Privacy
Privacy policy
An argument, in continuous prose, about what a company whose systems read player behaviour owes the people that behaviour belongs to.
In force from 12 August 2026Revision 2.0Privacy Act 1988 (Cth)
The company, and the reach of this page
AIDEOLOGY TECHNOLOGIES PTY LTD, ACN 698 536 953 and ABN 81 698 536 953, is an Australian proprietary company whose main business location is New South Wales. Where this page says we, it means that single registered entity and nothing wider. No parent sits above it, no subsidiary sits beneath it, and there is no affiliate somewhere else whose conduct is being quietly folded into these paragraphs. That matters more than it sounds. A great deal of privacy writing gains its comfort from vagueness about who exactly is promising what, and the first honest move available to a company this small is to name the promisor precisely.
Three surfaces fall inside this page. The first is the website you are reading. The second is anything you send to [email protected], which is the only address we publish. The third is any mobile title we publish ourselves, on our own account and under our own name.
Two things fall outside it. Sites we link to run under their own policies, and linking is not endorsement of how they behave. And a game published by another studio that happens to run engine code written here is governed by that studio's policy, not by ours, for reasons the section on roles sets out at some length.
Why this page is written this way
Adaptive difficulty is a technology that reads people: how they cope, when they falter, at which precise moment they put the phone down. A policy covering it that spoke vaguely about "usage data" would be omitting the only part worth reading, which is why this document is longer and more specific than a company of this size would ordinarily bother with.
Australian Privacy Principle 1 — APP 1, in the abbreviation used from here on where a principle is cited more than once — requires an entity bound by the Privacy Act 1988 (Cth) to manage personal information openly and transparently, and to keep a clearly expressed and current policy describing that management. The obligation is usually met backwards: the data flows get chosen by whoever is closest to a deadline, and the policy then describes them in language calculated not to alarm anyone. Every genuinely contestable decision has been taken by the time a reader sees a word of it.
This page runs the other way round, and the commitments in it are the constraints the engineering actually answers to. That is why they are specific enough to be inconvenient: a difficulty subsystem holding no purchase state, a generator whose output is solved before it is served, a retention schedule carrying numbers instead of the phrase "as long as necessary". Anything here we later find costly has to be changed in public, with a version number and a date against it, and that visibility is the point rather than a side effect of it.
An exemption we have decided not to use
An Australian business whose annual turnover is three million dollars or less is a small business operator under the Privacy Act, and a small business operator is generally not an APP entity at all. Several exceptions claw the exemption back — providing a health service, trading in personal information, contracting to the Commonwealth — but none of them presently describes us. A company of that size is, on the ordinary reading, outside the Act.
We are not going to rely on that. The exemption is a threshold about company size, not a finding that the people whose information a small company holds are owed less. It is also temporary in the most predictable way possible: it disappears the moment the business succeeds, and a company that builds its habits inside the exemption then has to rebuild them under deadline. Reasoning from the eventual obligation backwards produces better engineering than reasoning from the current loophole forwards.
So this page is written as though every Australian Privacy Principle binds us, and we intend to be held to it on that basis. If some future dispute turns on whether we were technically an APP entity on a particular date, the answer we will give is that we said in advance we would behave as one.
Two positions, one of which we do not occupy
Software of this kind can sit in a company's hands in two quite different ways, and conflating them is how privacy notices become dishonest without anyone writing a false sentence.
In the first position, a studio embeds our difficulty system in its own game. Players are that studio's players. The studio decides what the model is fed, keeps the account records, answers the support mail, and carries the relationship the Privacy Act cares about. Our involvement would be as a supplier acting on that studio's written instruction, handling whatever it directs us to handle for the purposes it specifies and no others. Australian law does not draw the controller-and-processor line that European readers will be reaching for; both parties can be APP entities in their own right. What the arrangement changes is who owes the explanation to the player, and in that arrangement it is the studio. The correct place to read about a game's data handling is always that game's own policy.
In the second position, we publish the title ourselves. Then there is no one to point at. The players are ours, the model is ours, the retention decision is ours, and this page is the document that answers for all of it.
The second position is ours. We describe the first anyway, in the conditional, because a reader deserves to know where the line falls should the question ever arise, and because a company that publishes only the flattering half of its architecture has told you something about itself.
