Privacy Policy
Last updated: 1 August 2026 · Version 1.0
Interlink AI builds and operates AI systems, CRM and automation for businesses, and runs its own ventures on the same platform. That means we handle personal information both as a business in our own right and on behalf of clients. This policy sets out what we collect, why, who receives it, and how you control it.
1. Who we are
Interlink AI is a business name of Hayden Clive Mitchell trading as Interlink AI, ABN 60 460 171 068, registered for GST and based in Victoria, Australia. In this policy, “we”, “us” and “our” mean Interlink AI.
Privacy contact
Email: hayden@interlinkai.io
ABN: 60 460 171 068
A postal address is available on request.
We aim to acknowledge privacy enquiries within 5 business days and resolve them within 30 days.
2. What this policy covers
This policy applies to interlinkai.io, the Interlink AI platform and admin application, and our dealings with prospective clients, clients, partners and other business contacts.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we send commercial electronic messages we also comply with the Spam Act 2003 (Cth), and telephone contact is subject to the Do Not Call Register Act 2006 (Cth).
Our ventures and client brands each publish their own privacy policy covering the people who deal with that brand. This policy does not replace them.
3. What we collect
3.1 Enquiries through this website
- Name, email address and business name
- The category of help you select and any message you choose to write
- Technical details captured with the submission, including the page used and the time
3.2 Clients, partners and business contacts
- Name, business name, role, email address, phone number and postal or billing address
- Correspondence, meeting notes and project documentation
- Account details for the platform, including login email
- Invoices, purchases, payment status and related records
We do not collect or store full card details. Card payments are processed by Stripe, which handles that information directly under its own terms.
3.3 Platform users
- Login email, authentication records and the role or permissions assigned to the account
- Activity within the platform, such as records created, edited or viewed, kept for security and support
Access to the Interlink AI platform is invite only. We do not offer public self-service sign-up.
3.4 Website and technical information
- IP address, browser type, device type, referring page and pages viewed
- Cookies and similar technologies, as described in our Cookie Policy
- Server logs and error reports used to keep the service running
We do not knowingly collect information from anyone under 18, and we do not collect sensitive information as defined in the Privacy Act, such as health, racial or ethnic origin, or political or religious information. Please do not send us that information.
4. How we collect it
We collect personal information directly from you wherever reasonably practical, through:
- The contact form on interlinkai.io
- Email, phone and messaging correspondence with us
- Calls and meetings, including scheduling tools you use to book
- Your use of the Interlink AI platform
- Automatically, through cookies and analytics, and only to the extent you allow on our cookie banner
If you provide personal information about someone else, such as a colleague, you must have their authority to do so.
5. Why we use it
| Purpose | Whose information |
|---|---|
| Responding to enquiries and scoping potential work | Prospective clients |
| Delivering, operating and supporting the systems we build | Clients and platform users |
| Account administration, invoicing and payment | Clients |
| Service messages such as sign-in links and system alerts | Platform users |
| Direct marketing, where permitted and with an opt out | Business contacts |
| Improving the website and product, preventing fraud or misuse | All |
| Meeting our legal, tax and record keeping obligations | All |
We do not use personal information for automated decision-making that produces a legal or similarly significant effect on an individual.
We do not use client data, or personal information collected through our services, to train foundational AI models.
6. Who we disclose it to
6.1 Service providers
We use third party providers to run the business. They may access personal information only to perform their function for us.
| Provider | Function |
|---|---|
| Vercel | Website and application hosting |
| Supabase | Database, authentication and file storage |
| Email, documents and sign-in | |
| n8n (self-hosted) | Workflow automation |
| Resend and MailerLite | Transactional and marketing email delivery |
| Twilio | SMS delivery, where enabled |
| Stripe | Payment processing and invoicing |
| Sentry and PostHog | Error monitoring and product analytics |
| Anthropic and other AI providers | Model inference for features you use, under terms that prohibit training on our data |
6.2 Other disclosures
- Our professional advisers, such as accountants and lawyers, under confidentiality
- Where required or authorised by law, including to courts, regulators or law enforcement
- To a buyer or successor if we sell or restructure the business, subject to equivalent privacy protection
We do not sell, rent or trade personal information to data brokers, list sellers or marketing aggregators.
7. Information we handle for clients
When we build or operate a system for a client, that client is responsible for the personal information in it and decides what is collected and why. In that situation we act on the client's instructions as a service provider, not as the owner of the data.
If you dealt with one of our client brands and want access, correction or deletion, contact that brand directly. If you are not sure who holds your information, email us and we will point you to the right organisation.
We keep client data logically separated per venture, restrict staff access by role, and do not use one client's data for another client's benefit.
8. Overseas disclosure
Some of our providers store or process data outside Australia, principally in the United States and the European Union. This includes the hosting, database, email, analytics, AI and error monitoring providers listed above.
Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles, including relying on the provider's contractual data protection commitments. By using our services you acknowledge that information may be handled overseas on this basis.
9. Direct marketing and opting out
We may send business contacts marketing about our services where you have consented or would reasonably expect it. Every marketing message includes a working unsubscribe, and we honour opt outs promptly.
To opt out, use the unsubscribe link in any message or email hayden@interlinkai.io. You may also ask us not to disclose your information for direct marketing purposes, and ask us to tell you the source of information we hold about you.
10. Cookies and tracking
We use cookies and similar technologies. Non-essential cookies, including analytics, stay switched off until you accept them on our cookie banner, and you can change your choice at any time. See the Cookie Policy for detail.
11. Security and retention
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption in transit, access controls and role-based permissions, secrets held server-side only, row level security on our database, and monitoring and error tracking.
No system is completely secure, and we cannot guarantee the absolute security of information transmitted to us.
We keep personal information only as long as we need it for the purposes above or to meet legal and record keeping obligations, generally up to seven years for transaction records. When it is no longer needed we destroy or de-identify it.
12. Data breaches
We maintain a data breach response plan. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the breach affects data we hold for a client, we will notify that client without undue delay.
13. Access and correction
You can ask us for a copy of the personal information we hold about you, and ask us to correct anything inaccurate, out of date or incomplete. Email hayden@interlinkai.io.
We will need to verify your identity. We normally respond within 30 days and do not charge for a request, although we may charge a reasonable cost for supplying information in an unusual format. If we refuse access or correction we will tell you why in writing and how to complain.
You can also ask us to delete information we hold about you. We will do so unless we are required to keep it by law or need it to resolve a dispute.
14. Complaints
If you think we have breached the Australian Privacy Principles, email hayden@interlinkai.io with the details. We will acknowledge within 5 business days and respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner:
- Web: oaic.gov.au
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001
15. Changes to this policy
We may update this policy as our services or the law change. The current version is always available at interlinkai.io/privacy, with the version number and date at the top. Material changes affecting how we handle your information will be notified to active clients by email.