AuraSearch Privacy Policy
Thanks! We'll be in touch soon.
Privacy Policy
Privacy Policy
Your privacy is important to us therefore please see our Privacy Policy below. For any questions on how we use or store your information please fill out the contact form.
Privacy Policy
AuraSearch Pty Ltd
Last Updated: 16/09/2026
Effective Date: 16/09/2026
1. Introduction
AuraSearch Pty Ltd (“we,” “us,” “our,” or the “Company”) is an Australian digital marketing agency providing Google Ads management, ChatGPT Ads Management, Meta Ads management, Search Engine Optimisation (SEO), Generative Engine Optimisation (GEO), website development, and related analytics and reporting services (collectively, the “Services”).
This Privacy Policy explains how we collect, hold, use, disclose, and protect personal information in accordance with the Privacy Act 1988 (Cth) (the “Privacy Act”) and the Australian Privacy Principles (“APPs”), when you (a “client,” “user,” “visitor,” or “you”) interact with our Platform, our websites, our client dashboards, and our Services — including where that information is processed by artificial intelligence (“AI”) and large language model (“LLM”) systems as part of campaign strategy, content generation, reporting, or optimisation.
Where you, or the individuals whose data we handle on a client's behalf, are located in the European Union, the United Kingdom, or the United States, Sections 13.2 and 13.3 set out the additional rights that apply under the GDPR, UK GDPR, and applicable US state privacy laws.
By using the Platform or engaging our Services, you acknowledge that you have read and understood this Policy. If you do not agree with its terms, please do not use the Platform.
2. Scope and Who This Policy Applies To
This Policy applies to:
- Prospective, current, and former clients of AuraSearch Pty Ltd;
- Authorised users of client accounts (e.g., marketing managers, business owners) who access the Platform or client dashboards;
- Visitors to our corporate website(s);
- End-users/consumers whose data reaches us indirectly through client advertising accounts (e.g., Google Ads, Meta Ads audience or conversion data), where our client is the APP entity that originally collected that data and we act as its service provider.
Where we handle a client's own customers' data on that client's behalf (for example, conversion data synced from a client's CRM into an ad platform), a separate agreement or Data Processing Terms govern that relationship, and the client remains responsible under the Privacy Act as the entity that originally collected the data. This Policy applies to our own handling of client and Platform-user personal information as an APP entity in our own right.
3. Data We Collect
3.1 Information You Provide Directly
- Identity and contact details (name, business name, email, phone, billing address)
- Account credentials and authentication data
- Business information (industry, target audience, budget, marketing goals, brand assets, logos, ad copy)
- Payment and billing information (processed via Stripe)
- Communications with us (support tickets, emails, call recordings, chat transcripts)
- Prompts, inputs, and uploads submitted to AI-assisted tools within the Platform (e.g., ad copy generation requests, SEO content briefs, campaign strategy questions, uploaded documents, images, or datasets)
3.2 Information Collected Automatically
- Device and browser data, IP address, log files, cookies and similar technologies (see Section 9)
- Platform usage and interaction data (features used, session duration, click paths)
- Behavioural analytics used to improve the Platform and personalise reporting dashboards
3.3 Information from Connected Third-Party Platforms
Where you authorise us to connect your accounts, we may receive data from:
- Google Ads, Google Analytics, Google Search Console, Google Business Profile
- Meta Ads Manager, Meta Business Suite
- Other ad networks, CRMs, e-commerce platforms, or analytics tools you connect
This may include campaign performance metrics, audience segments (aggregated/pseudonymised where provided by the platform), conversion events, and ad account structure data.
3.4 Sensitive Information
Under section 6 of the Privacy Act, sensitive informationincludes health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, and criminal record, among other categories, and attracts a higher standard of protection under APPs 3.3–3.4 and 6.
We do not intentionally collect sensitive information and ask that you do not submit it into prompts, uploads, or campaign targeting instructions unless it is strictly necessary and you have your own lawful basis to provide it to us — for example, a healthcare client's own compliant audience data. Where sensitive information is submitted to us, we will only collect, use, or disclose it with your consent, or as otherwise permitted by law (for example, to lessen or prevent a serious threat to someone's life, health, or safety).
