Managed AI · Trust packUpdated 24 July 2026

Where your data goes, and who touches it.

If you run a clinic, a bookkeeping practice, or anything else where the data matters, this page is for the person who has to sign off on it. It covers where your data lives, who can reach it, the services involved, how long it’s kept, and what happens when an agent gets something wrong.

A small studio, on purpose

We’re a small Gold Coast studio, and for your data that’s a feature. Fewer hands touch it, and one named person is accountable for it: Nicholas Gee, our sole director. There’s no offshore support team and no rotating cast of contractors with access to your systems.

This page covers how we run managed AI agents. For the website itself, our privacy policy and terms apply.

Where your data goes

A managed agent sits between the tools you already use and the model that does the thinking. In order, a request usually travels like this:

  • It starts in your tools — Xero, Cliniko, ServiceM8, your inbox, your documents.
  • It reaches the agent, which runs on our infrastructure: data stored in Supabase’s Sydney region, the agent itself hosted on Vercel.
  • When a step needs one, it goes to a cloud model (Claude or OpenAI) and comes straight back. Sensitive, routine work can instead run on a local model such as Gemma that never connects to the internet.
  • The result comes back to you — as a draft for approval, or an action inside a tool you already control.

Your written plan draws this exact path for your business before anything is built, so you can see every place your data travels.

The services involved

These are the third parties that may handle your data as part of a running agent. Stored data stays in Australia; some model processing does not, and we say so plainly rather than implying otherwise.

ServiceWhat it doesWhereWhat it keeps
SupabaseDatabase and stored agent dataAustralia (Sydney region)Your agent's data, until deleted
VercelHosting and the agent runtimeMay run outside Australia by regionOperational logs, no business data at rest
Anthropic (Claude)The model that reasons and draftsMay process outside AustraliaNot used to train their models (API terms)
OpenAIAn alternative model for some workloadsMay process outside AustraliaNot used to train their models (API terms)
HubSpotEnquiry records — this website onlyUnited StatesContact-form submissions
Cal.comBooking and payment — this website onlyPer their termsBooking details and payment handling

If we ever need to add a service that touches your data, we tell you before it’s used.

Your data isn’t training data

We send model requests through Anthropic’s and OpenAI’s APIs. Under their API terms, data sent that way is not used to train their models. That’s their commitment, published in their terms, and it’s a large part of why we work through the API rather than consumer apps. For the most sensitive routine work, the local-model option keeps the request off the internet entirely.

Who can reach it

  • One named person — Nicholas Gee — has production access to client systems.
  • Multi-factor authentication is on every provider account.
  • Each client’s agent uses its own separate credentials, so one client’s data can’t be reached from another’s.

How long we keep things, and how to get rid of them

  • Ask us to delete your stored agent data and it’s gone within 30 days, backups included.
  • How long the agent keeps its interaction logs is set in your written plan, not left to a silent default. We recommend a sensible retention for your situation and you decide.
  • Supabase takes automated daily backups. Deleted data ages out of those backups within the same retention window, so a deletion is a real deletion.

When an agent gets it wrong

AI makes mistakes, so we build for that rather than pretending it doesn’t. Agents draft; a nominated person on your side approves anything that goes to a customer or a patient. A wrong answer gets caught at that approval step instead of reaching someone. If something does slip through, you tell us, we pause that workflow, and we fix it before it runs again. We don’t promise a call centre or an overnight pager roster we don’t have; we promise a named person who answers.

What we won’t touch

Payroll records and health records are excluded from what an agent can access unless we agree otherwise, in writing, in your plan. Where a task is sensitive but routine, we can run it on the local model so the data never leaves your environment.

Documents on request

A data-processing agreement, and answers to a specific security questionnaire, are available on request and put in place before any regulated work begins. If you need something particular for your own compliance, ask on the free fit check and we’ll sort it out then. Email hello@geeit.com.au any time.

This page is general information, not legal advice. Your engagement’s written plan and our terms govern the specifics. Last updated 24 July 2026.