ClearByte.AU operates the AiMe (AI Marketing Manager Enterprise) platform at aime.clearbyte.au.
ClearByte.AU
DOOLEY TWO PTY LTD
BEACON HILL NSW
ACN: 673 088 385
Email: info@clearbyte.au
For the purposes of the Australian Privacy Act 1988, the UK GDPR, and the EU GDPR, ClearByte.AU is the data controller of personal information collected through the Platform.
| Category | Data Points | When Collected |
|---|---|---|
| Account Data | Full name, email address, password (hashed), company name | Registration |
| Billing Data | Payment method (processed by Stripe — we do not store card numbers), billing address | Subscription signup |
| Profile Data | Profile photo (optional), job title, phone number (optional), timezone | Account settings |
| Brand Data | Brand name, logo, colour palette, typography, brand voice, industry | Brand guide setup |
| Content Data | All content you create, generate, upload, or publish through the Platform | Platform use |
| CRM Data | Contact records, lead data, campaign data you manage through the Platform | CRM module use |
| Terms Acceptance | Timestamp and version of Terms of Service accepted | Registration and re-acceptance |
| Category | Data Points | Purpose |
|---|---|---|
| Usage Data | Pages visited, features used, actions taken, timestamps | Platform improvement |
| Technical Data | IP address, browser type, device type, operating system | Security, rate limiting |
| Log Data | API requests, error logs, performance metrics | Debugging, security monitoring |
| Cookie Data | Session tokens, preference cookies | Authentication, preferences |
For UK and EU users:
| Processing Activity | Legal Basis |
|---|---|
| Providing Platform Services | Contract — necessary to perform our agreement |
| Billing and payment | Contract — necessary to fulfil the subscription |
| Security monitoring and fraud prevention | Legitimate interests |
| Marketing communications | Consent — you may withdraw at any time |
| Legal obligations | Legal obligation |
| Platform improvement (aggregated) | Legitimate interests |
We do not sell your personal data. We share your information only:
The table below lists the third-party services that process personal data on our behalf, grouped by purpose.
| Provider | Role | Data Processed |
|---|---|---|
| Google (Gemini via Vertex AI) | Primary AI text generation; bound by Google's commercial DPA prohibiting training on customer data | Content prompts and generated outputs |
| Anthropic (Claude API) | Optional AI text generation, activated only when user supplies own API key | Content prompts when user key is used |
| OpenAI (GPT, DALL-E) | Optional AI text + image generation, user API key only | Prompts when user key is used |
| Stability AI | Optional AI image generation, user API key only | Image prompts when user key is used |
| Replicate (Flux models) | Optional AI image generation, user API key only | Image prompts when user key is used |
| RunwayML | AI video clip generation | Video prompts and scene descriptions |
| Pika Labs | Optional AI video generation, user API key only | Video prompts when user key is used |
| Kling AI | Optional AI video generation, user API key only | Video prompts when user key is used |
| Shotstack | Cloud video assembly and rendering | Assembled scripts, clip URLs, render specifications |
| Pexels | Stock image search | Search query strings |
| Provider | Role | Data Processed |
|---|---|---|
| Cloudflare (CDN & Pages) | Content delivery, DNS, edge security; hosting of published landing pages and websites | IP addresses, request metadata, published page content (publicly accessible once deployed) |
| Cloudflare (Registrar) | Domain registration on your behalf | Registrant data submitted to ICANN: name, email, postal address, phone number of the registering business |
| Bunny.net (Bunny CDN) | Video hosting and delivery for digital products | Uploaded video files, viewer playback metadata |
| WordPress.com (Automattic) | Content publishing to WordPress-hosted sites | Published blog posts, pages, SEO metadata, site configuration |
| SuiteCRM (self-hosted by ClearByte; enterprise tier may use customer-hosted instance) | CRM functionality, lead management, email execution | Contact records, lead data, campaigns, email engagement metrics |
| Provider | Role | Data Processed |
|---|---|---|
| Stripe | Payment processing and subscription management | Customer name, email, tokenised payment method, billing address, subscription status. We do not store raw card data — Stripe handles this under PCI-DSS. |
| Twilio | SMS verification and phone number provisioning for 2FA during social account setup | Phone numbers |
The integrations below are activated only when you explicitly connect the relevant account via OAuth. We receive the data scopes you authorise during the consent flow.
