Effective date: 29 July 2026
1. Purpose and operator
This Privacy Policy explains how Michael Phillip Peters ABN 26 569 038 118 trading as Enterprise Corporated handles personal information in connection with the authorised websites, portals, applications, AI interfaces, enterprise services, communications and business activities that link to this policy.
We use Enterprise Corporated, we, us and our to refer to the legal operator. Privacy enquiries and requests may be sent to [email protected].
2. Australian privacy position
The Privacy Act 1988 (Cth) and Australian Privacy Principles apply to organisations that fall within the Act, including organisations above the statutory turnover threshold and certain small businesses covered because of their activities. Whether a specific small business is legally bound can depend on its conduct and exemptions.
Where the Privacy Act applies, we will comply with it. Whether or not every activity is legally required to comply, our policy is to handle personal information consistently with the core Australian Privacy Principles, including transparency, data minimisation, purpose limitation, security, access and correction.
This policy does not create a waiver of a lawful exemption or an admission about regulatory status. It records the standards we intend to apply.
3. Meaning of personal information
Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable, whether true or not and whether recorded in material form or not.
Sensitive information may include health information, biometric information used for identification, racial or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, criminal record, professional or trade association membership and other categories defined by law. We only seek sensitive information where reasonably necessary, authorised and accompanied by any required consent or legal basis.
4. Information we may collect
Depending on how you interact with us, we may collect:
- identity details, including name, title, organisation, role and authority;
- contact details, including email address, telephone number, business address and communication preferences;
- account and authentication information, including username, access logs, multi-factor status, device identifiers and recovery information;
- transaction and commercial information, including enquiries, proposals, orders, invoices, payment status, licence scope, support records and contract history;
- customer and project material, including prompts, instructions, files, documents, source code, invention material, patent material, evidence records, diagrams, specifications, verification data and deliverables;
- communications, including email, contact-form messages, meeting notes, support interactions, complaint records and lawful call or session records where notice and consent requirements are met;
- technical and usage information, including IP address, browser, operating system, device type, language, time zone, referral source, pages viewed, actions, timestamps, error logs, security events and approximate location inferred from IP address;
- cookie, local-storage, pixel and similar technology information described in the Cookie Statement;
- AI interaction information, including prompts, outputs, safety classifications, model routing, feedback and human approval records;
- recruitment, supplier, contractor and professional contact information;
- public-source and third-party business information reasonably necessary for due diligence, identity verification, sanctions screening, fraud prevention, intellectual-property research or business development; and
- other information you choose to provide or that is required by law.
5. Information we do not request through public channels
Do not send private cryptographic keys, passwords, seed phrases, access tokens, classified information, unlawfully obtained data, privileged legal files, full identity documents, unpublished enabling patent disclosure, sensitive health information or highly confidential trade secrets through a public form or ordinary email unless we have confirmed a secure authorised process.
If unsolicited information is received, we will assess whether it could lawfully have been collected. Where appropriate and lawful, we may securely delete, de-identify, quarantine or return it.
6. How we collect information
We may collect information:
- directly from you through forms, email, account registration, contracts, uploads, support, surveys, meetings, transactions and service use;
- automatically through servers, security systems, cookies, telemetry, APIs and analytics;
- from an organisation that authorises you or engages us;
- from service providers, payment processors, referral partners and professional advisers;
- from public registers, official records, websites, repositories, publications, conferences and lawful commercial sources; and
- from another person where authorised, reasonably expected or permitted by law.
At or before collection, or as soon as practicable, we will provide an appropriate collection notice where required.
7. Purposes of collection, use and disclosure
We may handle personal information to:
- operate, secure and improve the websites and Services;
- establish identity, authority, Accounts and access permissions;
- respond to enquiries and provide requested information;
- assess, negotiate, enter and administer contracts, licences, evaluations, pilots and services;
- process transactions, invoices, subscriptions, refunds and accounting records;
- provide AI, software, evidence, verification, invention, patent-support, licensing, technical and customer-support functions;
- generate, preserve and verify authorised logs, hashes, signatures, timestamps, manifests and chain-of-custody records;
- maintain quality, safety, testing, auditability, human review and release governance;
- prevent fraud, misuse, security incidents, rights infringement and prohibited activity;
- investigate complaints, disputes, suspected breaches and legal claims;
- comply with legal, regulatory, court, taxation, law-enforcement, sanctions and professional obligations;
- protect people, rights, systems, confidential information and intellectual property;
- perform research, analytics and service improvement using aggregated or de-identified information where reasonably practicable;
- send service communications and, with an appropriate basis, marketing communications;
- conduct recruitment, supplier management and corporate administration; and
- support a genuine business restructure, financing, acquisition or transfer subject to confidentiality and law.
