• Features
  • Pricing
  • About
  • Blog
  • Updates
  • Contact
Log in
  • Features
  • Pricing
  • About
  • Blog
  • Updates
  • Contact

Privacy Policy

1. OVERVIEW & SCOPE

This Privacy Policy explains how Tim Jones Consulting Pty Ltd ACN 655 446 414 and our related bodies corporate (“we”, “our”, “us”), collect, use, store, protect, share, and disclose your personal information. We act as the 'Data Controller' for the personal information we process, unless otherwise stated.

This policy applies to this website and all related websites, web and mobile applications, services, and tools (together the “Website” or "Services"). By visiting or using the Website, you acknowledge that you have read and understood this Privacy Policy.

This policy incorporates requirements from the Australian Privacy Act 1988 (Cth) and, where applicable, the EU General Data Protection Regulation (GDPR) for individuals located in the European Economic Area (EEA).

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting an updated version on the Website and/or via email if appropriate. We encourage you to review this policy periodically. The date of the last update will be indicated at the top/bottom of the policy.

2. WHAT IS PERSONAL INFORMATION?

‘Personal Information’ (or 'Personal Data' under GDPR) means any information relating to an identified or identifiable natural person ('Data Subject'). This includes information or an opinion that allows you to be reasonably identified, such as your name, email address, phone number, location data, online identifiers (like IP addresses or cookie IDs), and factors specific to your physical, physiological, genetic, mental, economic, cultural, or social identity. It doesn't matter whether the information or opinion is true or not, or whether it is recorded in a material form or not.

3. INFORMATION WE COLLECT

We collect personal information in the following ways:

  • Directly from you: When you provide it to us via forms on the Website, during registration, when contacting us (email, phone, in person), making offers for property, registering interest, processing payments, or interacting with our representatives.
  • Automatically: When you use our Website, we collect technical information sent by your device (computer, mobile). This includes IP address, device type/ID, browser type, operating system, referring URLs, pages viewed, time/date stamps, geo-location data (if enabled), mobile network info, and standard web log data. We use Cookies and similar technologies for this (see Section 7).
  • From Third Parties: From related entities, representatives (yours or ours), service providers, publicly available sources, operators of linked websites/applications, and advertising networks, where permitted by law.

The types of personal information we may collect include:

  • Contact Details: Name, address, email address, telephone numbers.
  • Identification Details: Date of birth, gender (where necessary and lawfully collected), information to verify identity (e.g., driver's license details for specific transactions, collected with explicit consent or legal obligation).
  • Professional Details: Information about your agents or service providers (e.g., lawyer, finance provider) if relevant to a transaction.
  • Financial Information: Bank account or credit card details for processing payments related to our services (processed securely via compliant payment gateways).
  • Transaction & Enquiry Details: Information about products/services you've used, enquired about, or expressed interest in (e.g., property preferences).
  • Technical & Usage Data: As described under 'Automatically' above (IP address, device info, Browse activity, etc.).
  • Marketing Preferences: Your choices regarding receiving marketing communications from us.

4. HOW WE USE YOUR INFORMATION (PURPOSES & LAWFUL BASIS)

We use your personal information only for specific purposes and rely on a valid lawful basis under GDPR and Australian law for each purpose. These include:

  • Providing and Managing Services: To offer, administer, and deliver our products and services (e.g., property information, managing estates, facilitating transactions).
    Lawful Basis (GDPR): Primarily Contract Necessity (to fulfil our agreement with you); sometimes Legitimate Interests (to operate our core business).
  • Communication: To respond to your enquiries, provide customer support, send service-related notices (e.g., updates, security alerts), and manage our relationship with you.
    Lawful Basis (GDPR): Contract Necessity; Legitimate Interests (effective communication).
  • Website Operation & Improvement: To operate, maintain, secure, personalize, and improve the Website and our Services, analyse usage patterns, generate aggregated statistics, and conduct research.
    Lawful Basis (GDPR): Legitimate Interests (to ensure functionality, security, and improve offerings); Consent (for non-essential cookies/tracking technologies - see Section 7).
  • Marketing & Promotions: To send you information about new estates, developments, investment opportunities, or other services we think may interest you, where you have agreed to receive such communications.
    Lawful Basis (GDPR): Consent (for electronic direct marketing like email/SMS); Legitimate Interests (may apply in limited B2B contexts or for existing customers regarding similar products, subject to opt-out - requires careful assessment). See Section 10 for your choices.
  • Compliance & Legal Obligations: To comply with applicable laws, regulations, court orders, or requests from government/regulatory authorities (including the OAIC and EU/EEA authorities); to enforce our Terms of Use and other policies; to detect, prevent, and investigate fraud, security breaches, or potentially prohibited/illegal activities; and to protect the rights, property, or safety of us, our users, or others.
    Lawful Basis (GDPR): Legal Obligation; Legitimate Interests (protecting our business and rights).
  • Verification: To verify information for accuracy or completeness (e.g., identity verification where required).
    Lawful Basis (GDPR): Legal Obligation; Legitimate Interests; Contract Necessity.
  • Business Transactions: In connection with a proposed or actual merger, acquisition, or sale of business assets.
    Lawful Basis (GDPR): Legitimate Interests (conducting business transactions).

