Privacy Policy - Bobble

PRIVACY POLICY
Last updated: 11/08/2026
Effective date: 11/08/2026
1 INTRODUCTION
This Privacy Policy explains how N2 Therapy Australia Pty Ltd trading
as Bobble App, ABN 16 633 627 219 (‘Bobble’, ‘we’, ‘our’ or ‘us’),
collects, holds, uses, discloses and otherwise processes personal
information in connection with the Bobble mobile application, our
website and the related products and services we provide (‘Services’).
This Privacy Policy applies when you create or use a Bobble account,
access or use the Services, visit our website, communicate with us or
otherwise provide personal information to us.
Bobble is an AI-powered voice transcription and personal organisation
application. The Services may allow you to record voice notes, create
transcripts and generate summaries, tasks, reminders, goals and other
outputs. Because voice recordings and transcripts may contain
personal information about you or other people, you should read this
Privacy Policy carefully before using the Services.
For the purposes of applicable privacy and data protection laws, we are
generally responsible for determining how and why personal
information collected through the Services is processed. In some
circumstances, another organisation may be responsible for
information that it directs you to provide or process through the
Services.
We take our privacy obligations seriously and are committed to
handling personal information lawfully, fairly and transparently and
taking reasonable steps to protect it from misuse, interference, loss
and unauthorised access, modification or disclosure.
Personal information means information or an opinion about an
identified individual or an individual who is reasonably identifiable.
Where applicable law uses terms such as ‘personal data’, ‘processing’,
‘controller’ or ‘data subject’, those terms have the meanings given
under that law.


This Privacy Policy should be read together with our Terms and
Conditions and any additional privacy notice or consent request
presented to you when we collect or use personal information for a
particular purpose.
You can contact us using the details in the Contact Us section if you
have any questions, concerns or complaints about this Privacy Policy
or how we handle personal information.
2 DEFINED TERMS
(a) Capitalised terms used but not defined in this Privacy
Policy have the meanings given to them in our Terms and
Conditions.
(b) In this Privacy Policy, De-identified Data means
information that no longer identifies an individual and is not
reasonably capable of being used, alone or together with other
information reasonably available to us, to re-identify an
individual.
3 APPLICABLE PRIVACY LAWS
(a) We handle personal information in accordance with the
privacy and data protection laws that apply to us and our
processing activities, which may include:
(i) the Privacy Act 1988 (Cth) and the Australian
Privacy Principles;
(ii) Regulation (EU) 2016/679 (General Data
Protection Regulation) and applicable data protection
laws of the European Economic Area, where we offer
the Services to individuals in those jurisdictions or
monitor their behaviour;
(iii) the United Kingdom General Data Protection
Regulation and the Data Protection Act 2018, where
applicable; and
(iv) other privacy, data protection, electronic
communications and direct marketing laws that apply in
the countries where we make the Services available.
(b) The application of a particular law may depend on
factors including your location, the location in which personal
information is processed and the nature of our activities.


(c) We aim to adopt privacy and security practices that are
proportionate to the nature and sensitivity of the personal
information we handle.
(d) We may consider recognised security frameworks and
guidance, including guidance published by the Australian
Signals Directorate, when developing our security practices.
This does not mean that we are certified, accredited or fully
compliant with any particular security standard unless we
expressly state otherwise.
(e) Nothing in this Privacy Policy represents that we hold
any SOC, ISO 27001, IRAP or other certification or accreditation
unless that certification or accreditation has been
independently obtained and remains current.
4 TYPES OF PERSONAL INFORMATION WE COLLECT
(a) The types of personal information we collect depend on
how you interact with the Services and may include:
(i) your name, date of birth, age and account
identifiers;
(ii) your email address, telephone number,
country, time zone and other contact details;
(iii) your login credentials and information used to
create, authenticate and secure your Account;
(iv) voice recordings you create or upload through
the App;
(v) transcripts generated from voice recordings;
(vi) summaries, tasks, reminders, goals, dates,
notes, instructions and other content generated from or
added to your User Data;
(vii) information contained in your voice
recordings, transcripts and other User Data, which may
include personal information about you or another
person;
(viii) information accessed as needed through
connected services, including Google Calendar, solely
to provide a requested integration; Bobble does not
store a persistent copy of your calendar;


