In short: lagstyr.com sets no cookies, runs no analytics, and carries no advertising or tracking scripts. If you give us your email address, we use it to talk to you about lagstyr and nothing else. Email you send to support@lagstyr.com is triaged and drafted with the help of an AI agent working under human oversight — §5 explains exactly how. When lagstyr is deployed in your own cloud, your data stays in your cloud: you control it, and we do not have routine access to it. We do not sell, rent, or trade personal information, and we do not use your data to train AI models.
#Who we are
lagstyr.com is operated by VSPRY AUSTRALIA PTY LIMITED (ABN 41 631 026 330) of Level 38, 71 Eagle Street, Brisbane QLD 4000, Australia. In this policy, "lagstyr", "we", "us" and "our" mean that entity, which is the APP entity under the Privacy Act 1988 (Cth) and the controller of the personal information described below.
Vspry Australia Pty Limited is a wholly-owned subsidiary of VSPRY INTERNATIONAL PTY LIMITED (ABN 59 631 026 027), which owns the lagstyr intellectual property and copyright. Vspry International does not operate the website and is not the controller of the personal information described in this policy.
Privacy contact: support@lagstyr.com, using the subject prefix [PRIVACY]. Postal enquiries may be sent to the address above, marked Attention: Privacy Officer.
#1.Scope of this policy
#1.1What this policy covers
This policy covers personal information we handle:
- when you visit or use lagstyr.com, including the AI-native operating guide and its downloads;
- when you submit the early-access signup form on lagstyr.com;
- when you correspond with us — by email to support@lagstyr.com or otherwise;
- in the course of pre-sales, evaluation and commercial discussions about lagstyr; and
- in our customer and prospect records, which we maintain to manage those relationships.
#1.2What this policy does not cover
This policy does not cover personal information held inside a lagstyr deployment that runs in a customer's own cloud environment. lagstyr is licensed and deployed BYOC — bring your own cloud — and in that model the customer, not us, holds and controls the data. Section 7 sets out our position on customer deployments in full.
This policy also does not cover third-party websites we link to. Those sites are governed by their own privacy policies.
#1.3Who this policy is written for
lagstyr is a business product and lagstyr.com is a business website. The personal information we handle is overwhelmingly business contact information — a work email address, a name, a role, an employer — supplied by people acting in a professional capacity. We have written this policy on that basis. Where a privacy law that applies to you treats business contact information as personal information (as Australian law does), we treat it that way too.
#2.Information we collect
#2.1Early-access signup
The signup form on lagstyr.com collects one field: your email address. When you submit it, we record:
| Field | Value | Why |
|---|---|---|
| Email address | The address you type | So we can reply to you and keep you posted about lagstyr |
| Source | A fixed label identifying which page the signup came from (currently lagstyr-landing) |
So we know the context in which you got in touch |
| Timestamp | The UTC date and time of submission | Record-keeping, and so we can apply the retention rule in §9 |
We do not ask for your name, employer, role, phone number, or any other detail at signup, and the form does not collect them silently. Duplicate submissions of an address already on the list are discarded rather than stored twice.
The form contains a hidden field that human visitors never see or fill in. Automated bots do fill it in. When that field is populated, the submission is silently discarded and nothing is stored — we do not retain bot submissions or the addresses in them.
#2.2Correspondence with us
When you email us, or we email you, we handle the content of that correspondence: your email address and display name, the subject and body of your messages, any attachments you send, and the message metadata your mail system supplies (timestamps, message identifiers, and the routing headers that email requires to function). We retain the thread so that we have a record of what was asked and what we answered.
Section 5 explains how that correspondence is processed, including the role of our AI support agent.
#2.3Commercial and relationship records
If we enter into pre-sales, evaluation, or contractual discussions with your organisation, we keep records of the relationship: the names, roles, and business contact details of the people we deal with; notes of meetings and calls; the documents exchanged; and the status of the opportunity. This is ordinary business record-keeping about people acting for their employer.
