Skip to content
FrequencyVision

Legal

Privacy Policy

Frequency Vision · Suite 489, 2 Griffith Street, Coolangatta QLD 4225, Australia
Version 1.0 · Last updated 6 August 2026

1. Who we are, and why this policy matters

Frequency Vision (“Frequency Vision”, “we”, “us”, “our”) is a venture studio for life-serving founders, based on the Gold Coast, Queensland, Australia. We help founders and founder-led organisations turn meaningful visions into clear, credible ventures.

We take privacy seriously because of the kind of work we do. Some of the information we hold is deeply personal — including birth data and Gene Keys / Hologenetic “Self Map” profiles, for our clients and for the people around them. We treat that information as sensitive and handle it with corresponding care.

This policy explains, in plain language, what personal information we collect, why, how we use and protect it, who we share it with, and the rights you have. It applies to our public websites (including frequency.vision), our private client workspace at workspace.frequency.vision (the “Workspace”), and our services, communications and business operations generally.

We are the entity responsible for the personal information described in this policy (in Australian terms, the APP entity), except where we act as a processor on behalf of a client (see clause 4.2). For any privacy question, concern or request, contact us at connect@frequency.vision. We aim to acknowledge privacy enquiries within 5 business days.

2. The laws we follow

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and — where it applies to you — the EU General Data Protection Regulation (“GDPR”) and the UK GDPR. The GDPR can apply to us because we offer services to, and process the personal data of, individuals located in the EU / EEA.

We have not appointed an EU / UK representative under Article 27, on the basis that our processing of EU / UK personal data is occasional and low-risk. If the nature of our processing changes, we will appoint one and update this policy.

3. The personal information we collect

We only collect personal information we genuinely need. What we collect depends on how you interact with us.

3.1 Information you give us directly

  • Identity and contact details — full name, email address, phone number, business or project name, and role.
  • Enquiry and project information — what you’re building, project type, budget range, timelines, links, and the content of messages you send us (for example through our Apply form).
  • Account and Workspace information — login credentials (managed by our authentication provider), profile details, and settings.
  • Payment information — billing details and transaction records. We do not store full card numbers.
  • Content you upload — documents, notes, brand inputs, strategy materials and other files you place in the Workspace.
  • Discovery responses — if we invite you to a private discovery room on our site, the answers you write, voice notes you record and files you upload there, so we can prepare your engagement.
  • Communications — emails, form submissions, call notes, and support requests.

3.2 Sensitive information — birth data and Self Map profiles

Some of our work uses the Gene Keys / Hologenetic Profile framework. To do this we collect birth data (date, time and place of birth) and the profiles and contemplative material derived from it. This information can reveal or be used to infer deeply personal characteristics. We treat it as sensitive information under the APPs and as special-category data under Article 9 of the GDPR. We do not collect it without explicit consent (or the explicit consent of the individual concerned), and we only use it for the purposes consented to.

This material is contemplative, not clinical — a mirror, never a gate. It is not a diagnosis, prediction, assessment of health, or a form of therapy, and it is not used to make any decision that produces a legal or similarly significant effect about you. It is not affiliated with, endorsed by, or connected to Gene Keys Publishing or Richard Rudd.

3.3 Information about other people (stakeholders)

Our clients sometimes ask us to hold information — including birth data and Self Map profiles — about their family members, team members or community members. Where we do this, we act as a processor on the client’s instructions (clause 4.2), and we require the client to have obtained each person’s explicit, per-person consent first. If you are a stakeholder and want to exercise your rights, contact the client who invited you, or contact us and we’ll help route your request.

3.4 Information we collect automatically

Technical data such as IP address, browser and device type, pages viewed and actions taken in the Workspace, collected through server logs and similar technologies. Our public marketing site does not run third-party analytics or advertising trackers — see clause 11.

3.5 Information from third parties

We may receive information about you from your organisation, from someone who refers you, from your client (if you are a stakeholder), or from the service providers listed in clause 6.