(ix) subscription, transaction and billing
information, including your selected Plan, payment
status, purchase history and payment provider details;
(x) limited payment information received from
Apple, Google or another payment provider; Bobble
does not receive or store full payment card details,
including any full primary account number (PAN),
because payment card details are processed directly by
the payment provider;
(xi) information about your device and use of the
Services, including device identifiers, device type,
operating system, browser type, IP address, language,
time zone, app version, crash data, diagnostic data,
access times and activity logs;
(xii) information about how you interact with the
App, website, available features, notifications and
communications; Bobble does not currently implement
advertising or advertising analytics;
(xiii) advertising identifiers, advertising interactions,
inferred interests and related information only if Bobble
implements advertising or advertising analytics in the
future and provides any notice and obtains any consent
required by applicable law;
(xiv) approximate location information derived from
your IP address, device settings or country selection;
(xv) information you provide when you contact us,
request support, respond to a survey, enter a
promotion, make a complaint or otherwise communicate
with us;
(xvi) feedback, ratings, reviews and suggestions
you provide about the Services;
(xvii) information received from app stores,
payment providers, analytics providers, advertising
partners, connected services and other third parties;
(xviii) information about another person that
you provide through the Services; and
(xix) any other personal information you choose to
provide to us or that we are required or permitted to
collect by law.


(b) Voice recordings and transcripts may reveal sensitive or
special category information, including information about
health, disability, racial or ethnic origin, religious or
philosophical beliefs, political opinions, trade union
membership, sexual orientation or other private matters.
(c) We do not require you to provide sensitive or special
category information to use the Services. You should avoid
recording or uploading that information unless it is necessary
for your use of the Services and you have any consent or other
lawful authority required to do so.
(d) Where applicable law requires explicit consent or
another specific legal basis to process sensitive or special
category information, we will seek that consent or rely on
another available legal basis before carrying out the relevant
processing.
(e) We may also collect information that does not identify
you, including aggregated, statistical or de-identified
information. Information will only be treated as de-identified
where it is not reasonably capable of being used to identify or
re-identify you.
5 PERSONAL INFORMATION OF MINORS
(a) The Services are not intended for individuals under 16
years of age, and individuals under 16 must not create an
Account or use the Services.
(b) If you are between 16 and 18 years of age, you must
have permission from your parent or legal guardian to create an
Account and use the Services, as required by our Terms and
Conditions.
(c) We do not knowingly collect personal information
directly from individuals under 16. If we become aware that we
have collected personal information from an individual under 16
without valid consent or other lawful authority, we will take
reasonable steps to delete or de-identify that information.
(d) A parent or legal guardian who believes that an
individual under 16 has provided personal information to us
may contact us using the details in the Contact Us section to
request that we:
(i) confirm whether we hold the individual’s
personal information;


(ii) provide access to or correct that information;
or
(iii) delete the information, subject to any legal
basis or obligation that permits or requires us to retain
it.
(e) Voice recordings, transcripts and other User Data may
contain personal information about minors who do not hold an
Account. A user who records, uploads or otherwise provides
that information is responsible for obtaining any consent or
other lawful authority required to collect and provide it to us.
(f) We may take reasonable steps to verify a user’s age or
the identity and authority of a parent or legal guardian where
necessary to protect a minor, respond to a request or comply
with applicable law.
(g) Where applicable privacy or data protection law provides
additional protections for minors or requires parental or
guardian consent for particular processing activities, we will
apply those protections and obtain the required consent before
carrying out that processing.
6 HOW WE COLLECT PERSONAL INFORMATION
(a) We may collect personal information directly from you
when you:
(i) create or update an Account;
(ii) provide your name, date of birth, email
address, telephone number, country, time zone or other
account information;
(iii) record, upload, edit, organise, export, share or
delete voice recordings, transcripts, summaries, tasks,
reminders, goals or other User Data;
(iv) purchase, renew, change or cancel a Paid
Subscription;
(v) connect the App with Google Calendar or
another supported third-party service, in which case
calendar information is accessed only as needed to
provide the requested functionality and no persistent
copy of your calendar is retained by Bobble;
(vi) contact us, request support, make a complaint
or otherwise communicate with us;