#2.4Website request data
Our website is served through Cloudflare, which operates the network edge and the hosting platform. As part of delivering and protecting the site, Cloudflare processes request metadata including your IP address, the requested URL, the referring URL, your browser user-agent string, approximate country, and the time of the request. This processing is necessary to serve the page to you at all, and to defend the site against denial-of-service and automated abuse.
We do not export, archive, or enrich Cloudflare's traffic logs, we do not join them to any other information we hold, and we do not build visitor profiles from them. Cloudflare's retention of those logs is governed by Cloudflare's own policies and is typically short.
#2.5Guide downloads
The AI-native operating guide and its document set are free and require no registration. The files are served as ordinary static downloads. We do not require an email address, we do not gate the files, we do not put a tracking parameter in the download links, and we do not know who has downloaded a document beyond the request metadata described in §2.4.
#2.6Information you give us about other people
If you send us the personal information of a third party — for example, by copying a colleague into an email, naming a member of your team as a contact, or sending us a document that includes someone's details — you must have the authority to do so, and you are responsible for ensuring that person has been given whatever notice their applicable privacy law requires. We handle that information under this policy and use it only for the purpose for which you supplied it.
#3.Information we do not collect
We think what a website does not do is as material as what it does. On lagstyr.com:
- We set no cookies. Not for tracking, not for advertising, not for sessions, not for preferences. Our site emits no
Set-Cookieheader of its own. Because we set no cookies of our own, we display no cookie consent banner. Cookies that our infrastructure provider may set are disclosed in §4. - We run no analytics. There is no Google Analytics, no Plausible, no PostHog, no Hotjar, no Matomo, and no self-hosted analytics of any kind. We do not measure your page views, scroll depth, session duration, or click behaviour.
- We run no advertising or marketing trackers. No Meta pixel, no LinkedIn Insight Tag, no Google Ads remarketing tag, no advertising SDK, no conversion pixel.
- We load no third-party scripts. Every script, stylesheet, font, and image on lagstyr.com is served from our own domain. In particular, our web fonts are self-hosted, so loading our pages does not disclose your visit to a font provider.
- We do not fingerprint your device, and we do not use any device or browser fingerprinting technique for identification, tracking, or attribution.
- We do not use local storage or session storage to store an identifier for you.
- We collect no special categories of information through this website — no health, biometric, genetic, racial or ethnic origin, political opinion, religious belief, trade union membership, sexual orientation, or criminal record information. Please do not send us such information.
- We take no payment on this website. There is no checkout, no payment form, and no card data.
- We do not sell, rent, or trade personal information, and we do not disclose it for cross-context behavioural advertising or any equivalent purpose, for money or for any other valuable consideration.
- We do not use your personal information, your correspondence, or your data to train AI models — ours or anyone else's. See §5.4.
#4.Cookies and similar technologies
We set no cookies of our own (§3).
Our infrastructure provider, Cloudflare, may set short-lived strictly necessary cookies on the lagstyr.com domain — for example __cf_bm, which distinguishes automated traffic from human traffic for bot management, and cf_clearance where a security challenge has been issued. These cookies exist to keep the site available and secure. They are not used for cross-site tracking, profiling, or behavioural advertising, they give us no tracking capability, and we do not read them. They are governed by Cloudflare's privacy policy.
There are no analytics cookies, no advertising cookies, and no third-party marketing cookies on lagstyr.com to consent to, reject, or manage.
#5.AI-assisted handling of your enquiries
We want to be direct about this, because it is exactly the discipline lagstyr exists to enforce: when you email support@lagstyr.com, an AI agent participates in handling your message.
#5.1What the AI agent does
The agent reads the incoming message, classifies it (for example: general enquiry, access request, privacy request, security report, or something requiring escalation), and drafts a proposed response. To do this, the content of your message — including your email address, your name as it appears in the message, and anything you have written or attached — is sent to a third-party large-language-model provider for processing. That provider is listed in §8.