What difficulty reads
Adaptive difficulty has no way to be honest and vague at the same time. A system that adjusts to how a person is coping must observe how that person is coping, and the observation is made of behaviour: how many attempts a level took, where within it the attempts ended, how long each one ran, how quickly inputs arrived and how that pace changed as the round went on, whether a session was closed at a point of failure or a point of completion, how long the gap was before the next one. That is the raw material. Pretending it is anonymous telemetry rather than a record of a person's conduct would be a lie of framing rather than of fact, and this page will not tell it.
What we can say honestly is where the boundaries sit. The difficulty model is given gameplay events and nothing else. It has no read path to purchase history, wallet balance, offer state or the store catalogue, and no write path to anything that can present an offer. That is a structural claim rather than a policy one: the subsystem cannot know whether you have ever spent money, so it cannot respond to whether you have. Nor is it given a name, an email address, contacts, precise location, or anything from another application on the device.
Signals of this kind are still personal information when they attach to an identifier that can single you out, and we treat them that way rather than arguing about it. Collection under Australian Privacy Principle 3 is limited to what the feature actually needs, which in practice means the model reads what it needs to estimate difficulty and is not given a second, larger stream to be curious with later.
The website, and the record it does not keep
The pages you are reading now are close to inert. Nothing here stores a cookie of our own making, no analytics package is installed, no advertising or measurement pixel is embedded, no session recorder is watching the cursor, and there is no account to create because there is nothing to be an account for. This is not a claim about intentions. It is a claim about the file you can read: the stylesheet and the small script that opens the navigation are served from this domain, and you are welcome to check them.
The site's type is requested from Google's font service, which means your browser makes one connection outward while rendering a page. Google receives what any web server receives on a request of that kind, including your IP address, and applies its own terms to it. We receive nothing back and set nothing as a result. That single dependency is described more fully in the cookie notice, along with the two strictly necessary security cookies our hosting provider is permitted to set to keep the site standing up.
Beyond that, our host keeps ordinary server logs — request lines, timestamps, rough origin, user agent — for a short operational window, in the way that any web server anywhere keeps them. We do not build them into profiles, do not join them to anything else, and do not attempt to work out who you are from them. There is no banner on this site because there is nothing here that a banner could meaningfully ask you to permit.
Correspondence
Writing to us is the one interaction on this website that produces a durable record with your name attached, and it is worth being exact about it. When mail arrives at [email protected] we hold what you chose to send: your address, whatever you wrote, any attachment, and the ordinary headers a mail system carries. We use it to answer you, to keep track of what was promised in reply, and for nothing else.
Australian Privacy Principle 5 asks that a person be told at or around the point of collection what is being collected and why, and the honest way to meet that here is to make the whole exchange legible in advance rather than after. So: there is no form on this site, and no address is quietly harvested by loading a page. Nothing you send subscribes you to anything, because there is no list for you to land on. Australian Privacy Principle 2 lets you keep your name out of a dealing altogether, or conduct it under an invented one, wherever anonymity is both lawful and workable. For a general question it is obviously workable: mail us from any address that suits you and volunteer nothing whatever about who you are. Identity only becomes relevant when you ask us to act on records about a specific person, for the obvious reason that we should not hand one person's information to another.
Send us something nobody asked for, which we then have no lawful footing on which to retain, and Australian Privacy Principle 4 obliges its destruction or de-identification wherever doing either is lawful and reasonable. We follow that, instead of tucking the material away against the chance it later turns out to be interesting.
The day a title reaches a store
Everything above concerns a website and an inbox. A mobile title on a store changes the scale of the question entirely, so the answers to it are set out here rather than left to be settled under release pressure and explained afterwards.
On iOS, App Tracking Transparency governs whether an application may access the advertising identifier and track a user across apps and websites owned by other companies. Our position is that we will not request that permission. A title of ours will not call the tracking authorisation prompt, will not read the advertising identifier, and will not attempt to reconstruct a cross-app identity by any indirect route — device fingerprinting included, since evading the prompt while honouring its wording would be a cheat rather than a compliance strategy. If a title ever does show that prompt, the honest reading is that this paragraph has been changed, and the version history at the foot of this page will show when.
On Google Play, the Data Safety section of a store listing is a declaration to players about what an app collects, what it shares, whether transmission is encrypted, and whether deletion can be requested. We will complete it to match this page exactly. Where the store's categories are coarser than the description here — and they are, necessarily — the store form is the summary and this page is the detail. Should the two ever disagree, tell us, because one of them is wrong and we would like to know which.
