Privacy Policy
My Trade Cover Pty Ltd ABN 44 662 186 389 Website: madereal.com.au Effective date: 28 July 2026 Version: 2026-07-28.3 Privacy contact: [email protected]
1. About this policy
This Privacy Policy explains how My Trade Cover Pty Ltd (referred to as My Trade Cover, we, us or our) collects, holds, uses and discloses personal information through the website at madereal.com.au and the AI-assisted project intake service available through that website.
The name madereal.com.au is the domain name of the website. It is not a separate legal entity or trading name. My Trade Cover Pty Ltd is the organisation responsible for personal information collected through the website.
We aim to handle personal information transparently and consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. If the Privacy Act does not apply to a particular activity because an exemption is available, we will still seek to follow the privacy practices described in this policy.
This policy applies only to the website and service described above. A separate policy may apply to another website, product or service operated by My Trade Cover.
2. Plain-English summary
When you use the website:
- you may speak with an AI assistant;
- what you type is sent, message by message, to a third-party AI model provider outside Australia;
- if you submit a project brief, we collect your name and email address and any optional information you provide;
- the complete AI conversation is stored with the submitted brief, not merely a summary;
- the brief is stored in a private GitHub repository, and emails are sent from our own mailbox at [email protected] and handled by our mail provider;
- GitHub may process or store personal information in the United States, and our mail provider may process email outside Australia;
- the website hosting infrastructure is located in Sydney, but this does not mean all personal information remains in Australia;
- we do not provide user accounts, passwords or payment facilities through this intake service;
- we do not use the intake service for advertising cookies or cross-site behavioural tracking;
- information removed from the current version of our Git repository may remain in its version history; and
- you may contact us about access, correction, deletion or a privacy complaint at [email protected].
Please do not include sensitive, confidential or third-party information unless it is genuinely necessary for us to understand your project and you are authorised to provide it.
3. Information we collect
3.1 Information you provide
We collect the information you choose to provide through the website, including:
- your name;
- your email address;
- your phone number, if supplied;
- your business name, if supplied;
- free-text answers about your idea, business, project, objectives or requirements;
- documents or other content you upload, if the website permits uploads;
- the complete content of your conversation with the AI assistant; and
- communications you later send to us, including emails and attachments.
Your name and email address are required to submit a brief. Other form fields are optional unless the website clearly states otherwise.
3.2 AI conversation information
Every message you enter into the AI assistant, and every response produced during that conversation, may be retained as part of the project transcript.
The transcript may contain personal information if you include names, contact details, circumstances, business information or other identifying details. We do not require you to include unnecessary sensitive information.
3.3 Information collected automatically
When you use the website, limited technical information may be generated, including:
- your internet protocol address;
- request date and time;
- browser and device information;
- pages or functions requested;
- error and diagnostic information; and
- standard web server log information.
For submission rate-limiting, the application temporarily uses an IP address in memory to count how many briefs have been sent from that address during the day. That rate-limit value:
- is not written to the submitted brief;
- is not intentionally stored alongside your name or contact details;
- is lost when the application restarts; and
- is used only to protect the service from excessive or abusive submissions.
Separate infrastructure or server logs may still record IP addresses as part of ordinary hosting operations.
3.4 Information we do not collect through this service
The current intake service does not require or provide:
- user accounts;
- usernames;
- passwords;
- customer logins;
- payment card details;
- online payment processing;
- advertising profiles;
- advertising cookies; or
- cross-site behavioural tracking.
Because there is no user account, there is no account to close. Privacy requests must be made by contacting us.
4. How we collect information
We collect personal information:
- directly from you when you type into the AI assistant, complete the form, submit a brief, upload material or contact us;
- automatically through ordinary website and server operation;
- from service providers that process website requests, AI messages, stored briefs or emails for us; and
- from another person where they submit information about you, provided it is lawful and reasonable for us to collect it.
If we receive personal information that we did not request, we will assess whether we could lawfully have collected it. Where appropriate and reasonably practicable, we may delete or de-identify information we do not need.
5. Why we collect and use information
We collect, hold and use personal information to:
- provide and operate the website and AI-assisted intake service;
- generate AI responses during your conversation;
- understand your project, business, objectives and requirements;
- create and retain a project brief and complete transcript;
- review your enquiry and decide whether and how we may assist;
- contact you about your enquiry;
- prepare proposals, scopes, recommendations or next steps;
- provide customer support and respond to questions;
- send submission confirmations and internal alerts;
- prevent spam, fraud, misuse and excessive submissions;
- diagnose faults and improve reliability;
- maintain business and legal records;
- comply with applicable laws, court orders and regulatory requirements;
- establish, exercise or defend legal claims; and
- improve the service using operational learnings, provided we do not use your identifiable project transcript to train a general-purpose AI model unless we first tell you and obtain any consent required by law.
