← Back to EPI

Legal

Privacy Policy

Last updated: March 2026

1. About this policy

This Privacy Policy explains how Energy Policy Intel Pty Ltd (ACN 696 543 085) ("EPI", "we", "us", "our") collects, uses, stores, and discloses personal information. EPI operates the Australian Energy Policy Intelligence platform at energypolicyintel.com and may operate similar platforms in other jurisdictions in future.

We are committed to protecting personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where our services are accessed by individuals in the European Economic Area, we also comply with the General Data Protection Regulation (GDPR). Where services are accessed in other jurisdictions, we comply with applicable local privacy laws.

By using our services, you agree to the collection and use of information as described in this policy.

2. Information we collect

We collect only the minimum personal information necessary to provide our services:

Email address — collected when you join our waitlist, create an account, or subscribe to our service. Used to deliver daily briefings, account notifications, and service communications.

Payment information — when you subscribe, payment is processed by Stripe (our payment processor). EPI does not store credit card numbers or banking details. We receive confirmation of payment and your billing email address.

Usage data — we may collect anonymised, aggregated data about how our platform is used (such as page views and email open rates) to improve our service. This data cannot be used to identify you individually.

We do not collect sensitive personal information as defined under the Australian Privacy Act, including health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data.

3. How we use your information

We use personal information for the following purposes:

To deliver our service — sending daily intelligence briefings, account notifications, and service updates to your email address.

To manage your subscription — processing payments, handling cancellations, and maintaining your account.

To improve our service — analysing anonymised usage patterns to enhance content quality and platform performance.

To communicate with you — responding to inquiries, providing support, and sending information about material changes to our service.

We do not use your personal information for advertising, profiling, or sale to third parties. We do not use your information for any purpose incompatible with the purposes listed above without your consent.

4. Disclosure of information

We share personal information only with the following third-party service providers, solely to the extent necessary to provide our service:

Supabase (database and authentication) — stores subscriber records and account data. Data is hosted in Sydney, Australia (AWS ap-southeast-2). Supabase complies with GDPR and SOC 2 Type II standards.

Stripe (payment processing) — processes subscription payments. Subject to their own privacy policy and PCI DSS compliance.

Resend (email delivery) — delivers briefing emails and transactional notifications. Subject to their own privacy policy.

Vercel (platform hosting) — hosts the EPI web application. Subject to their own privacy policy.

We do not sell, rent, or trade personal information with any third party. We do not disclose personal information to government bodies or law enforcement except where required by law.

5. International data transfers

Some of our service providers may process data outside Australia. Where this occurs, we take reasonable steps to ensure that overseas recipients handle personal information in a way consistent with the Australian Privacy Principles.

For subscribers in the European Economic Area, personal data transfers outside the EEA are conducted under appropriate safeguards including Standard Contractual Clauses where applicable.

6. Data retention

We retain personal information for as long as necessary to provide our service and comply with legal obligations.

Subscriber records are retained for the duration of your subscription and for seven years following cancellation for accounting and legal compliance purposes.

Waitlist email addresses are retained until you request deletion or we determine the waitlist is no longer needed.

System logs are automatically deleted after 90 days.

You may request deletion of your personal information at any time by contacting us at hello@energypolicyintel.com. We will action deletion requests within 30 days, subject to any legal obligations to retain certain records.

7. Security

We implement reasonable technical and organisational measures to protect personal information against unauthorised access, disclosure, alteration, or destruction. These measures include encrypted data storage, secure HTTPS connections, access controls, and regular security reviews.

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.

In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.

8. Your rights

Under the Australian Privacy Act, you have the right to:

Access the personal information we hold about you. Contact us at hello@energypolicyintel.com to request access.

Correct personal information that is inaccurate, incomplete, or out of date.

Request deletion of your personal information, subject to legal retention requirements.

Opt out of receiving marketing communications at any time by clicking the unsubscribe link in any email or contacting us directly.

For subscribers in the European Economic Area, you additionally have rights under GDPR including the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, contact us at hello@energypolicyintel.com. We will respond within 30 days.

9. Cookies

Our website uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies that identify individual users.

By using our service, you consent to the use of essential cookies as described above.

10. Children

Our service is intended for use by business professionals and is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately at hello@energypolicyintel.com.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify active subscribers of material changes by email at least 14 days before the changes take effect. The current version of this policy is always available at energypolicyintel.com/privacy.

Continued use of our service after changes take effect constitutes acceptance of the updated policy.

12. Contact and complaints

For privacy inquiries, access requests, or complaints, contact us at:

Energy Policy Intel Pty Ltd hello@energypolicyintel.com energypolicyintel.com

If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

For subscribers in the European Economic Area, you may also lodge a complaint with your local data protection authority.

Energy Policy Intel Pty Ltd (ACN 696 543 085) — energypolicyintel.com