hdls.aiLegal

Privacy Policy

Effective: 9 June 2026

This Privacy Policy explains how Bluebird AI Pty Ltd (ABN 85 696 013 788) (“hdls”, “we”, “us”) collects, uses, and protects personal data when you use the hdls platform, websites, and APIs (the “Service”). For the records and content you store inside hdls products, you are the controller and we act as a processor on your behalf.

1. Data we collect

  • Account data — your email, workspace name, role, and authentication metadata, used to create and secure your account.
  • Usage / metering events — records of tool calls and other usage events used to enforce plan limits, bill accurately, and operate the Service.
  • Customer Data — the content and records you store in installed products (e.g. accounts, contacts, tickets). This may contain personal data about your own contacts; you control it and we process it on your instructions.
  • Technical data — IP address, device and request metadata, and logs used for security, debugging, and abuse prevention.

2. Why we use it & legal basis

We process data to provide and secure the Service, to authenticate users, to meter and bill usage, to provide support, and to comply with legal obligations. Where GDPR applies, our legal bases are performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement), consent (where required, e.g. certain cookies), and legal obligation. We do not sell personal data.

3. Subprocessors

We use the following subprocessors to operate the Service. Each is bound by contractual confidentiality and data-protection obligations.

SubprocessorPurpose
NeonManaged Postgres — stores workspace and Customer Data
VercelApplication hosting and edge delivery
StripeSubscription billing and payment processing
AI / embeddings provider (e.g. OpenAI)Enrichment and semantic search over content you submit
ResendTransactional email (sign-in codes and notifications)

4. Data location

Customer Data is stored in managed Postgres (Neon) and the Service is hosted on Vercel. Depending on configuration, data may be processed in regions outside your own; where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses. Business and Custom plans may pin storage to a chosen region or use your own Postgres.

5. Retention

We retain account and Customer Data for as long as your workspace is active. After termination, we retain data for a limited wind-down period to allow export, then delete or anonymize it, subject to legal and billing-record retention requirements. You can delete records at any time through the relevant product’s tools.

6. Security

  • Tenant isolation enforced by Postgres row-level security (RLS);
  • OAuth 2.1 for human sign-in and scoped API keys for agents;
  • Encryption in transit and at rest;
  • Signed webhooks and audited administrative actions.

No method of transmission or storage is perfectly secure, but we work to protect your data using industry-standard controls.

7. Your rights

Subject to applicable law, you may request access to, correction of, export of, or erasure of your personal data, and you may object to or restrict certain processing. Under GDPR you also have the right to data portability and to lodge a complaint with a supervisory authority. Under the CCPA/CPRA you have the right to know what personal information is collected, to request deletion, and to not be discriminated against for exercising your rights — we do not sell or share personal information as those terms are defined. To exercise any right, contact us at the address below; we may need to verify your identity.

8. Cookies

We use strictly necessary cookies to keep you signed in and to secure the Service. We minimize non-essential tracking; where any analytics or optional cookies are used, we will request consent as required by law.

9. Contact for privacy requests

For privacy questions or to exercise your rights, contact privacy@hdls.ai (or hello@hdls.ai). hdls is a service of Bluebird AI Pty Ltd (ABN 85 696 013 788), operating from New South Wales, Australia.

10. Changes

We may update this policy. Material changes will be communicated through the Service or by email, and the effective date above will be revised.