Privacy Policy

Effective: 10 February 2026 · Last updated: 10 February 2026

This Privacy Policy explains how Corey McIvor trading as ZYNTHIO™ (ABN 31 314 627 918) (“we”, “us”, “our”) collects, uses, discloses, and protects personal information through:

We are committed to protecting your privacy in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Information We Collect

Information you provide directly

Information collected automatically

Information from third parties

2. How We Use Your Information

PurposeLegal basis (APP reference)
Provide and maintain our services (CoreyAI SaaS, ZYNTHIO engagements)APP 6 — primary purpose
Process payments and subscriptionsAPP 6 — primary purpose
Send service notifications, security alerts, threat briefings you subscribed toAPP 6 — primary purpose
Administer the AI Disaster Olympics competitionAPP 6 — primary purpose
Improve our services and develop new featuresAPP 6 — related secondary purpose
Respond to support requests and communicationsAPP 6 — primary purpose
Comply with legal obligationsAPP 6 — required by law
Produce anonymised research and community resourcesAPP 6 — related secondary purpose

We will not use your personal information for direct marketing without your consent. You can opt out of any non-essential communications at any time.

3. How We Share Your Information

We do not sell your personal information. We may share information with:

We do not share client-specific findings, assessment reports, or engagement data with any third party without explicit written consent.

4. Competition Submissions (AI Disaster Olympics)

5. Client Data (ZYNTHIO Engagements)

ZYNTHIO client data is handled under the specific terms of each Statement of Work (SOW). Generally:

6. Data Storage and Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure (APP 11). No method of electronic transmission or storage is 100% secure.

7. Cross-Border Disclosure

Some service providers (Stripe, Cloudflare, AWS) process data outside Australia, including the United States. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs (APP 8).

8. Cookies

Our websites use essential cookies only: session management, security (CSRF protection), Cloudflare performance/security. We do not use advertising cookies, tracking pixels, or third-party analytics. We do not use Google Analytics.

9. Your Rights

Under the Australian Privacy Principles, you have the right to:

Contact us at corey@zynthio.ai. We will respond within 30 days.

10. Data Breach Notification

In the event of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme within 30 days of becoming aware (or sooner where practicable).

11. Complaints

If you believe we have breached the APPs:

We will investigate and respond within 30 days. If not satisfied, lodge a complaint with the OAIC.

12. Changes to This Policy

Changes will be posted on this page with an updated effective date. For material changes, we will notify registered users by email.

13. Contact

Corey McIvor trading as ZYNTHIO™
ABN 31 314 627 918
Email: corey@zynthio.ai
Web: zynthio.ai · coreyai.ai