Skip to content
aicial
Legal

Privacy Policy

Version: 1.0

Effective date: 18 August 2026

Last reviewed: 18 August 2026

This Privacy Policy explains how Aperim Pty Ltd, which operates the aicial brand, handles personal information when providing aicial services, operating our website and waitlist, and communicating with customers and other individuals.

1. About this policy

Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this policy, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; and “you” refers to an individual whose personal information we handle.

This policy applies to our website, waitlist and services. Those services include fixed-scope social-media audits, monthly reporting retainers and benchmark studies, as well as the aicial technology used to deliver them. It also applies to our planned self-serve software service when made available. If we process personal information solely on a customer’s documented instructions, the customer is responsible for its own privacy notices and lawful basis, while we remain responsible for our obligations as its service provider or processor.

We are the controller of account, waitlist and billing information and personal information used for our own service operations. Where we process personal information solely on a customer’s documented instructions, such as data from a social account or audience the customer connects, we act as the customer’s processor or service provider. Individuals whose information appears in a customer’s connected account or content should direct privacy requests to that customer in the first instance; we support the customer in responding to those requests.

Our principal Australian obligations arise under the Privacy Act 1988 (Cth), including the 13 Australian Privacy Principles (APPs). We do not rely on the small-business exemption because our activities include trading in personal information. Additional laws described below apply when we offer services to, or monitor relevant behaviour of, people in other jurisdictions. “Trading in personal information” is a technical status under section 6D of the Privacy Act that is relevant to why the small-business exemption does not apply; it is distinct from selling or brokering personal information to third parties, which we do not do.

2. Information we collect

We collect only information reasonably necessary for our functions and activities.

Information you provide directly. This may include your name, email address, organisation, role, account and contact details, service requests, communications, billing and transaction records, and material you submit for analysis or content creation. Joining the waitlist requires an email address. You may optionally provide social handles, brand information and audience details for priority review. Priority review is not sold and payment cannot be used to skip the waitlist.

Information from connected social accounts. When a customer connects an account through OAuth, we receive the information within the scopes the customer authorises and the platform makes available. Depending on the platform and service, this can include account identifiers, profile and post information, content, engagement and performance metrics, audience insights, publishing permissions and OAuth tokens. We do not ask for the customer’s platform password. Customers can revoke a connection through the relevant platform or by contacting us, although revocation does not by itself delete information already lawfully retained.

Information collected automatically. Our website and services may collect basic device, browser, IP address, log, diagnostic, security and usage information needed to operate, secure and improve them. The separate Cookie Policy explains our use of cookies and similar technologies, including available choices.

Information from consented, licensed and public sources. Our social listening and benchmarking work may use information supplied with consent, obtained under licence, or lawfully available from public sources in accordance with platform terms and technical controls. We do not circumvent access controls. Except for a customer’s own connected accounts, or public figures where we have obtained legal advice supporting that analysis, outputs derived from third-party public data are presented at an aggregate level, not at profile level.

Our deal, rate and payment-experience benchmarks are built from data customers choose to contribute in exchange for access to the resulting aggregate benchmarks. We present those benchmarks only at an aggregate level consistent with this policy.

Where a partner refers a prospective customer to us under our Reseller and Partner Program Agreement, we may use the prospective customer’s contact information to reach out to them about aicial’s services. For personal information we collect about someone from another source in other contexts, including public social content mentioning or posted by someone who is not a customer, we provide notice through our published privacy policies where direct notice to each individual is not practicable, and we limit use of that information to the aggregate outputs described above. Any such individual may contact privacy@aicial.com about information concerning them.

3. Sensitive information and identity protection

We do not seek sensitive information unless it is necessary for a stated service and we have consent or another lawful basis. Please do not provide sensitive information that we have not requested.

We do not seek to identify or infer special-category attributes from ingested content, do not use any such information for a purpose connected to that special-category status, and treat any such information identified in submitted or connected-account content in the same way as other content data under this policy’s security and retention commitments.

