Privacy policy.
The short version
- We collect the information you give us, for example when you book a call, and information our website and tools record automatically.
- We use it to reply to you, prepare for and deliver our work, run our business and tell you about our services.
- Our public website uses analytics and advertising tools from Google, Meta and OpenAI. We don’t show a cookie banner, so the section on cookies, analytics and advertising explains how to control these tools.
- Our main database is in Sydney. Some of our service providers and some of our engineers are overseas, mainly in the United States and Vietnam.
- We don’t sell personal information.
- To see or correct your information, unsubscribe or make a complaint, email team@mileon.ai.
About this policy
Liquid Ledger Pty Ltd (ABN 72 646 721 931), trading as Mileon (“Mileon”, “we”, “us” or “our”), is an Australian company based in Sydney, New South Wales. We build, integrate and run technology systems for organisations, with a current focus on property developers and medical clinics. We operate the website at www.mileon.ai, including our client portal.
This policy explains how we handle personal information, and how we send marketing messages under the Spam Act 2003 (Cth). We choose to handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Personal information is information or an opinion about an identified person, or a person who is reasonably identifiable. Sensitive information, such as health information, has extra protection.
This policy applies to:
- people who visit our website;
- people who make an enquiry, book a call or request a billing report;
- our clients and the people who work for them, including client portal users and people we interview during an engagement;
- people our sales team contacts; and
- people who apply to work with us.
It doesn’t cover records about our own employees, which the Privacy Act treats separately. When we work for a client, our agreement with that client also applies (see the section on information we handle for clients).
What we collect
What we collect depends on how you deal with us.
- Website visitors: the pages you view, what you click, how you reached our site (including any campaign tags in the link), your device and browser, your IP address and approximate location, and identifiers stored in cookies (see the section on cookies, analytics and advertising).
- Enquiries and bookings: your name, work email, organisation, role, industry and company size, what you’d like help with, and anything else you choose to tell us. For a billing report request, we also ask about your practice: its state or territory, number of locations and GPs, practice software and the billing history available. When you book, Calendly records the time you choose.
- Resource sign-ups: if you ask us to send you new checklists, trackers and guides from our articles, your email address, your first name if you give it, the resource and page you signed up from, and the wording you agreed to. Downloading a resource doesn’t require this.
- Sales contacts: your name, role, organisation, work email and phone number; information about your organisation from its website and other public sources; notes and transcripts of our calls and meetings; and the emails and messages we exchange.
- Clients and their staff: contact details; client portal sign-in details (your email address and when you sign in); payment records; and, for our delivery and diagnostic work, interview recordings and transcripts, notes, documents, screenshots and system exports your organisation shares with us, and work information such as job titles, roles, hours, type of employment and pay rates by role.
- Job applicants: your name, contact details, CV or portfolio, and anything else you send us.
We don’t ask for health information through our website. The section on health information explains how we handle it in client work.
How we collect it
- From you, when you fill in a form, book a call, email or phone us, join a meeting, use the client portal or work with us.
- Automatically, through our website and the tools described in the section on cookies, analytics and advertising.
- From other organisations: Calendly, when you book a call; Meta, when you submit one of our lead forms on Facebook or Instagram; your employer or organisation, when it is our client or refers you to us; and people who recommend us.
- From public sources: your organisation’s website and other publicly available sources.
You can browse our website and ask general questions without telling us who you are. We need your name and contact details to arrange a call or work with you.
If we receive personal information we didn’t ask for and couldn’t have collected ourselves, we destroy or de-identify it when it is lawful and reasonable to do so.
How we use it
We use personal information to:
- reply to enquiries, and arrange, prepare for and follow up calls;
- work out whether and how we can help, and prepare proposals;
- deliver our services, including diagnostics, systems, reports and support;
- run the client portal and send sign-in links;
- invoice clients and take payments;
- send information about our services (see the section on marketing and unsubscribing);
- measure and improve our website and advertising;
- protect our website, systems and people, and prevent spam and misuse;
- consider job applications; and
- meet our legal, tax and record-keeping obligations, and handle disputes.
We use and disclose personal information for the purpose we collected it, for a related purpose you would reasonably expect (for sensitive information, a directly related purpose), with your consent, or where the law requires or allows it. We don’t sell personal information.
How we use AI
Our staff use AI tools to help with their work, for example to:
- research an organisation from its website and other public sources before we contact it;
- transcribe and summarise calls and meetings;
- find and summarise information in interview transcripts and documents during an engagement; and
- draft emails, notes and reports.
We don’t use computer programs to make decisions that could significantly affect your rights or interests.
We use AI models from Anthropic and OpenAI through the Vercel AI Gateway and Anthropic’s own tools, and we use Granola for meeting notes.
