Privacy at a glance
- The current website prototype does not transmit the operational-review form. It prepares a summary in your browser for you to copy.
- The current prototype does not use advertising pixels, marketing cookies, or analytics services.
- Please do not include health information, identity documents, client records, passwords, or other sensitive or confidential information in an initial website enquiry.
- Information used in a client project is handled under separate scope, access, processing, retention, and service-provider decisions.
1. Who this policy covers
In this policy, Glivent, we, and us refer to the Glivent legal entity identified below. You means a website visitor, person making an enquiry, client contact, supplier, contractor, or other person whose personal information we handle.
Legal entity and ABN: to be inserted before publication.
This policy is intended to describe Glivent's practices under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, together with any other privacy obligations that apply to a particular activity. It does not itself establish that every activity or entity is subject to the Privacy Act.
2. Personal information we may collect
The information we collect depends on how you deal with us and may include:
- Identity and contact details: your name, role, business, work email, phone number, and preferred contact method.
- Enquiries and communications: information you provide about your business, operational challenges, meetings, correspondence, feedback, and requests.
- Commercial and administrative information: proposal, contract, project-contact, invoice, payment, support, and relationship records where you or your organisation deals with Glivent.
- Project information: information about people, roles, permissions, systems, and processes where it is necessary to understand or deliver an agreed engagement.
- Technical information: if the website is publicly hosted, the host may generate IP address, browser, device, request, error, security, and access-log information needed to serve and protect the website.
We do not ask for sensitive information through the public website. Where an agreed engagement genuinely requires Glivent to handle sensitive information, we will first define why it is needed, who may access it, where it will be processed, which providers are involved, and the safeguards and retention arrangements that apply. We will only collect and handle that information where authorised by law and, where required, with consent.
3. How we collect information
We may collect personal information:
- directly from you in conversations, email, meetings, forms, or documents;
- from your organisation or another person you have authorised;
- from public professional sources where reasonably necessary;
- through project systems and records within an agreed scope; and
- automatically through essential hosting and security logs once the site is deployed.
If you provide personal information about another person, you should have authority to do so and, where appropriate, make them aware of this policy.
4. Why we handle personal information
We may use or disclose personal information to:
- respond to enquiries and arrange conversations;
- assess, scope, propose, deliver, secure, and support Glivent services;
- manage client, supplier, contractor, and business relationships;
- administer contracts, invoicing, records, and legal obligations;
- operate, maintain, troubleshoot, and protect the website and our systems;
- improve our services using appropriately controlled information; and
- handle disputes, protect lawful interests, or respond to regulators and courts.
We do not sell or rent personal information. We will not use personal information for an unrelated purpose unless you would reasonably expect that use, you consent, or the use is otherwise authorised or required by law.
5. Who may receive personal information
Where reasonably necessary for the purposes above, information may be disclosed to:
- Glivent's founders, personnel, and authorised contractors;
- hosting, email, communications, document, security, accounting, and other service providers selected for the relevant activity;
- professional advisers, insurers, auditors, and financiers;
- your organisation and people authorised within an agreed project;
- regulators, courts, law-enforcement bodies, or other parties where required or authorised by law; and
- another party with your consent or at your direction.
Access to client project information is not automatically given to every provider or Glivent team member. The access and processing path should be defined for the particular engagement.
6. Overseas disclosure and cloud providers
Some technology providers may process or store information outside Australia or permit support access from another country. Before public launch, Glivent will identify the providers used for this website and the countries in which overseas recipients are likely to be located, where required and reasonably practicable.
For client work, any use of an overseas or public cloud provider should be a deliberate design and contracting decision. A Private AI or onsite workflow does not mean that every supporting service or all business data is necessarily local. The agreed data flow will identify any approved cloud step and the information involved.
7. Website forms, cookies, and analytics
The operational-review form collects your name, business name, work email address, and the description you provide, and sends them to Glivent as an email. Delivery uses Resend, a third-party email delivery service that processes the message (including in the United States) for the purpose of delivering it. Glivent uses this information to respond to your enquiry. If sending fails, the form instead shows you a summary to email to Glivent yourself, and nothing is transmitted. If Glivent later connects the form to scheduling, customer-management, or other services, this policy must be updated before that change goes live.
The current prototype does not use marketing or analytics cookies. A production host may use essential technical storage or server logs to provide and secure the site. Any analytics, advertising, session recording, or non-essential cookie introduced later must be assessed and disclosed before use.
8. AI systems and client-controlled information
The current website enquiry is not sent to an AI model provider and is not used to make an automated decision about you. If Glivent proposes AI processing as part of a client system, the project should identify the purpose, information involved, model or provider, processing location, human oversight, access, logging, retention, and any material limitations.
A client may control personal information processed through a system Glivent builds or supports. In that case, the client's privacy policy, instructions, and legal obligations may also apply. The service agreement should allocate the parties' responsibilities and explain how requests, incidents, and deletion are handled.
9. Security and retention
Glivent will take technical and organisational steps that are reasonable in the circumstances to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. The appropriate steps depend on the information and may include access controls, authentication, least-privilege permissions, encryption, backups, logging, update management, provider review, and incident procedures.
No system can be described as completely secure. If a data incident occurs, Glivent will assess and respond to it under applicable law and the relevant client agreements.
We retain personal information only for as long as reasonably needed for the purpose for which it was collected, an ongoing relationship, dispute management, backup cycles, or legal and accounting requirements. When it is no longer required, we will take reasonable steps to delete, de-identify, or place it beyond use as appropriate. Project-specific retention periods should be documented separately.
10. Accessing or correcting your information
You may ask for access to personal information Glivent holds about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We may need to verify your identity.
We will respond within a reasonable period and explain any lawful reason why access or correction cannot be provided. We will not charge for a correction request. If a charge is permitted for providing access, we will explain it before proceeding.
11. Privacy questions and complaints
Please contact Glivent first if you have a privacy question or believe we have mishandled personal information. Include enough detail for us to understand the concern and the outcome you are seeking. We will acknowledge the matter and aim to respond within 30 days. If more time is reasonably required, we will explain why and provide an updated timeframe.
Privacy contact, email, phone, and postal address: to be inserted before publication.
If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner. Information is available at oaic.gov.au/privacy/privacy-complaints.
12. Changes to this policy
We may update this policy when our website, services, providers, or legal obligations change. The current version will be published on this page with its revision date. Material changes should be communicated through an appropriate additional notice where reasonably necessary.
Use of this website is also subject to our Website terms.
Pre-publication draft updated 23 July 2026.