(vii) respond to a survey, promotion or request for
feedback; or
(viii) otherwise provide personal information
through the App, our website or related Services.
(b) We may collect personal information automatically when
you access or use the App or website, including through:
(i) device permissions that you enable, such as
microphone, notification or calendar permissions;
(ii) cookies, software development kits, local
storage and similar technologies that are currently
implemented to operate the Services; pixels and other
analytics or advertising technologies are not currently
implemented;
(iii) server logs, diagnostic tools and security
systems; Bobble does not currently use third-party
analytics tools;
(iv) advertising technologies and identifiers only if
advertising is implemented in the future, after any notice
and consent required by applicable law; and
(v) information generated through your
interactions with the App, website, advertisements,
notifications and other features.
(c) The App collects a voice recording only when you
activate the relevant recording function and grant any device
permission required for that function. Voice recordings are sent
to AssemblyAI for transcription, and the resulting transcripts or
related content are sent to OpenAI for artificial intelligence
processing and generation of summaries, tasks, reminders,
goals and other requested outputs; voice recordings and other
service data are also stored and processed through Bobble’s
United States-hosted infrastructure as described in this Privacy
Policy.
(d) We may collect personal information from third parties,
including:
(i) Apple and Google, including information about
app downloads, subscriptions, transactions, refunds
and account status;
(ii) payment providers, including information
about payment status and transactions;


(iii) Amazon Web Services in a United States
region, including Amazon S3 for audio-file storage, and
MongoDB hosted in the United States for database
storage;
(iv) AssemblyAI, which receives voice recordings
for transcription, and OpenAI, which receives
transcripts or related content for artificial intelligence
processing;
(v) Google Calendar and other supported services
that you choose to connect with the App; calendar
information is accessed only as needed to provide
requested functionality, and Bobble does not retain a
persistent copy of your calendar;
(vi) analytics and advertising providers;
(vii) a parent or legal guardian who provides
information or consent concerning a user under 18;
(viii) other users who record, upload, share or
otherwise provide information about you through the
Services; and
(ix) publicly available sources or other third parties
where collection is authorised or required by law.
(e) Where you connect a third-party service with the App, we
may collect information from that service in accordance with
the permissions you grant and the settings of your third-party
account.
(f) The App and website may use cookies and similar
technologies that are currently implemented to operate the
Services, remember preferences, maintain security and
diagnose errors; analytics and advertising technologies are not
currently implemented and will not be used unless this Privacy
Policy is updated and any notice or consent required by
applicable law is provided or obtained.
(g) You may be able to control cookies through your
browser settings and mobile permissions through your device
settings. Disabling a cookie, permission or similar technology
may prevent some features of the Services from operating
properly.
(h) Where required by applicable law, we will obtain your
consent before using non-essential cookies, advertising
technologies or similar tracking tools.


(i) If another person provides personal information about
you through the Services, we may collect that information
without receiving it directly from you. Users are responsible for
ensuring that they have any consent or other lawful authority
required to provide another person’s information to us.
7 USE OF YOUR PERSONAL INFORMATION
We may collect, use and otherwise process personal information for
the following purposes:
providing, operating, maintaining and supporting the App, website and
Services;
(a) creating, administering, authenticating and securing
Accounts;
(b) recording and processing voice notes at your
request;
(c) generating transcripts, summaries, tasks, reminders,
goals and other outputs using transcription, automated and
artificial intelligence technologies;
(d) allowing you to review, edit, organise, export, delete
and share User Data;
(e) providing features currently available under your
Plan; advertising-supported features are not currently
implemented;
(f) processing subscriptions, payments, renewals,
cancellations and refunds;
(g) enabling integrations that you choose to connect,
including Google Calendar and social media platforms;
(h) sending service messages, reminders, notifications,
security alerts, account communications and other information
relating to the Services;
(i) responding to enquiries, support requests,
complaints and feedback;
(j) monitoring, analysing, testing and improving the
performance, reliability, security and functionality of the
Services;
(k) developing new products, services, features,
transcription systems, algorithms and artificial intelligence
technologies;


