Privacy Notice — Metabole Labs
DRAFT FOR LEGAL REVIEW · not legal advice
Read this first. This is a working draft prepared to accelerate legal review — it is not legal advice and must be reviewed and finalised by a qualified privacy lawyer before publication. Metabole Labs will be an Australian-incorporated entity offering services to individuals in Australia, the United Kingdom, the European Union / EEA and the United States, so the notice is written to address the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs), the EU GDPR, the UK GDPR + Data Protection Act 2018, and applicable US state privacy laws (led by the California CCPA/CPRA).
Items you (or your lawyer) must confirm before publishing are marked inline as
» CONFIRM:and collected in the checklist at the very end. Nothing factual about your business (addresses, entity numbers, third-party processors, retention periods) should be published until verified — do not rely on the placeholder values.
Effective date: [DATE] · Last updated: [DATE]
1. About this notice and who we are
Metabole Labs ("Metabole Labs", "we", "us" or "our") respects your privacy. This Privacy Notice explains how we collect, use, disclose and protect your personal information (referred to as "personal information" under Australian law and "personal data" under the GDPR — used interchangeably here) when you visit our website, request a demo, apply for a role, contact us, or otherwise interact with us.
We are the company behind Metabole, an enterprise platform that governs how organisational change is assessed and approved against regulatory obligation.
Controller / APP entity. Metabole Labs is the entity responsible for the personal information described in this notice.
- Legal entity:
[Metabole Labs Pty Ltd — CONFIRM exact registered name] [ACN / ABN — CONFIRM]- Registered address:
[AUSTRALIAN REGISTERED ADDRESS — CONFIRM] - Privacy contact:
privacy@metabolelabs.com» CONFIRM this inbox exists and is monitored
» CONFIRM:whether you will appoint a Privacy Officer (recommended under the APPs) and/or a Data Protection Officer (only required under GDPR in specific cases; usually not mandatory for a company of your size, but you may appoint one voluntarily). Name them here if so.
Controller vs processor — an important distinction. This notice covers personal information for which Metabole Labs is the controller — principally data from our website, marketing, sales enquiries and recruitment. When our customers use the Metabole platform, any personal information they put into the product is controlled by them; for that data we act as a processor on the customer's instructions, and our handling of it is governed by our customer agreement and data processing terms, not by this notice. If you are an individual whose data appears in a customer's use of Metabole, please contact that customer (the controller) to exercise your rights.
EU and UK Representatives (Article 27)
Because Metabole Labs is established in Australia and offers services to individuals in the EU/EEA and the UK, we have appointed representatives under Article 27 of the EU GDPR and the UK GDPR. You may contact them on data protection matters:
- EU/EEA Representative:
[NAME, EU ADDRESS, EMAIL — TO BE APPOINTED] - UK Representative:
[NAME, UK ADDRESS, EMAIL — TO BE APPOINTED]
» ACTION:These representatives are a legal requirement for a non-EU/non-UK entity targeting EU/UK residents. Appointment is inexpensive (specialist providers offer combined EU+UK packages) and must be in place before you actively market to those regions. Do not publish this section with placeholders — either appoint them or remove the claim until you have.
2. Scope of this notice
This notice applies to personal information we collect through:
- our website and any subdomains;
- demo requests, contact forms and expressions of interest;
- careers / job applications, including any CV or supporting documents you submit;
- marketing and events (e.g. webinars, newsletters);
- correspondence with us by email, phone or otherwise.
It does not apply to third-party websites we link to, or (as noted above) to personal information processed within the Metabole product on behalf of our customers.
3. The personal information we collect
Depending on how you interact with us, we may collect the following categories:
- Identity and contact data — name, work email address, phone number, employer / organisation, job title or role.
- Enquiry and demo data — the content of your request, the change or use-case you describe, and any information you choose to include.
- Recruitment data — for applicants: your CV/resume, cover note, work history, qualifications, and any other information you submit or that is contained in your application.
» CONFIRM:whether you collect anything further in a later interview stage. - Marketing preferences — your subscription and communication preferences.
- Technical and usage data — IP address, approximate location derived from IP, browser and device type, referring site, and pages viewed, collected via cookies and similar technologies (see section 8).
- Correspondence — records of your communications with us.
We do not intentionally collect sensitive information / special category data (such as health, racial or ethnic origin, political or religious beliefs, biometric data) through our website or standard forms, and we ask that you do not submit it. » CONFIRM: if any recruitment step could involve sensitive information (e.g. diversity monitoring, right-to-work documents), disclose it here and identify the lawful basis / consent.
4. How we collect personal information
- Directly from you — when you complete a form (demo request, contact, expression of interest, job application), subscribe to communications, register for an event, or correspond with us.
- Automatically — as you use our website, via cookies and similar technologies (section 8).
- From third parties / public sources —
» CONFIRM:state honestly whether you obtain business contact data from any third-party sources (e.g. LinkedIn, enrichment providers, referrals). If you do not, say so plainly (this is a credibility point — do not claim practices you don't follow, and do not omit ones you do).