We do not collect 'special categories' of personal data (sensitive data like health, race, political opinions under GDPR) unless necessary for a specific purpose and with your explicit consent or as permitted by law.

5. SHARING & DISCLOSURE OF PERSONAL INFORMATION

We may share your personal information with the following categories of recipients, only where necessary and based on a lawful basis:

  • Our Related Bodies Corporate: Within our corporate group for operational purposes.
  • Service Providers: Third parties who provide services on our behalf, such as web hosting, IT support, payment processing, data analytics, email/SMS delivery, marketing platforms, CRM systems, cloud storage, professional advisors (lawyers, accountants, auditors, insurers), and debt collectors. These providers are contractually bound to protect your data and use it only for the purposes we specify.
  • Your Representatives: Your authorized agents, lawyers, or finance providers, when necessary for a transaction you are involved in.
  • Business Partners: Other companies or individuals involved in providing services related to estates or developments we manage (e.g., real estate agents, developers engaging our services), where necessary to fulfil service requests.
  • Legal & Regulatory Authorities: Government agencies, courts, regulators, and law enforcement bodies where required or authorized by law, or to protect our legal rights.
  • Third Parties in Business Transactions: Entities involved in a potential or actual merger, acquisition, or asset sale involving our business.
  • Third Parties with Your Consent: Other third parties where you have explicitly consented to the disclosure.

We do not sell your personal information to third parties.

6. INTERNATIONAL DATA TRANSFERS

Some of our service providers or related bodies corporate may be located or process data outside of Australia and/or the European Economic Area (EEA). This means your personal information might be transferred to countries with different data protection laws than your own.

When we transfer personal information of individuals in the EEA to countries outside the EEA that have not been deemed adequate by the European Commission, we rely on specific GDPR-approved transfer mechanisms to ensure your data is protected. These may include:

  • The European Commission's Standard Contractual Clauses (SCCs).
  • Binding Corporate Rules (BCRs) for intra-group transfers.
  • Other mechanisms permitted under GDPR.

Where we transfer data outside Australia (for non-EEA individuals), we take reasonable steps to ensure the overseas recipient handles the information in accordance with the Australian Privacy Principles, often through contractual clauses.

In limited circumstances, we may rely on your explicit consent for a specific transfer, after informing you of the potential risks due to the absence of an adequacy decision or appropriate safeguards.

You can request more information about the safeguards we use for international transfers by contacting us.

7. COOKIES AND SIMILAR TECHNOLOGIES

We and our third-party service providers (e.g., for analytics, advertising) use cookies, pixel tags, and similar technologies (“Cookies”) to collect information automatically when you use our Website. Cookies are small text files placed on your device.

We use Cookies for purposes such as:

  • Essential Operations: Enabling basic site functionality and security. These are necessary for the Website to work correctly.
  • Performance & Analytics: Understanding how visitors interact with our Website, measuring usage, improving performance, and remembering your preferences (e.g., language).
  • Marketing & Advertising: Personalizing content and advertisements, measuring the effectiveness of campaigns, and enabling targeted advertising (sometimes based on your activity across different sites).

Your Consent (Especially for EEA users): For Cookies that are not strictly necessary for the operation of the Website, we require your explicit consent before placing them on your device, particularly if you are accessing the site from the EEA. We obtain this consent through a Cookie Consent Banner/Manager when you first visit our site (or subsequently if you clear your cookies). You can manage your preferences and withdraw your consent at any time via the Cookie Consent Manager [Link to Cookie Settings/Manager if you have one].

Most web browsers allow you to control Cookies through their settings. However, disabling essential Cookies may affect the functionality of the Website. Disabling non-essential Cookies will prevent tracking for those specific purposes.

This Privacy Policy applies to personal information collected via Cookies.

8. DATA SECURITY

We take reasonable technical and organisational measures to protect your personal information from misuse, loss, unauthorised access, modification, or disclosure. These measures include:

  • Using secure servers and data encryption (e.g., SSL/TLS).
  • Implementing access controls to limit who can access personal information.
  • Regularly reviewing our security practices.
  • Training staff on data privacy and security obligations.
  • Using secure payment gateways for financial transactions.

