01 / Scope and operator
Who this policy covers
This Privacy Policy explains how THE HAPPY COMPANY PTY LTD, trading as UX Robot (we, us or our), handles personal information through the UX Robot website, application, managed services and related communications.
Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable. This policy is intended to describe our practices under the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply, together with other privacy laws that may apply to a particular person or activity.
This policy does not replace collection notices shown for a specific feature or the privacy policies of Stripe, Google, OpenAI or another third-party service. Our Terms of Service govern use of UX Robot. Read the Terms of Service.
02 / Information we collect
The information needed to operate UX Robot
Depending on how you interact with us, we collect and hold the following kinds of personal information:
- identity and account information, including name, work email, password credentials in protected form, email-verification status, passkeys, two-factor authentication settings and account role;
- access-request, invitation and contact information, including organisation, role, website, phone, country, enquiry topic, messages, review notes and communications;
- organisation and team information, including stakeholder names, roles, work emails, responsibilities and workspace memberships;
- billing information, including Stripe customer and subscription identifiers, payment status, invoices, purchases, analysis-unit records and limited payment-method details supplied by Stripe;
- service and security information, including IP address, user agent, session records, timestamps, login and account activity, Terms acceptance evidence, error records and audit information;
- optional public-page analytics information, including online identifiers, approximate location, browser and device information, pages viewed, referring pages and engagement information when consent is given; and
- Customer Content, connected-source information, uploaded files, notes, reports and other evidence that may contain information about users, customers, members, staff or website visitors.
UX Robot does not require sensitive information for ordinary account use. Do not provide health, biometric, financial-account, government-identifier, children’s or other sensitive information unless it is necessary for an authorised analysis and you have a lawful basis and all required consents to provide it.
03 / Collection
How information reaches us
We collect information directly when someone requests access, registers, uses the application, completes a profile, connects a source, uploads evidence, purchases a subscription or unit pack, contacts us or otherwise communicates with our team.
We also collect information from account owners and organisation administrators who invite team members or add stakeholders; from Google services that an authorised user connects; from Google Analytics after a visitor accepts optional analytics cookies; from Stripe about billing events; from service providers that help operate and secure the platform; and automatically from browsers, devices, servers and application logs.
You may browse public pages without creating an account. You may contact us using an alias if we can still respond, but accurate identity, work contact and billing information is generally required to approve access, create an account, secure a workspace, provide the service and process payments. If required information is not provided, we may be unable to respond, approve access or provide the requested feature.
04 / Customer content and website evidence
Information supplied about other people
Customer Content can include Google Analytics 4 and Google Search Console data, heatmaps, screenshots, sitemaps, support themes, survey material, CRM or membership exports, stakeholder notes, uploaded documents and other website evidence. This material may contain identifiers, search terms, free-text comments or other information relating to people who are not UX Robot users.
The customer organisation determines what evidence to connect or upload and is responsible for its collection notices, permissions, consent, minimisation and lawful disclosure to UX Robot. Customers should remove direct identifiers and unnecessary personal or sensitive information before uploading evidence wherever possible.
We process Customer Content to provide the organisation’s workspace, analysis, reports, recommendations, review and support. Authorised organisation members, assigned UX Robot analysts or engineers, and people given a report-sharing link may be able to view relevant content. Customers control their team and report recipients and should only grant access to authorised people.
05 / Use
Why we handle personal information
We collect, hold, use and disclose personal information where reasonably necessary to:
- review qualified access requests, create and authenticate accounts, manage workspaces and provide requested features;
- connect authorised data sources, organise evidence, generate and review analyses, prepare reports and deliver managed UX services;
- manage subscriptions, trials, analysis units, payments, invoices, cancellations and account deletion;
- respond to enquiries, provide support, send operational notices and communicate about the service relationship;
- detect abuse, investigate errors, secure the service, maintain audit records and enforce our Terms;
- improve reliability, workflows and service quality using feedback and appropriately aggregated or de-identified information; and
- meet legal, tax, accounting, regulatory, dispute-resolution and law-enforcement obligations.
We do not sell personal information. We do not use Customer Content for third-party advertising or permit third parties to advertise to people through UX Robot.
06 / AI-assisted processing
How evidence is used with AI providers
UX Robot uses OpenAI, or another AI provider configured for the service, to prepare structured draft analyses and stakeholder reports. Prompts and attachments can include organisation context, goals, connected analytics and search evidence, uploaded evidence, prior report material, notes and other Customer Content needed for the requested run.
AI providers process that material under their applicable API or business terms and our arrangements with them. Processing may occur outside Australia. Avoid including unnecessary personal or sensitive information because AI systems can reproduce supplied information in an output and cannot guarantee that every inferred statement is accurate.
