Privacy Policy | AgentReady
Legal

Privacy Policy

This policy explains what information AgentReady collects, why we collect it, who we share it with, and the choices you have. We've written it in plain English — no dark patterns, no buried clauses.

Effective: 1 January 2026 Last updated: 1 January 2026 Applies to: agentready.au and the AgentReady audit platform

AgentReady™ ("AgentReady", "we", "us" or "our") provides an AI readiness auditing platform that evaluates how AI systems discover, understand and recommend websites. We are based in Australia and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle the personal data of people in the European Economic Area or the United Kingdom, we also comply with the General Data Protection Regulation (GDPR).

By using our website or requesting an audit, you agree to the handling of your information as described in this policy. If you don't agree, please don't use the service.

Information we collect

We only collect what we need to run an audit, respond to an enquiry, and process a payment. Here's the full list.

CategoryWhat it includesWhen we collect it
Audit input The website domain or URL you submit for analysis. When you run a free or paid audit.
Contact details First and last name, business email address, company name, and company website. When you submit the contact or quote form.
Business profile Industry, company size, the services you're interested in, indicative budget range, and any comments you choose to include. When you submit the contact or quote form.
Payment details Billing information needed to complete a purchase. Card numbers are entered directly with our payment processor and are never transmitted to or stored on our servers. When you buy a paid report or engagement.
Technical data IP address, browser and device type, referring page, and request timestamps, captured by our servers in the ordinary course of operating the service. Automatically, on each request.
Audit output The scores, findings and recommendations our engine generates for a domain you submit, stored against your audit record. When an audit completes.
Correspondence The content of emails and messages you send us, and our replies. When you contact us.
We don't collect sensitive information

We do not ask for, and do not want, sensitive information as defined by the Privacy Act — health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, or biometric data. Please don't include any of it in a form field or email.

Providing information about other people

If you give us someone else's personal information — for example, a colleague's email address so they receive a report — you confirm you're authorised to do so and that they've been made aware of this policy.

How audits work, and what they touch

When you submit a domain, our crawler requests publicly accessible pages on that website — the same pages any search engine or AI crawler can reach — and analyses signals such as structured data, content depth, trust markers, robots.txt directives and technical accessibility.

  • We only read what's public. Our crawler does not log in, bypass authentication, or attempt to access private, gated or password-protected areas of a site.
  • We only crawl what you submit. We fetch the domain you enter and pages reachable from it. We do not crawl unrelated sites, and we do not build a background index of the web.
  • We respect robots.txt. We follow standard crawling etiquette, honour robots directives, and rate-limit our own requests so an audit never places meaningful load on the site being analysed.
  • The audit is read-only. We do not modify, submit forms to, or place any code on the site being audited.
  • Audit results are cached briefly. To avoid re-crawling the same site repeatedly, results are held in a short-lived server cache (approximately 30 minutes) before being discarded.
  • Rate limiting uses your IP. We count requests per IP address over a rolling one-minute window to prevent abuse. These counters are held in memory only and are not written to a database or used to build a profile of you.
You are responsible for ensuring you have the right to request an audit of any website you submit.

Auditing a website you neither own nor have permission to assess may breach the terms of service of that site. Please only submit domains you own or are authorised to analyse.

How we use your information

We use the information described above to:

  • Run the audit you requested and generate your AI Readiness Score, report and recommendations.
  • Respond to your enquiry, prepare a quote, and deliver the services you've engaged us for.
  • Process payments, issue receipts and maintain financial records.
  • Send you service communications — your report, your quote, delivery updates, and important changes to the service.
  • Operate, secure, debug and improve the platform, including protecting it against abuse and fraud.
  • Produce aggregated and de-identified insights about AI readiness across industries. This output never identifies you or your business.
  • Meet our legal, tax and regulatory obligations.

Marketing

If you've given us your details, we may occasionally send you information about AgentReady services and relevant AI visibility research. Every marketing email includes an unsubscribe link, and we'll action opt-outs promptly. Service communications relating to an audit or engagement you've requested are not marketing and will continue regardless.

What we never do

We do not sell your personal information. We do not rent or trade contact lists. We do not use your data to train third-party AI models, and we do not disclose your report or enquiry details to your competitors.

Who we share your information with

We share personal information only with the service providers we need to run AgentReady, and only to the extent required. Each is bound by contract to protect your data and to use it solely for the purpose we've engaged them for.

ProviderPurposeData involved
SupabaseDatabase hosting for leads, quotes and audit records.Contact details, business profile, audit records.
StripePayment processing. Stripe is PCI-DSS compliant and handles card data directly.Billing and payment details.
ResendTransactional email delivery — reports, quotes and service notifications.Name and email address.
Hosting & infrastructureServing the website and running the audit engine.Technical data, including IP address.

