Privacy Policy
PIONEER TACTICS · ABN 38 040 611 969 · LAST UPDATED 16 JULY 2026
The short version
We collect very little. We tell you what we collect and why. We don't sell your details, and we don't add you to anything you didn't ask for. Some of the tools we use store data overseas, and we've named every one of them below rather than hiding it in a clause.
If you'd rather not read the rest, that's the whole of it. The detail follows.
Who we are
Pioneer Tactics is a consultancy based in Toowoomba, Queensland, delivering project management, AI automation and web design services locally and Australia-wide. In this policy, "we", "us" and "our" mean Pioneer Tactics.
This policy covers pioneertactics.com.au and the services we deliver to clients.
On the small business exemption: businesses turning over under $3 million a year are generally exempt from the Privacy Act 1988 (Cth). We don't rely on that exemption. We handle personal information in line with the Australian Privacy Principles because it's the right way to run, because the exemption is under active review, and because our clients expect it regardless of our size.
What we collect
When you contact us. Your name, email address, phone number if you give it, your business name, and whatever you choose to tell us about what you need.
When you complete the AI Readiness Diagnostic. Your email address, if you ask us to send the breakdown, plus your answers to the seven questions. Those answers describe how your business currently operates — your tools, your processes, how your team works. See section 4.
When you visit the site. Standard analytics data: pages viewed, approximate location at a city level, device and browser type, how you arrived, how long you stayed. This is aggregated and we don't use it to identify you.
When you become a client. Whatever is necessary to do the work — which varies by engagement and is covered in section 5.
What we don't collect
- We don't collect payment details through this website.
- We don't collect sensitive information as defined in the Privacy Act — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric data. Don't send it to us; we don't want it and we don't need it.
- We don't buy contact lists, and we don't scrape them.
- We don't sell, rent or trade your personal information to anyone. Not ever, not to anyone, for any price.
The AI Readiness Diagnostic
This one gets its own section because it collects more than a contact form does.
What we collect: your seven answers and, only if you ask for the breakdown, your email address.
What we do with it: we score it, and we send you the breakdown you asked for. That's it. We also look at the answers in aggregate to check the diagnostic is working — if everyone lands on the same level, our scoring is wrong and we need to know.
Your result is not gated. You see your level and your recommendations without giving us anything. The email is only if you want the fuller write-up.
What your answers reveal. Your answers describe how your business runs — where your enquiries land, what's documented, who owns your tools. That's commercially useful information about your operation, and we treat it as confidential. We don't share it, publish it, or use it in any case study, marketing material or client example without asking you first and getting a yes.
Where it goes. Your submission is processed by Formspree, which stores data in the United States. See section 7.
One email. If you give us your address, you get the breakdown. We may follow up once if it seems useful. You will not be added to a mailing list, a nurture sequence, or anything else. If you'd rather we deleted it, ask and we will.
Client information
When you engage us, the work often means handling your business information — project documents, meeting notes, contracts, process documentation, system access, and sometimes personal information about your staff or customers.
We treat all of it as confidential. We don't use client information for any purpose other than delivering the engagement. We don't reference identifiable client work in marketing without written permission.
Access. Where an engagement needs access to your systems, we ask for the minimum required, for the shortest time required, and we tell you when we no longer need it. We don't retain credentials after an engagement ends.
Return and deletion. At the end of an engagement, we return or delete your material on request. Some records are retained where we're legally required to keep them — see section 8.
If your engagement involves personal information about your customers or staff — for example, an automation touching your CRM, or a document summary containing employee details — we'll agree in writing beforehand what we're handling, why, and for how long. That conversation happens before the work starts, not after.
Why we collect it
We collect personal information to:
- respond to your enquiry
- send you the diagnostic breakdown you asked for
- deliver services you've engaged us for
- issue invoices and keep the financial records the law requires
- understand how the site is used, so we can improve it
- meet our legal obligations
If you don't give us the information we need, we may not be able to help you. That's the only consequence.
We don't use your information for automated decision-making that has a legal or similarly significant effect on you. The diagnostic scores your answers and shows you a result — it doesn't decide anything about you, and a person reviews every recommendation before it goes anywhere.
Third parties, and where your data goes
We use third-party services to run the business. Several store data outside Australia, which under Australian Privacy Principle 8 we're required to tell you about. Here's the complete list.
| Service | What it handles | Where it's stored |
|---|---|---|
| Formspree | Diagnostic and contact form submissions | United States |
| Google Analytics | Aggregated website usage data | United States and elsewhere |
| Lovable | Website hosting | United States |
| Microsoft 365 / Outlook | Our business email | United States and elsewhere |
| Anthropic (Claude) | AI processing during service delivery — see section 9 | United States |
By using this website or engaging us, you accept that your information may be handled in these countries. Their privacy laws differ from Australia's, and Australian Privacy Principle 8.1 may not be enforceable against an overseas recipient in the same way it would be against us. We choose providers with published privacy commitments, but we can't guarantee foreign law will treat your information the way Australian law does. If that's a problem for your organisation, tell us before you engage us — we can usually work around it, and we'd rather have the conversation early.
We may also disclose your information where we're required or authorised by law to do so.
How long we keep it
| What | How long |
|---|---|
| Enquiries that don't become work | 12 months |
| Diagnostic submissions | 24 months, or until you ask us to delete them |
| Client records | 7 years after the engagement ends, as required by Australian tax and business record-keeping law |
| Client working material (documents, notes, system access) | Returned or deleted at the end of the engagement on request |
| Analytics data | Per Google Analytics' retention settings, currently 14 months |
Ask us to delete something and we will, unless we're legally required to keep it. If that's the case, we'll tell you which record and why.
AI tools
We're an AI consultancy. You're entitled to know exactly how we use AI on your information, so here it is plainly.
We use Claude (Anthropic) in delivering some services — document and meeting summaries, content production, and analysis work. Where an engagement involves putting your material through an AI tool, we tell you before it happens, and it's covered in your engagement terms.
We don't put client information into AI tools that train on it. We use business-tier services with contractual commitments against training on customer data.
Nothing we produce with AI goes to you unreviewed. Every output has a human checkpoint. That's a delivery standard, not a privacy nicety, and it applies to everything we build.
Your diagnostic answers are not fed into an AI tool. They're scored by a formula. Your breakdown is written by a person.
Security
We hold your information in access-controlled accounts with multi-factor authentication enabled. We keep the number of tools handling your data deliberately small, because every extra tool is another place data can leak from.
We'll be straight with you: no system is completely secure, and we're a small business, not a bank. If we ever have a data breach that's likely to cause you serious harm, we'll notify you and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Access and correction
You can ask us what personal information we hold about you, and we'll tell you. You can ask us to correct it, and we will. You can ask us to delete it, and we will unless the law requires us to keep it.
Email pioneertactics@outlook.com. We'll respond within 30 days, usually much sooner. There's no charge.
Complaints
If you think we've mishandled your personal information, email pioneertactics@outlook.com and say so. We'll respond within 30 days.
If you're not satisfied with our response, you can take it to the Office of the Australian Information Commissioner:
Web: oaic.gov.au
Phone: 1300 363 992
Changes to this policy
We may update this policy. The date at the top tells you when it last changed. If we change it in a way that materially affects how we handle information we already hold about you, we'll tell you directly rather than quietly updating the page.
Contact
Pioneer Tactics
ABN 38 040 611 969
Toowoomba, Queensland, Australia
pioneertactics.com.au