Legal
Privacy
This is the privacy policy for agentone.team and for AgentOne. It covers what we collect when you visit this site, and how personal information is handled inside a discovery engagement.
Effective 7 September 2026
AgentOne (formerly Agent One) is a product of 1Question Pty Ltd, trading as 1QLabs (ABN 58 643 556 889), based in Sydney, Australia. We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles, and by the Notifiable Data Breaches scheme. This policy is the current version; it applies from the effective date above until it is replaced here.
Two roles, and the difference matters
We handle personal information in two distinct capacities, and which one applies changes who is accountable for it and who you approach with a request.
- In our own right, for this website, for enquiries you send us, and for the account records of the client staff and operators who use the platform. We decide what is collected and why, and a request or complaint about it comes to us.
- On a client’s behalf, for everything captured during a discovery engagement. The client organisation that commissioned the engagement is the entity accountable for that information. We hold and process it on their documented instruction, we do not decide the purpose it is put to, and we do not reuse it for our own.
- If you took part in an interview and want to see, correct or delete what you said, the decision sits with the organisation that commissioned the engagement — usually your own employer or client. Write to us anyway and we will point you to the right contact there.
What this website collects
- The contact form: your name, email address, organisation if you give one, the enquiry type you pick, and your message. It is emailed to us so we can answer you. This site has no database and stores none of it.
- The Scout panel: what you type is sent to Google Cloud Vertex AI to generate a reply, and is not retained once the session ends. It is not written to any database, and nothing you type is stored on your device.
- Your IP address, held briefly in memory to rate-limit the Scout panel against abuse, then discarded. It is not written to a record we keep.
- Ordinary server and load-balancer request logs — IP address, timestamp, the URL requested, browser user agent, and the response status — kept in Google Cloud for a limited period so we can keep the site secure and diagnose faults, then discarded.
- We do not collect sensitive information through this website, and we do not ask for it.
What this website stores on your device
- A theme preference, so the site opens in the light or dark setting you chose. It is held in your browser and never sent to us.
- Your answer to the cookie notice, held in a cookie named agentone-consent for six months, so you are not asked again.
- Analytics cookies, only if you accept the notice. Measurement starts denied and stays denied unless you accept; declining means no measurement tag runs at all, and nothing on the site depends on it. Where no measurement tag is configured, the notice does not appear, because there is nothing to consent to.
- You can clear these at any time in your browser. Clearing the consent cookie means you will be asked again.
What an engagement collects
Inside a discovery engagement, held on the commissioning client’s behalf rather than our own:
- Interview transcripts and messages from stakeholders who take part.
- Documents stakeholders choose to upload for analysis.
- Derived process intelligence: blueprints, findings, opportunities and proposals.
- Account records for the client staff and operators who access the platform.
What we do with it, and what we never do
- We use what you send through this site to answer your enquiry, to keep the site working and secure, and — only where you have accepted the notice — to understand which pages are useful.
- Engagement data is used to conduct that engagement and produce its deliverables, and for nothing else.
- It is not used to train models. The Vertex AI service terms prohibit training on customer data, including where a model is served from outside Australia.
- It is never aggregated across clients and is never reachable from another engagement.
- It is not sold, rented, or shared for anyone else’s marketing, and it is not used to enrich a third-party dataset.
- We do not carry out automated decision-making that produces a legal or similarly significant effect about you.
Who else handles it
For this website, two providers are involved, and both are named here rather than described in the abstract:
- Google Cloud, which hosts the site, keeps its request logs, and serves the Scout panel’s model through Vertex AI.
- Resend, which delivers the contact-form email and sends it via Amazon Simple Email Service.
- Google Analytics, where a measurement tag is configured and you have accepted the cookie notice. It is not loaded otherwise.
- Inside an engagement, the providers involved are named in the client’s own agreement, and a sub-processor register is available to a client or a prospective client on request.
Where it is held, and when it goes overseas
Storage is in Australia. Every resource in a client cell that holds data — database, object storage, embeddings, secrets, compute — is locked to Australian regions by a Google Cloud organisation policy rather than by configuration convention. This website runs in an Australian region too.
Some processing happens outside Australia, and we would rather state it plainly than have a security review find it:
- Model inference. Some of the models we rely on are not served from an Australian region. Those calls are processed elsewhere within Google Cloud, under the Cloud Data Processing Addendum and the Vertex AI service terms. This includes the Scout panel on this website, whose model is served from the United States. Nothing is handed to a separate AI vendor, and no call goes directly to a model provider’s own API. Serving regions are named on request.
- Contact-form email, which is delivered by Resend through Amazon SES and is processed outside Australia in transit.
- Website analytics, but only if you accept the cookie notice. Where a measurement tag is configured, Google Analytics processes what it collects in the United States. Decline, and no tag runs and nothing is sent.
- For disclosures of this kind we take the steps Australian Privacy Principle 8 requires, through the contractual terms above, and we remain accountable for how an overseas recipient handles the information.
How it is protected
- Each client engagement runs in an isolated Google Cloud project, network and database, enforced at the infrastructure level rather than in application code.
- Databases have private IP only, with no public endpoint, and row-level security within each project.
- Identity uses workload identity federation with service account impersonation. No service account keys are created or imported, and creating them is blocked by organisation policy.
- TLS 1.2 is the enforced floor, at both organisation policy and load balancer. Data is encrypted in transit and at rest.
- AgentOne holds no write access to the systems it studies, so discovery cannot alter the environment it is analysing.
- No system is perfectly secure. If an eligible data breach occurs we will notify affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and where the breach concerns engagement data we will notify the client without undue delay so they can meet their own obligations.
How long it is kept
- Enquiries sent through this site are kept as ordinary business correspondence for as long as the conversation is live and for a reasonable period afterwards. Ask us to delete yours and we will.
- Scout panel conversations are not retained after the session.
- Request logs are kept for a limited period for security and troubleshooting, then discarded.
- Engagement data is retained according to the policy the client specifies at the start of the engagement. Export and deletion cover transcripts, embeddings, blueprints and findings — not only the visible records — and are actioned on the client’s instruction.
Access, correction and complaints
- To ask what personal information we hold about you, to correct it, or to have it deleted, email hello@1qlabs.ai. We will acknowledge promptly and respond within 30 days.
- We may need to verify who you are before acting, and there are narrow grounds in the Privacy Act on which a request can be refused. If we refuse one, we will tell you why in writing.
- If your request concerns engagement interview data, we will route you to the client organisation that commissioned it, because the decision is theirs to make.
- If you are unhappy with how we have handled a privacy matter, tell us first and we will try to resolve it. If you are still unsatisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes and contact
- We update this policy as the platform changes. The version published here, with the effective date shown above, is the one that applies.
- Privacy enquiries: hello@1qlabs.ai, or write to 1Question Pty Ltd, trading as 1QLabs (ABN 58 643 556 889), Sydney, Australia.