Skip to content

GotDux

Privacy Policy

Effective date: 30 July 2026  ·  Last updated: 30 July 2026

1. Who we are

GotDux is a product of AMAVIS.AI PTY LTD (ABN 49 685 475 932) (“GotDux”, “we”, “us”). We build a dashboard that helps organisations understand how their staff use AI tools such as Google Gemini, and recognises high adopters through an opt-in leaderboard.

GotDux is fully cloud-based. There is nothing to install on any device; your organisation accesses GotDux through a web browser only, which means there is no local software and no local copy of your data to separately account for.

This policy is written to put your organisation’s interests first. Wherever we had a genuine choice in how a policy could be written, we have chosen the version that gives you more control, not less.

2. Our core commitment to you

Before the detail, the principles that shape everything below:

  • Your data belongs to you. The usage data GotDux processes on behalf of your organisation remains your organisation’s property at all times. We are a processor of your data, not its owner.
  • Your data is not our commodity. We do not sell, rent, or trade your data, or your staff’s data, to anyone, for any reason, ever.
  • Your data is not our product. GotDux’s business model is the subscription you pay us. It is not monetising your data or your staff’s data.
  • Our access is read-only. GotDux connects to your Google Workspace using read-only API scopes. We cannot change, delete, or send anything on your organisation’s behalf through that connection. We can only read usage statistics.
  • We do not use your data to train AI models. Your organisation’s data is used only to power your organisation’s own dashboard. It is never used to train, fine-tune, or improve any machine-learning or AI model, for GotDux or anyone else, beyond your own account’s reporting.
  • You choose where your data lives. By default we store your data in Sydney, Australia. If your organisation would prefer your data held in a different region, closer to home, you can ask us to move it (section 5).
  • Leaving is as easy as joining. You can cancel at any time, your data is deleted automatically, and we will not hold your organisation to ransom over an export before you go (section 7).

3. What we collect

3.1 From Google Workspace (via Google APIs)

The application that requests access is GotDux, operated by AMAVIS.AI PTY LTD — that is the name and logo you see on Google’s consent screen. When an administrator connects your organisation’s Google Workspace, GotDux requests only the following read-only scopes, and uses each one solely for the purpose shown next to it:

  • openid, email, profile — to identify the administrator who connects the account and to keep them signed in to GotDux.
  • admin.reports.audit.readonly — to read Gemini activity events (which Google/Gemini features were used, how often, and by whom) via Google’s Admin SDK Reports API, over a rolling window (see section 7).
  • admin.reports.usage.readonly — to read per-user usage figures, such as active days, via Google’s Admin SDK Reports API.
  • admin.directory.user.readonly — to read names, team/organisational unit, and headcount via Google’s Admin SDK Directory API, so usage can be shown against a real (or anonymised, where a person has not opted in) organisational structure.

We never access, read, or store the content of any prompt, document, email, or file. Google’s APIs return counts and categories of activity only (for example, “used Gemini in Gmail 4 times this week”), never the substance of what was written or asked.

An administrator can review or revoke GotDux’s access at any time from the Google Account permissions page or from the Google Admin console. Revoking access stops all further data collection immediately.

Where a customer’s Google environment also includes student accounts within the scope of the connected domain, GotDux may process usage data for those accounts too. In that case we apply Google’s own privacy commitments for Workspace for Education on top of everything else in this policy. See section 11.

3.2 Account and product data

  • Details of the organisation’s account: admin contact name and email, billing details, plan tier.
  • Product usage data you generate directly in GotDux: opt-in preferences for the leaderboard, settings such as seat cost assumptions used for reporting estimates, and support requests.
  • Session data needed to keep you signed in: an encrypted, httpOnly session token. This is a functional cookie required for the product to work, not a tracking or advertising cookie, and it is never shared with any third party.

3.3 Cookies

GotDux does not use tracking, advertising, or analytics cookies on gotdux.ai. The only cookie the product sets is a single, encrypted, httpOnly session cookie, used solely to keep you signed in. It is never shared with any third party and never used to track you across other websites.

4. How we use Google user data (required disclosure)

This section exists specifically to satisfy Google’s API Services User Data Policy for apps that access Google Workspace data, and describes our actual practice exactly, with no exceptions:

Limited Use. GotDux’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We use Google user data only to provide and improve the GotDux features your organisation has purchased: usage dashboards, the opt-in leaderboard, and governance/opportunity insights.
  • We do not use Google user data for advertising of any kind, including retargeting.
  • We do not sell Google user data to any third party.
  • We do not allow humans to read Google user data, except in the narrow cases of: (a) your explicit consent or request (e.g. a support ticket), (b) where necessary to investigate a security incident or technical fault, (c) to comply with a legal obligation, or (d) internal analysis using data that has been aggregated and de-identified so no individual can be recognised.
  • We do not transfer Google user data to any other party, except: with your consent, to our subprocessors solely to provide the service (section 6), where required by law, or as part of a merger, acquisition, or sale of business assets. Even then, your organisation can instead request full deletion of your data rather than have it carried over to a new owner (section 7).
  • We do not use Google user data to train or improve any generalised artificial intelligence or machine-learning model. Any computation we run on your data is used only to produce your own organisation’s reports.