We will not sell your personal information.
We will not use your personal information for unrelated direct marketing unless permitted by law. You may opt out of marketing communications at any time.
6. How the AI assistant works
6.1 Third-party AI processing
The AI assistant is powered by a third-party AI model provider. The model is not owned or operated by My Trade Cover.
Each message you enter is transmitted to the provider as the conversation occurs so the provider can process the message and return a response. The provider may process that information outside Australia, including in the United States.
The website should display a clear AI and overseas-processing notice before you begin typing. By choosing to start or continue the AI conversation after seeing that notice, you acknowledge that this processing will occur.
6.2 AI is not a person or professional adviser
The AI assistant is an automated system. It may misunderstand information, omit important details or produce inaccurate, incomplete or inappropriate responses.
AI responses are provided to assist with intake and discovery. They are not legal, financial, tax, medical, engineering or other professional advice. You should not rely on an AI response as a substitute for advice from an appropriately qualified professional.
6.3 Human review
A member of our team may review a submitted brief and its complete transcript. Submission does not guarantee that we will accept a project, provide a service or contact you.
The AI assistant does not make a final decision that creates a contract with you. Any engagement, price, scope, acceptance or commitment must be separately confirmed by an authorised person.
6.4 Do not provide unnecessary sensitive information
Do not enter information such as health records, biometric information, government identifiers, financial account details, passwords, private legal advice, trade secrets or information about another person unless it is necessary and you are authorised to provide it.
If you provide sensitive information voluntarily, you consent to us collecting and handling it for the purpose for which you supplied it, subject to applicable law. We may ask you to provide additional express consent where required.
7. The full conversation is stored
If you submit a project brief, we retain the full AI conversation associated with that submission, including:
- your messages;
- the AI assistant’s responses;
- questions, corrections and clarifications;
- the contact and project information supplied through the form; and
- relevant submission metadata.
We retain the full transcript rather than only an AI-generated summary because the original conversation records what you actually told us and provides context for reviewing your project.
You should assume that anything entered into the AI conversation may become part of the stored brief.
8. How your information moves through the service
The normal data flow is:
- You type a message into the AI assistant.
- The message is transmitted to a third-party AI model provider, generally outside Australia, to generate a response.
- The response is returned to the website and displayed to you.
- The process repeats for each turn of the conversation.
- When you submit the brief, your contact details, project answers and full transcript are assembled into a project record.
- The project record is stored in a private GitHub repository.
- Confirmation and internal alert emails are sent from our own mailbox at [email protected], through our website and mail hosting provider.
- Our team may review the brief and contact you.
- The record is retained in accordance with section 13 of this policy.
The website application may be hosted in Sydney, Australia. However, AI processing and repository storage involve providers that operate outside Australia, and email handled by our mail provider may also be processed outside Australia. Hosting the website in Sydney does not mean all personal information remains in Australia.
9. Disclosure of personal information
We may disclose personal information to:
- AI model providers that generate responses;
- GitHub, which provides private repository hosting;
- website, mail hosting, infrastructure, security and technical support providers;
- contractors and professional advisers who need the information to support us;
- a prospective purchaser, investor, financier or adviser in connection with a genuine business transaction, subject to appropriate confidentiality arrangements;
- regulators, courts, law enforcement bodies and government agencies where required or authorised by law; and
- another person where you direct or authorise us to disclose it.
We limit disclosures to what is reasonably necessary for the relevant purpose.
We do not publish your submitted brief publicly merely because it is stored through GitHub. The repository used for submitted briefs is intended to be private. However, no online system can be guaranteed to be completely secure.
10. Overseas disclosure and processing
Personal information collected through this service is likely to be disclosed to or processed by recipients outside Australia.
The likely destination is the United States, including for:
- AI model processing; and
- GitHub repository storage.
Confirmation and internal alert emails are sent from our own mailbox rather than through a separate email processor engaged for that purpose. Email is nonetheless handled by our mail provider and may be processed outside Australia, including in the United States.
A provider may also use infrastructure, support personnel or subprocessors in other countries. Where it is practicable, we will update this policy if the countries of likely disclosure materially change.
Where the Privacy Act applies, we take reasonable steps in the circumstances to assess and manage overseas privacy risks. These steps may include reviewing provider privacy and security terms, using appropriate service configurations, limiting the information disclosed and requiring contractual protections where reasonably available.