Under APP 3 / APP 5, we collect personal information only where reasonably necessary for our functions and activities, and we notify you (through this notice) at or before the time of collection.
5. Why we use your personal information, and our legal bases
We use personal information for the purposes below. For individuals in the EU/EEA and UK, the GDPR requires a lawful basis for each purpose; the relevant basis is shown alongside.
| Purpose | Personal information used | GDPR lawful basis |
|---|---|---|
| Respond to demo requests, enquiries and expressions of interest | Identity, contact, enquiry data | Steps at your request prior to entering a contract; legitimate interests (responding to and developing business relationships) |
| Provide, operate and improve our website | Technical and usage data | Legitimate interests (running and securing our site); consent for non-essential cookies |
| Assess and manage job applications | Recruitment data | Steps prior to a possible employment contract; legitimate interests (evaluating candidates); consent where required |
| Send marketing communications you have not opted out of, and measure their effectiveness | Contact data, marketing preferences | Consent, or legitimate interests where permitted, always with an opt-out |
| Communicate with you and provide support | Identity, contact, correspondence | Legitimate interests; performance of a contract |
| Protect the security of our systems and prevent fraud or misuse | Technical data, correspondence | Legitimate interests; legal obligation |
| Comply with legal, regulatory, tax and accounting obligations | As required | Legal obligation |
Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may object to processing based on legitimate interests (see section 13).
6. Automated decision-making, profiling and AI
» CONFIRM the accuracy of this section — it carries specific legal weight.
Metabole Labs does not make decisions that produce legal or similarly significant effects about you based solely on automated processing, on our website or in our recruitment process. Applications and enquiries are reviewed by a person before any decision that materially affects you.
Our product includes an AI copilot (Kai) that drafts, surfaces and flags information to assist users — but within the product, Kai does not make governance decisions; a human always decides, and Kai's involvement is logged. Personal information processed by the product is handled on behalf of our customers as described in section 1.
» CONFIRM:If, in future, you introduce any automated scoring, ranking or filtering of job applicants (e.g. an applicant-tracking system that scores CVs) or any automated decision with significant effect, this section must be updated. Note in particular:
- Australia: from 10 December 2026, APP entities must disclose in their privacy policy where personal information is used in automated decisions that significantly affect individuals — build this in ahead of time.
- EU/UK GDPR (Art. 22): individuals have rights concerning solely automated decisions with legal/significant effect, including a right to human intervention.
- US (e.g. California): new rules address automated decision-making technology (ADMT); confirm applicability with counsel if you adopt such tools.
7. [reserved]
*(Numbering kept stable for legal review; merge as preferred.)*
8. Cookies, analytics and tracking technologies
We use cookies and similar technologies to operate our website, remember your preferences, and understand how the site is used. » CONFIRM the specifics of what you actually deploy.
- Strictly necessary cookies — required for the site to function; these do not require consent.
- Analytics cookies —
» CONFIRM:e.g. Google Analytics or a privacy-focused alternative — help us measure and improve the site. In the EU/UK these require your consent before they are set. - Marketing cookies —
» CONFIRM:only if you run advertising/retargeting; require consent.
» ACTION:If you use any non-essential cookies (most analytics do), EU/UK law requires a cookie consent banner with genuine opt-in before those cookies load, and this notice should link to a separate Cookie Policy. Several US state laws also require honouring the Global Privacy Control (GPC) browser signal as a universal opt-out. Confirm your cookie set and implement a consent tool accordingly.
You can control cookies through your browser settings and, where offered, our cookie banner.
9. When we disclose or share personal information
We do not sell your personal information. We may disclose it to:
- Service providers (processors) who help us run our business, under contracts that require them to protect it and use it only on our instructions. Categories include:
» CONFIRM your actual vendors —website hosting, form-submission handling, email delivery, analytics, cloud storage, and customer-relationship / marketing tools. - Professional advisers — lawyers, accountants, auditors and insurers, where necessary.
- Authorities and others — where required by law, to comply with legal process, or to protect our rights, users or the public.
- In a business transaction — if we reorganise, merge, or sell all or part of our business, personal information may be transferred to the successor entity, subject to this notice.
» CONFIRM:List (at least by category, ideally by name) the real processors you use — a regulator-credible notice names them rather than gesturing vaguely.
10. Overseas and international data transfers
Because we operate from Australia and use service providers in other countries, your personal information may be stored or processed outside your country of residence, including in [LIST COUNTRIES — CONFIRM, e.g. Australia, United States, EU/EEA, United Kingdom].
- Australia (APP 8): before disclosing personal information overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the APPs.
- EU/EEA and UK (GDPR): where we transfer personal data out of the EU/EEA or UK to a country without an adequacy decision, we use appropriate safeguards — such as the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement / Addendum — and carry out transfer risk assessments where required.
» CONFIRM:the countries and the transfer mechanisms you actually rely on with counsel.