| Provider | Role | Data Processed |
|---|---|---|
| Google (OAuth — Sign-In) | Single Sign-On (when used) | Google account ID, email, profile name |
| Microsoft (OAuth — Sign-In) | Single Sign-On (when used) | Microsoft account ID, email, profile name |
| Google Workspace (OAuth — Integrations) | Optional Gmail / Calendar integration when you connect Google Workspace | Calendar events, email metadata, contact data within the scopes you grant. Specific OAuth scopes (e.g. gmail.send, calendar.events) are shown to you on the Google consent screen at connection time. |
| Microsoft Graph (OAuth — Integrations) | Optional Microsoft 365 integration: Outlook calendar / mail when you connect Microsoft 365 | Calendar events, email metadata within the scopes you grant. Specific scopes are shown on the Microsoft consent screen. |
| Meta (Facebook & Instagram Graph API) | Social account connection for content publishing | Page access tokens, page/post engagement metrics, content you publish |
| LinkedIn API | Social account connection for content publishing | Profile data, company page access, content you publish |
| Twitter / X API | Social account connection for content publishing | Account credentials (token), tweet content you publish |
| Webflow (OAuth — CMS Publishing) | Optional Webflow CMS connection when you connect your Webflow workspace. Publishes AIME-generated content (and any media you include) into a CMS collection you select. | OAuth access & refresh tokens (encrypted at rest), the email address associated with your Webflow account, the Webflow site and collection IDs you select, the field mapping you configure, and the content you publish (titles, body HTML, slugs, excerpts, author names). Featured images you publish are copied to Webflow's asset storage and become publicly retrievable from Webflow's CDN; any personal data depicted in those images (faces, identifying details) is processed and hosted by Webflow under their own terms. Images already uploaded to Webflow persist there after you disconnect from AIME — removing them requires action in your Webflow workspace. Scopes: cms:read, cms:write, sites:read, assets:write, authorized_user:read — shown on the Webflow consent screen at connection time. |
User-supplied API keys: When you provide your own keys for third-party AI providers (Anthropic, OpenAI, Stability AI, Replicate, Pika Labs, Kling AI), those providers' policies govern processing of your content. We store your keys using AES-grade encryption at rest and use them solely to make API calls on your behalf.
Bespoke customer integrations: ClearByte may operate additional integrations on a per-customer basis under direct contract or DPA between ClearByte and that customer. Such integrations are not available to other customers and the relevant data flows are governed by the individual contract rather than this Policy. Current bespoke integrations are disclosed in writing to affected customers at the time of activation.
ClearByte.AU operates from Australia and may transfer your data to countries including the United States where our third-party providers are located. For UK/EU users, transfers are covered by Standard Contractual Clauses (SCCs). For Australian users, transfers are made under contractual arrangements requiring equivalent protection to the Australian Privacy Principles.
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 30 days post-closure |
| Billing data | 7 years (tax and financial record obligations) |
| Content data | Duration of account + 30 days post-closure |
| Security logs | 12 months |
| Audit logs | 2 years |
| Terms acceptance records | 7 years (legal evidence) |
| Anonymised analytics | Indefinitely (no personal data) |
We implement industry-standard security measures including:
In the event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities within required timeframes (72 hours under GDPR/UK GDPR).
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| access_token | Essential | Authentication — maintains your login session | 30 minutes |
| refresh_token | Essential | Renewing your authentication session | 7 days |
| theme | Preference | Stores your light/dark mode preference | 1 year |
We do not use third-party advertising or tracking cookies and do not track your activity across other websites.
You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Two routes are available:
When you connect a Facebook Page or Instagram account, we store: the Facebook user ID of the connecting user; the IDs, names and (for Pages) category and profile-picture URL of the specific Pages and Instagram accounts you select; and the access tokens Meta issues for them. Access tokens are encrypted at rest. This data is used solely to display your connected accounts and to publish the content you create and schedule. We do not read other people's content, and we do not use Meta data for advertising, profiling, or resale.
You can delete this data at any time through any of these routes:
When you connect LinkedIn, we store: your LinkedIn member identifier and basic profile information returned at sign-in; the IDs, names and vanity URLs of the Company Pages you explicitly select to connect (only pages you administer are ever listed); encrypted access tokens; records of the posts AIME publishes on your behalf; and, where you enable analytics, engagement metrics for your connected page's own posts. This data is used solely to display your connections, publish the content you create and schedule, and show you your own page's performance. We do not read other members' data, and we do not use LinkedIn data for advertising, profiling, resale, or AI-model training.
Deletion works the same way as for Meta data: disconnecting LinkedIn in Social Accounts immediately deletes the stored tokens and connected-account records; closing your account deletes all connected-platform data under Section 8; and you can additionally revoke AIME's access from LinkedIn's own settings at any time, after which our stored tokens cease to function and are removed. Email requests: privacy@clearbyte.au.
The Platform is not intended for individuals under 18. If you become aware that a person under 18 has created an account, please contact us and we will delete the account promptly.
The Platform uses AI to generate content, analyse marketing data, and make recommendations. When you enable Autonomous Operations, the Platform may take automated actions (publishing, emailing, adjusting campaigns) without real-time human intervention based on your configuration. All Autonomous Actions are logged with reasoning transparency in your audit trail. We do not use your personal data to build behavioural profiles for advertising or resale.
Privacy Officer, ClearByte.AU
Email: privacy@clearbyte.au (privacy and data-rights matters)
General inquiries: info@clearbyte.au
BEACON HILL NSW
Supervisory authorities: ICO (UK) · Your local DPA (EU) · OAIC (Australia) · CPPA (California)
When we make material changes, we will update the "Last Updated" date, notify you by email, and display a notice within the Platform. Continued use after the effective date constitutes acceptance.