Skip to content

Independent. Non-partisan.
For Australia’s AI future.

Privacy policy

Australian Council on AI Strategy (ACAIS)
Effective: Friday 25 September 2026
This policy applies to acais.au.

1. Who we are

The Australian Council on AI Strategy (ACAIS) is an independent, non-partisan charitable body. We exist to help Australia make AI choices in the national interest: informed, precise, and on Australia’s own terms.

This policy explains what personal information we collect through our website, why we collect it, how we hold it, who we disclose it to, and how you can ask to see it, correct it, or complain. It is written in plain language because the people who use this site should not need a lawyer to understand what happens to information they give us.

Legal entity: Australian Council on AI Strategy Ltd.
ABN: 58 700 593 326.

2. What this policy covers

This policy covers personal information we collect when you:

  • Send us a message through the contact form on this website

  • Subscribe to receive ACAIS analysis and briefings

  • Visit the website (limited technical information created by that visit)

It also covers names, roles and biographical information about our leadership that we publish on the site with those people’s agreement.

It does not currently cover employment records, recruitment, event registration, donations or research-participant records. We do not operate those processes through this website today. If we start to, we will update this policy before we collect that information.

A separate, short notice on each form will repeat the purpose of that collection at the point you submit it.

3. How we treat the Privacy Act

The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set the national standard for handling personal information in Australia. Whether ACAIS is legally required to comply as an “APP entity” — including whether the small-business exemption in the Act applies to us — is a matter our lawyers will confirm. We use the APPs to guide our handling of personal information and comply with the privacy obligations that apply to us.

In this policy, “personal information” has the same meaning as in the Privacy Act: information or an opinion about an identified person, or a person who is reasonably identifiable.

We do not sell or rent personal information. We do not buy mailing lists. We do not use the contact form or the newsletter list to profile you, score you, or target advertising.

4. What we collect, and when

Contact form

When you write to us through the contact form, we collect:

  • First name and last name

  • Email address

  • Organisation, if you choose to give it

  • The message you write

  • The date and time of the submission, and any technical identifiers the form service records with it (for example, an IP address)

We collect this so we can read your message, reply, and keep a record of the correspondence. If you do not provide a name and a working email address, we cannot respond through this form.

The message field is free text. We do not ask for sensitive information (for example health information, political opinions, or membership of a professional association). Please do not include it. If you do, we will only use it to deal with your enquiry.

Newsletter

When you subscribe to stay informed, we collect:

  • First name and last name

  • Email address

  • Organisation, if you choose to give it

  • The date of subscription, your confirmation of it, and later unsubscribe or bounce records

We use confirmed opt-in. When you subscribe, MailerLite sends a confirmation email to the address you gave us, and we add you to the list only after you follow the link in it. If you do not confirm, we do not send you the newsletter and we do not keep your details on the list.

We collect this so we can send you ACAIS analysis and briefings, and so we can honour an unsubscribe. Subscribing is optional. A contact enquiry is not a newsletter subscription, and a newsletter subscription is not a request for us to reply as if you had written to us.

Visiting the website

Our hosting provider’s systems typically record technical information about a visit: the pages requested, the date and time, your browser and device type, and the IP address from which the request came. We use this to keep the site available, to diagnose faults, and to protect it against misuse. We do not use it to identify you in the ordinary course of running the site. A law enforcement or regulatory body with lawful authority could require us to produce logs.

Information we did not ask for

If someone sends us personal information we did not solicit — for example an unsolicited CV, or another person’s details in a message — we will decide whether we could have collected it under this policy. If we could not, we will destroy or de-identify it where that is lawful and practicable. If we could have collected it, we will handle it as we handle the equivalent information we collect ourselves.

Children

This website is for adults concerned with public policy. We do not knowingly collect personal information from children.

5. Why we collect it

We collect personal information only where it is reasonably necessary for our work:

  • To answer enquiries about our analysis, our programmes, media comment, or how we operate

  • To send the newsletter you asked for, and to keep that list accurate

  • To operate, secure and improve the website

  • To publish, with their agreement, who governs and leads ACAIS

  • To meet a legal obligation, or to establish, exercise or defend a legal claim

If we later want to use information for a purpose that is not related to these, we will explain that purpose and ask for your consent first, unless the law allows or requires us to proceed without it.

You can deal with us without identifying yourself where that is practicable. It is not practicable for a reply through the contact form, or for a newsletter, because both require a working email address.

6. How we hold it, and for how long

Contact submissions are received by Netlify Forms and delivered to hello@acais.au. They are stored by that form service and in the inbox of the people who handle enquiries.

Newsletter details are stored by MailerLite. That provider also holds the sending history needed to deliver mail and to record unsubscribes.

Website logs are stored by Netlify. Website content, including leadership biographies and portraits, is managed in Storyblok. Contact submissions and newsletter lists are not stored in Storyblok.

Access is limited to people who need it to do this work: the ACAIS staff who read enquiries and send briefings, and the service providers and named contractors who operate those systems for us. We take reasonable steps to protect personal information against misuse, interference, loss, and unauthorised access, modification or disclosure. We do not describe those steps in detail here, because that would weaken them. No transmission over the internet is completely secure.

