Privacy Policy
What we collect, why we collect it, who sees it and how to get it back or corrected. In plain English rather than boilerplate.
Last updated 18 August 2026
- 01
Who this policy covers
This policy explains how 2Gen (ABN 85 126 837 232) handles personal information. It applies to this website and to the services we provide, including AI and automation builds, custom applications, integrations, MCP gateways, security testing and assurance work.
We are bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where we handle health information or the personal information of your customers on your behalf, we also comply with the obligations that apply to that information.
You can reach us through the contact form, call (07) 5676 7240 or write to us at 6/14–16 Kohl Street, Upper Coomera QLD 4209.
- 02
What we collect
We collect only what we need to respond to you and to deliver work you have engaged us for.
- When you use our contact form: your name, business name, email address, phone number, the service you selected and whatever you write in the message field.
- When you email or call us: your contact details and the contents of the correspondence.
- During an engagement: the names, roles and contact details of the people we work with at your business, plus notes and records relating to the work.
- Automatically: our hosting provider keeps standard server logs, which may include IP addresses, browser type and the pages requested. These are used for security and reliability rather than to build a profile of you.
We do not collect sensitive information through this website and we ask that you do not send it to us through the contact form.
- 03
Cookies and tracking
This website sets no cookies of its own. It runs no analytics, no advertising pixels and no third-party tracking scripts. Fonts are served from our own domain rather than requested from a third party, so simply reading this site does not report your visit to anyone else.
The live chat is the one exception. It only runs if you start it. The chat button in the corner is ours and loads nothing. Clicking it loads the 3CX chat widget, which is supplied by a third party and may set cookies or browser storage to hold your conversation. Until you click, nothing from 3CX is requested and 3CX is not told you were here. Conversations run on our own 3CX system hosted in Australia. If you would rather not use it, the contact form and the phone number do the same job.
The contact form carries a short human check to keep automated submissions out. It is generated and verified on our own server, so unlike a third-party captcha it sends nothing about you to anyone else and sets nothing on your device.
If that changes we will update this policy and say so here before the change takes effect.
- 04
How we use it
We use personal information to:
- respond to your enquiry and have a conversation about whether we can help
- scope, quote and deliver work you have engaged us for
- provide support, invoice you and keep proper business records
- meet our legal, insurance and professional obligations
We do not sell personal information. We do not use your enquiry to add you to a marketing list without your agreement. Any commercial electronic message we do send will let you opt out.
- 05
Information we access during an engagement
Our work often involves access to systems that hold your business's information, including email, document stores, line-of-business databases and customer records. Two things follow from that.
We access the minimum required. Where the work can be done against test or de-identified data, we ask for that instead of production data. Where production access is genuinely necessary, we scope it to what the task needs and for as long as the task takes.
Your data stays yours. We treat information we encounter in your systems as confidential. We do not use it to train models, we do not reuse it for other clients and we do not retain copies beyond what the engagement requires. Where an engagement has its own confidentiality or data handling terms, those terms apply in addition to this policy.
- 06
Where your information is stored
Your information stays in Australia. This website and the systems holding information you send us are hosted in Australian data centres. That is a deliberate choice. For clients in financial services, healthcare and anything touching government, data sovereignty is a requirement rather than a preference. We would rather meet it by default than by exception.
The same principle applies to what we build for you. Where an engagement involves hosting, we default to Australian regions and will tell you plainly if a particular service cannot be provisioned onshore, before you commit to it.
A limited number of general business tools we use to run our own operation may process some information overseas. Where that happens we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles it consistently with the Australian Privacy Principles.
- 07
Who we share it with
We disclose personal information only where it is necessary and only to:
- service providers who support our own operations, such as hosting, email and accounting
- professional advisers such as our accountants, insurers or lawyers
- a party you have asked us to deal with on your behalf
- anyone we are required or authorised by law to disclose it to
Our hosting is Australian, as set out above. We do not sell or rent personal information to anyone and we do not disclose it for anyone else's marketing.
- 08
How we protect it
We use access controls, multi-factor authentication, encryption in transit and the principle of least privilege across our own systems. Access to client information is limited to the people doing the work.
No system is perfectly secure and we will not claim otherwise. If a data breach occurs that is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
- 09
How long we keep it
We keep personal information only for as long as it is needed for the purposes described above, or for as long as we are required to keep it by law, whichever is longer. Business and financial records are generally kept for seven years. Enquiries that do not lead to work are cleared out once they are no longer of any use. When information is no longer needed we destroy it or de-identify it.
- 10
Accessing and correcting your information
You can ask us what personal information we hold about you and ask us to correct anything that is wrong. Send the request through our contact form or call us. We will respond within a reasonable period, normally 30 days.
There is no charge for making a request. If we refuse access or a correction we will tell you why in writing.
- 11
Complaints
If you think we have mishandled your personal information, tell us through the contact form or call us. We will acknowledge your complaint, investigate it and respond in writing, normally within 30 days.
If you are not satisfied with our response you can take the complaint to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
- 12
Changes to this policy
We may update this policy as our services or obligations change. The current version always lives at this address and the date at the top tells you when it last changed. See also our terms of use.