When we analyse interviews across an engagement, we replace speakers’ names with aliases and leave out the names, pay rates and email addresses in our records. What people say in interviews, and the text of documents, is analysed as recorded, so it can still include names and other details.
Health information
Health information is sensitive information. We only collect it with consent or where the Australian Privacy Principles otherwise allow.
- Our website doesn’t ask for it. Please leave out patient details and other sensitive records when you contact us.
- Billing optimisation reports. To prepare a practice’s free billing report, we may need its billing data, which can include information about patients and the services they received. Before any data is shared, we agree the scope and data handling with the practice. The practice is responsible for making sure it can share the data with us.
- Other work with clinics. Patient information can appear in documents, screenshots, exports or recordings a clinic shares with us. We handle it only for that engagement, as our agreement with the clinic allows, and we never use it to contact patients.
We use health information only for the work the practice or clinic has asked us to do.
Some States and Territories have their own health privacy laws, such as the Health Records and Information Privacy Act 2002 (NSW). Where State or Territory health privacy laws apply to us, we also comply with them.
Information we handle for clients
When we work for a client, we handle personal information about its staff, customers or patients for the client’s purposes and under our agreement with it. We use that information only to deliver the work, protect it as this policy describes and don’t use it for our own marketing.
The client is responsible for telling its people about the work and for having the authority to share their information with us. If we interview you as part of a diagnostic, we ask for your consent at the start of the session before we record. Our reports to your organisation describe findings by role, not by name.
If you’re one of a client’s staff, customers or patients and want to access or correct your information, you can contact the client or us. We’ll work with the client to respond.
Our service providers
These providers hold or process personal information for us. Locations are where each provider stores or processes the information, based on our settings and the provider’s own information.
| Provider | What they do for us | Personal information | Where |
|---|---|---|---|
| Vercel | Hosts our website, client portal and staff workspace, runs our server code, and routes our requests to AI models (Vercel AI Gateway) | Everything sent through our website and portal while it is processed, and IP addresses and browser details in technical logs. The AI Gateway doesn’t keep prompts after a request is complete. | United States (our server code runs in Washington DC). Web pages are delivered from locations worldwide. |
| Supabase | Our main database and file storage, and sign-in for the client portal and staff workspace | Enquiries and bookings, sales records, our unsubscribe list, client and engagement records, uploaded documents and portal accounts | Australia (Sydney). Supabase staff may access it from the United States or Singapore to provide support. |
| Calendly | Our booking calendar | Your name, email address, booking notes and meeting time | United States and other countries where Calendly and its providers operate |
| Stripe | Client payments | Payer name, email address, and card and billing details. Stripe holds card details; we don’t see or store full card numbers. | United States, India and other countries where Stripe operates |
| HubSpot | Our customer relationship management system for sales | Business contact details, organisation, sales stage, meetings, emails and call notes | May be outside Australia |
| Google Workspace | Email, calendars and documents | Emails and attachments, including job applications, and calendar invitations | United States and other countries where Google operates |
| Slack | Internal messaging, including notices of new enquiries and call notes | Enquiry details, research notes about organisations, and call notes | United States and other countries where Slack operates |
| Granola | Meeting notes and transcripts | Transcripts and summaries of calls and meetings, and attendees’ names and email addresses. Granola doesn’t keep audio after transcription. | United States. Granola also operates from the United Kingdom. |
| Anthropic | AI models for research, summaries, drafting and analysis | The content we send for a task, which can include names, business details, transcript extracts and documents | United States and other countries where Anthropic operates |
| OpenAI | A backup AI model for the same work | As for Anthropic | United States and other countries where OpenAI operates |
| n8n | Passes the answers to our lead forms on Facebook and Instagram to our database | Name, email address, phone number, organisation and form answers | May be outside Australia |
| KrispCall | Sends text messages | Mobile numbers and message content | May be outside Australia |
| Logo.dev | Shows software logos in the client portal and staff workspace | Your IP address and browser details when a logo loads | Mainly the United States |
| Provider | What they do for us | Personal information | Where |
|---|---|---|---|
| Google Tag Manager and Google Analytics | Website activity, identifiers, device and approximate location, and hashed contact details from forms | United States and other countries where Google operates | |
| Meta | The Meta Pixel, our lead forms on Facebook and Instagram, and ad reporting | Website activity and identifiers, and the answers you give in a lead form: name, email address, phone number and organisation | United States and other countries where Meta operates |
| OpenAI | Measuring our ads in ChatGPT | Website activity, identifiers, and booking events with a hashed email address, IP address and browser details | United States and other countries where OpenAI operates |
We update this list when we change providers.
