Home · Legal · Privacy Policy

Privacy Policy.

How Mycelium collects, uses and protects personal information. Aligned to the Australian Privacy Principles (APPs), the Privacy Act 1988 (Cth) and the Privacy Act 1988 (ADM 2026) amendments.

LAST UPDATED 13 JUNE 2026 · PRIVACY-POL v1.0
01 · Who we are

Myce|ium

Mycelium (ABN 42 683 446 186, ACN 625 637 023) is an Australian AI security, governance and agents advisory practice based in Australia, Victoria. We are bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the amendments introduced under the Privacy Act 1988 (ADM 2026).

This policy explains how we handle personal information collected through our website, our engagements and the operation of our business.

02 · Information we collect

What we collect.

We collect only the personal information we need to deliver our services and operate our business. This typically includes:

  • Contact details — name, organisation, role, business email, phone and, where relevant, postal address.
  • Engagement information — information you share with us during a diagnostic call, workshop, assessment, briefing or agent build.
  • Booking and diagnostic responses — data you submit via our scheduling tool (Calendly) or any inline diagnostic form on this site.
  • Site usage — anonymised IP address, browser type, pages viewed, referring URL and dwell time, where you have consented to non-essential cookies.
  • Correspondence — email, letters and meeting notes related to enquiries and engagements.

We do not knowingly collect sensitive information unless it is necessary for an engagement and you have consented.

03 · How we collect it

Direct, transparent, scoped.

  • Directly from you — through forms, calls, email, workshop participation and contract documents.
  • From your organisation during an engagement, with consent where required.
  • Through our website — via essential and (with consent) analytics cookies.
  • From third-party tools we use to operate, including our scheduling platform, hosting provider and email infrastructure.
04 · Why we use it

The purposes we collect for.

We use personal information to:

  • Respond to your enquiry, schedule a diagnostic call, and conduct that call.
  • Deliver our services and produce deliverables — scorecards, reports, frameworks and agents.
  • Issue invoices, manage engagements, and provide ongoing support.
  • Maintain records required by law, regulators or our professional obligations.
  • Improve our services, content, framework and website performance.

We do not sell personal information. We do not use personal information for behavioural advertising.

05 · Disclosure

Who sees what.

We share personal information only:

  • With staff and contractors bound by written confidentiality obligations.
  • With your organisation, where you have provided information to us on its behalf.
  • With regulators, auditors or law enforcement, where required by law.
  • With third-party tools strictly needed to deliver our services (scheduling, hosting, document storage, email).

We do not disclose personal information to third parties for marketing purposes.

06 · Security

How we protect it.

We protect personal information using physical, technical and administrative controls. These include role-based access controls, encryption in transit, secrets management, supplier assurance and audit logging on systems that hold engagement materials.

No system is perfectly secure. In the event of a breach, we will assess and notify in accordance with the Notifiable Data Breaches scheme.

07 · Cookies and analytics

Minimal by design.

Our website uses minimal cookies. Essential cookies enable core site functions and the scheduling widget. Non-essential cookies (analytics) are only set where you have consented, and let us understand how the site is used. We do not use advertising cookies. You can disable cookies in your browser at any time. Our website analytics (Plausible) is privacy-focused: it sets no cookies, and does not collect personal information or track you across other sites.

08 · Cross-border data

Where your data may travel.

Some of our service providers operate outside Australia — for example, our hosting provider, scheduling platform, font and analytics providers. Where personal information may be processed offshore, we take reasonable steps to ensure those providers handle it consistently with the APPs and applicable Australian law.

09 · Access, correction and complaints

Your rights.

You can request access to the personal information we hold about you, ask us to correct it, or make a complaint by emailing admin@themyceliumgroup.com.au. We will respond within 30 days.

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

10 · Notifiable data breaches

If something goes wrong.

If we become aware of a data breach that is likely to result in serious harm, we will assess and notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

11 · Changes to this policy

Maintained, versioned, dated.

We may update this policy from time to time. The “Last updated” date and version above show the most recent change. Material changes will be communicated to active engagement clients directly.

12 · Contact

Privacy queries, requests and complaints.

Email · admin@themyceliumgroup.com.au
Phone · +61 401 844 836
Mail · Mycelium, Australia, Australia

Privacy Officer: Sara Shakib.

PRIVACY ACT 1988 (CTH) · PRIVACY ACT 1988 (ADM 2026) · APP COMPLIANT · OAIC · NOTIFIABLE DATA BREACHES SCHEME
Questions about how we handle your data?

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.

Book a diagnostic