Privacy Policy
Last updated: August 2026
This policy explains how we collect, use, disclose and protect personal information through this website. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where it applies to visitors in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR).
1. Who we are
This website is operated by NG AI LEARNING & AUTOMATION PTY LTD (ACN 700 302 781), trading as Naghmeh G., based in Sydney, Australia. We are the entity responsible for the personal information described in this policy — under the GDPR, the data controller. For any privacy question, request or complaint, contact hello@naghmehelahi.com.au.
2. Information we collect
We collect what you choose to give us in the contact and consultation forms: your name, email address, business details and the content of your message. Consultation requests also record a limited technical footprint — IP address and browser user agent — used solely to prevent spam and abuse. If you book a consultation, our scheduling provider collects the details needed to create the booking. If you use Nova, our AI assistant, we store your messages together with a pseudonymous session identifier. We do not collect sensitive information as defined by the Privacy Act, and we ask that you do not submit health, financial, biometric or confidential business information through any form or chat on this site.
3. How we use information
We use personal information to respond to your enquiry, to assess and arrange consultations, to deliver services you have asked for, to prevent abuse of the site, and to improve the website and Nova. We do not sell personal information, we do not disclose it for advertising, and we do not use it for automated decision-making that produces legal or similarly significant effects. Under the GDPR our lawful bases are your consent (when you submit a form or start a chat), the performance of a contract (when arranging and delivering services), and our legitimate interests (site security and abuse prevention).
4. Nova, our AI assistant
Nova answers questions using a large language model. When you send a message, that message and the relevant retrieved context are transmitted to a third-party AI provider (OpenRouter, which routes the request on to the underlying model provider) in order to generate a reply. We have configured our OpenRouter account so that requests are never routed to endpoints that train on the data sent to them, whether paid or free, and so that our prompts are not shared with OpenRouter to improve their own product. The models behind Nova are served by Google. Conversations are stored in our database against a pseudonymous session identifier rather than your name. We do not use your conversations to train any model of our own, and we do not sell or share them for advertising. What we cannot promise is that nothing is retained at all: a provider may hold a request briefly for abuse monitoring, and we have not restricted routing to zero-retention endpoints only. So please still avoid entering confidential, sensitive or personally identifying information. Nova can be wrong — its answers are general information, not professional advice, and nothing it says forms a contract or a professional opinion.
5. Cookies and tracking
This site uses one cookie: a functional cookie that remembers your language preference so the site loads in the language you chose. It is strictly necessary to deliver the service you asked for, so no consent banner is required. We use no analytics, no advertising pixels, no session recording and no cross-site tracking of any kind — there is no Google Analytics, no Meta pixel and no third-party tracker on this website. We also send a browser instruction opting out of Google's interest-based advertising topics. You can block or delete cookies in your browser settings; the only effect will be that the site forgets your language preference.
6. Service providers and overseas disclosure
We use a small number of providers to run this site, and share information with them only to the extent needed to deliver the relevant service: Vercel (website hosting), Supabase (database and authentication), Cloudflare (DNS and email routing), Resend (email notifications), Cal.com (consultation scheduling), Upstash (abuse rate limiting), Peivand CRM (lead notifications), and OpenRouter together with Cohere (the AI models and search indexing behind Nova). Several of these providers are located outside Australia, including in the United States and the European Union, so your information may be stored or processed overseas. Consistent with APP 8, we take reasonable steps to ensure these providers handle personal information appropriately, and we do not disclose personal information to any other third party except where required or authorised by law.
7. How long we keep information
We keep personal information only for as long as it is needed. Contact and consultation enquiries are retained for 24 months from your last contact with us, so we can maintain continuity if you return. Nova conversation transcripts are retained for 12 months. Technical records collected for abuse prevention, such as IP addresses, are retained for a short period and then discarded. Where we are required to keep records for longer to meet a legal, tax or accounting obligation, we keep only what that obligation requires. When information is no longer needed we delete it or de-identify it, in line with APP 11.2. You can ask us to delete your information sooner — see section 9.
8. Security and data breaches
We protect this site with encryption in transit (HTTPS on every page, with HSTS), a content security policy, database row-level security so records are only reachable by those authorised to see them, and rate limiting to blunt automated abuse. Administrative access is restricted and authenticated. No system connected to the internet can be guaranteed completely secure, and we do not claim otherwise. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and — where the GDPR applies — the relevant supervisory authority within 72 hours of becoming aware of it. If you believe you have found a security vulnerability in this site, please report it to hello@naghmehelahi.com.au.
9. Your rights, and how to complain
You can ask us to access the personal information we hold about you, correct it if it is wrong, or delete it. Where the GDPR applies you also have the right to restrict or object to processing, to receive your data in a portable format, and to withdraw consent at any time without affecting processing already carried out. To exercise any of these rights, email hello@naghmehelahi.com.au. We will respond within 30 days and will not charge you for making a request. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992; if you are in the EEA or UK, you may instead complain to your local data protection authority. We may update this policy from time to time, and will change the date at the top of this page when we do.