Overseas recipients may be subject to foreign laws. Those laws may permit courts, regulators, law enforcement agencies or government authorities to access information in circumstances different from Australian law.
11. Cookies and similar technologies
The intake service does not currently use cookies for third-party advertising or cross-site behavioural tracking.
The website may use strictly necessary local storage, session technologies or cookies where required for basic functionality, security or user preferences. Standard hosting and server systems may also generate technical logs.
If we later introduce analytics, advertising or other non-essential tracking technologies, we will update this policy and implement any notice or consent mechanism required by law before using them.
12. Security
We take reasonable steps appropriate to the size and nature of the service to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Current safeguards may include:
- encrypted HTTPS connections between your browser and the website;
- use of a private repository for submitted briefs;
- restricted access to operational systems;
- access controls provided by our service providers;
- software and dependency maintenance; and
- limiting collection to information reasonably needed for the service.
We do not claim that this service is ISO 27001 certified, monitored by a 24-hour security operations centre, protected by enterprise role-based access controls, or supported by disaster-recovery capabilities unless and until those controls are actually implemented and verified.
No method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security.
If we become aware of a data breach, we will assess and respond to it in accordance with applicable law, including the Notifiable Data Breaches scheme where it applies.
13. Retention
13.1 Current position
Submitted briefs and complete AI transcripts are currently retained without a fixed automatic expiry period. They may be kept so we can:
- review and respond to the enquiry;
- maintain a reliable record of what was submitted;
- refer to the project if you contact us again;
- manage disputes or legal claims; and
- meet business, insurance, accounting or legal obligations.
We are reviewing an appropriate formal retention schedule. Until that schedule is implemented, you may request deletion or de-identification as described below.
13.2 Other records
Temporary IP rate-limit counts are held only in application memory and are lost when the application restarts.
Standard server logs are retained according to the settings and practices of the relevant hosting or infrastructure provider.
Emails and business correspondence may be retained for as long as reasonably required for the purposes described in this policy or to comply with law.
13.3 Future retention changes
If we adopt a fixed retention schedule, we will update this policy and implement technical processes capable of supporting that schedule. We will not state that information is automatically deleted after a set period unless the system actually performs that deletion.
14. Deletion requests and Git version history
You may ask us to delete personal information by emailing [email protected].
Where appropriate and reasonably practicable, we may:
- remove the brief from the current active state of the repository;
- remove contact information from current operational records;
- delete or de-identify information in systems under our direct control; and
- ask relevant service providers to delete information where their tools and contractual arrangements allow.
However, submitted briefs are stored using Git version-control technology. Git retains historical versions of repository content. Removing a file from the current repository state does not, by itself, erase that information from previous commits or version history.
Accordingly:
- deletion from the active repository does not necessarily mean complete erasure;
- historical copies may remain in Git history;
- copies may also remain in email systems, logs, backups, legal records or service-provider systems;
- removing information from all historical Git commits may require repository rewriting and may not be reasonably practicable in every case; and
- we will not represent that information has been completely erased unless we have verified that outcome.
Where complete erasure is not reasonably practicable, we may instead restrict access, remove the information from active use, de-identify it where possible, or retain it only for a lawful purpose.
We may refuse or limit a deletion request where retention is required or authorised by law, reasonably necessary for legal claims, needed to prevent fraud or security misuse, or otherwise permitted by applicable privacy law. We will explain our decision where required.
Important: Git-based storage places practical limits on deletion. Users who require guaranteed complete erasure should not submit information through the service.
15. Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Send requests to [email protected] and provide enough information for us to identify the relevant brief.
We may ask you to verify your identity before providing access or making a correction. We will respond within a reasonable period.
In some circumstances, applicable law may permit or require us to refuse access or correction. If so, we will give you written reasons where required and explain available complaint options.
16. Anonymity and pseudonyms
You may browse general public pages without identifying yourself.
It is not practicable to submit a project brief anonymously because we need a name and email address to associate the submission with a person and respond to the enquiry.
You may choose not to provide optional information such as a phone number or business name. However, providing less information may limit our ability to understand or respond to your project.
17. Direct marketing
We may contact you about the enquiry you submitted. This is a service communication, not necessarily marketing.
We may send marketing communications only where permitted by law. Marketing emails will provide a way to unsubscribe where required.
You may ask us not to send marketing communications by using the unsubscribe facility or contacting [email protected]. We may still send necessary administrative, legal or service-related communications.
