Privacy Statement
How BrightPath AI Solutions handles personal information in DeskMate. Last updated 27 July 2026.
Our commitment and compliance
BrightPath AI Solutions Pty Ltd operates DeskMate in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). This statement explains what we collect, why, and what we will never do with it.
Our role and the Customer's role
Where DeskMate processes information on behalf of a Customer, the Customer is the controller and BrightPath is the processor. We act on documented instruction and nothing else.
Personal information we process
- Names and contact details of the Customer's personnel and their clients
- Content of emails and documents relevant to a Skill
- Chat history, OAuth tokens for connected systems, and audit logs
How we use personal information
Only to run the Skills a Customer has configured, to keep the service secure and available, and to meet our legal obligations. We do not sell it, and we do not profile individuals.
We do not use your data to train AI models
Customer content is never used to train, fine-tune or evaluate any model — ours or a third party's. Model endpoints are region-locked and stateless between calls.
Where your data is stored and processed
All application, database, object-storage and model infrastructure runs in Google Cloud's australia-southeast1 (Sydney) region. There is no cross-region replication.
Disclosure and sub-processors
We disclose to a short list of sub-processors strictly necessary to run the service. The current list is available on request and Customers are notified before it changes.
Cross-border disclosure
We do not disclose personal information overseas in the ordinary operation of DeskMate. Where that ever changes, affected Customers are notified in advance.
Access, correction and data subject requests
Individuals should contact the Customer that holds their data. Where a request reaches us directly, we forward it to the relevant Customer within five business days.
Data breaches
We operate an assessment process under the Notifiable Data Breaches scheme. Customers are notified without undue delay and in any case within 72 hours of assessment.
Retention and deletion
Chat history follows the tenant's configured window. Run logs are kept 18 months. On termination, tenant data is hard-deleted within 30 days including backups.
How to contact us
Privacy enquiries: privacy@brightpathaisolutions.com. Postal address available on request.
Questions about this?
Legal and privacy enquiries go straight to a human, not a ticket queue.
Contact us