(l) detecting, preventing and investigating fraud,
misuse, unlawful activity, security incidents and breaches of
our Terms and Conditions;
(m) maintaining records, administering our business and
managing our relationships with users, service providers and
other third parties;
(n) complying with legal and regulatory obligations,
responding to lawful requests and establishing, exercising or
defending legal claims;
(o) enforcing our Terms and Conditions and protecting
our rights, property, systems, users and other persons;
(p) supporting a proposed or completed financing,
investment, merger, acquisition, corporate restructure or sale of
all or part of our business or assets; and
(q) carrying out any other purpose disclosed to you at
the time of collection or for which you provide consent.
7.2 LEGAL BASES FOR PROCESSING
(a) Where the General Data Protection Regulation, United
Kingdom General Data Protection Regulation or another law
requiring a legal basis applies, we process personal information
on one or more of the following bases:
(i) performance of a contract, where processing is
necessary to provide the App and Services you request,
administer your Account or Paid Subscription, process
your instructions or provide support;
(ii) consent, where you have freely given specific
and informed consent to particular processing,
including where required for sensitive information,
personalised advertising, non-essential tracking
technologies or the use of identifiable User Data for
artificial intelligence training;
(iii) legitimate interests, where processing is
necessary for our legitimate interests or those of
another person and those interests are not overridden
by your rights and interests, including securing and
improving the Services, preventing fraud,
understanding App performance and administering our
business;


(iv) compliance with legal obligations, where
processing is necessary to comply with applicable law,
lawful regulatory requirements, court orders or legal
processes; and
(v) protection of vital interests, where processing
is necessary to protect the life or physical safety of an
individual.
(b) Where we rely on legitimate interests, those interests
may include:
(i) providing, maintaining and securing the
Services;
(ii) detecting and preventing fraud, misuse and
security incidents;
(iii) understanding and improving the performance
and functionality of the Services;
(iv) responding to enquiries and enforcing our
legal rights; and
(v) administering and developing our business.
(c) We will not rely on legitimate interests where your rights
and interests override those interests.
(d) Where we rely on consent, you may withdraw that
consent at any time. Withdrawal does not affect processing that
occurred lawfully before consent was withdrawn.
7.3 AI TRAINING AND SERVICE IMPROVEMENT
(a) We may analyse usage information and De-identified
Data to test, evaluate, develop and improve the App,
transcription systems, artificial intelligence systems,
algorithms, models, features and Services.
(b) We will not use identifiable voice recordings, transcripts
or other identifiable User Data to train general-purpose artificial
intelligence models unless:
(i) we have clearly informed you of the proposed
use;
(ii) we have a valid legal basis for that use;
(iii) we have obtained your express consent where
required by applicable law; and


(iv) you have been provided with any withdrawal or
opt-out right required by applicable law.
(c) Where you provide consent, you may withdraw it through
[insert method] or by contacting us using the details in the
Contact Us section.
(d) Withdrawal of consent will not affect processing that
occurred lawfully before withdrawal. It may not require us to
remove information that was previously and irreversibly
de-identified or incorporated into aggregated statistical
information that is no longer reasonably capable of identifying
you.
(e) Our service providers may process User Data to provide
transcription, artificial intelligence and related functionality to
us. We will configure the Services and contractually require
those providers not to use identifiable User Data for their own
purposes except as necessary to provide services to us or as
required by applicable law.
7.4 ADVERTISING
(a) If you use the Free Plan, we may use personal
information to select, deliver, measure and improve advertising
displayed through the App or related Services.
(b) Depending on your location and settings, this may
include the use of device information, advertising identifiers,
approximate location, App activity, advertising interactions and
inferred interests.
(c) Where required by applicable law, we will obtain your
consent before using personal information for personalised
advertising or sharing information with advertising partners for
that purpose.
(d) You may be able to manage advertising preferences
through the App, your device settings or any consent
management tool we make available.
7.5 MARKETING COMMUNICATIONS
(a) We may use your contact details to send you information
about our products, services, promotions and updates where
permitted by applicable law.
(b) Where consent is required, we will send direct marketing
communications only with your consent.