UX Robot is a decision-support service. AI-generated material remains subject to human review and is not used by UX Robot as the sole basis for legal, employment, credit, health, eligibility or similarly significant decisions about an individual.
08 / Overseas processing
Information may leave Australia
Some providers and their subprocessors operate globally. Personal information is therefore likely to be stored, accessed or processed in Australia, the United States and other countries where our hosting, Stripe, Google, OpenAI, email, monitoring or support providers operate. Exact locations may change as providers update their infrastructure and subprocessors.
Where Australian Privacy Principle 8 applies to an overseas disclosure, we take reasonable steps appropriate to the circumstances to address overseas handling, subject to the exceptions in the Privacy Act. Overseas recipients may also be required to disclose information under the laws of their country.
09 / Payments
Stripe handles payment card information
Stripe collects and processes full payment card details through Stripe Checkout and the Stripe customer portal. UX Robot does not store full card numbers or card security codes. We receive information needed to manage the commercial relationship, such as Stripe customer identifiers, subscription and invoice status, transaction identifiers, payment failures and limited card details such as brand and last four digits where Stripe provides them.
Stripe handles payment information under its own privacy policy and terms. Billing, tax, fraud-prevention and transaction records may need to be retained after cancellation or account deletion.
11 / Retention and deletion
How long information remains
We retain personal information and Customer Content for as long as reasonably necessary to provide the service, maintain security and auditability, respond to disputes, enforce agreements and meet legal, tax, accounting and regulatory obligations. The period depends on the kind of record, why it was collected, contractual requirements and applicable law.
Account deletion removes access and deletes associated account and organisation records from the active application database. Information can remain for a limited period in private file storage, logs, queued work and backups while it is deleted, overwritten or aged out through operational processes. Shared copies exported by a customer or sent to report recipients are outside our control.
We retain minimum records where reasonably necessary after deletion, including Terms acceptance evidence, billing and transaction records, fraud and security records, analysis-run accounting, legal correspondence and records needed to establish or defend claims. Those retained records are restricted to their remaining purpose and are deleted or de-identified when no longer reasonably required.
12 / Security and data quality
Reasonable safeguards, not absolute security
We use administrative, organisational and technical safeguards designed for the nature of the information, including access controls, authentication, private file storage, encryption of Google access and refresh tokens, HTTPS in production, restricted administrative access, provider security controls, logging and backups. No internet service, storage system or transmission is completely secure.
Customers must protect credentials, use individual accounts, remove former team members, control report-sharing links and tell us promptly about suspected unauthorised access. We may ask for information needed to verify identity before discussing an account or fulfilling a privacy request.
We take reasonable steps to keep personal information accurate, current, complete and relevant for its purpose. Users can update core profile information in the application and should tell us if other information needs correction.
13 / Access, correction and choices
Your privacy requests
You may ask what personal information we hold about you, request access to it, or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask about deletion, object to or restrict certain processing, withdraw consent where processing relies on consent, or request a portable copy where those rights apply under relevant law.
Use the contact form and select the most relevant topic. Describe the information or account involved and the request you are making. We may need to verify your identity and authority before responding. We aim to respond within a reasonable period and ordinarily within 30 calendar days, subject to applicable law, complexity and permitted extensions.
Some requests may be limited where access would affect another person’s privacy, reveal confidential or commercially sensitive information, undermine security, conflict with legal obligations, or where another lawful exception applies. If we refuse a request, we will explain the reason and available complaint options where required.
14 / Privacy complaints and contact
Contact the Privacy Officer
Use our contact form for privacy questions, access or correction requests, complaints, or to request this policy in another accessible format. Select “Legal notice” and include enough information for the Privacy Officer to understand the issue. Do not include identity documents or sensitive information unless we specifically request them through an appropriate channel.
Postal address: 27 Wallace Ave Toorak, 3142
We will acknowledge and investigate a complaint, consult relevant people and service providers, and explain the outcome and any action taken. Please raise the issue with us first. If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner or another regulator with jurisdiction. Visit the OAIC privacy complaints page.
15 / Children
The service is for adults and organisations
UX Robot accounts are intended for people aged 18 or older acting for an organisation. We do not knowingly invite children to create accounts. Customer evidence should not include information about children unless it is necessary, lawful, appropriately minimised and supplied with all required authority and consent.
Contact us if you believe a child has provided personal information directly to UX Robot without appropriate authority so we can investigate and take suitable action.
16 / Changes to this policy
Keeping the policy current
We review this policy as the service, providers, information-handling practices and law change. The current version and effective date appear at the top of this page. If a change materially affects how we handle existing personal information, we will take reasonable steps to provide additional notice where required.