provider governs where it is stored. If your account is provisioned in Australia, that generally means your mail and files stay in Australia. We will help you confirm your own position if that is useful.

Our storage

We are not the system of record for your files. You are.

Wherever possible we work inside your systems rather than taking copies out of them, so the authoritative version of your material stays where it already lives, under your control and your own backup arrangements.

What we do hold is narrower, and it is real storage rather than a transit point: documents you send us, and the work we produce for you. Those sit on encrypted, access-controlled systems under our control. Today that means a workstation in Perth, Western Australia, and our business email and cloud storage. As the business grows it will extend to server infrastructure we operate. All of them are covered by this policy and by the security commitments in section 9, so what follows is written to cover any of them.

We do not hold a data-region commitment for cloud storage. No region is configured, which means content may sit in any of the provider's data centres, including in the United States. We would rather tell you that than imply a guarantee we do not have.

We should be straight about one limit of this. Because we hold copies rather than the original, the protection that matters most for your material is the protection on your own systems. What we owe you is that our copies are held securely, used only for your work, and deleted when the periods in section 8 run out.

One specific disclosure about our tooling. The AI development tool we use writes a copy of each working session to that workstation as plain text, held for 30 days by default. Where a session involved your material, that copy contains it. It sits behind the machine's own encryption and access controls and is not transmitted anywhere by being written, but it is a real copy in a known location and you are entitled to know it exists.

5. Who else holds your information

We use other companies to run our business, and some of them hold information you give us.

What it doesWhere it holds informationWhat happens there
Form handling for our website enquiry formOperated from outside Australia, hosted in the United StatesHolds your enquiry for 30 days on the free service we use, then deletes it. Only applies before you become a client
AI processing for analysis, drafting and buildingUnited StatesSee section 7. This is the one that matters most and it has its own section
Your own email, documents and filesYour account's regionGoverned by your agreement with your provider, not ours
Our email, calendar and file storageNo region configured, so this includes the United StatesOur business correspondence and documents

Your website enquiry does not come straight to us. It goes first to a form-handling service, which then forwards it to our email.

We tell clients which services will touch their information before the work starts, not afterwards, and we name them. If you want the current list of providers by name, ask and we will send it. We have kept the names out of this public document because it changes and a stale list is worse than none, not because we are unwilling to say.

Where we build something for you that needs hosting or a database, we set those up in your name, on your account, with you as the owner. You grant us the access we need to build it and to manage it for you. Three things follow, and all of them are in your favour: the provider's relationship is with you rather than with us, your infrastructure is not something you have to extract from us later, and if our relationship ends you revoke our access and everything keeps running.

We will tell you which providers are involved, and what each will hold, before the work starts.

If the business changes hands. If Scáil, or a part of it, is ever sold, merged or transferred, information we hold may transfer with it. Whoever acquires it is bound by the commitments in this policy on the same terms we are, and we will tell you it has happened. A change of ownership is not a way for these commitments to quietly lapse.

6. Your information going overseas

Some of it does, and we would rather you heard it here. AI processing happens in the United States. Our form handling is operated from outside Australia on United States infrastructure. Our own business storage has no region configured, so content there may sit anywhere including the United States.

Before we use any service that will hold client information, we check where it holds it, what it does with it, and whether it uses it for anything other than providing the service to us. We do not use a tool whose data handling we cannot explain to a client in plain language.

If you need your information to stay in Australia, tell us before the engagement starts. It is a real constraint that we can usually design around, but it has to be a requirement from the beginning rather than a request afterwards.

7. AI tools, model training and your information

This is the question clients ask most, and we would rather set out our actual position than a comfortable one.

Our AI provider operates two different legal regimes, and we are currently on the consumer one. We are moving to the commercial one. The difference is real, so here it is.

Consumer plan — what we use todayCommercial plan
Training on your contentA setting the account holder chooses. Not a contractual restrictionContractually prohibited
How long it is held30 days with training off, 5 years with it onPer the commercial agreement
Data processing agreementNone. It sits inside the commercial terms, which do not applyIncluded, with standard contractual clauses
Who controls the dataThe providerUs, with the provider acting on our instructions

Where we stand today, stated plainly. Model training is switched off on our account, which puts the retention period at 30 days. That was verified on the account itself on 29 August 2026, not assumed from the provider's general documentation.

What that does and does not give you. Your information is not used to train AI models and is held for 30 days rather than five years. It rests on an account setting rather than a contractual restriction, and there is no data processing agreement between us and the provider. We are moving to a commercial plan, which turns both of those from a setting into a contract.

