Policy
Privacy Policy
Who we are
Scáil is the trading identity of Lagantyne Pty Ltd, ACN 612 682 434, ABN 63 612 682 434, a proprietary limited company registered in Australia and operating from Western Australia. The company's registered business name is Scail Masters. In this policy, "we", "us" and "Scáil" all mean Lagantyne Pty Ltd.
We help businesses adopt AI by mapping how they already work and building systems around it. That work means we handle information belonging to our clients, and sometimes information about the people who work for them. This policy explains what we do with it.
1. Our position on the Privacy Act
We want to be straight with you about this, because most privacy policies are not.
The Privacy Act 1988 (Cth) does not currently bind every Australian business. There is a long-standing exemption for businesses with an annual turnover of $3 million or less. On turnover, Lagantyne Pty Ltd falls within that exemption.
We have chosen to comply with the Australian Privacy Principles anyway, and to hold ourselves to this policy as though the Act applied to us.
We have done that for three reasons. Our clients are entitled to the same standard of care whether or not a threshold says we owe it. Several of our clients work for government agencies and universities that are themselves bound by privacy law, and a supplier who is not is a problem for them. And an advisory practice that tells clients how to handle information responsibly has no business claiming an exemption from doing so.
Two things follow that you should understand.
This is a commitment, not a registration. We have not formally opted in to the Privacy Act. That means the Office of the Australian Information Commissioner does not regulate us, and the Notifiable Data Breaches scheme does not bind us as a matter of law. We will nonetheless notify you of any data breach affecting your information, and we will do it on the same timeframe the scheme requires.
Some privacy law binds us regardless of the exemption. Since 10 June 2025 there has been a statutory right to sue for a serious invasion of privacy, and it reaches businesses that the Privacy Act itself does not. The exemption is narrower than it looks, and we do not treat it as protection.
2. What we collect, and when
When you contact us through our website
Our enquiry form asks for your name and surname, your email address, and a description of the problem you want help with. You can also give us your company name, your company web address, and email addresses for other people you want included in the conversation.
The problem description is a free-text box, and people often use it to describe how their business works today. That sometimes includes information about their staff. We treat anything you write there as confidential from the moment it arrives.
If you give us other people's email addresses, please only add people who are expecting to hear from us. The form asks you to do this at the point you fill it in. We have no way to tell those people we hold their address until we contact them, and we would rather you asked them first.
When you become a client
We collect what the work requires and no more. In practice that means the names, roles and business contact details of the people we will be working with, and whatever business information is needed to do the job.
Working on your systems means we see your information. Where we connect to your email, your documents or your files, we see what is in them. That is the nature of the work. We do not use it for anyone else, and section 4 sets out exactly where it ends up.
What we do not collect
We do not track you. Our website sets no cookies. There is no analytics, no advertising pixel, no session recording and no behavioural profiling of any kind. We do not know who visits scail.au, how many times, or what they looked at.
Our website loads its typeface from Google Fonts, which means your browser contacts a Google server and Google sees your IP address when the page loads.
3. Why we collect it
Only for these purposes:
- To respond to your enquiry and arrange a conversation.
- To provide the services you have engaged us for.
- To issue invoices and keep the financial records the law requires us to keep.
- To meet our obligations under our agreement with you.
We do not sell information, we do not rent it, and we do not trade it. We do not use your information to market to you unless you have asked us to, and if you ever do, every message will carry a working unsubscribe link.
4. Where your information actually lives
Your information sits in three places: your own systems, our storage, and the services listed in section 5. They are governed differently, and only one of them is ours.
Your own systems
Most client work happens inside your email, document and file systems, using access you grant us. That information stays under your control, and your agreement with your own provider governs where it is stored. If your account is provisioned in Australia, that generally means your mail and files stay in Australia. We will help you confirm your own position if that is useful.
Our storage
We are not the system of record for your files. You are.
Wherever possible we work inside your systems rather than taking copies out of them, so the authoritative version of your material stays where it already lives, under your control and your own backup arrangements.
What we do hold is narrower, and it is real storage rather than a transit point: documents you send us, and the work we produce for you. Those sit on encrypted, access-controlled systems under our control. Today that means a workstation in Perth, Western Australia, and our business email and cloud storage. As the business grows it will extend to server infrastructure we operate. All of them are covered by this policy and by the security commitments in section 9, so what follows is written to cover any of them.
We do not hold a data-region commitment for cloud storage. No region is configured, which means content may sit in any of the provider's data centres, including in the United States. We would rather tell you that than imply a guarantee we do not have.
We should be straight about one limit of this. Because we hold copies rather than the original, the protection that matters most for your material is the protection on your own systems. What we owe you is that our copies are held securely, used only for your work, and deleted when the periods in section 8 run out.