For account protection, a customer may provide reference content relating to their own identity. We may create perceptual-hash fingerprints of that content and compare handles and metadata to identify likely impersonation or deepfake risks. We do not search third-party or scraped media using biometric templates and do not perform voice biometric matching. Where a customer submits reference images of their own identity to enable identity-protection matching, we compare faces against that customer-submitted material only. We obtain the customer’s express, separate biometric consent before enabling this feature. The customer may withdraw that consent at any time, which disables the feature going forward. We do not offer biometric search and do not use identity protection data for data brokering.

4. How we use personal information

We use personal information to:

  • provide, administer and support requested services;
  • connect authorised social accounts and produce cross-platform performance reports;
  • generate and schedule content based on a customer’s own top-performing content and instructions;
  • detect likely impersonation and deepfake risks affecting a customer’s identity;
  • produce social-listening insights and honest deal, rate and performance benchmarks;
  • assess and administer waitlist applications;
  • communicate about services, support, security and material policy changes;
  • process transactions and maintain business, tax and compliance records;
  • secure, troubleshoot, maintain and improve our website and services; and
  • comply with law, enforce agreements and establish, exercise or defend legal claims.

We do not use personal information to manipulate platforms or people, artificially inflate engagement, circumvent platform controls, or broker personal information.

6. AI and personal information

Some aicial features use artificial intelligence or machine learning. The Responsible AI Usage Policy and AI Usage & Disclosure Matrix identify the features involved and explain how each system is used. This section addresses the handling of personal information in those systems.

Model inputs may include a customer’s instructions, authorised account content and performance information, or other material the customer chooses to submit, but only to the extent needed for the requested feature. We minimise personal information in model inputs and apply the same access, disclosure and retention controls that apply to other service data. We do not use content containing another individual’s personal information to train models shared across unrelated customers, whether or not the submitting customer consents, unless that information has first been de-identified. AI-generated content is labelled in accordance with the Responsible AI Usage Policy.

Benchmarking, audience insights, social listening and performance scoring involve profiling because they use personal information to analyse or predict aspects of a person’s performance, interests, behaviour or other characteristics. Where we rely on legitimate interests for that processing, you may object to it, including the related profiling, as described in section 12.

We do not make solely automated decisions that produce legal or similarly significant effects about any person. A human genuinely reviews any consequential output before action is taken, including every adverse identity-protection finding before any external action such as a takedown request; that review is not a rubber stamp. Under the UK GDPR, “solely automated” means that there is no meaningful human involvement and the extent of any profiling must be weighed when applying Articles 22A–22D. Article 22C requires us to maintain safeguards for any significant decision based solely on automated processing, including providing information about the decision and enabling the individual to make representations, obtain human intervention and contest the decision. Separately, where Article 22 of the EU GDPR applies, individuals retain the right not to be subject to such decisions and the associated rights to human intervention, to express their view and to contest a decision.

7. Sharing and disclosure

We may disclose personal information:

  • to service providers and sub-processors that host, secure, analyse or support our services, process communications or payments, or provide AI functionality;
  • to the social platforms a customer directs us to connect with or publish to;
  • to professional advisers, auditors and insurers subject to appropriate duties of confidentiality;
  • where required or authorised by law, or where reasonably necessary to protect rights, safety, security and the integrity of our services; and
  • in connection with a proposed or completed corporate transaction, subject to confidentiality and applicable law.

The Sub-processor List identifies the providers that may process customer data and their relevant locations and functions. We require providers to process personal information only for authorised purposes, protect it appropriately and comply with applicable data-protection obligations. We do not sell or broker personal information.

8. International transfers

We are based in Australia. Our infrastructure provider, Cloudflare, operates a global network and may process data in multiple jurisdictions depending on where a request is served, including the United States. The current Sub-processor List identifies each sub-processor and, where it operates from a specific location rather than a global network, that location. Before disclosing personal information to an overseas recipient, we take the reasonable steps required by APP 8 to ensure that the recipient does not breach the APPs in relation to that information, unless a statutory exception applies. We also assess providers, impose contractual protections and apply data minimisation and security controls.

Australia is not covered by a UK adequacy regulation. A transfer of UK personal data from the UK to Australia or another non-adequate country is governed by an Article 46 safeguard, ordinarily the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required transfer-risk assessment and supplementary measures.