We use Google user data only for the practices disclosed in this policy. If we ever need to request a new Google scope, or to use Google user data for a new purpose not described here, we will update this policy and ask your administrator to consent to the change before we access or use that data.

5. Data storage and location

GotDux runs on Google Cloud Platform (GCP), not a third-party cloud provider, meaning the same company that supplies your Workspace data also supplies the infrastructure it is processed on:

  • Cloud Run hosts the application itself.
  • Firestore is our operational database (organisations, users, sessions, dashboard caches).
  • BigQuery is our analytics data warehouse (usage facts, computed scores).
  • Secret Manager stores encrypted secrets, such as session-signing and token-encryption keys.
  • Cloud Load Balancing, with a Google-managed TLS certificate, serves the gotdux.ai domain globally at the network edge. This is standard internet architecture for reaching you quickly and securely; it does not mean your data at rest sits anywhere other than the region below.
  • GoDaddy is our domain registrar and DNS provider for gotdux.ai. GoDaddy does not process your organisation’s personal data.

Default region: Sydney, Australia (australia-southeast1), for Cloud Run, Firestore, BigQuery and Secret Manager alike.

Your choice of region: if your organisation would prefer its data stored in a different region, closer to your own location, you can ask us to configure this for your account. We will confirm the available regions and any implications in writing before making the change. This applies to your operational and analytics data together, not just part of the stack.

6. Who we share data with

We do not sell your data. We share it only with the following categories of third party, solely to run the service:

  • Google, as the source of the usage data itself (via the OAuth connection your administrator authorises and can revoke at any time), and as our infrastructure provider (GCP: Cloud Run, Firestore, BigQuery, Secret Manager, Cloud Load Balancing).
  • GoDaddy, for domain registration and DNS only. No personal data is processed by GoDaddy.
  • Professional advisers or authorities, only where required by law, to enforce our terms, or to protect the rights, property, or safety of GotDux, our customers, or the public.
  • A buyer or successor, only in the event of a merger, acquisition, or sale of all or part of our business, and only on the condition the data continues to be protected under this policy or one materially as protective. As above, you can ask us to delete your data instead.

7. Data retention and deletion

  • Individual-level usage data is retained on a rolling basis for 90 days to support trend reporting, after which older raw records are automatically deleted.
  • Organisation-level aggregates, with all individual identifiers removed, are kept for the life of your account, so your organisation can see long-term adoption trends even as the underlying detail ages out. These aggregates can never be traced back to a named person.
  • If your organisation cancels its subscription, your data is deleted automatically. We do not use data deletion as a lever to make cancellation harder; if you want an export first, ask us before you cancel and we will provide one at no extra cost.
  • You can request deletion of your organisation’s data, correction of inaccurate data, or an export of your data, at any time by contacting us (section 13). We aim to respond to any such request within 30 days.

8. Security

We apply industry-standard safeguards to protect your data, including:

  • Encryption in transit and at rest across our GCP infrastructure.
  • Refresh tokens and other credentials encrypted at rest (AES-256-GCM), never stored in plain text.
  • Access controls limiting our own staff’s access to data on a need-to-know basis.
  • Regular review of our security practices.

No system is completely immune to risk. If a data breach occurs that is likely to result in serious harm, we will notify affected customers directly and, where required, the Office of the Australian Information Commissioner (OAIC), in line with Australia’s Notifiable Data Breaches scheme. We will do this as promptly as we reasonably can, without waiting until the last legally permitted moment.

9. Your rights

We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You and your staff have the right to:

  • Ask what personal information we hold and request a copy of it.
  • Ask us to correct information that is inaccurate or out of date.
  • Ask questions about how your information is collected, used, or disclosed.
  • Ask us to delete your data or export it, even outside a cancellation (section 7).
  • Lodge a complaint with us directly, or with the OAIC, if you believe we have mishandled personal information. We will not treat a complaint as a reason to restrict your access to your own data while it is resolved.

10. Cross-border data flows

By default, all customer data is stored and processed in Sydney, Australia, across every layer of our stack (Cloud Run, Firestore, BigQuery, Secret Manager). Our global load balancer terminates and routes web traffic at the network edge closest to the person using GotDux, which is standard practice for any web application and does not place your data at rest outside Australia.

If your organisation asks us to relocate its data to a different region (section 5), we will confirm in writing which country that region is in and any safeguards that apply, consistent with our obligations under Australian Privacy Principle 8.

11. Student data

GotDux is designed primarily to measure staff and employee use of AI tools. Where a customer’s connected Google Workspace domain also includes student accounts, and those accounts appear within the scope of the same usage reporting APIs, GotDux may process usage data for those accounts as well.

In that case, we handle that data consistent with Google’s own privacy commitments for Workspace for Education, including not using it for advertising, not selling it, and applying the same read-only, non-training-data principles set out in section 4.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new “last updated” date, and notify your organisation’s administrator directly of any material change, with reasonable notice before it takes effect rather than after the fact.

13. Contact us

Questions about this policy, or requests relating to your data, can be sent to hello@gotdux.ai, or in writing to:

AMAVIS.AI PTY LTD (ABN 49 685 475 932)
Melbourne, VIC 3187, Australia