18. Information about other people
If you provide personal information about another person, you must:
- have authority or a lawful basis to provide it;
- ensure the information is accurate;
- tell the person that their information may be provided to us where reasonable; and
- avoid providing unnecessary sensitive or confidential information.
You must not use the service to submit another person’s personal information unlawfully.
19. Children
The service is intended for adults and business users. It is not directed to children under 18.
A person under 18 should not submit a project brief without the involvement and consent of a parent or legal guardian.
If we reasonably believe we have collected a child’s personal information without appropriate authority, we may delete, restrict or de-identify it where reasonably practicable.
20. Third-party websites and services
The website may contain links to third-party websites or services. We do not control and are not responsible for their privacy practices.
This policy does not apply to information you provide directly to another organisation outside the operation of our service. You should review that organisation’s privacy policy before providing personal information.
21. Business changes
If My Trade Cover is involved in a merger, acquisition, financing, restructuring, sale of assets or similar transaction, personal information may be disclosed to advisers and prospective transaction parties and may be transferred as part of the transaction.
We will take reasonable steps to protect confidentiality and ensure that personal information remains subject to applicable privacy obligations.
22. Privacy complaints
You may make a privacy complaint by emailing:
Please include:
- your name and contact details;
- a description of the issue;
- the outcome you are seeking; and
- any information that may help us locate the relevant record.
We will acknowledge the complaint and aim to provide a substantive response within 30 days. More complex matters may require additional time, in which case we will keep you informed.
If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner. Information about making a privacy complaint is available at oaic.gov.au.
23. Changes to this policy
We may update this policy when our service, providers, technology or legal obligations change.
The updated policy will be published on this page with a revised effective date. Where a change is material, we may also provide additional notice through the website or by email where appropriate.
You should review this page periodically.
24. Contact us
For questions, access or correction requests, deletion requests or privacy complaints, contact:
My Trade Cover Pty Ltd ABN: 44 662 186 389 Website: madereal.com.au Email: [email protected]
Short Privacy Collection Notice
My Trade Cover Pty Ltd (ABN 44 662 186 389) collects the information you provide through madereal.com.au to operate the AI-assisted intake service, understand your project, prepare and retain your brief, and contact you.
Your messages are sent, turn by turn, to a third-party AI provider outside Australia. If you submit a brief, we store your full conversation—not only a summary—together with your contact and project information. GitHub stores the brief, and confirmation and alert emails are sent from our own mailbox and handled by our mail provider. GitHub and the AI provider may process or store information in the United States, and email may be processed outside Australia.
Please do not enter unnecessary sensitive, confidential or third-party information. Git version history means that removing a brief from the current repository may not erase every historical copy.
By starting the AI conversation and submitting your brief, you acknowledge this processing. Read our full Privacy Policy or contact [email protected].
Before You Start
You are about to speak with an AI assistant operated for My Trade Cover Pty Ltd.
- What you type is sent to a third-party AI provider outside Australia as the conversation occurs.
- If you submit a brief, the complete conversation will be stored with it.
- GitHub stores submitted briefs and may process information in the United States; related emails are sent from our own mailbox and handled by our mail provider, which may process email outside Australia.
- Do not include passwords, payment details, unnecessary sensitive information or information about another person unless you are authorised to provide it.
- AI responses may be inaccurate and are not professional advice.
Select Start conversation only after reading the Privacy Policy and acknowledging this notice.
Privacy FAQ
Is AI reading what I type?
Yes. Each message is sent to a third-party AI model provider to generate the next response.
Is the entire conversation stored?
Yes. If you submit a brief, the full transcript is stored with the brief, not only a summary.
Does my information stay in Australia?
No. The website may be hosted in Sydney, but AI processing and GitHub storage may involve the United States, and email handled by our mail provider may also be processed outside Australia.
Do you sell my personal information?
No.
Do you use advertising cookies?
The current intake service does not use advertising cookies or cross-site behavioural tracking.
Does the site store anything in my browser?
Yes. While you are in a conversation, your answers are held in your own browser so the assistant can keep track of what you have said. That information stays on your device until you choose to submit your brief. It is not used for advertising or for tracking you across other websites.
Can I ask for my brief to be deleted?
Yes. Email [email protected]. We may remove it from active systems where reasonably practicable. However, Git version history, emails, logs or backups may retain historical copies, so complete erasure cannot always be guaranteed.
Do I need an account?
No. The service does not provide customer accounts or passwords.
Who controls the information?
My Trade Cover Pty Ltd, ABN 44 662 186 389.