Australia does not have an EU adequacy decision. Transfers of EU personal data to Aperim in Australia, whether directly or through a sub-processor, are governed by the European Commission’s 2021 modernised Standard Contractual Clauses where required, together with transfer-impact assessments and supplementary measures.

Cross-border transfers of personal information collected in China use an approved PIPL mechanism as applicable: a security assessment, the China Standard Contract, or personal-information protection certification. We also obtain separate explicit consent and provide the required transfer information where PIPL requires it.

9. Direct marketing

We may send service updates or marketing communications where permitted by law. Each electronic marketing message provides a practical way to unsubscribe, and you may opt out at any time by using that method or emailing privacy@aicial.com. We action opt-out requests within the period required by law and do not charge for opting out.

If you are in Australia and personal information used for direct marketing was collected from someone other than you, you may ask us to identify its source, unless it is impracticable or unreasonable for us to do so.

Opting out of marketing does not prevent us from sending non-promotional messages that are necessary to provide a service, respond to you, or communicate security, legal or account information.

10. Data quality, retention and deletion

We take reasonable steps to ensure that personal information is accurate, up to date, complete and relevant for the purposes for which we use or disclose it. Please contact us if information we hold about you changes or appears inaccurate.

We retain personal information only for as long as needed for the purposes described in this policy, to meet contractual and legal obligations, to resolve disputes, and to establish or defend claims. We then delete or de-identify it, subject to lawful backup and record-keeping requirements. Customers can request an export or deletion of their data at any time. The Data Retention & Deletion Policy sets out the applicable retention periods, deletion process, backup treatment and exceptions.

We retain waitlist information until you ask us to delete it, you are enrolled as a customer, or our waitlist programme concludes, whichever happens first. We retain OAuth connection tokens only while the connection remains active and delete them promptly when the connection is disconnected.

11. Security and data breaches

We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Measures include access controls based on role and need, authentication and secrets management, encryption in transit and where appropriate at rest, logging and monitoring, secure development and change controls, provider assessment, backups and incident-response procedures. If you discover a suspected vulnerability in our website or services, our Security and Vulnerability Disclosure Policy explains how to report it and what to expect from us in response.

No system is completely secure. We investigate suspected incidents promptly and comply with applicable notification requirements. This includes Australia’s Notifiable Data Breaches scheme: where an eligible data breach is likely to result in serious harm and remedial action has not prevented that risk, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

Where the UK GDPR or EU GDPR applies, we notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a qualifying personal data breach. We notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

12. Your privacy rights

You may ask us to explain our handling of your personal information or exercise rights available where you live. We may need to verify your identity and authority before acting. We do not discriminate against an individual for exercising a privacy right.

Australia. You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. The Privacy Act contemplates a response within a reasonable period, and we target responding to access and correction requests within 30 days. We give written reasons, and information about available complaint mechanisms, if we refuse a request. If we decline to make a correction, you may ask us to associate a statement with the information.

United Kingdom and European Union. Subject to applicable conditions and exceptions, you may request access, rectification, erasure, restriction of processing and data portability; object to processing based on legitimate interests or for direct marketing, including profiling based on legitimate interests; withdraw consent; and exercise the applicable EU Article 22 rights or UK Articles 22A–22D safeguards described in section 6. We respond to a valid request within one month. We may extend that period by up to two further months where necessary because a request is complex or numerous and will notify you of an extension within the first month. You may also complain to the UK Information Commissioner’s Office or, in the EU, the supervisory authority in your place of residence, work or the alleged infringement.

To make a request, email privacy@aicial.com. There is generally no charge, although we may charge a lawful reasonable fee or refuse a request that is manifestly unfounded or excessive. An authorised agent may submit a request where permitted by law, subject to verification of the agent’s authority.

13. Australian privacy considerations

Australian law includes a statutory tort for serious invasions of privacy. Independently of whether a particular use would meet its legal threshold, we take a conservative approach to identifiable profile-level information. Except for a customer’s own connected accounts, or public figures where we have obtained legal advice supporting that analysis, insights derived from scraped or other third-party public data are presented at an aggregate level, not at profile level.