4. How We Use Your Data
We use collected data to:
- Deliver, operate, and improve the Services (campaign builds, SEO audits, GEO optimisation, reporting)
- Generate ad copy, keyword strategies, landing page content, and reports using AI-assisted tools (see Section 5)
- Communicate with you regarding account status, support, and billing
- Conduct internal analytics to improve Platform performance and service quality
- Comply with legal, tax, and regulatory obligations
- Detect, prevent, and investigate fraud, security incidents, or misuse
- With your consent, or where otherwise permitted, send you direct marketing about our own Services (see Section 9.1)
Under APPs 3 and 6, we only collect personal information that is reasonably necessary for our functions and activities, and we only use or disclose it for the purpose it was collected for (the primary purpose) or a related secondary purpose you would reasonably expect — or otherwise with your consent or as authorised by law. Where you or the relevant individuals are connected to the EU/UK, we additionally rely on the following GDPR/UK GDPR legal bases: performance of a contract, legitimate interests (service improvement, security, fraud prevention), consent (marketing, AI training where applicable), and legal obligation.
5. AI and LLM Data Processing
5.1 How AI Is Used on the Platform
The Platform uses internal and third-party AI/LLM systems to support:
- Ad copy, headline, and creative generation (Google Ads, Meta Ads)
- SEO/GEO content drafting, keyword clustering, and content briefs
- Campaign performance analysis and automated reporting narratives
- Chatbot/support assistance within client dashboards
When you submit a prompt, upload, or instruction to any AI-assisted feature, that content — along with relevant account and campaign context needed to generate a useful response — is transmitted to the AI system processing your request (internal model or third-party sub-processor, per Section 7).
5.2 What Is Processed
AI systems may process:
- Text prompts and instructions you type
- Uploaded documents, briefs, images, or brand assets
- Relevant campaign metadata (e.g., industry, target keywords, past ad performance) needed for context
- Interaction/behavioural signals used to refine suggestions (e.g., which AI-generated ad variants you select)
5.3 Human Oversight
AI-generated outputs (ad copy, SEO content, strategic recommendations) are treated as drafts and are reviewed by our team before being deployed live on your ad accounts or published to your website, unless you have explicitly enabled a fully automated workflow in your account settings.
6. Model Training: Opt-Out and Opt-In Rights
6.1 Our Default Position
By default, your prompts, uploads, campaign data, and Platform usage data are NOT used to train, fine-tune, or align any AI model — whether our own internal models or third-party foundation models — beyond the single session/request in which they are submitted.
6.2 Where Training Use May Occur
We may use de-identified, aggregated, or synthetic data (see Section 10) derived from Platform usage to improve our internal AI features (e.g., improving ad-copy suggestion quality across the client base), but only where such data cannot reasonably be used to re-identify you or your business.
If, in the future, we introduce a feature allowing raw client content to be used for model improvement, this will be:
- Opt-in only for EU/UK/EEA users, and offered as a clear, easy opt-out for Australian and other users, consistent with the Privacy Act's notification and consent requirements;
- Presented as a clear, separate toggle in Platform settings (Settings → Privacy → AI & Data Use);
- Never a condition of accessing core Platform functionality.
6.3 How to Exercise Your Opt-Out
You may opt out of any AI-training-related data use at any time via:
- Platform Settings: Settings → Privacy → AI & Data Use → “Do not use my data to improve AI models”
- Email: privacy@aurasearch.ai
- Written request to our Privacy Team (Section 18)
Opting out will never disable, degrade, or limit your access to core AI-assisted features, campaign management tools, or reporting. You will continue to receive AI-generated suggestions generated at inference time; only the downstream use of your data for model improvement is affected.
6.4 Third-Party Model Providers
Where third-party LLM providers (Section 7) have their own default training policies, we contractually require — via enterprise/API terms — that data submitted through our Platform is excluded from that provider's general model training (see Section 7.2).