One specific disclosure about our tooling. The AI development tool we use writes a copy of each working session to that workstation as plain text, held for 30 days by default. Where a session involved your material, that copy contains it. It sits behind the machine's own encryption and access controls and is not transmitted anywhere by being written, but it is a real copy in a known location and you are entitled to know it exists.
5. Who else holds your information
We use other companies to run our business, and some of them hold information you give us.
| What it does | Where it holds information | What happens there |
|---|---|---|
| Form handling for our website enquiry form | Operated from outside Australia, hosted in the United States | Holds your enquiry for 30 days on the free service we use, then deletes it. Only applies before you become a client |
| AI processing for analysis, drafting and building | United States | See section 7. This is the one that matters most and it has its own section |
| Your own email, documents and files | Your account's region | Governed by your agreement with your provider, not ours |
| Our email, calendar and file storage | No region configured, so this includes the United States | Our business correspondence and documents |
Your website enquiry does not come straight to us. It goes first to a form-handling service, which then forwards it to our email.
We tell clients which services will touch their information before the work starts, not afterwards, and we name them. If you want the current list of providers by name, ask and we will send it. We have kept the names out of this public document because it changes and a stale list is worse than none, not because we are unwilling to say.
Where we build something for you that needs hosting or a database, we set those up in your name, on your account, with you as the owner. You grant us the access we need to build it and to manage it for you. Three things follow, and all of them are in your favour: the provider's relationship is with you rather than with us, your infrastructure is not something you have to extract from us later, and if our relationship ends you revoke our access and everything keeps running.
We will tell you which providers are involved, and what each will hold, before the work starts.
If the business changes hands. If Scáil, or a part of it, is ever sold, merged or transferred, information we hold may transfer with it. Whoever acquires it is bound by the commitments in this policy on the same terms we are, and we will tell you it has happened. A change of ownership is not a way for these commitments to quietly lapse.
6. Your information going overseas
Some of it does, and we would rather you heard it here. AI processing happens in the United States. Our form handling is operated from outside Australia on United States infrastructure. Our own business storage has no region configured, so content there may sit anywhere including the United States.
Before we use any service that will hold client information, we check where it holds it, what it does with it, and whether it uses it for anything other than providing the service to us. We do not use a tool whose data handling we cannot explain to a client in plain language.
If you need your information to stay in Australia, tell us before the engagement starts. It is a real constraint that we can usually design around, but it has to be a requirement from the beginning rather than a request afterwards.
7. AI tools, model training and your information
This is the question clients ask most, and we would rather set out our actual position than a comfortable one.
Our AI provider operates two different legal regimes, and we are currently on the consumer one. We are moving to the commercial one. The difference is real, so here it is.
| Consumer plan — what we use today | Commercial plan | |
|---|---|---|
| Training on your content | A setting the account holder chooses. Not a contractual restriction | Contractually prohibited |
| How long it is held | 30 days with training off, 5 years with it on | Per the commercial agreement |
| Data processing agreement | None. It sits inside the commercial terms, which do not apply | Included, with standard contractual clauses |
| Who controls the data | The provider | Us, with the provider acting on our instructions |
Where we stand today, stated plainly. Model training is switched off on our account, which puts the retention period at 30 days. That was verified on the account itself on 29 August 2026, not assumed from the provider's general documentation.
What that does and does not give you. Your information is not used to train AI models and is held for 30 days rather than five years. It rests on an account setting rather than a contractual restriction, and there is no data processing agreement between us and the provider. We are moving to a commercial plan, which turns both of those from a setting into a contract.
If your obligations require a data processing agreement to be in place before work starts, tell us at the outset. It is a legitimate requirement, it is one we intend to meet, and it is far better raised before an engagement is scoped than discovered during it.
The rest of our position, which does not depend on any of the above:
- Personal information about identifiable individuals is not entered into any AI tool unless you have agreed to it in writing and we have assessed that tool's data handling as suitable.
- Credentials are never entered into an AI tool.
- We do not use one client's information for another client's work.
- Anything a system we build records about how your business makes decisions belongs to you. We do not reuse it.
Automated decisions. From 10 December 2026, Australian privacy law requires businesses covered by it to disclose where a computer program uses personal information to make a decision that significantly affects someone. Scáil does not currently make any such decision about any individual. Where we build a system for a client that does, we tell the client, we document it, and we build it so the client can meet that obligation themselves.
8. How long we keep it
These periods are commitments, not aspirations.
| What | How long | Why this period |
|---|---|---|
| Website enquiries that do not lead to an engagement | 24 months, then deleted | Our sales cycle is long and a business that enquires today may engage us eighteen months later. Twelve months would delete live conversations; indefinite retention would not be a policy at all |
| Client engagement records and correspondence | 7 years after the engagement ends | Covers the ATO's five-year record-keeping requirement, with margin |
| Documentation of systems we have built | For as long as you hold a licence to use it | You hold a perpetual licence. We cannot support a system whose documentation we have destroyed, and you are entitled to the record of how your own system works |
| Financial records and tax invoices | As required by law | Not ours to choose |
When a period ends, we delete the information or strip out anything that identifies a person. This is done on a scheduled quarterly review rather than on the exact day a period expires, so material may sit for a short time past its period before it is removed. We would rather describe the process accurately than imply a precision we do not have.