However, the transmission of information via the internet is not completely secure. While we do our best to protect your data, we cannot guarantee the security of information transmitted to our Website; any transmission is at your own risk. Once we receive your information, we use strict procedures and security features to try to prevent unauthorised access.

9. DATA RETENTION

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements, and resolving disputes.

To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether we can achieve those purposes through other means, and the applicable legal requirements.

For example, contact details for marketing may be kept until you withdraw consent. Transaction data may be kept for several years to comply with tax and accounting laws. Once personal information is no longer needed, we take reasonable steps to securely destroy or permanently anonymise it.

10. YOUR PRIVACY RIGHTS AND CHOICES

Depending on your location and applicable law (including the Australian Privacy Act and GDPR for EEA residents), you have certain rights regarding your personal information:

  • Right to Access: You can request a copy of the personal information we hold about you.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal information.
  • Right to Erasure ('Right to be Forgotten'): You can request deletion of your personal information under certain conditions (e.g., it's no longer necessary for the purpose collected, you withdraw consent and there's no other legal ground).
  • Right to Restrict Processing: You can request that we limit the processing of your personal information under certain circumstances (e.g., while accuracy is contested).
  • Right to Data Portability: Where processing is based on consent or contract and carried out by automated means, you can request to receive your personal information in a structured, commonly used, machine-readable format, or have it transferred directly to another controller where technically feasible.
  • Right to Object: You have the right to object to processing based on legitimate interests. We must then stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for legal claims. You also have an absolute right to object to processing for direct marketing purposes.
  • Right to Withdraw Consent: Where we rely on consent as the lawful basis, you can withdraw your consent at any time (this won't affect the lawfulness of processing before withdrawal).
  • Rights Related to Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects on you, except under certain conditions. (Specify if you use such processes).
  • Marketing Choices: You can opt-out of receiving direct marketing communications from us at any time by using the unsubscribe link in emails/SMS or by contacting us directly. We will process your request promptly.

To exercise any of these rights, please contact us using the details in Section 14. We will respond to your request within a reasonable timeframe (usually within one month for GDPR requests, subject to extensions). We may need to verify your identity before processing your request. There is generally no fee to exercise these rights, but we may charge a reasonable fee or refuse to act if requests are manifestly unfounded, excessive, or repetitive.

11. IF WE CAN’T COLLECT YOUR PERSONAL INFORMATION

If you do not provide us with the personal information we request or need, we may not be able to provide you with our Services, respond to your enquiries, process transactions, or fulfil other purposes outlined in this policy.

12. DATA BREACHES

We have procedures in place to detect and respond to suspected personal data breaches. In the event of a breach that is likely to result in a risk (or high risk under GDPR) to the rights and freedoms of individuals, we will comply with our legal obligations to notify the relevant supervisory authorities (such as the OAIC in Australia and relevant EU/EEA authorities under GDPR within 72 hours where feasible) and affected individuals, where required by law.

13. LINKS TO OTHER WEBSITES

Our Website may contain links to third-party websites, applications, or services ("Linked Sites") that are not operated by us. These links are provided for your convenience. We have no control over, and are not responsible for, the content or privacy practices of Linked Sites. We recommend you review the privacy policies of any third-party sites you visit.

14. CONTACT US & COMPLAINTS

If you have any questions about this Privacy Policy, wish to exercise your rights, or have concerns or complaints about our handling of your personal information, please contact our Privacy Officer / Data Protection Contact:
Email: hello@getatom.ai

We take complaints seriously and will investigate any complaint received and respond to you within a reasonable timeframe, outlining the steps we will take to resolve it.

Lodging a Complaint with Authorities: If you are not satisfied with our response, or believe we are not processing your personal data in accordance with the law, you have the right to lodge a complaint with the relevant data protection authority.

  • In Australia: The Office of the Australian Information Commissioner (OAIC).
    Website: www.oaic.gov.au
    Phone: 1300 363 992
    Email: enquiries@oaic.gov.au
  • In the EEA: The data protection supervisory authority in your country of habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities can be found here: https://edpb.europa.eu/about-edpb/about-edpb/members_en

Last Updated: 29th April 2025

An AI study assistant for asking, writing, reading and revising - in your browser and in Chrome.

Product

  • Features
  • Pricing
  • Updates
  • Chrome extension

Company

  • About
  • Blog
  • Contact
  • Review us on the Chrome Web Store

Legal

  • Privacy Policy
  • Terms of Service
© 2026 AtomAI. All rights reserved.