7. Third-Party AI Sub-Processors, Infrastructure Providers, and Cross-Border Disclosure
7.1 Categories of AI Sub-Processors
We rely on the following categories of third parties to power AI features:
- LLM / Generative AI APIs— Example Providers: OpenAI, Anthropic, Google Vertex AI, AWS Bedrock; Purpose: Ad copy, content generation, reporting narratives
- Cloud Infrastructure— Example Providers: Amazon Web Services (AWS), Google Cloud Platform, Microsoft Azure; Purpose: Hosting, storage, compute
- Ad Platform APIs— Example Providers: Google Ads API, Meta Marketing API; Purpose: Campaign management, reporting
- Analytics— Example Providers: Google Analytics, Looker Studio; Purpose: Performance dashboards
7.2 Zero-Retention / No-Training Enterprise Terms
Where we transmit client or user data to third-party AI infrastructure providers, we do so under enterprise or business-tier API agreements that contractually provide:
- No use of submitted data to train the provider's foundation models, and
- Zero or time-limited data retention by the provider (data is processed transiently for the purpose of generating the response and not retained beyond the period required for abuse monitoring or the timeframe specified in the provider's enterprise terms).
Where a provider's standard consumer-tier terms would otherwise permit training or extended retention, we do not route client data through that tier; only enterprise/API-tier access governed by the above protections is used for production features.
7.3 Cross-Border Disclosure of Personal Information (APP 8)
Before disclosing personal information to an overseas recipient — including AI sub-processors and cloud infrastructure providers located outside Australia (e.g., in the United States) — APP 8 and section 16C of the Privacy Act require us to take reasonable steps to ensure the overseas recipient does not breach the APPs in relation to that information, and generally make us accountable for the overseas recipient's handling of it as if the act or practice were our own.
We meet this requirement through a combination of: enterprise/API-tier contractual terms with AI and cloud providers (Section 7.2); data processing addenda that mirror APP obligations; and, where the recipient is in the EU/UK or subject to GDPR/UK GDPR, reliance on Standard Contractual Clauses (SCCs) or the UK International Data Transfer Addendum as an additional safeguard. Where we cannot obtain adequate assurances from an overseas recipient, we will seek your consent to the disclosure or decline to make it.
8. Automated Decision-Making and Profiling
8.1 Where Automated Decision-Making Occurs
Certain features of the Platform involve automated or AI-assisted decision-making, including:
- Automated bid/budget adjustment recommendations (Google Ads/Meta Ads optimisation)
- Automated audience segmentation and targeting suggestions
- AI-flagged “underperforming campaign” or “anomaly” alerts
- Automated content quality or compliance scoring for AI-generated ad copy
8.2 Logic Involved
These features generally work by analysing historical performance data (e.g., click-through rate, conversion rate, cost-per-acquisition) against configurable thresholds and machine-learning models trained to identify patterns correlated with campaign performance. They are designed to surface recommendations, not to make final, unreviewed decisions affecting individuals' rights or interests.
8.3 Automated Decision-Making Transparency (APP 1.7–1.9)
From 10 December 2026, APPs 1.7–1.9 of the Privacy Act require an APP entity to include certain information in its privacy policy where it has arranged for a computer program to make, or to do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using that individual's personal information. In line with this obligation, we disclose that:
- Kinds of personal information used: campaign performance metrics (spend, click-through rate, conversion rate, cost-per-acquisition), audience and targeting data, and account configuration history are used in the operation of our automated bid/budget, audience-segmentation, and anomaly-detection tools described in Section 8.1.
- Kinds of decisions made solely by automated means: we do not currently allow any of these tools to make final, unreviewed changes to a live campaign without a human decision-maker; all budget, bid, and targeting changes generated by these tools are queued for client or team review before they take effect, unless you have explicitly enabled a fully automated workflow in your account settings (Section 5.3).
- Kinds of decisions substantially and directly supported by automated means: recommendations to increase/decrease budget or bids, flags for underperforming ad sets, and suggested audience segments are generated by these tools and, while reviewed by a human before implementation, substantially shape the decision that is ultimately made.
This is a transparency measure only: unlike the EU GDPR, APP 1.7 does not itself create a right to contest an automated decision or demand an explanation, but our existing Section 8.4 right to request human review reflects the same underlying protection, and you may also have review rights under other frameworks (e.g., consumer or industry-specific law) that apply to a particular decision.
8.4 Your Right to Human Review
If you believe an automated recommendation or output has been applied to your account without adequate human oversight, or you wish to contest an AI-driven decision or recommendation, you may request:
- An explanation of the logic involved;
- Human review of the decision by a member of our team;
- Correction or reversal of the automated action.