Both stores also carry their own commerce, receipts and refund records. Those are the platform's records of a transaction with you, held under the platform's terms; we see what the store reports to a developer and no more, and we do not receive your payment card details at any point.
Purpose, and the drift away from it
Australian Privacy Principle 6 confines the use and disclosure of personal information to the purpose it was collected for, with narrow exceptions for a related secondary purpose a person would reasonably expect, for consent, and for certain legal requirements. The principle is easy to state and easy to erode, because erosion happens one small reasonable-sounding step at a time. Gameplay signals collected to estimate difficulty get looked at to understand retention. Retention analysis suggests a segment. The segment is useful to a marketing decision. No step in that chain looks like the moment anyone broke a promise, and yet the end of the chain is nothing like the beginning.
Our defence against that is not a stronger adjective. It is the architecture already described: the difficulty subsystem holds gameplay signals and has no path to purchase or offer state, so the third step in that chain has nowhere to run. Beyond that, we use what we hold to make a title work as intended, to keep it secure and stable, to answer correspondence, to meet the record-keeping that Australian tax and corporations law imposes on any company, and to establish or defend a legal claim if we are unlucky enough to have one.
What we will not do is sell personal information, rent it, or trade access to it as a commercial product in its own right. We will not train a model on data belonging to another studio's players. Direct marketing is governed by Australian Privacy Principle 7 and, for commercial electronic messages, by the Spam Act 2003 (Cth); we send none, hold no marketing list, and if that ever changes it will be with consent, a working unsubscribe, and a sender you can identify at a glance.
Who else would touch it
No organisation of any size operates alone, and a list of the categories of other hands involved is more useful than a promise that there are none. The list is short and it is specific: a hosting and content delivery provider serves these pages, and a mail provider carries correspondence. That is the whole of it. Neither is given our data as a product to work with; both are suppliers performing a defined function under their own contractual and security terms.
A title on a store adds a small number of further categories — crash and stability reporting, the store platform itself for distribution and payment, and an advertising network where a title carries advertising. Each gets named specifically on this page rather than buried in a settings screen, and named before it starts receiving anything rather than after.
An advertising network, where one is ever used, is worth separating out. It is not a supplier processing data on our behalf; it collects for its own purposes under its own policy, and describing that relationship as processing would misrepresent it. Personalised advertising in any title of ours will be off unless a player turns it on, non-personalised advertising will be the default, and the difficulty model will never see advertising data in either configuration.
The remaining category is compulsion. If a law, a court order or a properly issued warrant requires disclosure, we will comply, but we will read the instrument first, satisfy ourselves it covers what it claims to cover, disclose only what it actually reaches, and tell the affected person unless we are prohibited from doing so. We would also sooner say plainly that we have never received such a request than construct a warrant canary that is more theatre than protection.
Across a border
APP 8, on cross-border disclosure, is the provision that trips up companies that think of cloud infrastructure as a place-less utility. Hand personal information to somebody located outside the country and you are first obliged to take reasonable steps towards satisfying yourself that they will not go on to breach the Australian Privacy Principles. Section 16C then does something people underestimate: it makes you answerable for that recipient's conduct as though the conduct had been your own. Picking an offshore supplier spreads none of the responsibility around. It concentrates all of it on you.
We take that seriously in the only way a company this size honestly can. We prefer Australian regions where a supplier offers them and the cost is not absurd. Where a supplier is a global content delivery network, we accept that content is served from wherever a request lands, which for a public website of static pages is a very low-stakes form of overseas disclosure. And when a supplier is engaged, the contract has to carry Australian Privacy Principle obligations through to it, because an unwritten expectation is not a reasonable step.
Concretely, at the time of writing: this website is served by a global content delivery network with edge locations in many countries, and correspondence is handled by a mail provider whose infrastructure includes servers in the United States. No other overseas recipient receives personal information from us. Any material change to the countries involved is described here rather than announced by inference.
One boundary is worth stating separately. Australian Privacy Principle 9 restricts the adoption, use and disclosure of government related identifiers — a tax file number, a Medicare number, a driver licence number. We do not collect them, will not use them as an account key, and will not accept them as proof of identity for a privacy request. If you send one to us unprompted, we will delete it and ask you for something else.
Retention
Once information has stopped serving any purpose we are permitted to hold it for, APP 11 says it has to be destroyed, or else stripped of whatever links it to a person. No figures are attached, which is why so many policies substitute the phrase "as long as necessary" and leave it there. That phrase is not a retention schedule; it is a way of declining to write one. The numbers below are ours, and the reasoning for each is included so that a reader can judge whether it is defensible rather than merely stated.
