Support Privacy Notice
Effective Date: 4 September 2026 Last Updated: 29 September 2026 Version: 1.7
This notice is for people who contact Maelstrom support. It applies to every support request you send us. It supplements the Privacy Policy, Section 13, and does not replace it.
1. Who we are
Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792) operates the support portal.
| Legal entity | Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust |
| ABN | 61 633 823 792 |
| Postal address | PO Box 169, St Arnaud VIC 3478, Australia |
| Privacy contact | support@maelstrom.au |
Maelstrom has two roles for your support data:
- Controller of your contact and ticket data: your name, email address, message content, and any operator notes. We decide the purpose and means of that processing, and you contact us directly.
- Processor of the content of any bundles or attachments you send us. We handle that content only on your organisation’s instruction, under the support data processing agreement (DPA).
Cloudflare, Inc. stores this data, in our own Cloudflare account, as our processor for both roles.
2. What we collect
When you contact support, we hold:
- Your name and email address
- Your message content
- Any attachments or support bundles you send us, including bundles uploaded through a one-time upload link
- Operator notes added to your ticket
- Diagnosis notes that the support platform adds to a ticket that carries a support bundle (see Section 8)
- Your entitlement record at the time of the ticket
- Technical log records in Cloudflare Workers Logs and a Cloudflare R2 log bucket: the caller IP address your request came from, and the email address of the operator who handled it
This notice applies to all support requests we receive.
3. Why we process it
We use this information to answer your request, track it to resolution, and run our support service.
- Legal basis: contract. Where support relates to a product or service you have engaged, processing is necessary to perform that contract.
- Legal basis: legitimate interest. Where no contract applies, we rely on our legitimate interest in operating a support service and responding to enquiries. This is consistent with the Privacy Policy, Section 13.
4. Where it lives
Cloudflare storage services (Durable Objects and R2) hold your support data, within Maelstrom’s own Cloudflare account. This includes your ticket, message and operator-note data, raw email content, attachments, and any support bundles you send us.
Cloudflare, Inc. is our processor for this data, under the Cloudflare master Data Processing Addendum.
5. Retention
We keep closed tickets and attachments for 365 days after the ticket closes.
We keep support bundles for 30 days after upload, and we also delete them when the ticket closes.
Technical log records are kept for 90 days, then deleted automatically.
6. Sub-processors
- Cloudflare, Inc. stores and processes your support-ticket data, as described in Section 4. See the Sub-Processors List, Section 2.1, for the full record.
- Proton AG (Switzerland) hosts Maelstrom’s company mailboxes on the maelstrom.au domain, including support@maelstrom.au. If you email a maelstrom.au address, your email is stored in that mailbox. Support tickets are stored by the support platform on Cloudflare, as described above. See Proton AG in the Sub-Processors List.
No other sub-processor is engaged for your support data.
7. Your rights
You have a right of access to the support data we hold about you, a right to have inaccurate data corrected, and a right to ask us to delete or restrict it. Contact us using the details below.
If you are not satisfied with our response, you may lodge a complaint with:
- the Office of the Australian Information Commissioner; or
- if the GDPR applies to you, the data protection supervisory authority in your Member State.
8. Automated decision-making
We make no automated decision about you that has a legal or similarly significant effect. Human operators answer support tickets. A rule-based process classifies each ticket against its SLA, and an operator can review and change that classification.
When a ticket carries a support bundle, a rule-based diagnosis also annotates the ticket. The support platform reads facts from the bundle and compares them with fixed rules. It adds an internal note that names the rules that matched, and it can set the ticket’s priority, labels and category. No machine-learning model makes this diagnosis. An operator reviews the diagnosis and can change what it set.
9. Contact
| Privacy enquiries | support@maelstrom.au |
| Privacy enquiries about downpipes | support@maelstrom.au or support@downpipes.io |
| Postal address | Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust, PO Box 169, St Arnaud VIC 3478, Australia |
| Security disclosures | support@maelstrom.au |
Document control
| Owner | Privacy Officer |
| Version | 1.7 |
| Effective date | 4 September 2026 |
| Last updated | 29 September 2026 |
| Next review | 4 March 2027, or on material change to our support-data processing |
| Change history | 1.0 (2026-09-04): First publication. 1.1 (2026-09-04): Scope update. 1.2 (2026-09-04): Editorial update. 1.3 (2026-09-24): Editorial update. 1.4 (2026-09-24): Technical log records are now kept for 90 days. No change to your rights or our obligations. 1.5 (2026-09-25): Factual corrections: the postal address label and the location of technical log records. No change to your rights or our obligations. 1.6 (2026-09-25): Section 8 describes the rule-based diagnosis that annotates a ticket that carries a support bundle, and the operator review of it. Section 2 lists the diagnosis note. Section 6 links to the Proton entry on the Sub-Processors List. Section 9 gives support@downpipes.io for downpipes. No change to your rights or our obligations. 1.7 (2026-09-29): Plain English rewrite. No change to any commitment, right or obligation. |
| Related documents | Privacy Policy, Section 13, and the Sub-Processors List. |