Vinci Advisory

How we handle your data

Vinci Advisory Last updated: 25 August 2026

If you are considering letting an outside trainer near your team and your systems, you should know exactly what they will see, where it goes and who else can get at it. Most consultants make you ask. Here it is up front.

This is the practical version. The formal version is our Privacy Policy.


What we actually see

During discovery, you walk us through how your business runs. We see your processes, your bottlenecks, and the systems you use. We take notes and, with your agreement, we record the call.

During planning, we sometimes need to log in to a system to test whether the AI can genuinely do the job before we put it in front of your team. That might be a CRM, a portal or a supplier system. When that is necessary:

  • we ask first and explain exactly why
  • you provide the access, on an account you control
  • we prefer a limited test account over a real user account
  • you revoke the access when we are done, and we will remind you to

During the workshop, your team works on their own real tasks with their own logins. We are teaching, not operating. We do not need your credentials to run a workshop.

We do not need and do not want: your customers' personal data, employee records, financial account credentials, or health information. If a task involves any of that, we will show your team how to handle it safely rather than handle it ourselves.


Where it lives

WhatWhereWho hosts it
Meeting recordings and transcriptsSecure cloud platform, login protectedFathom and Otter, United States
Notes and engagement plansOur internal systems, MFA enabledCloud, United States
Your contact detailsOur internal systemsCloud, United States
Documents you send usOur internal systemsCloud, United States

Nothing sits on an unprotected laptop, a personal phone, or a shared drive outside our control.

Some of these platforms are US based, so your information may be stored overseas. We would rather tell you that plainly than let you discover it later. If your business has a policy against offshore storage, say so before we start and we will work around it, including not recording calls at all.


Who can access it

Two people. Toby Carroll and our operations manager. That is the complete list.

No contractors, no virtual assistants, no third-party trainers. If that ever changes, existing clients will be told before it does.


How long we keep it

Recordings and transcripts are kept on an ongoing basis and used internally to improve how we teach. They are never shared outside the business and never used in marketing.

Contact and invoicing records are kept for seven years, which is what Australian tax law requires.

Ask us to delete your recording and we will. Email toby@ai-guy.co and we will delete it and confirm in writing.


Confidentiality

We will sign your NDA before we start. If you do not have one, we can provide ours.

Whether or not an NDA is signed, everything you show us is treated as confidential. We do not discuss one client's business with another, and we do not use your situation as an example in a workshop without asking you first.


AI and your data

This is the question every leadership team asks, so here is the direct answer.

The tools we train you on. We train on Claude, on paid business plans. Under those plans your business data is not used to train the underlying models. That is one of the main reasons we standardised on it rather than on a free consumer tool that your staff may already be pasting company information into.

How we use AI ourselves. We use Claude internally to help prepare your engagement plan and workshop materials. A human reviews everything before it reaches you. We do not put client recordings or client documents into any tool that trains on the input. AI helps us prepare. The judgement stays ours.

What we teach your team. Part of every workshop is where the line sits: what should and should not go into an AI tool, how to tell a confident answer from a correct one, and how to check before something goes out the door with your name on it. Governance is part of the training, not an afterthought.

If you would rather we used no AI at all in preparing your engagement, tell us and we will not.


What we ask of you

A short list, because data handling only works if it goes both ways.

  • Tell us before we start if you have an internal policy we need to work within.
  • Give us the minimum access we need, not the maximum you can grant.
  • Revoke any test access once the engagement finishes.
  • Let us know who on your side is the point of contact for anything data related.

If something goes wrong

If a data breach ever occurred that was likely to cause you serious harm, we would tell you and the Office of the Australian Information Commissioner promptly, as required under the Notifiable Data Breaches scheme. You would hear it from us, not from somewhere else.


Anything else

If you want something handled differently, tell us before we start and we will write it into your working agreement so it is a commitment, not a conversation.

Questions about any of this: toby@ai-guy.co