Ordinary support correspondence is kept for twenty-four months from the last message in the thread. The period is long enough to recognise a recurring problem across two annual cycles of a product and to answer a follow-up from someone who wrote a year ago, and short enough that a mailbox does not silently become an archive of everyone who ever asked us a question.
Correspondence about a privacy complaint is kept for seven years. That is deliberately longer, and it is not a convenience: a complaint may reach the Office of the Australian Information Commissioner well after we thought a matter closed, and destroying the record of what was said would leave both sides arguing from memory. The person best protected by a durable complaint file is usually the complainant.
Financial and taxation records are kept for five years from the relevant transaction, which is what Australian tax law requires of any business, and corporate records are kept as the Corporations Act 2001 (Cth) directs. Server logs are held for a short operational window and then rotated away. Gameplay signals from a published title are retained only as long as the model and the live systems need them; the aggregate statistics that survive that period are not personal information and are not reconstructable into it.
Backups deserve their own sentence because they are where retention promises usually quietly fail. Deleting a record from a live system does not immediately remove it from a backup taken yesterday. Our commitment is that backups are held on a rolling cycle, are not mined for any purpose, and are not used to resurrect something you asked us to remove; deletion propagates as the cycle turns rather than instantaneously, and we would rather say that than imply a completeness no backup regime provides.
Security, and limits we will not paper over
That same principle carries a second limb, concerned with guarding information rather than disposing of it: reasonable steps against its being misused, against its being interfered with, against its going astray, and against anyone reaching it, altering it or passing it on without authority. Reasonableness here scales to the size of the entity and to how sensitive its holdings are, which for a company of this size means a short list of things actually done rather than a long list of things aspired to.
Traffic to this site is served over TLS and the certificate is renewed automatically. Administrative accounts on the systems that matter carry multi-factor authentication. Access follows from need rather than seniority, and that is the standing habit rather than a stage the company is passing through. Dependencies are patched on a routine rather than when something appears in the news. The mailbox is a business mail service, not a personal address forwarded somewhere convenient.
Privacy questions here are settled by the people who write the software. The Privacy Act requires no data protection officer of a company at this scale, and creating the title for a letterhead would misrepresent where the decisions are made: the escalation desk and the engineering desk are the same one, which is slower to hide behind and faster to get an answer out of.
No security posture is a guarantee, and a policy that implies otherwise is selling reassurance rather than describing a system. What we will commit to is that we will not describe a control we have not implemented, and will not answer a security question with a marketing sentence. If you find a weakness, the section below on failure explains how we would like to hear about it.
When it goes wrong
The Notifiable Data Breaches scheme lives in Part IIIC of the Privacy Act, and it is one of the few parts of Australian privacy law with a clock attached. Once there are reasonable grounds to suspect an eligible data breach — somebody reached information they had no business reaching, or it was let out, or it went missing, and serious harm to a person is the likely upshot — a thirty day assessment window opens, to be worked through reasonably and without dawdling. Confirm the suspicion and two sets of people have to hear about it as quickly as can practically be managed: the Commissioner, and everybody exposed.
We intend to treat those as ceilings rather than targets. Thirty days is the outer bound of an assessment, not a period to be used in full while a person who could be acting to protect themselves is left uninformed. Our practice will be to contain first, assess quickly, and notify the moment the threshold is reached rather than the moment the deadline approaches. A notification from us will say what happened, what information was involved, when we became aware, what we have done, and what you can usefully do — in that order, in plain sentences, without the passive constructions that make an incident report read like weather.
Where a breach falls below the statutory threshold we may still tell affected people, because the test for notifying is whether the information is useful to them, not whether the Act compels it. We keep a record of incidents we assess, including the ones we conclude are not notifiable and why, since the reasoning is exactly what an audit later needs.
If you believe you have found a vulnerability in this site or in anything we publish, write to us and we will reply on the same or the next business day. A report made in good faith will never be treated as an attack and will never attract a legal threat from us. In return we ask for the ordinary courtesy of the field: tell us before you tell anyone else, and give us a reasonable window to fix it.
