⚠️ This service is infrastructure, not legal advice. This Privacy Policy explains how we handle information across the FCFCOA SRL Ecosystem website, the free starter pack, and the paid services (Hosted Workspace MCP, Drive/Gmail Backup, and Setup & Support). For any legal question about your matter, consult a lawyer admitted to practise in your jurisdiction.
§01Scope
This policy applies to:
- the website at [DOMAIN] ("the Site")
- the free starter pack downloaded from the Site ("the Pack")
- the Hosted Workspace MCP service ("MCP Hosting")
- the Drive & Gmail Backup service ("Backup")
- the Setup & Support service ("Support")
Together, "the Services".
This policy is written to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). For users in jurisdictions with additional or different rights (e.g. EU/UK), those rights also apply where the law requires.
§02Who's collecting your information
DyCom Group Queensland Pty Ltd is the data controller for everything described in this policy. Contact details for privacy enquiries and complaints are in §13.
§03What we collect
3.1 When you visit the Site
- Server access logs: IP address, browser user-agent, timestamp, page accessed, referring URL. Retained for 30 days for security and abuse detection.
- We do not use third-party analytics, advertising trackers, or social media pixels on the Site.
- We use no cookies other than a session cookie if you contact us via a form (and only for that interaction).
3.2 When you download the Pack
- We log that a download occurred (IP, timestamp, file version) for capacity planning.
- We do not collect your name, email, or any other identifying information unless you contact us. No registration is required.
3.3 When you enquire about a paid service
- Your name, email address, and anything else you choose to tell us in your message.
- Used to respond to your enquiry and, if you proceed, to set up the service.
3.4 When you subscribe to MCP Hosting
- Account email (the Google account you authorise)
- OAuth refresh and access tokens issued by Google to you, encrypted at rest, used solely to honour your assistant's tool calls
- Subscription state (active, paused, cancelled), billing reference
- Request metadata (timestamp, endpoint, tool name, response size) for 14 days, used for abuse detection and billing dispute resolution
- We do not log, store, cache, or otherwise retain the content of your files, emails, calendar events, or any other Google Workspace data. The MCP server is a broker — it passes data between Claude (or your assistant) and Google, in memory only. See §6 for technical detail.
3.5 When you subscribe to Backup
- Account email and OAuth tokens (as above)
- The encrypted contents of your nominated Google Drive folders and/or Gmail labels, stored as part of the service (this is the service)
- Subscription state, billing reference
- Backup operation logs (start time, completion time, bytes transferred, error states) for the life of the subscription plus 30 days
- See §6 for storage location, encryption, and retention details
3.6 When you engage Setup or Support
- Whatever information you share with us during the engagement (which we recommend you keep to operational/technical material, not case content)
- Anonymised notes of work performed, retained for our own records and warranty purposes for 12 months after engagement
3.7 Billing
- Payments are processed by [PAYMENT PROCESSOR — e.g. Stripe]. We never see your full card number or banking credentials. We see only what the processor returns to us: a payment confirmation, last four digits, and the billing name and email.
§04How we use it
Information we collect is used only for:
- Providing the Services
- Communicating with you about the Services
- Sending invoices and receipts
- Security, abuse detection, and fraud prevention
- Complying with law (e.g. responding to a lawful subpoena or court order; see §10)
- Improving the Site and Pack (in aggregate, non-identifying form)
We do not use your information for:
- Advertising or marketing to third parties
- Selling, renting, or trading personal information
- Training AI models (ours or anyone else's)
- Profiling for any purpose beyond the operation of the Services
§05Who else sees it
We share information only with:
- Google, in the course of your authorised OAuth flow. We never share your Google credentials with anyone (we don't have your credentials — OAuth doesn't expose them).
- [PAYMENT PROCESSOR], for payments only.
- [HOSTING PROVIDER — e.g. AWS Sydney, Vultr Sydney], where the server infrastructure runs. They have access to disks at the infrastructure layer but cannot read encrypted content.
- Government agencies, only if required by valid Australian court order, subpoena, or warrant. We will notify you of any such request unless legally prohibited from doing so.
We do not share your information with Anthropic, OpenAI, or any other AI provider. Your assistant connects to your MCP server (and through it, your Google account); we are not in the data path of the assistant's reasoning or training.
§06How the MCP server and the Backup service differ
This distinction matters and we want to be explicit.
