How we handle your data
Vinci Advisory Last updated: 25 August 2026
If you are considering letting an outside trainer near your team and your systems, you should know exactly what they will see, where it goes and who else can get at it. Most consultants make you ask. Here it is up front.
This is the practical version. The formal version is our Privacy Policy.
What we actually see
During discovery, you walk us through how your business runs. We see your processes, your bottlenecks, and the systems you use. We take notes and, with your agreement, we record the call.
During planning, we sometimes need to log in to a system to test whether the AI can genuinely do the job before we put it in front of your team. That might be a CRM, a portal or a supplier system. When that is necessary:
- we ask first and explain exactly why
- you provide the access, on an account you control
- we prefer a limited test account over a real user account
- you revoke the access when we are done, and we will remind you to
During the workshop, your team works on their own real tasks with their own logins. We are teaching, not operating. We do not need your credentials to run a workshop.
We do not need and do not want: your customers' personal data, employee records, financial account credentials, or health information. If a task involves any of that, we will show your team how to handle it safely rather than handle it ourselves.
Where it lives
| What | Where | Who hosts it |
|---|---|---|
| Meeting recordings and transcripts | Secure cloud platform, login protected | Fathom and Otter, United States |
| Notes and engagement plans | Our internal systems, MFA enabled | Cloud, United States |
| Your contact details | Our internal systems | Cloud, United States |
| Documents you send us | Our internal systems | Cloud, United States |
Nothing sits on an unprotected laptop, a personal phone, or a shared drive outside our control.
Some of these platforms are US based, so your information may be stored overseas. We would rather tell you that plainly than let you discover it later. If your business has a policy against offshore storage, say so before we start and we will work around it, including not recording calls at all.
Who can access it
Two people. Toby Carroll and our operations manager. That is the complete list.
No contractors, no virtual assistants, no third-party trainers. If that ever changes, existing clients will be told before it does.
How long we keep it
Recordings and transcripts are kept on an ongoing basis and used internally to improve how we teach. They are never shared outside the business and never used in marketing.
Contact and invoicing records are kept for seven years, which is what Australian tax law requires.
Ask us to delete your recording and we will. Email toby@ai-guy.co and we will delete it and confirm in writing.
Confidentiality
We will sign your NDA before we start. If you do not have one, we can provide ours.
Whether or not an NDA is signed, everything you show us is treated as confidential. We do not discuss one client's business with another, and we do not use your situation as an example in a workshop without asking you first.
AI and your data
This is the question every leadership team asks, so here is the direct answer.
The tools we train you on. We train on Claude, on paid business plans. Under those plans your business data is not used to train the underlying models. That is one of the main reasons we standardised on it rather than on a free consumer tool that your staff may already be pasting company information into.
How we use AI ourselves. We use Claude internally to help prepare your engagement plan and workshop materials. A human reviews everything before it reaches you. We do not put client recordings or client documents into any tool that trains on the input. AI helps us prepare. The judgement stays ours.
What we teach your team. Part of every workshop is where the line sits: what should and should not go into an AI tool, how to tell a confident answer from a correct one, and how to check before something goes out the door with your name on it. Governance is part of the training, not an afterthought.
If you would rather we used no AI at all in preparing your engagement, tell us and we will not.
What we ask of you
A short list, because data handling only works if it goes both ways.
- Tell us before we start if you have an internal policy we need to work within.
- Give us the minimum access we need, not the maximum you can grant.
- Revoke any test access once the engagement finishes.
- Let us know who on your side is the point of contact for anything data related.
If something goes wrong
If a data breach ever occurred that was likely to cause you serious harm, we would tell you and the Office of the Australian Information Commissioner promptly, as required under the Notifiable Data Breaches scheme. You would hear it from us, not from somewhere else.
Anything else
If you want something handled differently, tell us before we start and we will write it into your working agreement so it is a commitment, not a conversation.
Questions about any of this: toby@ai-guy.co