We will not use personal information for a materially incompatible purpose without an appropriate legal basis, notice or consent.
8. AI processing and automated decisions
Personal information and Customer Material may be processed by AI or automated systems where necessary for the requested service, security, classification, routing, quality control or support.
We apply or seek to apply human oversight proportionate to risk. We do not intend to make a solely automated decision that has a legal or similarly significant effect on an individual without appropriate notice, safeguards and a lawful basis. Where applicable, individuals may request human review, provide relevant information and contest a decision.
Australian privacy-policy obligations concerning certain substantially automated decisions commence on 10 December 2026. This policy is drafted to accommodate those requirements, but the actual systems and decision classes must be documented before that date.
AI prompts and outputs may be retained for the period required to provide, secure and audit the service. Confidential-service configurations, external model routing and any model-training use must be identified in the service-specific notice or agreement.
9. Marketing
We may send marketing only where permitted by law and our records support consent or another lawful basis. Commercial electronic messages will identify the sender and include a functional unsubscribe mechanism. Unsubscribe requests will be honoured within the legally required period and suppression records may be retained to prevent further marketing.
We do not infer consent merely because an email address is publicly available, an enquiry was submitted or a person purchased an unrelated service. Service and security messages are not marketing unless they include promotional content that makes them commercial messages.
You can opt out by using the unsubscribe facility or contacting [email protected]. Opting out of marketing does not stop necessary service, legal, security or transaction communications.
10. Cookies and similar technologies
We use cookies, local storage, pixels, scripts and similar technologies as described in the Cookie Statement. Strictly necessary technologies may operate without consent where lawful. Non-essential analytics, personalisation and advertising technologies will be activated only in accordance with applicable consent requirements and the choices made through the consent tool.
A complete live cookie inventory, provider, purpose, duration and transfer location must be maintained and linked from the Cookie Statement.
11. Disclosure recipients
We may disclose personal information to:
- personnel, contractors and authorised representatives who need it for their functions;
- hosting, cloud, content-delivery, security, domain, website-building, repository, telecommunications and infrastructure providers;
- AI, machine-learning, transcription, search and automation providers authorised for the service;
- payment, accounting, banking, fraud-prevention and transaction providers;
- email, customer-relationship, support, analytics, consent-management and communication providers;
- professional advisers, insurers, auditors, experts, patent attorneys, lawyers and consultants;
- counterparties and due-diligence participants in an actual or proposed transaction under appropriate confidentiality controls;
- regulators, courts, tribunals, law enforcement and government bodies where required or authorised by law; and
- other recipients you authorise or that are identified in a collection notice or agreement.
We do not sell personal information for money. We do not disclose personal information for unrelated cross-context behavioural advertising unless expressly disclosed and supported by any consent or opt-out required by law.
12. Overseas processing and disclosures
Technology providers may process or store information outside Australia. Before publication, the actual Service Provider and Overseas Processing Schedule must identify the provider, function, data category, legal role, countries or regions, safeguards and retention.
Potential locations must not be guessed. The live policy should list countries where practicable based on actual provider contracts and configurations.
Where Australian Privacy Principle 8 applies, we will take reasonable steps before disclosing personal information to an overseas recipient to ensure appropriate handling, subject to statutory exceptions. Depending on the jurisdiction and service, safeguards may include contractual obligations, security review, access controls, encryption, data minimisation, transfer mechanisms and vendor assessment.
Foreign laws may require an overseas provider to disclose information. We will consider this risk in provider selection, contracting and notices.
13. Security
We use safeguards proportionate to the information, service and risk. Depending on the system, measures may include:
- encryption in transit and, where appropriate, at rest;
- access control, least privilege, multi-factor authentication and credential management;
- network, application, endpoint and infrastructure security controls;
- logging, anomaly detection, rate limits and incident monitoring;
- secure development, dependency review, change control and vulnerability management;
- backups, recovery procedures, retention controls and secure deletion;
- supplier due diligence and contractual controls;
- confidentiality obligations, training and role-based access;
- data classification and separation of public, customer, confidential and restricted environments;
- cryptographic integrity records, signatures, hashes or timestamps where appropriate; and
- incident response and notification procedures.
