The Privacy Act and AI automation: what an Australian SMB actually has to do
Which obligations bite, what changes when a system makes automated decisions, and the design choices that keep you out of trouble.
ReadFive Australian clients shipped across construction, energy, logistics, medical and B2B sales. Fixed price, two to six weeks, and a team on UTC+8 so we are working while you are.
Manual work is priced against the person doing it. At Australian rates, an hour of reconciliation, data entry or report assembly is one of the most expensive hours in the business. That is why the same automation that is a nice-to-have elsewhere pays back faster here.
Our team runs on UTC+8 with no daylight saving. That is identical to Perth, two hours from Brisbane year round, and two to three hours from Sydney and Melbourne. Compare that with a European agency who is asleep for your whole working day.
Australian Privacy Principle obligations shape how a system stores, moves and logs personal information. We build access control, data minimisation and audit trails as defaults, because retrofitting them after the fact is where projects go over budget.
We work with all of Australia remotely. These four have their own pages because the industry mix and the overlap with our working day genuinely differ.
No, and we will not pretend to be. The operating entity is Sellrise Limited, registered in Hong Kong, and the team works from Bali. We have no ABN and no Australian address. What we do have is five Australian clients shipped and a working day that overlaps yours. If having an Australian entity on the invoice is a hard requirement for your procurement, tell us on the first call and we will say so plainly rather than waste your time.
Yes. Published pricing is in USD because most of our work is international, but for Australian clients we can fix the AUD amount at scoping, which puts exchange movement on us rather than on you. GST does not apply to our invoices, as we are not registered for it in Australia.
The practical effect is on design rather than on paperwork. If a system touches personal information you need to know what it collects, why, where it is stored, who can reach it, and what happens in a breach. We build with those constraints in from the start - minimum necessary data, role-based access, audit logging, and clear documentation of data flows. We are engineers, not lawyers, so anything with real regulatory weight should also go past your own adviser before it goes live.
We have. Our medical tourism client operates into the Australian market under advertising rules considerably stricter than most industries face, which meant every piece of generated content had to pass a compliance gate before it could be published. That experience is why we treat compliance as a hard gate in the build rather than a review at the end.
All of them, since the work is remote. We have city pages for Sydney, Melbourne, Brisbane and Perth because the industry mix and the clock differ enough to matter. Perth is the standout: it is UTC+8, the same as our team, with no offset at any point in the year.
Two to six weeks for most builds, fixed price agreed before we start. Automation work runs two to four weeks, custom development three to six. We quote after a free thirty-minute scoping call, never before, because a quote given before looking at your stack is a guess with a number attached.