Mycelium (ABN 42 683 446 186, ACN 625 637 023) is an Australian AI security, governance and agents advisory practice based in Australia, Victoria. We are bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and the amendments introduced under the Privacy Act 1988 (ADM 2026).
This policy explains how we handle personal information collected through our website, our engagements and the operation of our business.
We collect only the personal information we need to deliver our services and operate our business. This typically includes:
We do not knowingly collect sensitive information unless it is necessary for an engagement and you have consented.
We use personal information to:
We do not sell personal information. We do not use personal information for behavioural advertising.
We share personal information only:
We do not disclose personal information to third parties for marketing purposes.
We protect personal information using physical, technical and administrative controls. These include role-based access controls, encryption in transit, secrets management, supplier assurance and audit logging on systems that hold engagement materials.
No system is perfectly secure. In the event of a breach, we will assess and notify in accordance with the Notifiable Data Breaches scheme.
Our website uses minimal cookies. Essential cookies enable core site functions and the scheduling widget. Non-essential cookies (analytics) are only set where you have consented, and let us understand how the site is used. We do not use advertising cookies. You can disable cookies in your browser at any time. Our website analytics (Plausible) is privacy-focused: it sets no cookies, and does not collect personal information or track you across other sites.
Some of our service providers operate outside Australia — for example, our hosting provider, scheduling platform, font and analytics providers. Where personal information may be processed offshore, we take reasonable steps to ensure those providers handle it consistently with the APPs and applicable Australian law.
You can request access to the personal information we hold about you, ask us to correct it, or make a complaint by emailing admin@themyceliumgroup.com.au. We will respond within 30 days.
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
If we become aware of a data breach that is likely to result in serious harm, we will assess and notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).
We may update this policy from time to time. The “Last updated” date and version above show the most recent change. Material changes will be communicated to active engagement clients directly.
Email · admin@themyceliumgroup.com.au
Phone · +61 401 844 836
Mail · Mycelium, Australia, Australia
Privacy Officer: Sara Shakib.
Thirty minutes. No pitch. No proposal until it makes sense.
Book a diagnostic