#5.2Human oversight
The agent operates under human oversight. A person at lagstyr is accountable for the mailbox and for what is sent from it. We do not use the agent to make decisions that produce legal effects for you or that similarly significantly affect you. Any decision of that kind — for example, refusing a privacy request, or acting on a complaint — is made by a person.
#5.3Your right to a human
You can ask for a human at any time. Reply to any message from us asking to deal with a person, or write to support@lagstyr.com with [HUMAN] in the subject line, and a person will take over the thread. You do not need to give a reason, and asking will not delay or prejudice your enquiry.
If you would prefer that your message never be processed by the AI agent at all, write to us with [NO-AI] in the subject line and we will route the thread for human-only handling. Note that we cannot apply this retrospectively to a message we have already received and processed.
#5.4What the AI provider may not do with your message
Our arrangement with the model provider is on commercial terms under which your content is not used to train the provider's models, and is retained by the provider only transiently for abuse monitoring and service delivery, in accordance with its published enterprise data-handling commitments. We do not consent to, and do not permit, the use of correspondence sent to us for model training.
#5.5Sensitive content
Please do not send us sensitive personal information, security credentials, or confidential material belonging to a third party by email. If you need to send us something sensitive, write to us first and we will agree a secure channel.
#6.Purposes and basis for handling
We handle personal information only for the purposes set out below. The "basis" column states why the handling is lawful; where a privacy law that applies to you requires a specific lawful basis to be identified, this is the basis we rely on.
| Information | Purpose | Basis |
|---|---|---|
| Early-access signup email (§2.1) | Replying to you; keeping you posted about lagstyr's development and availability | Your consent, given by submitting the form. You may withdraw it at any time (§10, §11) |
| Correspondence content (§2.2) | Answering your enquiry and keeping a record of what was asked and answered | Necessary to take steps at your request and to respond to you; our legitimate business interest in keeping accurate records |
| Commercial and relationship records (§2.3) | Managing the pre-sales, evaluation, and contractual relationship with your organisation | Necessary for the performance of, or steps preliminary to, a contract with your organisation; our legitimate business interest in managing customer relationships |
| Website request data (§2.4) | Delivering the website; keeping it available; defending against attack and automated abuse | Necessary to provide the service you requested; our legitimate interest in the security and availability of our own site |
| Bot-detection signals (§2.1, §4) | Preventing automated abuse of the signup form and the site | Our legitimate interest in preventing abuse of our systems |
| Marketing communications (§11) | Telling you about lagstyr | Your consent, and our compliance with the marketing rules in §11 |
| Any of the above | Complying with a law, a court order, or a lawful request from a regulator; establishing, exercising, or defending a legal claim | Compliance with our legal obligations; our legitimate interest in defending our legal position |
We do not use personal information for automated decision-making that produces legal effects for you or similarly significantly affects you, and we do not carry out profiling for that purpose.
If we ever want to use personal information for a purpose that is not listed above and that you would not reasonably expect, we will seek your consent first.
#7.Customer deployments — BYOC
lagstyr is licensed to organisations and deployed into the customer's own cloud environment. This has a direct and deliberate privacy consequence.
- The customer controls the data. Data processed in a lagstyr deployment — including any personal information the customer or its agents put into it — resides in infrastructure the customer owns and administers. The customer determines what goes in, who may reach it, how long it is kept, and where it is stored. In data-protection terms, the customer is the controller of that data and the APP entity in respect of it.
- We are not the custodian of it. We do not hold a copy of customer data, we do not route it through our systems, and we do not have routine access to it. We cannot access a customer's deployment because we operate it — we do not operate it.
- Support access is by exception, and by invitation. Where a customer asks us to help diagnose a problem and grants us access for that purpose, that access is temporary, scoped to the diagnostic task, subject to the customer's own controls, and governed by the agreement between us and the customer — not by this policy. The customer's own logging records it.
- We do not train on customer data. We do not use customer data to train, fine-tune, evaluate, or improve any model, ours or a third party's.