We do not apply one fixed retention period to every record. We keep personal information for as long as it is reasonably needed for the purposes described in this policy, or to meet legal obligations:

  • Contact enquiries: for as long as reasonably needed to respond, manage related follow-up or an ongoing relationship, and keep a record needed to resolve a complaint or legal claim.

  • Newsletter records: while you remain subscribed. After you unsubscribe, we may keep the minimum information needed to record your opt-out, prevent further unwanted mail and demonstrate consent where necessary. Unsubscribing stops newsletters; it does not automatically erase every record.

  • Website logs: for the retention periods applied by Netlify to the services we use. Relevant records may be kept longer where reasonably needed to investigate a security incident or meet a legal obligation.

When personal information is no longer reasonably needed and we are not required by law to keep it, we take reasonable steps to delete it or de-identify it. This includes information held for us by service providers.

If we become aware of a data breach, we will assess it and take steps to contain it and reduce potential harm. We will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where the Notifiable Data Breaches scheme requires us to do so.

7. Who we disclose it to, including overseas

We disclose personal information to the service providers who make this website and these communications work, and only for that work:

Service providers

WhatWhoWhere they are likely to hold it
Contact form submissionsNetlify FormsUnited States
Newsletter subscriptions and mailMailerLiteEuropean Union — the Netherlands for the current MailerLite platform, Germany for Classic, and Poland for group services
Website hosting and logsNetlifyUnited States, with website delivery through an international network
Website content, including leadership biographies and portraitsStoryblokGermany (our selected EU hosting region)
Email correspondence and copies of enquiriesMicrosoft email servicesThe region Microsoft sets for our tenancy, and other countries where Microsoft operates
Website analyticsNetlify AnalyticsUnited States

Those providers may also use subprocessors of their own. We will take reasonable steps, including through our contracts with them, to require handling that is consistent with this policy and with the APPs.

We may disclose personal information if the law requires it, or if it is necessary to deal with a serious threat to life, health or safety, or to our legal rights.

We do not disclose contact or newsletter information to funders, journalists, or other third parties for their own use. We do not disclose it to anyone because they asked us who has been in touch.

These services involve handling information outside Australia. The table identifies the relevant storage or processing locations we can specify. Providers may use other locations for delivery, support or their own subprocessors. Where APP 8 applies, we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs.

8. The newsletter, consent and opting out

We send the newsletter only to people who have asked for it. Every newsletter will identify ACAIS as the sender and include a working unsubscribe link. You can also ask us to remove you by writing to hello@acais.au. We will process an unsubscribe promptly.

Australian law on commercial electronic messages (the Spam Act 2003 (Cth)) sits alongside this policy. We will not use a contact-form message as consent to add you to the newsletter.

9. Cookies and analytics

We use Netlify Analytics to count page views and see which sites link to us. It works from our hosting provider’s server records, so it does not use cookies, does not add any tracking code to this website, and does not identify you.

The site and its form providers may use cookies or similar technology that are necessary for a page or a form to work. You can block cookies in your browser. If you do, some forms may not submit.

We do not use advertising cookies or social-media tracking pixels. If we introduce another analytics service, we will name it here and update this policy before it is switched on. Analytics is not required to use the site.

10. Access and correction

You can ask us what personal information we hold about you, and you can ask us to correct it.

Write to hello@acais.au. Tell us enough for us to find the information — at least the email address you used, and whether the request concerns a contact message, a newsletter subscription, or both.

We aim to respond within 30 days. If we need more time, we will explain why and keep you informed. If we refuse a request in whole or in part, we will say so in writing and explain why, and how you can complain.

There is no charge to make a request. We will not charge to give you access to the small amount of information this website holds about you.

If you only want to leave the newsletter, unsubscribing yourself is faster than an access request.

11. Complaints

If you think we have mishandled your personal information, write to us first at hello@acais.au. Please include:

  • Your name and a contact email address

  • What happened, and when

  • What you would like us to do

We will acknowledge your complaint and aim to respond within 30 days.

If you are not satisfied with our response, or you do not receive one in that time, you can complain to the Office of the Australian Information Commissioner. The OAIC generally expects you to have complained to us first.

Whether the OAIC can investigate a particular complaint depends on whether the Privacy Act covers the organisation complained about. That is the legal question noted in section 3. We will still deal with a complaint made to us under this policy.

12. Other websites

Our pages may link to other organisations. Their privacy practices are their own. This policy applies only to information we collect.

If you contact us through a third-party service (for example a professional network), that service’s terms also apply to whatever you send through it.

13. Changes to this policy

We will keep this policy aligned with what we actually do and publish the updated text on this page.

We will note material changes prominently on this page and update the effective date. Where the law requires additional notice or consent, we will provide or seek it.

The published policy on this page is the current one.

14. How to contact us

For access, correction, complaints, or questions about this policy:

For a general enquiry that is not about privacy, use the contact form on this website.