Children, and an age we cannot verify
Mobile games attract children, and any studio that says otherwise has not looked. No age appears anywhere in the Privacy Act at which somebody becomes competent to consent to their own information being handled. What the Commissioner's guidance supports instead is a judgement reached person by person, falling back on a rule of thumb around fifteen wherever judging individually is not feasible. The Children's Online Privacy Code being developed under the Act will sharpen this considerably, and we will follow it when it lands rather than waiting to be told.
Where consent would be needed and has not been obtained, we do not set out to gather a child's personal information at all. As sentences go, that one is entirely standard, and standing by itself it is close to worthless, because the mechanism it depends on is an age gate that a nine-year-old defeats by typing a different year. So the design decisions matter more than the declaration. A title of ours will not require a real name to play, will not require an account for the core experience, will not ask a child for contact details, and will not present personalised advertising to a user identified as a child. Where a store's own family programme imposes stricter rules on a title, those rules govern, and we would rather lose a feature than argue the point.
A parent or guardian who believes we hold information about their child can write to us and ask what it is and ask us to remove it. We will not put such a request through a slower or more sceptical process than any other, and we will not demand documentary proof of guardianship where the request can be verified more simply.
Access and correction
Two rights fall out of Australian Privacy Principles 12 and 13 — APP 12 and APP 13 — and both are worth rather more than most of the apparatus built around them. The first lets you ask which personal information about you sits here, and to be handed it. The second lets you require a correction wherever what is held turns out to be mistaken, stale, patchy, beside the point, or apt to mislead. Both rights are exercised by writing to [email protected], and no particular form of words is required — an email that makes the request recognisable is enough.
We answer within thirty days. Satisfying ourselves that you are the person concerned happens within those thirty days, not as an extra stage bolted on ahead of them, and whatever proof we ask for stays proportionate to what you have asked us to do: for a general enquiry, nothing at all; for records tied to an identifier, evidence of control of that identifier and nothing more invasive. Making a request costs nothing, and neither does having something put right. If producing a large volume of material genuinely costs us something, any charge would be reasonable, based on actual cost, and told to you in advance so that you can decline before it is incurred. In practice we expect never to make one.
Refusals happen, and the Act contemplates them: an unreasonable impact on another person's privacy, a frivolous or vexatious request, information relating to anticipated legal proceedings, and a handful of others. A refusal arrives with reasons in writing, identification of the particular ground being relied upon, and a plain account of how to complain about the refusal itself. What you will not receive is silence, which is the response the access right is actually designed to prevent.
Where we correct something, and where it is reasonable to do so, we will also tell anyone we previously disclosed it to. Should we refuse a correction, you are entitled to have your own account of the matter fastened to the record, and we will fasten it somewhere nobody reading that record could miss.
Deleting an account
Australia has no general right to erasure of the European kind. What it has instead is Australian Privacy Principle 11.2, which obliges us to destroy or de-identify information we no longer need — an obligation that runs on us continuously and does not wait for anyone to invoke it. We also think a person should be able to ask directly, so we treat deletion as a request we honour rather than a right we require you to establish.
Where a title of ours has an optional account, you will be able to delete your account from inside the application itself, and both major stores now expect exactly that of any app that offers accounts. The route will not be hidden behind a support conversation designed to talk you out of it. You can also simply write to us, and we will action the deletion of data associated with that account within thirty days.
Deletion means the account record and the identifiers linked to it are removed from live systems, and that the gameplay signals attached to that identifier stop being attached to anything that can point back at you. It does not mean we rewrite history: aggregate statistics that were derived earlier and cannot be resolved back to an individual remain, financial records of a purchase are kept for the five years tax law requires, and correspondence about a complaint remains within the retention period described above. A model that was trained on a dataset including your play is not retrained on the day you ask; what happens instead is that the underlying record is removed and does not enter the next training set. Saying this plainly is better than promising an instantaneous erasure that no honest engineering team could deliver.
Deleting an account is also irreversible, which is the point of it. Progress, purchases and history do not survive, and we will say so clearly at the moment you ask rather than afterwards.
Decisions we will not hand to a model
From 10 December 2026, the Privacy Act requires a policy to disclose where automated decisions that significantly affect a person's rights or interests are made using personal information. We are writing our disclosure before the obligation begins, and it is short: nothing we operate makes a decision of that kind.
No model of ours decides whether a person gets a refund, whether a purchase is honoured, whether an account is suspended or restored, or whether someone is given access to something they paid for. Where a title of ours ever needs an anti-cheat or abuse system, an automated signal may flag an account for review, but the decision that follows will be made by a person, and anyone affected will be told what happened and be able to contest it with a human being who has the authority to reverse it.
