Privacy Policy
Last updated 25 July 2026 · Kritsotakis Family Trust (ABN 45 984 876 899), trading as Komiti · Sydney, NSW
Who we are
Komiti is operated by the Kritsotakis Family Trust (ABN 45 984 876 899), based in Sydney, NSW. A business our size may fall under the Privacy Act 1988 (Cth)'s small-business exemption — but we've chosen to handle your information as if the Australian Privacy Principles apply to us regardless, rather than rely on that exemption. You can reach us at info@komiti.ai about anything in this policy, including access, correction, deletion or a complaint.
What we collect
| Information | When | Why |
|---|---|---|
| Name, email, business name, and what you need help with | When you join the founding list or contact us | To reply to you and understand who we're building for |
| Your answers to a checklist or question (industry, state, staffing, turnover band, free-text notes) | When you use the Setup Checklist, Business Q&A or Payday Super check | To generate the response you asked for |
| Financial figures you paste in (e.g. profit and loss data) | When you use Books Check | Sent to our AI provider to generate the answer, then discarded — not stored on our servers |
| Meeting recordings or files you upload, and any documents generated from them | When you use the recording or upload features | To produce your draft minutes |
| Consent confirmation and timestamp | At the point of recording or upload | To keep an audit record that consent was confirmed before recording |
| Your account: email address, and a sign-in token sent to it | When you create an account or sign in | To sign you in. There is no password — a single-use link is emailed instead |
| Your business profile: ABN, entity name and type, state, industry, GST status, staff numbers, annual wages, premises and lease dates | When you set up a business in the app (most of it is filled from the public ABN register) | To work out which obligations actually apply to you, which is the core of the product |
| Documents you upload to the vault, their file names and any expiry dates you set | When you add them to your document vault | To store them for you and turn expiry dates into watched dates |
| ABNs you enter into the ABN lookup or the structure check | When you use those free tools | To read the public ABN register and compare business names against it. These are public-register lookups and are not stored against an account |
| Email address and industry for change alerts | When you ask to be told when the rules change | To email you when something changes that affects your industry |
| Technical data: IP address, browser user-agent, timestamps | Automatically, on submission | Security, abuse prevention, and diagnosing faults |
Please don't put sensitive information (health, financial account numbers, government identifiers, or anything you wouldn't want processed by a third-party AI provider) into free-text fields. We don't need it and we'd rather not hold it.
Who processes your information
We use third-party providers to run the service. Some are located outside Australia, which means your information may be disclosed overseas — principally to the United States.
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare | Website hosting and delivery (the edge network that serves pages) | Global network — pages are served from wherever you are |
| Cloudflare (D1 database and R2 storage) | Your account, business profile, obligations and vault documents | Region-pinned to Oceania. Verified 6 Sep 2026: the database reports region OC (Sydney) and the vault bucket is created in OC |
| Resend | Sending your sign-in emails | United States (sending infrastructure in Asia-Pacific) |
| Anthropic (Claude) | Generating checklists, answers and document drafts from what you submit | United States |
| Deepgram | Transcribing meeting audio (recording and upload features only) | United States |
| Google Workspace | Our business email, if you contact us | Global, incl. United States |
We don't sell your information, and we don't use it for advertising or profiling.
How long we keep it
- Meeting recordings and uploaded files: kept encrypted for 60 days after the document is signed off, then deleted automatically.
- Generated documents and the related audit record (who approved what, and when): kept for the same period unless you ask us to keep them longer for your own record-keeping obligations.
- Checklist and Q&A submissions: retained so we can improve the service and respond if you follow up.
- Contact details from the founding list: kept until you ask us to remove them.
You can ask us to delete anything sooner, or to hold it longer, by emailing info@komiti.ai. We'll confirm when it's done.
Your rights
You can ask us to give you a copy of the personal information we hold about you, correct it if it's wrong, or delete it. Email info@komiti.ai and we'll respond within a reasonable time. If you're unhappy with how we've handled a privacy matter, you can complain to us first, and if that doesn't resolve it, to the Office of the Australian Information Commissioner at oaic.gov.au.
Security
Information is transmitted over encrypted connections and stored on Cloudflare infrastructure with access restricted to the operator. Your account data and vault documents are held in storage pinned to the Oceania region. Sign-in uses a single-use link emailed to you that expires in 20 minutes — there is no password to leak, and the link is never shown on screen or to anyone who did not receive the email. There is currently no second factor beyond access to your email account; if that matters for your business, tell us before you upload anything sensitive. No system is perfectly secure, and we can't guarantee against every risk. If a data breach occurs that is likely to cause serious harm, we'll notify affected people and the OAIC as required under the Notifiable Data Breaches scheme.
Recording other people
If you use Komiti to record a meeting, you are responsible for obtaining the consent of everyone being recorded before you start. We require you to confirm you've done this, and we log that confirmation — but the obligation is yours, not ours. See our Terms for more.
Changes
If we change this policy we'll update the date at the top. If a change materially affects how we handle information you've already given us, we'll contact you about it.