If you are an employee, contractor, or counterparty of an organisation that runs lagstyr and you want to exercise privacy rights over data in that deployment, your request should go to that organisation, which controls it. If you send such a request to us, we will tell you so and, where we can identify the organisation and it is appropriate to do so, refer it on.
The commercial terms governing a deployment — including any data processing terms — are set out in the agreement between us and the customer, not in this policy. See the Terms and Conditions of Use §8.
#8.Who we share information with
We disclose personal information only as described here. We do not sell it, rent it, trade it, or disclose it for anyone else's marketing.
#8.1Service providers
| Provider | What it does for us | What it handles | Location |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting, network edge, DNS, bot management, and the database that stores signup records | Website request metadata (§2.4); signup email addresses, source labels, and timestamps (§2.1) | United States and a global edge network |
| Twilio SendGrid | Sending and receiving email, including our support mailbox and any updates we send you | Your email address and the content of email to and from us | United States |
| Our AI model provider (currently Anthropic PBC) | Powering the AI support agent described in §5 — classifying incoming enquiries and drafting replies | The content of email you send to support@lagstyr.com, including your address and anything in the message | United States |
Each of these providers is engaged under terms that require it to handle the information only for the purpose of providing the service to us, to keep it secure, and not to use it for its own purposes. We review this list as our arrangements change, and the current list is always the one published here.
#8.2Other disclosures
We may also disclose personal information:
- to our professional advisers — lawyers, accountants, auditors, and insurers — where they need it to advise us, and under a duty of confidentiality;
- to Vspry International Pty Limited, our parent company, where necessary for group management, legal, or financial purposes;
- where the law requires it — in response to a court order, subpoena, statutory notice, or a lawful request from a regulator or law-enforcement agency with jurisdiction over us. We assess every such request, we require it to be valid and properly served, and we disclose no more than the request compels;
- to establish, exercise, or defend a legal claim; and
- in connection with a business transfer — if our business, or the part of it that operates lagstyr, is sold, merged, or reorganised, information may transfer to the acquirer as part of that transaction. We would require the acquirer to continue to handle it under terms no less protective than this policy, and we would tell you before your information became subject to a materially different policy.
#9.Sending information overseas
We are based in Australia. The providers listed in §8.1 are located in the United States and operate global infrastructure, so personal information we handle is disclosed to, and stored and processed in, countries other than Australia and other than the country you are in.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the standards in this policy and with the Australian Privacy Principles (APP 8.1), principally by contract with each provider. Where a transfer mechanism is required by a privacy law applying to you — such as standard contractual clauses or an equivalent safeguard — we rely on the mechanism incorporated in our agreement with the relevant provider. To ask which mechanism applies to information about you, write to support@lagstyr.com with the subject prefix [PRIVACY].
Where an exception under APP 8.2 does not apply, by giving us your information you acknowledge that it will be disclosed to the overseas recipients described above, and that we will not be accountable for their acts and practices under APP 8.1 to the extent that acknowledgement operates under section 16C of the Privacy Act 1988 (Cth). This does not reduce the contractual protections we put in place, and it does not affect our own obligations to you.
#10.How long we keep information
| Information | Retention |
|---|---|
| Early-access signup (§2.1) | Kept until you withdraw your interest or ask us to delete it. Otherwise reviewed periodically and purged where there has been no engagement for 24 months |
| Correspondence (§2.2) | Kept for as long as needed to deal with the matter and to keep a record of it, then deleted. Threads that form part of a commercial relationship are kept under the row below |
| Commercial and relationship records (§2.3) | Kept for the duration of the relationship and for 7 years afterwards, which is the period we are required to retain business records under Australian tax and corporations law (including section 262A of the Income Tax Assessment Act 1936 (Cth) and section 286 of the Corporations Act 2001 (Cth)) |
| Website request data (§2.4) | Held by Cloudflare under its own retention policy, typically for a short period measured in days to weeks. We keep no copy |
| Bot submissions (§2.1) | Not stored at all |
| Records needed for a legal claim or a legal hold | Kept until the claim or hold is resolved, then dealt with under the rows above |
When a retention period ends we delete the information, or de-identify it so that it can no longer be linked to you. Where information is held in a backup, deletion takes effect on the backup's ordinary rotation cycle.