MCP Hosting is a broker
- Your assistant sends a request → our server validates it against your OAuth scopes → our server forwards it to Google → Google returns data → our server forwards the response back to your assistant.
- File contents, email bodies, calendar events, and similar payloads pass through server memory and are immediately discarded.
- We retain only the request metadata listed in §3.4. We have never read your file contents and have no technical means of doing so after the request completes.
- The server is per-tenant. Your instance is isolated: separate OS-level user, separate process, separate filesystem namespace, separate OAuth credentials. ACLs restrict access so only your assistant session can reach your instance.
Backup is a store
- You authorise us to read nominated content from your Google account.
- We copy that content, encrypt it (AES-256 at rest, TLS 1.3 in transit), and store it on infrastructure in Sydney, Australia ([HOSTING PROVIDER]).
- We hold the encryption keys (necessary for restore). Keys are stored separately from the data and access is logged.
- You can request a restore (we send you the data) or deletion (we wipe and certify) at any time.
- Backup data is retained for the life of the subscription plus 30 days, then permanently deleted.
If you want zero storage of any content on our infrastructure, choose MCP Hosting only and not Backup. Both services can be subscribed to independently.
§07Security
- All traffic to and from the Services is encrypted in transit using TLS 1.3 or higher.
- Backup data is encrypted at rest using AES-256.
- OAuth tokens are encrypted at rest and never written to logs.
- Servers are patched on a [WEEKLY / MONTHLY] cycle. Critical security patches applied within 48 hours of public disclosure.
- We do not store your Google password. OAuth means we never see it.
- Access to production infrastructure is restricted to named individuals at DyCom Group, authenticated with hardware-key MFA, logged and reviewed.
- We are not a Cyber Incident Reporting Scheme entity but we follow industry-standard incident response practices. If a data breach occurs that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) within the timeframes required by Part IIIC of the Privacy Act.
No system is invulnerable. We do not guarantee absolute security and you should not treat any one provider's backup (including ours) as your only copy of important material.
§08Your rights
Under the Australian Privacy Principles, you have the right to:
- Access your personal information that we hold. Email us and we'll respond within 30 days.
- Correct information that's inaccurate.
- Request deletion of your information, subject to our legal obligations to retain certain records (e.g. tax invoices, anti-money-laundering records).
- Withdraw consent to OAuth access at any time via your Google Account → Security → Third-party apps. Once revoked, our MCP server and/or Backup will lose the ability to act on your behalf.
- Lodge a complaint with us (§13) or with the OAIC (oaic.gov.au).
We don't charge for access or correction requests in normal circumstances.
§09Retention
| Data type | Retention period |
|---|
| Site access logs | 30 days |
| Pack download logs | 30 days |
| Enquiry correspondence | 24 months after last contact |
| OAuth tokens (MCP, Backup) | Life of subscription, deleted within 7 days of cancellation |
| Backup content | Life of subscription + 30 days |
| MCP request metadata | 14 days |
| Support engagement notes | 12 months after engagement |
| Billing records | 7 years (ATO requirement) |
| Anything else | Not retained |
§10Legal disclosure
If we receive a valid Australian court order, subpoena, or warrant compelling disclosure of information we hold:
- We will comply only to the extent legally required.
- We will notify the affected user unless legally prohibited.
- We will challenge overbroad requests where there is a reasonable basis.
- We do not provide voluntary cooperation with informal law-enforcement requests; production must be on legal process.
We have not, to date, received any law-enforcement requests for user data. If that ever changes and we are not prohibited from disclosing, this section will be updated.
§11Children
The Services are intended for adults. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we'll delete it.
§12International users
Our infrastructure is in Australia. By using the paid Services, you consent to your information being processed in Australia under Australian law. If you are in the EU, UK, or another jurisdiction with cross-border transfer rules, the contractual terms we provide on engagement include standard data protection clauses.
§13Contact and complaints
For any privacy enquiry, request, or complaint:
- Email: [privacy@DOMAIN]
- Post: DyCom Group Queensland Pty Ltd, [ADDRESS], Queensland, Australia
We aim to respond within 7 days and to resolve complaints within 30 days.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner:
- Web: oaic.gov.au
- Phone: 1300 363 992
§14Changes to this policy
We may update this policy from time to time. Material changes will be notified to active subscribers by email at least 30 days before they take effect. The current version is always available at [DOMAIN]/privacy. Each version's effective date and change summary will be listed below.
Change log
- v1.0 — [DATE] — Initial publication.