3.6 AI-assisted content

We use artificial intelligence — specifically Anthropic’s Claude models — to help draft documents, generate Self Map contemplations, and prepare marketing content. When we do, your inputs (which may include sensitive information) are processed by our AI sub-processor. Clause 5 explains how this works and the safeguards that apply.

4. Why we use your information

We use personal information to:

  • respond to enquiries and scope work (consent / steps to enter a contract);
  • deliver our services and the Workspace (contract);
  • create Gene Keys / Self Map profiles and contemplations (explicit consent for the sensitive data; contract for the surrounding service);
  • use AI to draft and assist, always with human review (contract and legitimate interests; explicit consent where sensitive data is involved);
  • run accounts, security and access control (contract and legitimate interests);
  • invoice, keep accounting and tax records (contract and legal obligation);
  • improve our services and websites (legitimate interests);
  • send service messages and, with consent, occasional marketing (legitimate interests / consent); and
  • meet legal, regulatory and dispute obligations (legal obligation / legitimate interests).

4.1 Consent, and withdrawing it

For sensitive information (birth data and Self Map profiles) we rely on your explicit consent. You can withdraw that consent at any time by contacting us. Withdrawal doesn’t affect processing already lawfully carried out, but we will stop the relevant processing and, where appropriate, delete or de-identify the information (clause 7).

4.2 When we act as a processor for a client

When we hold information about a client’s stakeholders, the client is the controller and we are the processor. We process that information only on the client’s documented instructions under our engagement and data-processing terms, and the stakeholder’s rights are exercised primarily through the client, with our support.

4.3 We don’t sell your data

We do not sell personal information, and we do not use sensitive information for targeted advertising.

5. How we use AI (Anthropic Claude)

Because AI touches sensitive material, we want to be especially clear:

  • What we use it for. Drafting documents, generating Self Map contemplations, and preparing marketing content.
  • Grounded in your own inputs. AI-assisted outputs are generated from your own inputs and materials — not from assumptions or external profiling.
  • Always human-in-the-loop. Every AI-assisted output is reviewed by a person at Frequency Vision before it is used, sent or published. Nothing is auto-published.
  • Not a source of truth or advice. AI-assisted content can contain errors and should not be relied on as legal, financial, tax, medical or psychological advice.
  • Sub-processor safeguards. Anthropic acts as our AI sub-processor under commercial terms; to the extent it processes data outside Australia, the transfer safeguards in clause 8 apply. We do not consent to your inputs being used to train third-party foundation models except as permitted under the applicable commercial terms. If you would prefer that sensitive information not be processed by AI, tell us — we’ll discuss what that means for the relevant work.

6. Who we share your information with

We rely on a small, carefully chosen set of service providers, each acting on our behalf and bound to protect your information. As at the date of this policy they include:

  • Supabase — database, authentication, file storage and hosting for the Workspace (account data, content and, with consent, sensitive information).
  • Anthropic — AI drafting and contemplation assistance (United States; see clause 5).
  • Vercel — hosting and delivery of our websites and applications, and secure storage of discovery-room responses and uploads (United States and global edge).
  • MailerLite — enquiry and lead management, and email delivery for people who contact us or subscribe (European Union).
  • Proton — secure email infrastructure for our mailbox and the transactional emails we send you, such as application acknowledgements and discovery-room summaries (Switzerland).
  • Calendly — scheduling, when you book a discovery call with us (United States).
  • Optional tools for our own marketing and file handling (for example Metricool and Google Drive), used for marketing content and documents rather than client-sensitive material.

We may also disclose personal information to our professional advisers under confidentiality; to a client who is the controller of stakeholder information; in connection with a business sale, merger or restructure, subject to this policy; where required or authorised by law; and to protect the rights, safety or property of Frequency Vision, our clients, or others. We do not otherwise disclose your personal information without your consent.

