Privacy Policy
XTen (ABN 59 213 935 411, Perth, Western Australia) takes privacy seriously. Although businesses with an annual turnover under $3 million may be exempt from parts of the Privacy Act 1988 (Cth), we voluntarily adopt the Australian Privacy Principles (APPs) — both because it is right and because our clients (including government buyers) expect it.
What we collect
Enquiries and clients: name, business name, contact details, ABN, project and billing information, correspondence, and records of work performed. Website visitors: technical data such as IP address, browser type and pages visited, collected via privacy-respecting analytics. Support users: account details, support tickets and diagnostic information you send us. We collect only what we need, directly from you wherever possible.
Why we collect it
To respond to enquiries, scope and deliver engagements, provide support under service plans, invoice and collect payment, meet legal obligations (tax, records), improve our websites and products, and — only with your consent — send occasional service updates. We do not sell or rent personal information. We do not use your information for automated decisions that significantly affect you; if that ever changes, this policy will disclose it (as required from 10 December 2026 under the Privacy Act amendments).
Client application data
When we build, host or support an application for a client, the data inside that application belongs to the client and is processed on their instructions. We access it only as needed to deliver contracted work, under confidentiality obligations, and we never use client application data for any other purpose. Clients remain responsible for their own privacy obligations to their users; we help by shipping privacy-supporting defaults (role-based access, audit logging, encryption).
AI tooling
We openly use AI systems (including Anthropic's Claude) in our development and operations. We do not paste client personal information into AI tools except under agreements that prevent the provider training on it, and we strip or de-identify data wherever practicable.
Storage and security
Data is stored on Australian-region cloud infrastructure wherever practicable. Safeguards include encryption in transit (TLS) and at rest for credentials, role-based access on least-privilege terms, multi-factor authentication on all administrative accounts, patching disciplines, and tested backups.
Disclosure
We disclose personal information only to: service providers needed to run the business (hosting, payments via Stripe, email delivery, accounting), professional advisers, and where required by law. Some providers may process data overseas; we take reasonable steps to ensure they handle it consistently with the APPs.
Data breaches
We maintain a data breach response plan. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
Access, correction and complaints
You may request access to, or correction of, your personal information at any time: privacy@xten.au. We respond within 30 days. If you are dissatisfied with our response, you may complain to the OAIC (oaic.gov.au, 1300 363 992).
Retention
We keep personal information only as long as needed for the purposes above or as law requires (e.g. tax records, 5 years), then delete or de-identify it.
Changes
We will post updates to this policy at stack.xten.au/privacy-policy.html with the revision date.
Contact
privacy@xten.au · XTen, Perth WA · ABN 59 213 935 411
Last updated: 11 August 2026