Storing and sending information overseas
Our main database is in Sydney, but some personal information is stored, processed or accessed overseas:
- Our website’s server code runs in the United States, so information you send through our website passes through the United States before it is stored in Sydney.
- Many of our service providers and advertising partners are based overseas. The section on our service providers lists the locations we have confirmed.
- Some of our engineers are employees based in Vietnam. They can access personal information in our systems to do their work.
The countries we know of are the United States, Vietnam, Singapore, India and the United Kingdom. Information may also be stored or processed in other countries where our service providers operate.
How we protect it
We hold personal information in the services listed above and on the computers our team uses for work. We protect it with measures including:
- encryption in transit, and encryption of stored data by our database provider;
- access controls in our database and client portal, designed so that only Mileon staff with authorised accounts can see our records and client portal users see only their own organisation’s information;
- sign-in to the client portal and staff workspace through single-use links sent to an email address we have set up, rather than passwords;
- protections against spam and misuse on our website forms; and
- signed unsubscribe links that can’t be guessed or changed.
No system is completely secure. If you think your information has been misused, contact us straight away.
How long we keep it
We keep personal information only for as long as we need it for the purposes described in this policy, including to meet our legal, tax and record-keeping obligations. When we no longer need it, we delete or de-identify it.
We keep our unsubscribe list indefinitely, so your opt-out keeps working. It records your email address or phone number and when and how you opted out. If you use an unsubscribe link, it also records when that link was created and the browser details sent with your request.
Marketing and unsubscribing
We send marketing emails about our services to people at organisations we think we can help. We do this when you have agreed to hear from us, or when we can reasonably infer that you agree because of our dealings with you (for example, you asked about our services), as the Spam Act allows.
Downloading a resource from our articles doesn’t sign you up for anything. We email you new resources only if you sign up for them, and we keep a record of what you agreed to.
Every marketing email identifies Mileon as the sender and includes a way to unsubscribe.
To unsubscribe, use the link in any of our emails or email team@mileon.ai. Unsubscribing stops our marketing emails. We act on it within 5 business days, and usually straight away. We keep your details on our unsubscribe list so we don’t contact you again by mistake. If you use the link by mistake, the confirmation page lets you undo it.
You can also ask us where we got your contact details, and we’ll tell you unless that’s impracticable or unreasonable.
You’ll still receive service messages, such as booking confirmations, portal sign-in links, invoices and messages about work we’re doing for you.
Access, correction and deletion
You can ask for access to the personal information we hold about you, ask us to correct it, or ask us to delete it. Email team@mileon.ai.
- We’ll confirm your identity before we act, and respond within 30 days.
- We don’t charge for making a request. If giving you access involves significant work, we may charge a reasonable fee, and we’ll tell you before we do.
- If we refuse access or correction, we’ll explain why in writing and tell you how to complain. If we don’t correct information, you can ask us to attach a statement that you believe it is wrong.
- If you ask us to delete information, we’ll delete or de-identify it unless we still need it for a purpose in this policy or the law requires us to keep it.
- For information we hold for a client, we may refer your request to the client or work with it to respond.
Questions and complaints
For a privacy question, a request or a complaint, contact our Privacy Officer:
Privacy Officer
Liquid Ledger Pty Ltd trading as Mileon
ABN 72 646 721 931
Sydney, New South Wales, Australia
team@mileon.ai
Please tell us what happened and how you’d like it resolved. We’ll acknowledge your complaint, look into it and give you a written response within 30 days.
If you’re not satisfied with our response, or we haven’t responded within 30 days, you may be able to complain to the Office of the Australian Information Commissioner:
Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992
Web: www.oaic.gov.au
Post: GPO Box 5288, Sydney NSW 2001
If a State or Territory health privacy law applies to a complaint about health information, you may also be able to complain to its regulator. In New South Wales, that is the NSW Privacy Commissioner:
Information and Privacy Commission NSW
Phone: 1800 472 679
Web: www.ipc.nsw.gov.au
Visitors in the European Union and United Kingdom
We’re an Australian business and our services are aimed at organisations in Australia. If the European Union’s or the United Kingdom’s General Data Protection Regulation applies to how we handle your personal information, you may have extra rights, such as to object to how we use it, to ask us to erase it or limit its use, or to receive a copy in a portable format. Email team@mileon.ai and we’ll respond as those laws require. You can also complain to your local data protection authority.
Children
Our website and services are for organisations and aren’t directed at children. We don’t knowingly collect personal information from children through our website. Information about children can appear in records a clinic shares with us, and we handle it as described in the section on health information.
Changes to this policy
We’ll update this policy when our practices or the law change. The date at the top shows when it last changed.