7. How long we keep information

  • Enquiry data where no engagement follows — up to 24 months from last contact.
  • Client project and Workspace content — for the engagement, then up to 2 years after it ends, unless you ask us to delete it sooner.
  • Discovery-room responses (answers, voice notes and uploads) — treated as client project content: kept for the engagement, then up to 2 years after it ends, or deleted sooner on request.
  • Sensitive information (birth data, Self Map profiles) — only while consent stands and the work requires it; deleted or de-identified on request or when consent is withdrawn, subject to any minimum legal hold.
  • Billing and tax records — 7 years (Australian tax and record-keeping requirements).
  • Marketing subscriber data — until you unsubscribe, then a short suppression record.
  • Server and security logs — up to 12 months.

Where we must keep some information to meet a legal obligation or defend a legal claim, we retain only what is necessary for that purpose.

8. Sending information overseas

Some of our providers store or process information outside Australia — including in the United States (for example Anthropic and Vercel), the European Union (for example MailerLite) and Switzerland (Proton, our email provider).

For Australian individuals (APP 8): before disclosing information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, for example through contractual commitments. For EU / UK individuals (GDPR Chapter V): when we transfer personal data outside the EEA / UK to a country without an adequacy decision, we put in place an appropriate safeguard — typically the European Commission’s Standard Contractual Clauses (and the UK Addendum). You can ask us for a copy of the relevant safeguard.

9. How we protect your information

  • Row-level security in our database, so records are only accessible to the accounts entitled to them.
  • Encryption of data in transit (TLS) and at rest, as provided by our hosting and storage providers.
  • Least-privilege access controls, and restricting sensitive information to those who need it.
  • Per-person consent gating — sensitive stakeholder information is entered and accessed on the basis of that individual's consent.
  • Reputable sub-processors with their own security programs, and human review of AI outputs.

An honest limit: no method of transmission or storage is ever completely secure. If a data breach occurs that is likely to result in serious harm, we will assess it promptly and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable under the Notifiable Data Breaches scheme. Where the GDPR applies, we will also notify the relevant supervisory authority — within 72 hours where required.

10. Your rights and choices

You may ask for access to the personal information we hold about you; ask us to correct information that is inaccurate, out of date, incomplete or misleading; ask how we handle your information; and complain if you think we’ve mishandled it (clause 13). We respond to access and correction requests within a reasonable time — generally within 30 days.

Where the GDPR / UK GDPR applies, you also have rights to access, rectification, erasure, restriction, objection (including to direct marketing at any time), data portability, and withdrawal of consent — and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions; AI output is always subject to human review.

You can opt out of marketing at any time using the unsubscribe link in our emails or by contacting us. We’ll still send essential service messages about your account or engagement.

11. Cookies and similar technologies

Our public marketing site sets no advertising or analytics cookies and runs no third-party trackers, and if we ever introduce analytics we will update this policy before turning it on. What is stored in your browser is small and purposeful: a preference or two (for example, whether you’ve turned sound on); a draft of your in-progress application on our Apply page (including the contact details you’ve typed), kept in your browser so you don’t lose work and cleared when you submit; and, in private discovery rooms, a local copy of your answers — which are also saved automatically to our secure storage as you go, so you can continue on another device. The Workspace uses essential cookies for authentication — keeping you securely logged in — and nothing more. You can control cookies through your browser settings.

12. Children and minors

Our services and the Workspace are intended for adults (18+) and are not directed at children. Where a client asks us to hold information about a minor as a stakeholder — including birth data used for a Self Map — we require the client to have obtained verifiable parent or guardian consent for that specific child, on a per-person basis. If you believe we hold a child’s information without appropriate consent, contact us and we’ll delete it promptly.

13. How to make a complaint

Tell us first — contact us at connect@frequency.vision. We’ll acknowledge your complaint, look into it, and aim to respond within 30 days. If you’re not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au · 1300 363 992 · GPO Box 5218, Sydney NSW 2001). If the GDPR applies to you, you can also complain to your local supervisory authority.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our services, technology, sub-processors, or the law. When we do, we’ll update the “Last updated” date above and, for material changes, take reasonable steps to notify you. Continuing to use our services after a change means you accept the updated policy, except where your fresh consent is required.

See also our Terms of Service.