Requests can be submitted to privacy@aurasearch.ai
9. Cookies, Tracking Technologies, and Direct Marketing
We and our partners use cookies, pixels, and similar technologies for:
- Strictly necessary cookies (login sessions, security, load balancing)
- Functional cookies (remembering dashboard preferences)
- Analytics cookies (Platform usage, feature adoption)
- Advertising cookies (where we retarget visitors to our own marketing site via Google Ads/Meta pixels)
You can manage cookie preferences via our Cookie Consent Banner at first visit, or at any time via your browser settings. EU/UK visitors and California residents are presented with granular consent options and can withdraw consent at any time without affecting the lawfulness of prior processing.
9.1 Direct Marketing (Spam Act 2003 and Do Not Call Register Act 2006)
Where we send you commercial electronic messages (email, SMS) about our own Services, we comply with the Spam Act 2003 (Cth): we only send such messages with your consent (express or reasonably inferred from an existing business relationship), each message clearly identifies us as the sender, and every message includes a functional unsubscribe facility. If we contact you by phone for marketing purposes, we comply with the Do Not Call Register Act 2006 (Cth) and will not call numbers listed on the Do Not Call Register other than where an exemption applies. You can withdraw consent to marketing at any time via the unsubscribe link, privacy@aurasearch.ai, or your Platform settings.
10. Synthetic Data, De-Identification, and Anonymisation
10.1 De-Identification Standards
Where we generate aggregated benchmarks, industry reports, or synthetic training datasets from Platform data, we apply de-identification techniques designed to prevent re-identification, including:
- Removal or hashing of direct identifiers (names, emails, exact business identifiers)
- k-anonymity / minimum aggregation thresholds (data is only reported in groups of statistically sufficient size, e.g., a minimum number of accounts per industry benchmark)
- Noise injection / differential privacy techniques for numeric performance metrics where applicable
- Generation of synthetic datasets (artificially generated data that mirrors statistical properties of real campaign data without corresponding to any real, identifiable client or individual) for internal model testing and improvement
10.2 Re-Identification Safeguards
We implement technical and organisational measures — including access controls, contractual prohibitions on re-identification by sub-processors, and periodic re-identification risk assessments — designed to ensure that de-identified or synthetic data cannot reasonably be used, including through AI-based inference or reverse-engineering techniques, to re-identify a specific individual or business.
10.3 Status Under Law
Information that has been de-identified in accordance with this Section is treated as no longer “personal information” under the Privacy Act only to the extent the information could not reasonably be used to re-identify an individual, having regard to the OAIC's de-identification guidance. Where doubt exists, we treat the data as personal information and apply this Policy's protections.
11. How We Share Your Data
We share personal data with:
- Service providers/processors: hosting, AI infrastructure, payment processing, customer support tooling, analytics (see Section 7)
- Ad platforms: Google, Meta, and other networks, as necessary to run your campaigns, under your authorisation
- Professional advisors: accountants, auditors, legal counsel, under confidentiality obligations
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to continuity-of-protection commitments
- Legal/regulatory disclosures: where required by Australian or foreign law, court order, or to protect our rights, safety, or the rights of others
We do not sell personal information. We do not share personal information for cross-context behavioural advertising except via the cookie-based mechanisms disclosed in Section 9, and we honour Global Privacy Control (GPC) and similar opt-out signals where technically supported, in addition to any equivalent rights available to California residents under the CCPA/CPRA.
12. Data Retention
- Account and billing records— Duration of relationship + 7 years (Australian tax/legal requirements)
- AI prompts/uploads (session logs)— 30–90 days unless needed for active support ticket or dispute
- Campaign performance data— Duration of relationship + 24 months for reporting continuity
- Marketing communication data— Until consent/unsubscribe or 24 months of inactivity
- De-identified/aggregated/synthetic data— Retained indefinitely (no longer personal information, provided the de-identification threshold under the Privacy Act is genuinely met)
We take reasonable steps to destroy or de-identify personal information once it is no longer needed for the purposes described in this Policy, in line with APP 11.2, subject to legal retention obligations.