(c) You may opt out of marketing communications at any
time by using the unsubscribe facility in the communication or
contacting us using the details in the Contact Us section.
(d) Opting out of marketing communications does not
prevent us from sending service-related, security, transaction
or account communications.
7.6 DISCLOSURE TO SERVICE PROVIDERS
(a) We may disclose personal information to our Personnel,
contractors, professional advisers and service providers where
reasonably necessary for the purposes described in this
Privacy Policy.
(b) These recipients may provide services including:
(i) cloud hosting and data storage;
(ii) voice transcription, artificial intelligence and
language processing;
(iii) payment processing and subscription
administration;
(iv) performance monitoring necessary to operate
and secure the Services; third-party analytics and
advertising services are not currently implemented;
(v) communications, notifications and customer
support;
(vi) security, fraud prevention and identity
verification;
(vii) data backup, disaster recovery and
infrastructure auditing;
(viii) professional, legal, accounting and insurance
services; and
(ix) business administration and corporate
transaction support.
(c) We require service providers to handle personal
information only for authorised purposes and subject to
appropriate privacy, confidentiality and security obligations.
(d) Some recipients may be located outside Australia or the
country in which you are located. Further information about
overseas processing and international transfers is set out in the
International Transfers section.


8 AUTOMATED PROCESSING
(a) We use automated systems and artificial intelligence
technologies to:
(i) transcribe voice recordings;
(ii) generate summaries, tasks, reminders, goals
and other organisational outputs;
(iii) monitor the performance, security and
functionality of the Services using currently
implemented operational tools, but not third-party
analytics tools;
(iv) detect fraud, misuse and security risks; and
(v) select or measure advertising only if Bobble
implements advertising in the future and provides any
notice and obtains any consent required by applicable
law.
(b) These automated processes are intended to support the
operation and personal organisation features of the Services.
We do not currently use personal information to make decisions
based solely on automated processing that produce legal
effects or similarly significantly affect your rights or interests.
(c) You should review and verify transcripts, summaries,
tasks, reminders, goals and other automated outputs before
relying on or acting on them, particularly where an output may
affect health, safety, legal rights or financial interests.
(d) If we introduce automated decision-making that
produces legal effects or similarly significantly affects you, we
will provide any notice, explanation, consent mechanism, right
to object and human review required by applicable law.
9 SECURITY
(a) We take reasonable technical, organisational and
administrative measures designed to protect personal
information against misuse, interference, loss and unauthorised
access, modification or disclosure.
(b) These measures may include:
(i) access controls and authentication measures;
(ii) encryption at rest where implemented;
although some connections use encryption in transit,
limited production API endpoints currently use HTTP


and therefore are not encrypted in transit, and Bobble
intends to migrate those endpoints to TLS;
(iii) secure cloud hosting and infrastructure;
(iv) system monitoring, logging and vulnerability
management;
(v) backup, recovery and incident response
processes;
(vi) role-based limits on Personnel and service
provider access to personal information; Bobble does
not provide staff with a general administrative interface
to browse user recordings, transcripts or AI-generated
content, and any limited operational access is restricted
to authorised Personnel who need it for support,
security, incident response or legal compliance and is
subject to authentication and logging where
implemented; and
(vii) confidentiality, privacy and security obligations
for Personnel and service providers.
(c) We may use third-party hosting, transcription, artificial
intelligence, payment, analytics, advertising and other service
providers to process personal information on our behalf. We
take reasonable steps to select reputable providers and require
them to implement appropriate safeguards.
(d) No method of electronic transmission, storage or
processing is completely secure. We cannot guarantee that
personal information will never be lost, accessed, used,
modified, disclosed or destroyed without authorisation.
(e) You are responsible for:
(i) keeping your Account credentials confidential
and secure;
(ii) using a strong and unique password;
(iii) protecting the security of your device and
connected accounts;
(iv) installing available App and operating system
updates; and
(v) notifying us promptly if you suspect
unauthorised access to your Account or any other
security incident.