This approach also supports the APP requirements concerning transparent management, collection, use and disclosure, data quality, security, access and correction. It does not limit any right or remedy available under Australian law.

14. Additional regional information

United Kingdom. The UK GDPR and Data Protection Act 2018 apply when we offer services to individuals in the UK or monitor their behaviour there. Ahead of offering services to or monitoring individuals in the UK, Aperim Pty Ltd will appoint a UK representative under Article 27 for UK data subjects. The UK representative will be distinct from our EU representative, and we will publish the representative’s name and contact details in this section once appointed.

European Union. Under Article 3(2), the EU GDPR applies when we offer services to individuals in the EU or monitor their behaviour there. Ahead of offering services to or monitoring individuals in the EU, Aperim Pty Ltd will appoint a separate EU representative under Article 27 and publish the representative’s name and contact details in this section once appointed.

United States. The United States does not have a single comprehensive federal privacy law. Comprehensive state privacy laws apply where their respective thresholds and scope requirements are met. We use the California Consumer Privacy Act, as amended by the California Privacy Rights Act, as a practical benchmark. The separate US State Privacy Rights Notice describes applicable state disclosures and rights, including rights to know, access, correct, delete, obtain a portable copy, opt out of covered sale, sharing or targeted advertising, limit certain uses of sensitive information, and appeal a decision where the relevant state law provides those rights.

China. Article 3 of the Personal Information Protection Law (PIPL) applies extraterritorially when we offer services to people in China or analyse their behaviour there. Ahead of that processing, Aperim Pty Ltd will establish a dedicated entity or designate a representative in China under Article 53, file the required details with the relevant authority, and publish the representative’s name and contact details in this section once appointed.

India. The substantive provisions of the Digital Personal Data Protection Act 2023, including the extraterritorial-scope provision in section 3(b), come into force on 13 May 2027. Ahead of that date, we design our practices toward the Act’s requirements.

15. Children

Our services are not directed at children and must not knowingly be used by children. In this policy, “child” means an individual under 13 years of age — the age used by the United States’ Children’s Online Privacy Protection Act (COPPA), a widely recognisable baseline for children’s online privacy even outside the United States. We do not knowingly collect personal information directly from a child through the waitlist or customer onboarding. The Children’s Privacy Notice explains our age-related controls and how a parent, guardian or other person can report a concern.

If we learn that a child has provided personal information contrary to our requirements, we will take appropriate steps to delete it and restrict the account or submission, subject to any legal obligation to retain information.

We do not verify the age of every individual who appears within a customer’s connected social account or public social content because we do not directly interact with those individuals. We do not deliberately target individuals under 13 for any profile-level identification and apply the same aggregate-only treatment described elsewhere in this policy to protect them.

16. Privacy complaints

Send a privacy complaint to privacy@aicial.com with enough detail for us to understand and investigate it. We acknowledge and investigate complaints within a reasonable period, keep you informed where more time is needed, and explain our response and any available review options.

If an Australian privacy complaint remains unresolved, you may complain to the OAIC at oaic.gov.au. Individuals elsewhere may complain to their local privacy or data-protection authority where they have that right. Contractual disputes are handled in accordance with the Terms of Service, including its ACICA arbitration clause seated in Sydney, New South Wales.

Nothing in this policy or the Terms of Service’s arbitration clause limits any statutory right to complain to the OAIC, ICO, an EU supervisory authority or equivalent regulator, or any non-waivable statutory privacy remedy, including Australia’s statutory tort for serious invasions of privacy. Arbitration applies to contractual disputes, not to the exercise of a statutory privacy right.

17. Changes to this policy

We may update this policy to reflect changes to our services, practices or legal obligations. The version, effective date and last-reviewed date shown at the top identify the current policy. We publish the updated policy on our website and, where a change is material or law requires it, provide additional notice through the service or by email before the change takes effect.

Where we rely on consent, a policy update does not expand that consent. We seek fresh consent before materially changing a consent-based use where applicable law requires it.

18. Contact us

For privacy questions, complaints, access or correction requests, deletion or export requests, or to exercise any other privacy right, contact:

Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: privacy@aicial.com