Gust PR

Privacy Policy

Newsary Pty Ltd (ABN 72 669 333 902) trading as Gust PR

Version 1.0 — effective 30 June 2026 · Last updated 30 August 2026

1. Who we are and what this policy covers

Newsary Pty Ltd ABN 72 669 333 902, trading as Gust PR (Gust, we, us, our), operates gustpr.com and the Gust PR media intelligence platform, and provides public relations and communications services.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where it applies, the EU General Data Protection Regulation and the UK GDPR (GDPR).

This policy explains what personal information we collect, why, who we share it with, and how you can access, correct or object to it. It covers:

We are an APP entity. We do not rely on the small business exemption, including because we disclose personal information about individuals to others in the course of providing our services.

2. What personal information means

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. It includes "personal data" as defined in the GDPR.

Sensitive information (health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric information) receives additional protection under the Privacy Act. We do not seek sensitive information and ask that you do not submit it to the platform. If sensitive information appears incidentally in published media coverage we monitor, we handle it only as part of that public content.

3. What we collect

3.1 Account and client information

3.2 Content you put into the platform

3.3 Website visitors and free tools

3.4 Connected accounts

If you choose to connect a third-party account, we store the connection and the minimum needed to operate it:

3.5 Journalist workspace accounts (Gustfeel)

If you are a journalist using a Gust journalist workspace:

3.6 People named in published media coverage

When we analyse published news coverage for a client, our records include the article's title, URL, publication date, outlet and byline, together with our own derived analysis — sentiment, topic, narrative, and the organisations and individuals mentioned, such as spokespeople, executives and other named stakeholders. We store metadata, derived analysis and links rather than full article text. Copyright in the articles themselves remains with the publisher.

3.7 Media professionals

See section 6.

4. How we collect it

Where the Privacy Act requires it, and it is reasonable and practicable, we take steps to notify individuals when we collect their information from someone other than them. Our Privacy Notice for Journalists explains how we do this for media professionals.

5. Why we use it

We use personal information to:

Purpose
Examples
Provide the Services
create accounts, run monitoring, generate analysis, draft pitches, deliver campaigns
Media matching
identify journalists whose published work is relevant to a client's story, and score fit
Billing
process subscriptions and invoices through Stripe
Support and communication
respond to enquiries, send service notices, briefs and alerts
Improve the Services
diagnose faults, measure usage, improve models, prompts, scoring and taxonomies
Security and abuse prevention
rate limiting, spend caps, fraud detection, audit logging
Marketing
send our newsletter and updates, where permitted (section 11)
Legal compliance
meet obligations, respond to lawful requests, establish or defend legal claims

We will not use or disclose personal information for an unrelated secondary purpose unless you would reasonably expect it, you consent, or the law permits or requires it.

6. Media professionals — journalists, editors and contributors

If you are a journalist, this is covered by a separate notice.

We hold professional information about approximately 5,000 journalists and contributors — name, outlet, beat, coverage history, links to published work, and in a minority of cases a work email address. Because that audience has different questions from our customers, it has its own document rather than a section buried here:

Privacy Notice for Journalists

That notice sets out what we hold, where it came from (including which contact details are published and which are derived from an outlet's email format), what our clients may and may not do with it, and how to see, correct, suppress or delete your record. Removal is unconditional, free, and does not require an account.

Journalist privacy requests: marie@newsary.co

7. AI and automated processing

We use artificial intelligence throughout the platform. You should know:

What it does. AI is used to classify and summarise published articles, assign coverage to narratives and topics, score how well a journalist's published beat matches a client's subject, score and triage pitches, score the newsworthiness of a story, generate drafts and recommendations, and analyse writing style.

What information it uses. Published article content and metadata; journalist professional profiles and coverage history; brand, campaign and audience information supplied by clients; the content of prompts and conversations with our assistant; writing samples; and, for journalist workspaces, the content of forwarded pitches.

These are recommendations, not decisions about you. Our scores rank and prioritise. They do not determine anyone's eligibility for a service, employment, credit, housing or any other benefit, and we do not use them to make decisions that produce legal effects or similarly significant effects on an individual.

A human is always in the loop. Every pitch, draft and target list is reviewed and approved by a person before it is used or sent.

AI outputs can be wrong. They may misattribute an article, misjudge a beat, or contain factual errors. If you believe our system has recorded or characterised your work incorrectly, tell us and we will correct it (section 12).

Automated decision-making transparency. From 10 December 2026 the Privacy Act requires APP entities to disclose in their privacy policy where a computer program makes a decision that could reasonably be expected to significantly affect an individual's rights or interests. We have assessed our automated processing against this requirement and consider that it does not currently include such decisions. We will update this policy if that changes.