The adaptive difficulty model does make automated decisions in the ordinary engineering sense — it changes what the next round looks like — and we do not want to hide behind a narrow reading of the statute. But a decision about the shape of a puzzle is not a decision about a person's rights or interests, and the two are kept apart by design: the model has no access to money, entitlements or account status, so the category of decision the law is worried about is not available to it. If that ever ceases to be true, this section is where the change will appear.
Complaining, to us and then past us
Start with us, because most complaints are faster to resolve at the source and because the regulator will generally want to see that you tried. Put "Privacy complaint" in the subject line, send it to [email protected], set out the sequence of events, and name the outcome you want. You will get confirmation that it has landed within five business days and a decision within thirty. If we conclude we were wrong, we will say so without arranging the sentence to avoid the admission, tell you what we have changed, and tell you when.
Should our answer leave you dissatisfied — or should you simply prefer not to have the conversation with us at all — privacy complaints against Australian organisations are heard by the Office of the Australian Information Commissioner. The OAIC can be reached at oaic.gov.au, by telephone on 1300 363 992, or by post at GPO Box 5218, Sydney NSW 2001. Complaining costs nothing, needs no legal representation, and does not require our consent or cooperation. In the ordinary course the Commissioner asks that an organisation be given around thirty days to respond before a complaint is taken up, which is why the paragraph above exists — not as a hurdle, but because that is how the process is designed to run.
Australian law has additionally carried, since 10 June 2025, a statutory cause of action for serious invasions of privacy — pursued through a court, and standing entirely apart from the complaint route described above. We mention it because a document about your privacy that omits the remedy least convenient to its author is not a complete document.
Readers who are not in Australia
The company is Australian, what it offers is aimed at Australia, and this policy answers to Australian law. Nothing here should be read as a claim to comply with the General Data Protection Regulation, the United Kingdom's data protection regime, or any state privacy statute in the United States, and we are not going to imply otherwise by borrowing their vocabulary. You will not find the words controller or processor used as terms of art on this page, because they are not the terms the Privacy Act uses.
What we can say is that the substance underneath those regimes and this one overlaps a great deal. Collect only what is needed, say what it is for, keep it no longer than the purpose requires, let people see it and fix it, protect it properly, and tell people promptly when something goes wrong. Those commitments are made here to everyone who reads this page, whatever the law of the place they read it in, and we would apply them to a request from overseas exactly as we would to one from Sydney.
If a title of ours is ever distributed into a market whose law imposes obligations beyond the Privacy Act, we will meet those obligations in that market and describe them here rather than quietly hoping the question does not arise.
How this page will change
What you have been reading is revision 2.0, in force from 12 August 2026, and it displaces the first version of this policy entirely. It is a rewrite rather than an amendment: the earlier text was organised as numbered clauses and this one is organised as an argument, on the view that a person is more likely to finish reading a page that explains its reasoning than a page that enumerates its terms.
The date and version at the head of this page are the record. When something material changes — a new category of information collected, a new recipient, a shortened or lengthened retention period, a change to the advertising position or to the tracking commitments — the version number moves, the effective date moves, and the change is described rather than silently absorbed. Where a change reduces what you can expect from us, we will not treat continued use of a website as agreement to it; we will say what has changed and why, and we will do it before the change takes effect rather than after.
Typographical corrections and clarifications that do not alter meaning will be made without ceremony. The distinction between those two categories is one we will apply honestly, and it is exactly the sort of judgement a reader is entitled to hold us to.
Writing to us
Every route into this company is the same address: [email protected]. Privacy questions, access requests, corrections, deletions and complaints all arrive there and are read by the people who build the software rather than routed to an outsourced desk. The contact page sets out what to put in a message so that we can act on it without a round trip.
The company behind the address is AIDEOLOGY TECHNOLOGIES PTY LTD, ACN 698 536 953, ABN 81 698 536 953, with its main business location in New South Wales, Australia. Service of a formal document takes effect at the registered office entered against that ACN on the ASIC register. No second address is printed on this website, since a postal address carrying no legal effect amounts to ornament, and ornament here would only misdirect a notice that mattered.
Two further pages complete the picture: the cookie notice covers browser storage and the single outbound request this site makes, and the terms of use cover the contract itself. Where this policy and either of those describe the same handling, this policy is the one that governs the handling.