Privacy policy
What we collect when you ask for a free Leak Audit, why we need it, where it is stored, who else touches it, and how to have it deleted. It is a short list, and this page is the whole of it.
Last updated: 10 September 2026
Who we are
Applied Intelligence is the trading name of Applied Intelligent Systems & Automations, a sole trader business run by Nicholas Matthews from the Gold Coast, Queensland, Australia.
We are the ones responsible for the information described on this page. If you want to talk to a human about any of it, email [email protected]. It comes straight to Nicholas.
Why we have this policy at all
Small businesses with an annual turnover under $3 million are not automatically covered by the Privacy Act 1988, and we are almost certainly under that threshold today. So strictly speaking, we may not have to publish this.
We apply the Australian Privacy Principles anyway, and we intend to keep applying them whether or not we ever cross that line. You handing over your name and your mobile number should not depend on how big we happen to be that year.
This policy is written plainly, because you should not need a lawyer to work out what happens to your own information.
What we collect
There is exactly one form on this website: the enquiry box that books your free Leak Audit. When you send it, we collect what you typed into it.
- Your name.
- Your mobile number, because we text you back to lock in a time.
- Your email address.
- Your trade or business.
- The times of day that suit you for the call, which are the buttons you tap.
- A short summary message. The form writes it for you out of the answers above. There is no free-text box on this site, so you cannot accidentally tell us more than you meant to.
Alongside that, two things are collected automatically, the way they are on any website:
- Your IP address. Our server uses it to rate-limit the form, so a bot cannot flood us with fake enquiries. There is also a hidden field on the form that only automated bots fill in, and if it comes back filled in we quietly drop the submission.
- Standard server logs. The page requested, the time, the browser you used and the IP address it came from. Ordinary web server housekeeping.
Since 10 September 2026 there is one more automatic collection: the Meta Pixel, which reports your visit to Meta so we can measure our advertising. It is set out in full in section 04 below, and you can switch it off.
That is the lot. We do not ask for anything sensitive, and we would rather you did not send it.
Cookies, analytics and tracking
We advertise on Facebook and Instagram, so on 10 September 2026 we added the Meta Pixel to this website. It is a small script and a small image, loaded from Meta Platforms. Before that date this site carried nothing of the kind, and this section is the whole of what it now does.
It answers one question for us: did the people who saw an Applied Intelligence ad on Facebook or Instagram go on to visit this site, start the Leak Audit, or submit the form? Without it we are paying for ads and guessing.
The pixel sets and reads a cookie in your browser. It tells Meta the page you are on, the time you were on it, and standard browser and device information, which includes your browser, your operating system, your screen size and your IP address. It also tells Meta when one of three things happens: a page loaded, the audit was started, or the audit form was submitted. Meta may link that to a Facebook or Instagram account, and what Meta then does with it is governed by Meta's own privacy policy, not by ours.
What Meta is never sent. Not one of your audit answers. Not a single dollar figure off your Leak Map. Not your name, your mobile number, your email address or your business name. The pixel is told that a form was submitted. It is never told who submitted it, or what was in it. We have not switched on Meta's advanced matching, which is the setting that would send your email address and phone number, and we do not intend to.
Three ways to turn it off.
- Do Not Track, or Global Privacy Control. If your browser sends either signal, this site does not load the pixel at all. No cookie, no request to Meta, nothing. We check for both before anything loads, and most browsers and privacy extensions can send one of them. If JavaScript is switched off, nothing loads at all.
- Your Meta ad settings. You can see and limit what Meta does with off-Facebook activity like this in your Facebook ad preferences.
- Your browser. Blocking third-party cookies, or running a content blocker, stops this pixel the way it stops any other advertising tag. The site works normally either way, and the audit still runs.
That is the only third-party tag on this site. There is no Google Analytics, no session recorder and nothing else following you around the internet afterwards. We do count how far people get through the audit, but that runs on our own server, sets no cookie and records no individual, only a running total per step.
None of this changes the rest of this policy. We still apply the Australian Privacy Principles to everything described here, and if any of it changes again, this page changes first.
Why we collect it
To ring or text you back and run your free Leak Audit. That is the whole reason the form exists.
You give us these details on purpose, by filling in a form that asks us to contact you, so the basis for using them is simple: you asked us to. We use them for that, and we do not add you to a marketing list off the back of an enquiry.
If you go on to become a client, we keep using your business details to run the service you have hired us for. That relationship is covered by our terms of service.
Your IP address is used for one thing only: keeping the form working by stopping abuse.
Where it lives, and who else touches it
Your enquiry is stored in our own database, an SQLite file on a server we run, hosted with DigitalOcean. It is not stored in a third-party CRM or a marketing platform.
Two other companies see it, and only because they are how we find out an enquiry has arrived:
- Resend delivers an email to us containing your enquiry, so it lands in the inbox rather than sitting unseen in a database.
- Twilio sends a text message to Nicholas saying a new enquiry has come in, with your name, your business, your preferred times and your number, so a hot lead is impossible to miss.
Resend and Twilio are overseas companies, so that notification passes through their systems the way any email or text message does, and their own terms cover that part of the trip.
One more sits in front of the site itself: Cloudflare routes and shields all traffic to this website, the way a content delivery network does for most of the modern web. Every request to this site, your enquiry included, passes through Cloudflare on its way to us. It carries that traffic and sees visitor IP addresses in transit; it is not where your enquiry is stored.
Those four, plus us, are the only ones who touch your enquiry. Meta is not on that list and never sees it: the pixel in section 04 measures our advertising and is told nothing about what you sent us.
We take reasonable steps to keep what you send us safe and out of anyone else's hands. If you become a client, your business's data is kept isolated to your business.
Who we disclose it to
We never sell your information. We never rent it, trade it or hand it to a data broker, and we never will.
It goes to the providers listed above, only to the extent they need it to run the service, and beyond that only where the law requires it, such as a court order or a lawful demand from a regulator.
How long we keep it
An enquiry is kept while it is still relevant to serving you. If you become a client, we keep your details for as long as we are working together, and afterwards for as long as we are required to keep business records. If you do not become a client, the enquiry is kept only while it is still useful, and then it is deleted.
Ask us to delete it sooner and we will, without needing a reason from you.
Seeing, correcting or deleting your information
You can ask us at any time what we hold about you, ask us to correct anything that is wrong, or ask us to delete it altogether. Email [email protected] and we will take care of it, normally within a few days, and it costs you nothing.
If there is ever a reason we cannot do what you have asked, we will tell you what that reason is.
If you are not happy
Tell us first. Email [email protected], and we will listen and do our best to put it right. We will respond within 30 days.
If you are still not satisfied, you are entitled to take it further with the Office of the Australian Information Commissioner, the national privacy regulator, at oaic.gov.au.
Changes to this policy
If we change how any of this works, we update this page and change the "last updated" date at the top of it. The version published here is always the current one.