(f) If we become aware of a data breach affecting personal
information, we will assess and respond to the incident and
notify affected individuals and relevant regulators where
required by applicable law.
10 LINKS AND THIRD-PARTY SERVICES
(a) The App, website and Services may contain links to,
integrate with or allow you to access third-party websites,
applications, platforms and services.
(b) Those third parties operate independently from us and
may collect, use, disclose and retain personal information
under their own privacy policies and terms.
(c) We do not control the privacy, security, content,
availability or practices of independent third-party websites,
applications, platforms or services and, to the extent permitted
by law, are not responsible for their acts or omissions; however,
this does not exclude responsibility for our own acts or
omissions in selecting, integrating with or disclosing personal
information to a third party.
(d) Before using a third-party service or providing personal
information to it, you should review its privacy policy, terms and
settings.
(e) Where you choose to connect the App with a third-party
service, information transferred to that service will be handled
by the third party in accordance with its own privacy practices.
11 DATA RETENTION
(a) We retain personal information only for as long as
reasonably necessary for the purposes for which it was
collected, to provide the Services, comply with legal
obligations, resolve disputes, prevent fraud and security
incidents, and establish, exercise or defend legal claims.
(b) Subject to any legal requirement or exception:
(i) original voice recordings are currently retained
in Amazon S3 after Account termination and are not
deleted under Bobble’s current automated
Account-deletion process; Bobble will update this
Privacy Policy when a defined audio deletion event or
retention period is implemented, and recordings may


also be retained where required or permitted by
applicable law;
(ii) Account records and database records,
including transcripts, summaries, tasks, reminders,
goals and other database-stored User Data, will be
deleted when your Account is terminated or when
deletion otherwise occurs as stated in this Privacy
Policy, subject to legal retention requirements and the
separate treatment of original voice recordings stored in
Amazon S3;
(iii) if you request deletion of your Account, we will
delete or de-identify identifiable Account records and
database records from active database systems within
30 days, but original voice recordings currently remain
retained in Amazon S3 as disclosed above;
(iv) information contained in backups may remain
for a limited period until the relevant backup is
overwritten or securely deleted in accordance with our
backup cycle;
(v) transaction, subscription, tax and accounting
records may be retained for the period required by
applicable law;
(vi) complaint, security and legal records may be
retained for as long as reasonably necessary to
investigate the matter, protect individuals, comply with
law or establish, exercise or defend legal claims; and
(vii) De-identified Data may be retained indefinitely
where it is not reasonably capable of identifying or
re-identifying an individual.
(c) The precise retention period may depend on:
(i) the nature and sensitivity of the information;
(ii) the purpose for which it was collected;
(iii) whether the information remains necessary to
provide the Services;
(iv) the risks associated with continued retention;
(v) our legal, accounting and regulatory
obligations; and
(vi) whether the information is required to resolve
a dispute or establish, exercise or defend a legal claim.


12 ACCESS, CORRECTION AND YOUR PRIVACY RIGHTS
(a) You may contact us using the details in the Contact Us
section to request access to, correction of or deletion of
personal information we hold about you.
(b) You may also be able to access, update, export or delete
certain personal information and User Data directly through
your Account or the App.
(c) Before responding to a request, we may ask you to
provide information reasonably necessary to verify your
identity and authority to make the request.
(d) We will respond to privacy requests within the period
required by applicable law or, where no specific period applies,
within a reasonable time.
(e) We may charge a reasonable fee only where permitted by
applicable law, including where a request is manifestly
unfounded or excessive, and only after informing you of the fee
and the basis on which it was calculated. We will not charge a
fee merely for making a request where applicable law prohibits
us from doing so.
(f) We may refuse or limit a request where permitted or
required by applicable law, including where:
(i) we cannot reasonably verify your identity or
authority;
(ii) providing access would unreasonably affect
another person’s privacy or rights;
(iii) the information is subject to legal privilege or
confidentiality obligations;
(iv) the request is frivolous, vexatious, manifestly
unfounded or excessive;
(v) we are required or permitted to retain the
information;
(vi) responding would prejudice an investigation,
legal proceeding, enforcement activity or security
measure; or
(vii) another legal exception applies.
(g) If we refuse or limit a request, we will explain the
reasons where required by applicable law and provide
information about available complaint or review rights.