13. Your Privacy Rights
13.1 Australian Privacy Act Rights
If the Privacy Act applies to your personal information, you have the right to:
- Request access to the personal information we hold about you (APP 12);
- Request correction of personal information you believe is inaccurate, out of date, incomplete, irrelevant, or misleading (APP 13);
- Deal with us anonymously or under a pseudonym where it is lawful and practicable to do so (APP 2);
- Ask how your personal information is collected, held, used, and disclosed, including the matters set out in this Policy (APP 1);
- Lodge a complaint with us in the first instance, and if you are not satisfied with our response, with the Office of the Australian Information Commissioner (OAIC) (Section 18).
We will respond to access and correction requests within a reasonable period (ordinarily no more than 30 days) and will not charge you for making a request, though reasonable charges may apply to giving access in some cases.
13.2 EU/UK GDPR Rights
If you are located in the EEA/UK, you have the right to:
- Access, rectify, or erase your personal data
- Restrict or object to processing (including profiling and processing based on legitimate interests)
- Data portability
- Withdraw consent at any time
- Lodge a complaint with your local Data Protection Authority (e.g., the ICO in the UK)
13.3 US State Privacy Rights (CCPA/CPRA and Other State Acts)
Depending on your state of residence (e.g., California, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy laws in effect), you may have the right to:
- Know/access the categories and specific pieces of personal information collected
- Delete personal information
- Correct inaccurate personal information
- Opt out of the “sale” or “sharing” of personal information, and of use for targeted advertising
- Opt out of profiling in furtherance of decisions producing legal or similarly significant effects
- Limit use of sensitive personal information
- Non-discrimination for exercising these rights
- Appeal a denied request
13.4 How to Exercise Your Rights
Submit requests via:
- Platform Settings → Privacy → My Data
- Email: privacy@aurasearch.ai
- Web form: aurasearch.ai/contact-us
We will verify your identity before fulfilling requests and will respond within the timeframe required by applicable law (e.g., a reasonable period, ordinarily within 30 days, under the Privacy Act; 30 days under GDPR; 45 days under CCPA/CPRA, extendable as permitted).
13.5 Authorised Agents
Where permitted by law, you may designate an authorised agent to submit requests on your behalf, subject to identity verification.
14. Data Security and Notifiable Data Breaches
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, role-based access controls, API-level access restrictions to AI sub-processors, and regular security assessments, consistent with APP 11 (security of personal information). No system is completely secure, and we cannot guarantee absolute security.
14.1 Notifiable Data Breaches
If we experience a data breach that is likely to result in serious harm to an individual whose personal information is involved (an “eligible data breach”), we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. This means we will carry out a reasonable and expeditious assessment of a suspected breach, and where an eligible data breach has occurred, notify the OAIC and affected individuals as soon as practicable, including the kind of information involved and the steps we recommend individuals take in response.
15. Children's Privacy
The Platform and Services are intended for business use by individuals aged 18 or older. We do not knowingly collect personal information from children, and our Services are not directed to children. We note that the OAIC is developing a Children's Online Privacy Code under the Privacy Act, which may impose additional obligations on services likely to be accessed by children; we will update this Policy if and when that Code applies to our Services.
16. International Data Transfers
Where personal data is transferred outside Australia (including to AI sub-processors and cloud infrastructure providers as described in Section 7), we comply with APP 8 and section 16C of the Privacy Act by taking reasonable steps to ensure the overseas recipient does not breach the APPs, and additionally rely on safeguards such as Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or other lawful transfer mechanisms where GDPR/UK GDPR also applies.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology (including new AI features and sub-processors), or legal requirements — including any changes arising from the Privacy Amendment (Personal Data Protection) Bill 2026 if and when it is enacted. Material changes — including any change expanding the use of your data for AI model training — will be notified via email or a prominent Platform notice, with an updated “Last Updated” date, prior to taking effect.
18. Contact Us and How to Complain
AuraSearch Pty Ltd
20 Bailey Street, West End QLD
Email:privacy@aurasearch.ai
Phone: 1300 282 872
If you wish to make a complaint about how we have handled your personal information, please contact our Privacy Team using the details above. We will acknowledge your complaint and aim to resolve it within a reasonable period, ordinarily 30 days.
If you are not satisfied with our response, you may lodge a complaint with:
- The Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- Your local EU/UK Data Protection Authority (e.g., the ICO in the UK), if the GDPR/UK GDPR applies to you
- Your state Attorney-General or equivalent regulator, if a US state privacy law applies to you