#11.Marketing communications, consent, and unsubscribing
#11.1When we will email you
We send commercial email — updates about lagstyr, its development, availability, and launch — only where we have your consent to do so. In practice, that consent comes from you submitting the signup form on lagstyr.com, or from you asking us to keep you informed in the course of a conversation. We also treat the existence of a business relationship as consent to communicate with you about it, to the extent the law where you are permits.
We do not buy marketing lists, we do not scrape addresses, we do not send unsolicited cold outreach on the strength of an address we found somewhere, and we do not pass your address to anyone else so they can market to you.
#11.2What every commercial message from us will contain
Every commercial electronic message we send will:
- identify us clearly as the sender, and state that Vspry Australia Pty Limited (ABN 41 631 026 330) sent it, with accurate contact details including our street address at Level 38, 71 Eagle Street, Brisbane QLD 4000, Australia;
- use accurate and non-deceptive sender, "from", "reply-to", and subject-line information;
- contain a functional unsubscribe facility that is clearly presented, easy to use, and free; and
- honour an unsubscribe request within 5 business days of you making it — in practice, usually immediately.
The unsubscribe facility will remain operative for at least 30 days after the message is sent, and we will not charge you, require you to log in, require you to state a reason, or require you to provide anything beyond the address to be removed.
These commitments are given to meet the standards of the Spam Act 2003 (Cth), the United States CAN-SPAM Act of 2003 (15 U.S.C. §7701 et seq.), and the consent, notice, and withdrawal standards of comparable data-protection and electronic-marketing laws elsewhere — including the requirement that consent be freely given, specific, informed, unambiguous, given by a clear affirmative act, and as easy to withdraw as it was to give.
#11.3How to unsubscribe or withdraw consent
Use the unsubscribe link in any message from us, or write to support@lagstyr.com with [UNSUBSCRIBE] in the subject line. We will stop sending you commercial messages. You may still receive transactional or relationship messages that are not commercial in nature — for example, a reply to a question you asked us, or a notice about a change to these documents.
Withdrawing consent does not affect the lawfulness of anything we did while the consent was in force.
#12.Your rights and how to exercise them
#12.1Rights we honour for everyone
Whatever privacy law applies to you, we will:
- tell you what we hold about you, and give you access to it;
- correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading;
- delete it on request, unless we are required or entitled to keep it — for example, under a retention obligation in §10 or a legal hold, in which case we will tell you which exception applies and to what;
- stop sending you marketing, immediately and permanently, on request (§11.3);
- tell you where it came from, if we did not collect it from you directly; and
- not discriminate against you for exercising any of these rights.
Under the Australian Privacy Principles, these rights include access under APP 12 and correction under APP 13, and the right to opt out of direct marketing under APP 7.
#12.2Additional rights under other privacy laws
Privacy laws outside Australia may give you further rights — for example, rights to receive your information in a portable machine-readable format, to have it transmitted to another provider, to restrict how we handle it, to object to handling we base on our legitimate interests, to know the categories of information collected and disclosed in the past twelve months, to appeal a refusal of a request, or to authorise an agent to make a request for you.
Where a privacy law that applies to you gives you a right of that kind, we will honour it, on the same terms and within the same timeframes as the rights in §12.1, and we will not require you to identify the statute you are relying on. Ask for what you want in plain words and we will treat the request as made under whatever law gives you the strongest entitlement.
We confirm, for the avoidance of doubt, that we do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in privacy laws that regulate such practices. We have not done so in the past twelve months.
#12.3How to make a request
Write to support@lagstyr.com with the subject prefix [PRIVACY] and tell us what you want. There is no form to complete and no fee.
