A small studio, on purpose
We’re a small Gold Coast studio, and for your data that’s a feature. Fewer hands touch it, and one named person is accountable for it: Nicholas Gee, our sole director. There’s no offshore support team and no rotating cast of contractors with access to your systems.
This page covers how we run managed AI agents. For the website itself, our privacy policy and terms apply.
Where your data goes
A managed agent sits between the tools you already use and the model that does the thinking. In order, a request usually travels like this:
- It starts in your tools — Xero, Cliniko, ServiceM8, your inbox, your documents.
- It reaches the agent, which runs on our infrastructure: data stored in Supabase’s Sydney region, the agent itself hosted on Vercel.
- When a step needs one, it goes to a cloud model (Claude or OpenAI) and comes straight back. Sensitive, routine work can instead run on a local model such as Gemma that never connects to the internet.
- The result comes back to you — as a draft for approval, or an action inside a tool you already control.
Your written plan draws this exact path for your business before anything is built, so you can see every place your data travels.
The services involved
These are the third parties that may handle your data as part of a running agent. Stored data stays in Australia; some model processing does not, and we say so plainly rather than implying otherwise.
| Service | What it does | Where | What it keeps |
|---|---|---|---|
| Supabase | Database and stored agent data | Australia (Sydney region) | Your agent's data, until deleted |
| Vercel | Hosting and the agent runtime | May run outside Australia by region | Operational logs, no business data at rest |
| Anthropic (Claude) | The model that reasons and drafts | May process outside Australia | Not used to train their models (API terms) |
| OpenAI | An alternative model for some workloads | May process outside Australia | Not used to train their models (API terms) |
| HubSpot | Enquiry records — this website only | United States | Contact-form submissions |
| Cal.com | Booking and payment — this website only | Per their terms | Booking details and payment handling |
If we ever need to add a service that touches your data, we tell you before it’s used.
Your data isn’t training data
We send model requests through Anthropic’s and OpenAI’s APIs. Under their API terms, data sent that way is not used to train their models. That’s their commitment, published in their terms, and it’s a large part of why we work through the API rather than consumer apps. For the most sensitive routine work, the local-model option keeps the request off the internet entirely.
Who can reach it
- One named person — Nicholas Gee — has production access to client systems.
- Multi-factor authentication is on every provider account.
- Each client’s agent uses its own separate credentials, so one client’s data can’t be reached from another’s.
How long we keep things, and how to get rid of them
- Ask us to delete your stored agent data and it’s gone within 30 days, backups included.
- How long the agent keeps its interaction logs is set in your written plan, not left to a silent default. We recommend a sensible retention for your situation and you decide.
- Supabase takes automated daily backups. Deleted data ages out of those backups within the same retention window, so a deletion is a real deletion.
When an agent gets it wrong
AI makes mistakes, so we build for that rather than pretending it doesn’t. Agents draft; a nominated person on your side approves anything that goes to a customer or a patient. A wrong answer gets caught at that approval step instead of reaching someone. If something does slip through, you tell us, we pause that workflow, and we fix it before it runs again. We don’t promise a call centre or an overnight pager roster we don’t have; we promise a named person who answers.
What we won’t touch
Payroll records and health records are excluded from what an agent can access unless we agree otherwise, in writing, in your plan. Where a task is sensitive but routine, we can run it on the local model so the data never leaves your environment.
Documents on request
A data-processing agreement, and answers to a specific security questionnaire, are available on request and put in place before any regulated work begins. If you need something particular for your own compliance, ask on the free fit check and we’ll sort it out then. Email hello@geeit.com.au any time.
This page is general information, not legal advice. Your engagement’s written plan and our terms govern the specifics. Last updated 24 July 2026.