Model training. We instruct our AI providers not to use data submitted through our accounts to train their models. We use aggregated and de-identified data to improve our own scoring and taxonomies.

8. Cross-border disclosure

Our infrastructure and several of our service providers are located outside Australia, principally in the United States and the European Union. By using the Services you acknowledge that your information (and personal information you submit about others) may be stored and processed overseas.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual protections. Where a provider is not subject to a law substantially similar to the APPs, you acknowledge that APP 8.1 may not apply and we may not be accountable under the Privacy Act for that provider's handling, and that you will not be able to seek redress under the Privacy Act in that case.

For transfers of personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism.

9. Who we share it with

We do not sell personal information. We share it with:

Service providers, under contract and only as needed to run the Services:

Provider
Purpose
Location
Supabase
Database and application hosting
Ireland
Stripe
Payment processing and subscription billing
US / AU
Anthropic
AI model processing
US
[CONFIRM: OpenAI / Google AI]
AI model processing
US
Resend
Transactional and inbound email
US
Firecrawl
Web page retrieval for analysis
US
Hunter.io
Business contact data
EU
Google (Gmail API)
Draft creation in your own mailbox, where you connect it
US
Slack
Alerts and notifications, where you connect it
US
n8n
Workflow automation

Other recipients:

10. Security and data breaches

We protect personal information with measures including encryption in transit and at rest, row-level access controls in our database, role-based workspace permissions, secure secret storage for third-party tokens, hashing of identifiers such as IP addresses, audit logging, and access limited to personnel who need it.

No system is completely secure. If we suffer a data breach that is likely to result in serious harm, we will assess and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and, where the GDPR applies, notify the relevant supervisory authority within 72 hours where required.

11. Direct marketing

We may send you our newsletter, product updates and PR insights if you are a client, have subscribed, or have used one of our free tools and would reasonably expect to hear from us.

Every marketing email includes an unsubscribe link, and we action unsubscribes promptly, as required by the Spam Act 2003 (Cth). You can also email us to opt out. We will continue to send you service and account messages you cannot opt out of while you have an account.

We do not use the media database to market our own products to journalists.

12. Access, correction and your rights

Everyone may ask us to:

Email marie@newsary.co. We will respond within 30 days. We do not charge for access requests. We may ask you to verify your identity. If we refuse access or correction, we will explain why in writing and tell you how to complain.

If the GDPR applies to you, you also have the right to: erasure; restriction of processing; data portability; to object to processing based on legitimate interests (including an unqualified right to object to direct marketing); to withdraw consent where we rely on it; and to lodge a complaint with your local supervisory authority.

We have not appointed an EU or UK representative under Article 27, on the basis that our processing of EU and UK residents' data is occasional and low-risk.

13. Cookies and analytics

Our website uses cookies and similar technologies to keep you signed in, remember preferences, and understand how the site is used. You can block or delete cookies in your browser, though parts of the site may not work properly.

[CONFIRM: analytics provider, whether a consent banner is used, and whether any advertising or remarketing pixels are deployed.]

14. How long we keep it

Information
Retention
Client account and workspace data
For the life of the account, then [30] days after termination for export, then deletion
Billing and tax records
7 years, as required by Australian tax law
Media database records
While the individual is professionally active, or until they ask to be removed
Suppression records
Indefinitely, in minimal form, so we can honour the suppression
Free tool submissions and leads
24 months from last interaction
Support correspondence
24 months
Security and audit logs
12 months
Aggregated, de-identified analytics
Indefinitely (no longer personal information)

We delete or de-identify personal information when it is no longer needed for any purpose for which it may lawfully be used, unless we are required to retain it.

15. Children

The Services are for business use and not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe we have, contact us and we will delete it.

16. Anonymity

Where lawful and practicable you may deal with us anonymously or under a pseudonym — for example, when making a general enquiry. This is not practicable where we need to identify you to provide the Services or process payment.

17. Changes to this policy

We may update this policy. The current version is always at gustpr.com/privacy-policy with the effective date at the top. We will notify account holders of material changes by email or in-product before they take effect.

18. Contact us and complaints

Privacy enquiries and requests:
Privacy Officer, Newsary Pty Ltd t/a Gust PR
Email: marie@newsary.co
Post: Founder and CEO

Complaints. If you think we have breached the APPs or mishandled your information, contact us first. We will acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you may complain to:

Office of the Australian Information Commissioner (OAIC)
GPO Box 5218, Sydney NSW 2001 · 1300 363 992 · oaic.gov.au

If the GDPR applies to you, you may also complain to the supervisory authority in your country of residence, or to the UK Information Commissioner's Office (ico.org.uk).