11. How we protect your personal information
We use administrative, technical and organisational security measures designed to protect personal information from loss, misuse, and unauthorised access, disclosure, alteration or destruction, consistent with our legal obligations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Data breach notification. We maintain processes to detect and respond to data breaches. Where required, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals under the Notifiable Data Breaches (NDB) scheme, and the relevant EU/UK supervisory authority and individuals under the GDPR, within the timeframes the law requires.
12. How long we keep personal information
We retain personal information only for as long as necessary for the purposes we collected it for, including to satisfy any legal, regulatory, tax, accounting or reporting requirements, or to establish, exercise or defend legal claims. » CONFIRM your retention periods, for example:
- Demo / enquiry data:
[e.g. up to 24 months after last contact] - Unsuccessful job applications and CVs:
[e.g. 6–12 months, or longer with consent to keep you on file] - Marketing data: until you unsubscribe, then a suppression record only.
When no longer needed, we securely delete or de-identify personal information.
13. Your privacy rights
Your rights depend on where you live. To exercise any right, contact us at privacy@metabolelabs.com. We will verify your identity before responding, and will respond within the timeframe required by the applicable law. You will not have to pay a fee unless your request is manifestly unfounded or excessive.
Everyone / Australia (APPs). You may request access to the personal information we hold about you (APP 12) and ask us to correct it if it is inaccurate, out of date or incomplete (APP 13). You may also opt out of direct marketing at any time (APP 7).
EU/EEA and UK (GDPR). In addition, you have the right to: access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; to object to processing based on legitimate interests or to direct marketing; and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with a supervisory authority (see section 18).
United States (California and other states, where applicable). Subject to each state's applicability thresholds and exceptions, you may have the right to: know/access the personal information we collect and how we use it; delete it; correct it; opt out of any "sale" or "sharing" of personal information and of "targeted advertising"; limit the use of sensitive personal information; and not be discriminated against for exercising your rights. We do not sell or share your personal information as those terms are defined under US state privacy laws. Where required, we honour the Global Privacy Control (GPC) signal as an opt-out. You may use an authorised agent to submit a request.
» CONFIRM:with counsel whether any US state law's thresholds currently apply to you (most require a minimum number of consumers or revenue tied to data sales — a pre-launch company often falls below these). Offering the rights as a courtesy is fine; stating "we do not sell/share" must be accurate.
14. Direct marketing and opting out
If you receive marketing from us, you can opt out at any time using the unsubscribe link in any message or by contacting privacy@metabolelabs.com. We may still send you non-marketing, transactional communications (for example, about a demo you requested).
15. Children
Our website and services are intended for business users and are not directed at children. We do not knowingly collect personal information from children. » CONFIRM the age threshold with counsel — note Australia's forthcoming Children's Online Privacy Code treats individuals under 18 as children in scope for certain services, while other regimes use 13 or 16. If you become aware we hold a child's data without appropriate consent, contact us and we will delete it.
16. Third-party links
Our website may link to third-party sites we do not control. This notice does not apply to those sites, and we are not responsible for their privacy practices. Please review their privacy notices.
17. Changes to this notice
We may update this notice from time to time. We will change the "Last updated" date above and, for material changes, take additional steps as required by law. Please review it periodically.
18. How to contact us and how to complain
Contact us about this notice or to exercise your rights:
- Email:
privacy@metabolelabs.com - Post:
[REGISTERED ADDRESS — CONFIRM] - EU/UK data protection matters: contact our Article 27 representatives (section 1).
Complaints. If you are unhappy with how we have handled your personal information, please contact us first so we can try to resolve it. You also have the right to complain to a regulator:
- Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- EU/EEA: your local data protection authority (a list is maintained by the European Data Protection Board — edpb.europa.eu)
- United States: your state Attorney General, or the California Privacy Protection Agency (CPPA) for California residents, where applicable.
Pre-publication checklist (for you and your lawyer)
1. Entity details — confirm exact registered name, ACN/ABN, and Australian registered address. 2. Privacy contact — stand up and monitor privacy@metabolelabs.com (or chosen address). 3. Article 27 representatives — appoint an EU representative and a UK representative, and insert their details (legally required for targeting EU/UK residents). 4. Processors — list your real third-party service providers (hosting, form handler, email, analytics, CRM, cloud storage). 5. Cookies — confirm what you deploy; if any non-essential cookies, add a consent banner + Cookie Policy and honour GPC. 6. Retention periods — set and insert real periods, especially for CVs/applications. 7. Automated decision-making — confirm section 6 is accurate now, and revisit before adopting any CV-scoring/ATS tooling (AU rule lands 10 Dec 2026). 8. International transfers — confirm destination countries and transfer mechanisms (SCCs, UK IDTA/Addendum). 9. US applicability — confirm with counsel whether any state thresholds apply; keep the "we do not sell/share" statement accurate. 10. Companion pages — pair this with a Cookie Policy and Terms of Use; then re-add the footer legal links so they resolve. 11. Legal review — have a qualified privacy lawyer review and finalise before publishing.