If your obligations require a data processing agreement to be in place before work starts, tell us at the outset. It is a legitimate requirement, it is one we intend to meet, and it is far better raised before an engagement is scoped than discovered during it.

The rest of our position, which does not depend on any of the above:

Automated decisions. From 10 December 2026, Australian privacy law requires businesses covered by it to disclose where a computer program uses personal information to make a decision that significantly affects someone. Scáil does not currently make any such decision about any individual. Where we build a system for a client that does, we tell the client, we document it, and we build it so the client can meet that obligation themselves.

8. How long we keep it

These periods are commitments, not aspirations.

WhatHow longWhy this period
Website enquiries that do not lead to an engagement24 months, then deletedOur sales cycle is long and a business that enquires today may engage us eighteen months later. Twelve months would delete live conversations; indefinite retention would not be a policy at all
Client engagement records and correspondence7 years after the engagement endsCovers the ATO's five-year record-keeping requirement, with margin
Documentation of systems we have builtFor as long as you hold a licence to use itYou hold a perpetual licence. We cannot support a system whose documentation we have destroyed, and you are entitled to the record of how your own system works
Financial records and tax invoicesAs required by lawNot ours to choose

When a period ends, we delete the information or strip out anything that identifies a person. This is done on a scheduled quarterly review rather than on the exact day a period expires, so material may sit for a short time past its period before it is removed. We would rather describe the process accurately than imply a precision we do not have.

You can also ask us to delete your information sooner, and we will, unless we are required to keep it. If we cannot delete something, we will tell you what and why rather than simply refusing.

The form-handling service described in section 5 deletes enquiries from its own systems after 30 days, independently of the periods above.

When an engagement ends, your data remains yours, the documentation of your systems stays with you, and material we hold is retained and then deleted under the periods above.

9. How we protect it

We will never ask you to email us a password or an access key. If someone appearing to be from Scáil does, it is not us.

No system is perfect and we will not claim otherwise. If information you have given us is ever exposed, we will tell you, we will tell you what was affected, and we will tell you what we are doing about it. We will do that promptly and directly rather than through a notice on a website.

10. Tools that watch how you use them

Many business tools collect usage data and send it to their vendor, and most arrive with it switched on.

Where we recommend or configure a tool that does this, we tell you, and we offer you the option to turn it off. That is a standing practice, not a case-by-case favour.

We do it because a decision about your staff's usage data is yours to make, and because where personal information is involved it can engage obligations under the Privacy Act and, for public sector clients in this state, the Privacy and Responsible Information Sharing Act 2024 (WA). We surface it. You decide.

11. Getting to your information, and correcting it

You can ask us what we hold about you, and we will tell you. You can ask us to correct anything that is wrong, and we will.

Email privacy@scail.au with what you want. We will confirm we have received it within two business days and respond in full within 30 days. There is no charge.

We will check that you are who you say you are before we act. That is not bureaucracy. Without it, anyone who knew your name could ask us for information about you, and we would have promised to hand it over.

If your request is about information we hold for a client, for example because you work for a business that has engaged us, we will point you to that client rather than answer for them. The information is theirs, their own privacy process governs it, and it is not ours to give away on their behalf. We will tell you who to contact rather than leave you to find them.

If we cannot give you something, we will tell you why in writing rather than ignoring the request.

12. If you are not happy

Tell us first, at privacy@scail.au. We will acknowledge your complaint within two business days and give you a substantive answer within 30 days.

Because we comply with the Australian Privacy Principles voluntarily rather than by registration, the Office of the Australian Information Commissioner does not have jurisdiction to investigate a complaint against us. We think you should know that before you complain, not after.

13. Changes to this policy

We will update this policy when what we do changes. The current version always lives at scail.au/privacy and carries a version number and a date.

This policy is reviewed annually, and immediately whenever a service that touches client information is added, removed or materially changed.

If we change something that materially affects information we already hold about you, we will tell you directly. We will not rely on you noticing a new date on a web page.

Superseded versions are retained. If you want to see the version that applied when you engaged us, ask and we will send it.

14. Contacting us

FAO: The Managing Principal, Scáil Email: privacy@scail.au

Sources

Researched 29 August 2026 against primary sources. Every legal statement above rests on one of these, and anything not verifiable against a primary source has been left out.

Also relevant, though not relied on above: the Privacy and Responsible Information Sharing Act 2024 (WA) commenced 1 July 2026 and binds WA public entities including universities; it does not bind Scáil, but it binds several of our clients' customers and is relevant to what those clients will ask of us.

Scáil is a trading name of Lagantyne Pty Ltd. Questions about this policy: privacy@scail.au.