You can also ask us to delete your information sooner, and we will, unless we are required to keep it. If we cannot delete something, we will tell you what and why rather than simply refusing.
The form-handling service described in section 5 deletes enquiries from its own systems after 30 days, independently of the periods above.
When an engagement ends, your data remains yours, the documentation of your systems stays with you, and material we hold is retained and then deleted under the periods above.
9. How we protect it
- Credentials never sit in a file or a repository. They are held in an encrypted vault and supplied to a program only at the moment it runs, so the value never lands on disk. The vault holds credentials only. It never holds your information.
- Access is limited to what a job needs. Systems we build are given the narrowest access that lets them work, not the broadest that is convenient.
- Devices are encrypted and access is protected by multi-factor authentication.
- Client work is kept separate. One client's material is not stored with another's.
We will never ask you to email us a password or an access key. If someone appearing to be from Scáil does, it is not us.
No system is perfect and we will not claim otherwise. If information you have given us is ever exposed, we will tell you, we will tell you what was affected, and we will tell you what we are doing about it. We will do that promptly and directly rather than through a notice on a website.
10. Tools that watch how you use them
Many business tools collect usage data and send it to their vendor, and most arrive with it switched on.
Where we recommend or configure a tool that does this, we tell you, and we offer you the option to turn it off. That is a standing practice, not a case-by-case favour.
We do it because a decision about your staff's usage data is yours to make, and because where personal information is involved it can engage obligations under the Privacy Act and, for public sector clients in this state, the Privacy and Responsible Information Sharing Act 2024 (WA). We surface it. You decide.
11. Getting to your information, and correcting it
You can ask us what we hold about you, and we will tell you. You can ask us to correct anything that is wrong, and we will.
Email privacy@scail.au with what you want. We will confirm we have received it within two business days and respond in full within 30 days. There is no charge.
We will check that you are who you say you are before we act. That is not bureaucracy. Without it, anyone who knew your name could ask us for information about you, and we would have promised to hand it over.
If your request is about information we hold for a client, for example because you work for a business that has engaged us, we will point you to that client rather than answer for them. The information is theirs, their own privacy process governs it, and it is not ours to give away on their behalf. We will tell you who to contact rather than leave you to find them.
If we cannot give you something, we will tell you why in writing rather than ignoring the request.
12. If you are not happy
Tell us first, at privacy@scail.au. We will acknowledge your complaint within two business days and give you a substantive answer within 30 days.
Because we comply with the Australian Privacy Principles voluntarily rather than by registration, the Office of the Australian Information Commissioner does not have jurisdiction to investigate a complaint against us. We think you should know that before you complain, not after.
13. Changes to this policy
We will update this policy when what we do changes. The current version always lives at scail.au/privacy and carries a version number and a date.
This policy is reviewed annually, and immediately whenever a service that touches client information is added, removed or materially changed.
If we change something that materially affects information we already hold about you, we will tell you directly. We will not rely on you noticing a new date on a web page.
Superseded versions are retained. If you want to see the version that applied when you engaged us, ask and we will send it.
14. Contacting us
FAO: The Managing Principal, Scáil Email: privacy@scail.au
Sources
Researched 29 August 2026 against primary sources. Every legal statement above rests on one of these, and anything not verifiable against a primary source has been left out.
- Privacy Act 1988 (Cth), s 6D, small business operator and the exceptions to it.
- Office of the Australian Information Commissioner, Australian Privacy Principles quick reference and APP 1 guidelines.
- OAIC, guidance on the small business exemption and on opting in to the Privacy Act.
- OAIC, statutory tort for serious invasions of privacy, commenced 10 June 2025.
- Privacy and Other Legislation Amendment Act 2024 (Cth), APPs 1.7 to 1.9, automated decision-making transparency, commencing 10 December 2026.
- Australian Business Register, ABN 63 612 682 434, entity and GST details verified 29 August 2026.
- Our AI provider's published commercial and consumer terms, for the training, retention and data processing agreement positions in section 7. The consumer training setting was verified on the account itself.
- The form-handling service's published documentation for the 30-day retention figure. Their own documentation is inconsistent on this point and we have written to the less favourable reading rather than the more flattering one.
Also relevant, though not relied on above: the Privacy and Responsible Information Sharing Act 2024 (WA) commenced 1 July 2026 and binds WA public entities including universities; it does not bind Scáil, but it binds several of our clients' customers and is relevant to what those clients will ask of us.
Scáil is a trading name of Lagantyne Pty Ltd. Questions about this policy: privacy@scail.au.