- Verification. So that we do not disclose information to the wrong person, we will ask you to demonstrate control of the email address on the record, or otherwise verify your identity proportionately to the sensitivity of the request. If an agent makes a request for you, we may ask for evidence of their authority and confirm the request with you directly.
- Timing. We aim to acknowledge within 5 business days and to respond substantively within 30 days. If a request is complex, or you have made several, we may extend that period — we will tell you before the initial period expires, explain why, and give you a date.
- Refusals. If we refuse a request in whole or in part, we will tell you in writing, explain our reasons, identify the ground we rely on, and tell you how to complain.
#13.Security
We apply technical and organisational measures appropriate to the risk, in line with APP 11:
- Encryption in transit. Every connection to lagstyr.com is served over TLS, and HTTP requests are redirected to HTTPS.
- Encryption at rest. Signup records and other stored data are encrypted at rest by our infrastructure platform.
- Minimal collection. The most effective security control we apply is not collecting information in the first place. The website collects one field, sets no cookies, and runs no analytics precisely so that there is very little to lose.
- Access control. Access to systems holding personal information is restricted to the people who need it for their role, protected by strong authentication, and reviewed.
- Managed infrastructure. We use established providers (§8.1) rather than operating our own servers, and we take their platform security controls and patching as part of that choice.
- Input validation and abuse controls. Public endpoints validate their inputs, and the signup endpoint carries bot-detection measures.
- Static delivery. The website is a set of static files with a single narrowly-scoped server-side endpoint, which keeps the attack surface deliberately small.
No system can be guaranteed secure, and we do not claim otherwise.
Data breaches. If we become aware of unauthorised access to, unauthorised disclosure of, or loss of personal information we hold, we will assess it promptly and, where it is an eligible data breach likely to result in serious harm, notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, in accordance with Part IIIC of the Privacy Act 1988 (Cth) (the Notifiable Data Breaches scheme). Where another law that applies to the breach imposes a shorter deadline or a different notification path, we will meet that as well.
To report a vulnerability or a suspected breach, write to support@lagstyr.com with the subject prefix [SECURITY].
#14.Anonymity and pseudonymity
You may browse lagstyr.com and download the entire AI-native operating guide without telling us who you are. There is no account, no registration, and no gate.
Where it is lawful and practicable, you may also deal with us pseudonymously — for example, by signing up with a role-based address such as ops@yourcompany.com rather than a personal one. If we need to know who you are to deal with a particular request, we will tell you why (APP 2).
#15.Children
lagstyr is a business product. lagstyr.com is not directed at children, we do not market to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, write to support@lagstyr.com with the subject prefix [PRIVACY] and we will delete it.
#16.Complaints
If you are unhappy with how we have handled your personal information or your request, tell us first: write to support@lagstyr.com with the subject prefix [PRIVACY] and set out what went wrong. We will acknowledge your complaint within 5 business days and give you a written response within 30 days, including what we found and what we intend to do about it.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- Online: oaic.gov.au/privacy/privacy-complaints
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001, Australia
If a privacy law of another country applies to you, you may also complain to the supervisory authority, commissioner, or attorney-general responsible for privacy where you live. Nothing in this policy limits that right, and we will not require you to come to us first as a condition of going to a regulator.
#17.Changes to this policy
We may update this policy. The version number and effective date at the top of this page always identify the current version, and §18 records what changed.
A change that materially reduces your rights or materially expands how we handle your information takes effect 30 days after we publish it. During that period the previous version continues to apply to you. Other changes — corrections, clarifications, an updated provider name — take effect when published.
Where we hold your email address and the change is material, we will tell you by email as well as publishing it here.
#18.Change log
| Version | Effective date | Summary |
|---|---|---|
| 1.0 | 16 August 2026 | Initial publication. |
#19.Related documents
- Terms and Conditions of Use — the terms governing lagstyr.com, the free guide, and the lagstyr platform
- Privacy Policy in Markdown — the source of this page