(h) If personal information we hold about you is inaccurate,
incomplete, out of date, irrelevant or misleading, you may ask
us to correct it. We will take reasonable steps to correct the
information where required by applicable law.
(i) Depending on the law that applies to you, you may also
have rights to:
(i) receive a copy of your personal information;
(ii) request deletion or erasure of personal
information;
(iii) restrict or object to particular processing
activities;
(iv) withdraw consent where processing is based
on consent;
(v) object to direct marketing;
(vi) request transfer of personal information in a
structured, commonly used and machine-readable
format;
(vii) request that personal information be
transferred to another organisation where technically
feasible;
(viii) object to processing based on our legitimate
interests;
(ix) request human review of a decision based
solely on automated processing that produces legal or
similarly significant effects; and
(x) make a complaint to a privacy or data
protection regulator.
(j) These rights are subject to applicable legal conditions,
limitations and exceptions.
(k) Withdrawing consent does not affect processing that
was lawful before the withdrawal and may affect our ability to
provide some features of the Services.
(l) A request to delete your Account or personal information
does not automatically cancel a Paid Subscription managed
through the Apple App Store, Google Play Store or another
payment provider.
(m) We may retain information after receiving a deletion
request where retention is required or permitted by law,


reasonably necessary to establish, exercise or defend legal
claims, required for fraud prevention or security, or necessary
to complete deletion from backups and disaster recovery
systems.
(n) We may retain aggregated or De-identified Data that is
not reasonably capable of identifying you.
13 CHANGE OF CONTROL
(a) If we are involved in a proposed or completed merger,
acquisition, financing, corporate restructure, insolvency,
change of control or sale or transfer of all or part of our
business or assets, we may disclose or transfer personal
information, User Data and De-identified Data to:
(i) prospective or actual purchasers, investors,
financiers, advisers and their representatives;
(ii) a related body corporate;
(iii) a successor entity; or
(iv) another person that acquires or operates the
App, Services or relevant business assets.
(b) Before completing a transaction, we will take reasonable
steps to ensure that any recipient:
(i) receives personal information only to the
extent reasonably necessary to assess, negotiate,
complete or implement the transaction;
(ii) is subject to appropriate confidentiality,
privacy and security obligations; and
(iii) handles personal information in accordance
with applicable privacy and data protection laws.
(c) If responsibility for your personal information transfers
to another entity, we or the new entity will provide any notice
required by applicable law and explain any material change to
how your personal information will be handled.
(d) Where required by applicable law, we will provide you
with any available right to object, withdraw consent or request
deletion before personal information is used for a materially
different purpose.
(e) A transfer under this section does not permit identifiable
personal information to be sold or used for unrelated purposes


without a lawful basis and any consent required by applicable
law.
(f) We do not sell identifiable voice recordings, transcripts,
Account information or user profiles as a standalone
commercial database.
(g) We may use, disclose, license or commercialise
De-identified Data where it is not reasonably capable of
identifying or re-identifying an individual.
14 INTERNATIONAL TRANSFERS
(a) We are based in Australia, but our primary cloud storage
and processing occurs in the United States through Amazon
Web Services in a United States region, Amazon S3 and
MongoDB hosted in the United States, and personal information
is also processed by AssemblyAI and OpenAI as described in
this Privacy Policy.
(b) Based on our current service-provider arrangements,
overseas recipients are likely to be located in:
(i) the United States of America;
(ii) the European Union and European Economic
Area, including Austria, Belgium, Bulgaria, Croatia,
Cyprus, Czechia, Denmark, Estonia, Finland, France,
Germany, Greece, Hungary, Ireland, Italy, Latvia,
Lithuania, Luxembourg, Malta, the Netherlands, Poland,
Portugal, Romania, Slovakia, Slovenia, Spain, Sweden,
Iceland, Liechtenstein and Norway;
(iii) AssemblyAI receives voice recordings for
transcription and OpenAI receives transcripts or related
content for artificial intelligence processing; those
providers and their subprocessors may process
personal information in the United States and other
locations disclosed in their applicable subprocessors
documentation.
(c) We will update this list if our material overseas
processing arrangements change.
(d) Personal information may be transferred outside the
country in which you are located, including through our use of
cloud hosting, transcription, artificial intelligence, analytics,
advertising, payment, communications, security and support
providers.


