Daisy

Privacy Policy

Last updated: 23 July 2026

1. Who we are

Daisy is a business-to-business sales intelligence and account prioritisation platform. It is operated by The Trustee for JustJewels Master Trust (ABN 21 934 137 134), trading as The Demand Stream (also trading as Storytllr Group). In this policy, “Daisy”, “we”, “us” and “our” mean that entity.

This policy explains how we handle personal information, including information about the business contacts our clients research and reach out to. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. The personal information we collect

Depending on how Daisy is used, we collect:

  • Account and user information for the people who use Daisy on behalf of our clients: name, work email, job title, company, phone number, time zone, email signature, and authentication details.
  • Business contact information about the individuals our clients may wish to engage: name, job title, business email address, business phone number, employer, seniority, professional background, publicly available professional profile details (including LinkedIn profile URL and public activity), and similar work-related information.
  • Commercial insights and inferences we generate to support sales judgement: account-level hypotheses, relevance and engagement indicators, and recommended next actions. These are labelled inferences, shown with their supporting evidence, source and confidence, not statements of fact.
  • Connected mailbox information, if a user chooses to connect their own Google or Microsoft mailbox so that Daisy can send outreach the user has approved. See the “Google user data” section below.
  • Website and usage information: when you visit our web properties we may collect your IP address, browser user-agent and referring page, together with standard log and cookie data needed to operate and secure the service.

We do not seek to infer or use sensitive information (such as health, racial or ethnic origin, religious or political beliefs, trade union membership, sexual orientation, or criminal history) to prioritise accounts, rank individuals, form hypotheses or recommend outreach.

3. Where we collect it from

We collect personal information:

  • Directly from you when you register for, use, or contact us about Daisy.
  • From third-party data providers, principally Apollo.io, which supplies business contact information.
  • From publicly available sources and registers, including the Australian Securities Exchange (ASX), the Australian Securities and Investments Commission (ASIC), the Australian Prudential Regulation Authority (APRA), AusTender, and JAS-ANZ.
  • From LinkedIn, through the authenticated accounts of our clients’ own users who have connected them, to observe public professional activity relevant to their outreach.
  • From our clients, where they supply information about people they wish to engage.

Because some of this information is collected from sources other than the individual, we take reasonable steps to make people aware of the collection, including through this policy and through identification and opt-out information in our clients’ first outreach.

4. How we use personal information

We use personal information to:

  • provide, operate, maintain and secure the Daisy platform;
  • research accounts and form account-level commercial hypotheses;
  • recommend and draft outreach for a human user to review, edit and approve;
  • send outreach that a user has approved, on that user’s behalf and from their own identity;
  • provide support and respond to enquiries and requests;
  • maintain opt-out, unsubscribe and suppression records;
  • meet our legal, regulatory and record-keeping obligations; and
  • improve Daisy and our services using aggregated, anonymised or de-identified information.

5. Automated processing and human judgement

Daisy uses automated processing, including AI language models, to interpret evidence about organisations, form explainable commercial hypotheses, and help authorised users exercise better human judgement. The personal information used by this processing is the account and business-contact information described in section 2.

These automated steps substantially assist, but do not replace, human decisions. A person at our client reviews and approves account prioritisation and any outreach before it is sent. Hypotheses and recommendations are presented as inferences with their supporting evidence, source, age and confidence, and can be corrected. Daisy does not make decisions that produce legal or similarly significant effects about an individual without human involvement.

6. Google and Microsoft user data (connected mailboxes)

If a user connects a Google mailbox, Daisy requests only the gmail.send permission. If a user connects a Microsoft mailbox, Daisy requests only the Mail.Send permission. We use this access for one purpose: to send email messages that the user has reviewed and approved, from the user’s own mailbox.

With connected-mailbox access, Daisy does not:

  • read, search, download, modify or delete any messages in the mailbox;
  • access contacts, calendars, files or any other data in the connected account;
  • use the access for advertising, or sell or rent any data obtained through it; or
  • use it to train generalised or standalone artificial-intelligence models.

Daisy’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We transfer Google user data only as necessary to provide and improve this sending feature, to comply with applicable law, or as part of a merger or acquisition, and only in ways consistent with that policy. A user can disconnect a mailbox at any time in Daisy, and can also revoke Daisy’s access from their Google Account permissions (or the equivalent Microsoft account settings).

7. When we disclose personal information

We disclose personal information to:

  • Our clients, who receive the account intelligence, contact information and recommended outreach that Daisy produces for them, so that their authorised users can pursue business relationships.
  • Service providers who process data on our behalf, including Supabase (hosting and database), Anthropic (AI processing under zero-retention API terms), Apollo (contact data), Unipile (LinkedIn connectivity), Resend (email delivery), Stripe (payments), Sentry (error monitoring, configured to scrub personal information) and Netlify (application hosting).
  • Others where required or permitted by law, such as to comply with a legal obligation, enforce our terms, or protect our rights, safety or property.

We do not sell personal information.

8. Overseas recipients

Several of our service providers are located overseas, principally in the United States. This means personal information may be stored or processed outside Australia, including by Supabase, Anthropic, Apollo, Resend, Netlify, Sentry and Stripe. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.

9. How we protect personal information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include access controls, encryption of data in transit, restricted service credentials, tenant separation between clients, and monitoring configured to exclude personal information. No method of transmission or storage is completely secure, but we work to protect information consistent with our obligations and will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) of any eligible data breach as required.

10. How long we keep it

We retain personal information for as long as it is needed to provide the service and to meet our legal and record-keeping obligations. If you ask us to stop contacting you, we add you to our suppression list. If you ask us to access, correct, or delete the personal information we hold about you, we will action your request as described in “Your choices and rights” below.

11. Your choices and rights

You may, at any time:

  • Ask us what personal information we hold about you, and request access to it or correction of it;
  • Opt out of outreach and ask to be added to our suppression list, so that we and our clients do not contact you again. Where we send you a commercial electronic message, we identify ourselves and provide a way to opt out;
  • Ask us to delete the personal information we hold about you, subject to any information we are required to retain by law or to record your opt-out.

To exercise any of these choices, contact us at privacy@thedemand.stream. We will respond within a reasonable time. There is no charge to make a request, and you do not need to have an account with us.

12. Cookies and analytics

We use cookies that are necessary to sign users in and keep the application secure. On our public web properties we also collect limited analytics information (such as IP address, browser user-agent and referring page) to understand and improve how the service is found and used. We do not use this information to identify you personally beyond what is described in this policy.

13. Complaints

If you have a concern or complaint about how we have handled your personal information, please contact us at privacy@thedemand.stream and we will acknowledge it and work with you to resolve it. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au/privacy/privacy-complaints.

14. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. The current version is always available at this page, with the “Last updated” date shown above. Where changes are significant, we will take reasonable steps to bring them to the attention of affected users.

15. Contact us

For any privacy question or request, contact The Demand Stream (The Trustee for JustJewels Master Trust, ABN 21 934 137 134) at privacy@thedemand.stream.