Legal

Privacy Statement

Effective Date: 8 April 2026

1. Introduction

Wholegrain Pty Ltd (ABN 70 672 897 595) is a consulting-focused AI automation solution designed to enhance efficiency and scalability by completing work such as autonomous interviews and analysis for consulting projects. Wholegrain allows consulting professionals to extend their capabilities through AI agents, making the consulting process scalable and repeatable.

This Privacy Statement is provided in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It describes how we collect, hold, use, and disclose your personal information, and sets forth your privacy rights.

We recognise that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Statement as we undertake new personal data practices or adopt new privacy policies.

2. Data Protection Officer

Wholegrain is headquartered in Melbourne, Australia. Wholegrain has appointed an internal data protection officer for you to contact if you have any questions or concerns about Wholegrain's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Wholegrain's data protection officer:

Leigh Hunter — support@wholegrain.app

3. How We Collect and Use Your Personal Information

Wholegrain collects personal information about its website visitors and customers. This information generally includes:

  • Name and contact details (email address, mobile phone number) for identification, authorisation, and communication purposes
  • Agent Configuration (how you want the Wholegrain Agents to operate)
  • Transcripts (inputs and outputs from conversations with Wholegrain Agents)
  • Files (files you upload to Wholegrain to be researched by Wholegrain Agents)

We collect personal information directly from you when you use our services, visit our website, complete our contact or discovery forms, or communicate with us. We do not collect personal information from third parties without your knowledge.

We use this information to provide customers with services. We do not sell personal information to anyone and only share it with third-party subprocessors who are facilitating the delivery of our services.

As is true of most websites, Wholegrain's website collects certain information automatically and stores it in log files. This may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system, and other usage information about the use of Wholegrain's website, including a history of the pages you view and services you use. We use this information to help us design our site to better suit our users' needs.

Wholegrain has a legitimate interest in understanding how members, customers, and potential customers use its website. This assists Wholegrain with providing more relevant products and services, with communicating value to our partners, and with providing appropriate staffing to meet member and customer needs.

4. Encryption Technology

Agent Configuration, Transcripts and Files are encrypted at rest using an AES encryption key that is unique to the owner of the Agent.

5. Training on Your Data

Wholegrain and its third-party subprocessors NEVER use your data for training purposes.

6. Cookies and Tracking Technologies

Cookies are used to identify your previous authentication to our services and identifiers that assist in providing services.

7. Sharing Information with Third Parties

The personal information Wholegrain collects from you is stored in one or more databases hosted by third parties. These third parties do not use or have access to your personal information for any purpose other than providing cloud services to us.

Our third-party subprocessors and their primary locations are:

  • Anthropic — United States
  • AssemblyAI — United States
  • Cloudflare — United States
  • DigitalOcean — United States
  • Google — United States
  • OpenAI — United States
  • Oracle — United States
  • Perplexity — United States
  • RecallAI — United States
  • Supabase — United States

We do not otherwise reveal your personal data to non-Wholegrain persons or businesses for their independent use unless: (1) you request or authorise it; (2) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property, or safety, or the rights, property, or safety of our employees or others; (3) the information is provided to our agents, vendors, or service providers who perform functions on our behalf; (4) to address emergencies; or (5) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners, service providers, advertisers, and/or other third parties for marketing or promotional purposes.

The Wholegrain website connects with third-party services such as LinkedIn and others. If you choose to share information from the Wholegrain website through these services, you should review the privacy policy of that service. If you are a member of a third-party service, the aforementioned connections may allow that service to connect your visit to our site to your personal data.

8. Cross-Border Disclosure of Personal Information

In accordance with Australian Privacy Principle 8 (APP 8), we are required to inform you that your personal information may be disclosed to overseas recipients.

Wholegrain is headquartered in Melbourne, Australia. However, in order to provide our services, we use third-party subprocessors (listed in Section 7 above) that are primarily located in the United States. As a result, your personal information may be transferred to, stored, and processed in the United States.

Before disclosing personal information to an overseas recipient, Wholegrain takes reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to that information. These steps include:

  • Entering into contractual arrangements with subprocessors that require them to handle personal information in accordance with obligations substantially similar to the APPs
  • Assessing each subprocessor’s privacy and security practices before engagement
  • Limiting the personal information disclosed to what is necessary for the subprocessor to perform its function
  • Conducting ongoing review of subprocessor compliance with data protection commitments

By using Wholegrain's services, you acknowledge that your personal information may be processed in the United States, and that Wholegrain will take reasonable steps to ensure that overseas recipients handle your information in compliance with the Australian Privacy Principles. If you have concerns about cross-border disclosure, please contact us at support@wholegrain.app.

9. Your Rights

Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the following rights in relation to your personal information:

Right of Access (APP 12) — You have the right to request access to the personal information we hold about you. We will respond to your request within 30 days. In certain circumstances permitted by law, we may refuse access, but will provide you with reasons for doing so.

Right of Correction (APP 13) — You have the right to request that we correct any personal information we hold about you that you believe is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond to your request within 30 days. If we have previously disclosed the information to a third party and you request that we notify them of the correction, we will take reasonable steps to do so.

Right of Erasure — You may request that we delete your personal information where it is no longer necessary for the purpose for which it was collected. All personal data that Wholegrain controls may be deleted upon verified request from data subjects or their authorised agents.

To exercise any of these rights, please contact our Data Protection Officer at support@wholegrain.app.

10. Data Storage and Retention

Your personal data is stored by Wholegrain on its servers, and on the servers of the cloud-based database management services Wholegrain engages, located in Australia and the United States. Wholegrain retains service data for the duration of the customer's business relationship with Wholegrain and for a period of time thereafter, to analyse the data for Wholegrain's own operations, and for historical and archiving purposes associated with Wholegrain's services. Wholegrain retains prospect data until such time as it no longer has business value and is purged from Wholegrain systems.

For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at support@wholegrain.app.

11. Notifiable Data Breaches

Wholegrain complies with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). In the event that we become aware of an eligible data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:

  • Promptly assess whether the breach is likely to result in serious harm
  • Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
  • Notify affected individuals as soon as practicable, including a description of the breach, the types of information involved, and recommendations about steps individuals should take in response

We take the security of your personal information seriously and have technical and organisational measures in place to protect against unauthorised access, loss, or misuse.

12. Questions, Concerns, or Complaints

If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:

Email: support@wholegrain.app

Location: Melbourne, Australia

We will endeavour to respond to your complaint within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner

Website: www.oaic.gov.au

Phone: 1300 363 992

Email: enquiries@oaic.gov.au

Stay Updated

New insights and case studies, straight to your inbox.

Ready to Talk?

Tell us about your challenge and we'll show you how we can help.

Get in Touch