(e) The countries in which personal information may be
processed may have privacy and data protection laws that differ
from those in your country.
(f) Where the General Data Protection Regulation applies
and personal information is transferred outside the European
Economic Area to a recipient that is not covered by an
adequacy decision, we will use an approved transfer
mechanism where required, which may include:
(i) the standard contractual clauses approved by
the European Commission;
(ii) binding corporate rules;
(iii) an approved certification mechanism or code
of conduct together with binding commitments;
(iv) a permitted derogation for a specific situation;
or
(v) another lawful transfer mechanism available
under applicable data protection law.
(g) Where required, we will assess whether the laws and
practices of the recipient country may affect the effectiveness
of the transfer safeguards and implement supplementary
technical, contractual or organisational measures where
appropriate.
(h) Where United Kingdom data protection law applies, we
will use a lawful transfer mechanism recognised under that law,
which may include the United Kingdom International Data
Transfer Agreement or the United Kingdom Addendum to the
European Commission’s standard contractual clauses.
(i) You may contact us using the details in the Contact Us
section to request further information about the safeguards
used for an international transfer of your personal information.
(j) If Article 27 of the General Data Protection Regulation
requires us to appoint a representative in the European Union,
we will make the representative’s name and contact details
available below before offering the Services in circumstances
that trigger that requirement:
(i) European Union representative: To be
appointed if required under Article 27 of the GDPR
before the Services are offered in circumstances that
trigger that requirement


(ii) Address: To be published.
(iii) Email: To be published.
(k) If an equivalent representative requirement applies under
United Kingdom data protection law, we will also publish the
name and contact details of our United Kingdom representative.
15 COMPLAINTS
(a) If you have a question or complaint about this Privacy
Policy or how we handle personal information, please contact
us using the details in the Contact Us section.
(b) Your complaint should include sufficient information to
allow us to understand and investigate the matter, including:
(i) your name and contact details;
(ii) a description of the privacy issue;
(iii) any relevant dates, communications or
supporting information; and
(iv) the outcome you are seeking.
(c) We may ask you to provide additional information or
verify your identity before investigating the complaint.
(d) We will acknowledge and investigate your complaint and
respond within the period required by applicable law or, where
no specific period applies, within a reasonable time.
(e) We will explain the outcome of our investigation and any
steps we propose to take, where appropriate.
(f) If you are not satisfied with our response, you may have
the right to make a complaint to a privacy or data protection
regulator, including:
(i) the Office of the Australian Information
Commissioner, if the Privacy Act 1988 (Cth) applies;
(ii) the supervisory authority in the European
Economic Area country in which you live, work or
consider that an infringement occurred, if the General
Data Protection Regulation applies;
(iii) the Information Commissioner’s Office, if
United Kingdom data protection law applies; or
(iv) another privacy or data protection regulator
with jurisdiction over the matter.


(g) You may contact a regulator before completing our
internal complaints process where applicable law permits you
to do so.
16 CONTACT US
For further information about this Privacy Policy or our privacy
practices, or to exercise a privacy right, request access to or correction
of personal information, or make a complaint, please contact us using
the following details:
Email: privacy@bobble.au
Website: www.bobble.au
Privacy contact: To be published.
Postal address: To be published.
We may need to verify your identity or authority before responding to a
request.
Providing personal information to us does not by itself constitute
consent to every use described in this Privacy Policy. Where consent is
required by applicable law, we will request it separately and explain the
relevant purpose.
We may update this Privacy Policy from time to time to reflect changes
to the Services, our practices, technology, legal requirements or other
relevant circumstances.
The updated Privacy Policy will be made available through the App or
on our website and will state the date on which it was last updated.
Where a change materially affects how we handle personal information,
we will take reasonable steps to notify you before the change takes
effect and obtain any consent required by applicable law.
Your continued use of the Services after an updated Privacy Policy
takes effect does not override any privacy right or consent requirement
that applies under law.