Skip to main content
Back to home
Tradie Pilot AI
Privacy

Privacy Policy

Last updated: 21 July 2026

Tradie Pilot AI is an AI-driven SMS assistant for Australian tradies. This policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it. It is written to satisfy the Australian Privacy Principles (APPs) under the Privacy Act 1988.

1. Who we are

Tradie Pilot AI is operated by Alisya AI (the "business", "we", "us", "our"). Our registered business details, including ABN, will be published on this page once the V1 entity is finalised. Until then, the contact channel is [email protected].

In this policy, "tradie" means the business owner who subscribes to Tradie Pilot AI, and "customer" means the end customer who calls or texts the tradie's mobile number and receives a reply from our AI assistant on the tradie's behalf.

2. What we collect

2.1 Information tradies give us when signing up

When a tradie submits the /free-trialform, we collect: full name, business name, mobile number, email address, and suburb. We use this to run the concierge onboarding call and to provision the tradie's dedicated AI mobile number.

2.2 Information collected automatically by the AI assistant

When a customer calls the tradie's mobile and the call forwards to our service, or when a customer sends an SMS to the tradie's dedicated AI number, we receive: the customer's mobile number, the time of the call or message, and (for SMS) the text body of every message in the conversation. We do not record voice calls in V1 — the AI does not answer voice calls in V1.

2.3 Information our systems generate

In the course of replying, the AI generates: a classification (emergency vs standard vs spam vs out-of-hours), a generated outbound SMS body, a safety tip selected from our vetted library, and operational metadata (timestamps, latency, error codes). This metadata is stored against the conversation thread.

2.4 Unsolicited information

If a tradie or customer sends us information we did not ask for (for example, by forwarding a screenshot or a third party's contact details by accident), we will, where it is lawful and reasonable to do so, destroy or de-identify that information within 30 days of becoming aware of it.

3. Anonymity option

Australian Privacy Principle 2 entitles you to deal with us anonymously or under a pseudonym where it is practicable to do so. For Tradie Pilot AI it is not practicable: the entire purpose of the service is for the tradie to reply to a real customer at a real phone number. We cannot provide the service without the customer's phone number and the tradie's identity.

4. How we use your information

4.1 Primary purpose

We use the information to deliver the service the tradie pays for: receive the missed-call event, send a first-response SMS to the customer on the tradie's behalf, run customer-enquiry triage and scheduling inside tradie-approved rules, and surface the conversation in the work dashboard for the tradie.

4.2 Related secondary purpose

During the concierge-onboarding window, we send a real-time email + SMS notification to the founder when a new tradie lead lands on the /free-trial form. This is so the one-business-hour callback promise on the form is keepable. Tradies signing up to the service would reasonably expect this.

4.3 Direct marketing

We do not direct-market to your end customers. We may send service-improvement updates by email to tradies who have signed up. Every such email contains a one-click unsubscribe.

5. Who we share it with

We share information with the third-party service providers listed below. Each is bound by contract to handle the data only for the purpose described.

  • Twilio (global API endpoint by default): provisions the tradie's dedicated AU mobile number, receives missed-call and inbound-SMS webhooks, and sends outbound SMS. Twilio holds the customer's phone number and SMS bodies. The runtime currently uses Twilio's global API endpoint. AU1 is available only after credential validation and an approved rollout.
  • Amazon Web Services (Australia): hosts the SMS conversation runtime (API Gateway, Lambda, Step Functions, and DynamoDB conversation table), authentication (AWS Cognito), and Lambda compute for the lead form and tradie dashboard. Anthropic Claude Sonnet 4.6 on Amazon Bedrock receives the inbound SMS body and relevant tradie-approved context for classification and reply generation through the Australia inference profile. The request originates in Sydney (ap-southeast-2) and may be processed only in Sydney or Melbourne (ap-southeast-4); that AI processing remains in Australia.
  • Resend (United States): sends the founder-notification email when a new lead lands on the /free-trial form. Disclosed in §6 below.
  • Stripe (live billing not enabled): once founder-approved live billing is enabled, provides hosted Checkout for subscription payment collection and the customer portal. Payment details go directly to Stripe; Alisya AI does not receive raw card details.
  • Cloudflare (global edge, Australian termination): hosts the marketing site (tradiepilot.ai) and provides DNS, edge caching, and TLS termination.