We may also disclose personal information where we're required or permitted by law — for example, in response to a court order, a lawful request from a regulator or law enforcement, or to establish or defend a legal claim. If AgentReady is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that transaction; we'll notify you before it becomes subject to a materially different privacy policy.

Storage, security and overseas transfer

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our measures include:

  • Encryption in transit and at rest — all traffic is served over HTTPS/TLS, and data is encrypted at rest by our database provider.
  • Server-side input validation — every submitted domain is normalised and validated on the server before it reaches the audit engine.
  • SSRF protections — the crawler is blocked from resolving internal, private and loopback network addresses, so it cannot be pointed at infrastructure it shouldn't reach.
  • Rate limiting — per-IP request limits protect the platform against abuse and automated scraping.
  • Access controls — only the people who need production access have it, and API keys are held as server-side secrets that are never exposed to the browser.
No system is perfectly secure

We work hard to protect your information, but no method of transmission or storage is completely secure and we cannot guarantee absolute security. If we become aware of a data breach likely to result in serious harm, we'll notify you and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.

Overseas recipients

Some of our service providers store or process data outside Australia, including in the United States and the European Union. Where we transfer personal information overseas, we take reasonable steps to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, and — for EEA and UK data — we rely on appropriate safeguards such as Standard Contractual Clauses.

How long we keep your information

We keep personal information only for as long as we need it for the purpose it was collected, or for as long as the law requires.

  • Audit cache: approximately 30 minutes, then discarded automatically.
  • Rate-limit counters: held in server memory for a rolling one-minute window; not persisted.
  • Server logs: up to 30 days, then rotated out. We use them to diagnose faults and investigate abuse, not to profile visitors.
  • Enquiries and quotes: retained while we're in contact with you and for a reasonable period afterwards, so we can follow up and maintain a record of the engagement.
  • Client and audit records: retained for the duration of the engagement and afterwards where needed for support, warranty or dispute purposes.
  • Financial records: retained for at least seven years, as required by Australian tax law.

When information is no longer needed and we're not required to keep it, we delete it or de-identify it.

Cookies and tracking

AgentReady's website is deliberately light on tracking. We do not run third-party advertising cookies, and we do not sell or share browsing data with ad networks.

  • Essential storage: we may use browser local storage or session cookies to remember state within a session — for example, carrying your selected plan through to the quote form.
  • Payment cookies: Stripe sets cookies necessary to process a payment securely and to detect fraud, governed by Stripe's own privacy policy.
  • Fonts: we load web fonts from Google Fonts, which means your browser makes a request to Google's servers when a page loads.

You can block or delete cookies through your browser settings. Blocking essential cookies may stop parts of the checkout or quote flow from working.

Your rights and choices

You have the right to:

  • Access the personal information we hold about you.
  • Correct information that's inaccurate, out of date or incomplete.
  • Delete your information, where we're not required to keep it.
  • Opt out of marketing communications at any time.
  • Complain if you believe we've mishandled your information.

If you're in the EEA or UK, you also have the right to restrict or object to processing, to data portability, and to withdraw consent where we rely on it.

California residents

If you're a California resident, the California Consumer Privacy Act gives you the right to know what personal information we collect and why, to request a copy of it, to request deletion, and to not be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA, so there is no "Do Not Sell" opt-out to action — but you can still make any of the requests above using the contact details below.

To exercise any of these rights, email info@agentready.au. We'll verify your identity before acting on a request, and we'll respond within 30 days. Access is free; if a request is manifestly unfounded or excessive we may charge a reasonable fee or decline it, and we'll explain why in writing.

Children's privacy

AgentReady is a business tool intended for use by businesses and professionals. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we'll delete it.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices, our service providers, or the law. The "last updated" date at the top of this page always reflects the current version. If we make a material change, we'll take reasonable steps to notify you — for example, by email or a notice on the website — before it takes effect. Continuing to use AgentReady after a change means you accept the updated policy.

Contact and complaints

If you have a question about this policy, want to exercise a right, or want to make a privacy complaint, contact us first — we'd like the chance to put it right.

EntityAgentReady™
Privacy contactinfo@agentready.au
LocationAustralia
Response timeWithin 30 days of a verified request

We'll acknowledge your complaint, investigate it, and write to you with the outcome. If you're not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992. If you're in the EEA or UK, you may also lodge a complaint with your local supervisory authority.

Find out if AI recommends your business

Run your free AI Readiness Audit and discover how AI systems see your website — and exactly what to fix first.

Run Free Audit →
Free · No signup · Results in 60 seconds