These measures reduce risk but no system is completely secure. Security statements apply only to implemented and verified controls. Private keys should remain in user-controlled environments unless a specific managed-key service is contractually approved.
14. Data breaches
We maintain an incident-response process. Where the Notifiable Data Breaches scheme applies and we have reasonable grounds to believe an eligible data breach has occurred, we will assess, contain and remediate the incident and notify affected individuals and the Office of the Australian Information Commissioner as required.
We may also notify individuals, customers, regulators or contractual partners in other circumstances where required or reasonably appropriate.
15. Retention and deletion
We retain personal information only for as long as reasonably necessary for the disclosed purposes, contractual obligations, security, evidence integrity, dispute management and legal requirements. Legal holds and evidence-preservation duties may extend retention.
The following are default planning periods and must be confirmed against actual systems and professional advice:
- general enquiries: up to 24 months after closure;
- marketing records: until opt-out or inactivity, with a minimal suppression record retained as necessary;
- customer contracts, licences, invoices and material correspondence: generally 7 years after the relationship ends, or longer if a dispute, IP right or law requires;
- tax and accounting records: the applicable statutory period, commonly at least 5 years in Australia;
- unsuccessful recruitment applications: generally 12 months unless consent or law supports longer retention;
- security and access logs: usually 3 to 24 months according to risk, with relevant incident records retained longer;
- customer project material: the contract period plus the agreed return, export or deletion window;
- evidence and provenance records: according to the customer's instructions, contract, legal hold, patent strategy and custody requirements; and
- cookie data: the period shown in the live cookie inventory.
Deletion may involve secure erasure, cryptographic deletion, de-identification or removal from active systems. Backup copies may persist until normal rotation, subject to access restrictions.
16. Access, correction and privacy requests
You may request access to personal information we hold about you and ask us to correct inaccurate, out-of-date, incomplete, irrelevant or misleading information. Depending on applicable law, you may also have rights to deletion, restriction, portability, objection, withdrawal of consent or human review.
Send requests to [email protected] with enough information to identify the relevant records. We may verify identity and authority before acting. We will respond within a reasonable period, ordinarily within 30 calendar days where practicable, or within another period required by law.
Access may be refused or limited where law permits, including where disclosure would unreasonably affect another person's privacy, reveal privileged or confidential information, prejudice security, or be unlawful. We will provide reasons where required.
17. Anonymity and pseudonyms
Where lawful and practicable, you may interact anonymously or using a pseudonym for general enquiries. Identity may be required for contracts, payments, licensing, access control, rights requests, security, regulated transactions or where law requires.
18. Children
The Services are not directed to children under 16 and Accounts and commercial services are for persons aged 18 or older. We do not knowingly seek children's personal information through commercial or confidential services. If a parent or guardian believes a child has provided information without appropriate authority, contact [email protected].
Services likely to be accessed by children must undergo a separate child-safety and privacy assessment before launch, including applicable age, design and Online Safety requirements.
19. Third-party sites
Third-party links, embeds, plugins and services have their own privacy practices. Review their notices before providing information. Where we embed a third-party service, the Cookie Statement or collection notice should identify it and applicable choices.
20. Complaints
Send a privacy complaint to [email protected] with relevant details. We will acknowledge it, investigate fairly and seek to respond within 30 calendar days where practicable. Complex matters may require additional time, in which case we will provide an update.
If you are not satisfied and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner. Other regulators or dispute bodies may be available depending on the issue and jurisdiction.
21. International rights
The Global Privacy Addendum applies only where the relevant foreign law applies to our activities. It does not represent that every foreign privacy law applies merely because the website can be viewed from that jurisdiction.
22. Changes
We may update this policy to reflect legal, operational, provider or service changes. The current version and effective date will be published. Material changes will receive additional notice where required.
23. Contact
Privacy contact: [email protected]
Operator: Michael Phillip Peters ABN 26 569 038 118 trading as Enterprise Corporated
Location: New South Wales, Australia
Postal address: Formal correspondence is accepted through [email protected]. A serviceable postal address is supplied through verified formal channels where legally required.