We do not sell personal information to any third party.

6. Cross-border disclosure

Australian Privacy Principle 8 requires us to disclose any cross-border transfer of personal information. In V1, Resend (United States) processes founder-notification data for transactional email, and the global Twilio API endpoint may process SMS data outside Australia under Twilio's service terms.

Stripe is currently configured for test-mode billing only, with production live billing deliberately disabled. If live billing is approved, Stripe becomes the payment processor for the tradie account through hosted Checkout and its applicable cross-border processing terms must be accepted before card collection begins.

Twilio receives customer phone numbers, SMS metadata and message bodies for messaging delivery. The runtime defaults to the global Twilio API endpoint; AU1 is available only after credential validation and an approved rollout.

The data class shared with Resend is:

  • The lead's name, email address, mobile number, and suburb.
  • The lead's submitted business name.
  • The submission timestamp.

Customer SMS bodies, conversation transcripts, and AI replies are never sent to Resend. Conversation persistence remains in DynamoDB ap-southeast-2. AI processing uses the Amazon Bedrock Australia inference profile and may occur in Sydney or Melbourne, remaining within Australia. Twilio handles SMS data via the configured endpoint as disclosed above.

The safeguards we rely on for these transfers are encryption in transit (TLS), the providers' contractual data-protection terms, and limiting each provider to the data needed for the purposes described above.

7. Your rights

You have the right to:

  • Ask us what personal information we hold about you (APP 12).
  • Ask us to correct any personal information that is wrong or out-of-date (APP 13).
  • Ask us to delete personal information we no longer need to retain.
  • Withdraw any consent you have given (this may end the service if the consent was required to deliver it).
  • Complain to us, and if not satisfied, to the Office of the Australian Information Commissioner (OAIC).

Email [email protected] and we will respond within 30 days. We do not charge for these requests.

8. Security

We protect personal information using the controls documented in the repository's docs/SECURITY_BASELINE.md file. Highlights:

  • TLS 1.2+ on every customer-facing endpoint.
  • Encryption at rest in DynamoDB and inside Twilio's infrastructure.
  • IAM scoping per environment; no shared admin credentials; no per-user database root credentials.
  • Per-tradie isolation tests gate the conversation persistence layer before launch.

No system is completely secure. If we ever detect a breach affecting your information, we will notify you under the Notifiable Data Breaches scheme.

9. Cookies and analytics

The marketing site (tradiepilot.ai) does not set tracking cookies in V1. We do not use Google Analytics, Meta Pixel, or any third-party analytics that profile individual users. We may add a privacy-respecting analytics tool in the future; if we do, this policy will be updated and the change announced on the site.

The tradie dashboard (when launched, P1.8 in our roadmap) will use a session cookie issued by AWS Cognito to keep tradies signed in. This is strictly necessary for the service to function.

10. How long we keep it

  • Lead form submissions: kept for 24 months from submission, then deleted, unless the tradie became a customer (in which case it forms part of the customer record and is retained while the subscription is active plus 7 years for ATO record-keeping).
  • Customer SMS conversations: kept for 24 months in DynamoDB by default, then deleted via table TTL, unless the tradie configures a longer retention for business-record reasons.
  • Operational logs (CloudWatch, Sentry): kept for 90 days.
  • Founder-notification emails (Resend): retained inside Resend per Resend's own retention policy; the underlying data also exists in DynamoDB and is governed by the lead retention rule above.

11. Updates to this policy

We update this policy when our data flow, vendor list, or pricing changes in a way that materially affects what is described here. The "Last updated" date at the top of this page reflects the most recent change. Material changes are announced on the marketing site at least 14 days before they take effect.

12. Contact and complaints

For any privacy question, request, or complaint, email [email protected].

If we cannot resolve your complaint to your satisfaction, you can escalate to the Office of the Australian Information Commissioner (OAIC):

  • Web: oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001