Privacy Policy
LAST UPDATED: 10 SEPTEMBER 2026
1. Who we are
Hummbird is a go-to-market platform and service operated by North Arrow Pty Ltd (ACN 700 669 530, ABN 71 700 669 530), a company registered in Australia.
Registered office: 100 Taylors Road, Mount Macedon, Victoria 3441, Australia. Contact: [email protected].
In this policy, "we", "us" and "Hummbird" mean North Arrow Pty Ltd.
Velocitie is now part of Hummbird. The AI interview and content platform previously offered at velocitie.com under the Velocitie brand is now owned and operated by North Arrow Pty Ltd. This policy replaces the previous Velocitie Privacy Policy. North Arrow Pty Ltd is the entity responsible for personal information previously held in connection with Velocitie.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the EU or UK General Data Protection Regulation applies to you, we comply with it as described in section 11.
2. What this policy covers
This policy explains how we handle personal information across five groups:
- Visitors to hummbird.io (and velocitie.com)
- Applicants who complete our application form
- Platform users with a Hummbird (or former Velocitie) account
- Service clients who engage the done-for-you Hummbird service
- Prospects we contact on a client's behalf as part of that service
Section 7 deals specifically with prospects. If you received a LinkedIn message or email connected to Hummbird and want to know why, that is the section to read.
3. Website visitors
When you visit our sites we collect limited technical and usage information, including IP address, browser and device type, pages viewed, referring source, and time spent on the site. We use analytics tools to understand how the site performs and how people move through it.
We use this to operate and improve the site. You can block or delete cookies through your browser at any time. See section 15.
4. Applicants
When you complete our application form we collect what you provide, which may include your name, email address, company, website, role, information about your business stage and revenue band, your current go-to-market activity, and your answers to our qualifying questions.
We use this to assess whether Hummbird is a fit for your business, to reply to your application, and to prepare for a call if we take the conversation further. We may keep your application on file so we can contact you if a place opens later. You can ask us to delete it at any time.
We do not sell application data and we do not add you to unrelated marketing lists.
5. Platform users
If you create an account on the Hummbird platform (including a former Velocitie account), we handle:
- Account and contact details: name, email address, company name and website, LinkedIn profile URL where you provide it, and billing information (payments are processed by Stripe; we do not store full card details)
- Interview data: audio and video recordings of your AI-led interviews, and transcripts generated from them by AI speech recognition
- Generated content: the posts, video clips, captions and long-form content the platform creates from your interviews, and your edits and approvals
- Inputs and preferences: themes, questions, brand voice settings and other onboarding inputs
- Publicly available information from links you provide (such as your LinkedIn profile or company website), used to personalise onboarding and improve content quality; by providing these links you confirm you are entitled to authorise that access
- Usage data: plan, feature usage, interview minutes consumed, and content generated
We use this to provide the platform, generate your content, process payments, provide support, and improve the product. Interview recordings and generated content are yours; you can delete content through the platform or by contacting us.
AI processing. The platform uses third-party AI providers for speech recognition, transcription and content generation (currently including Anthropic, OpenAI, Deepgram and Speechmatics), operating under commercial API terms. Your content is not used to train these providers' models. AI output can contain errors; you review and approve all content before publishing. We do not use solely automated decision-making that produces legal or similarly significant effects about you.
6. Service clients
If you engage the done-for-you Hummbird service, we additionally handle:
- Business information you give us about your ideal customer, offer, positioning and brand voice
- Authorised account sessions for the accounts you connect, as described in our Terms of Service, stored encrypted and accessible only to the founders under MFA-protected accounts
- Campaign data, including outreach performance, replies and booked meetings
How we access your accounts. We access your LinkedIn account through an authorised session in order to send connection requests and messages on your behalf. We do not change your password. Where warm email follow-up is agreed, we send individual follow-up emails from your own mailbox to prospects who have shown interest, and access only the campaign-related threads needed to manage them. We do not otherwise access your personal or business email inbox. Where you connect a calendar, we do so on a read-only basis to check availability. You can revoke access at any time, which may pause or end the service.
Your own lists. Where you provide prospect or suppression lists you own, we process them only on your instruction, for your campaign, for the duration of the engagement. We do not use one client's lists for another client, and we do not sell them.
7. Prospects we contact on a client's behalf
This section applies if you received a LinkedIn message, connection request or email connected to Hummbird and you are not a client of ours.
What we hold. Typically your name, professional role and employer, LinkedIn profile URL, business email address where sourced, publicly stated professional information such as job changes or public posts you have engaged with, and a record of the messages sent to you and any reply.
Where we get it. We build lists from publicly available professional sources, primarily LinkedIn, and from information our client lawfully provides. Where a conversation warrants email follow-up, we may source a business email address from publicly available sources or professional data providers.
Why we do it. To introduce a business offering we believe is professionally relevant to your role. Contact is business-to-business, made in the name of our client, and identifies the sender clearly. Outreach is primarily by LinkedIn; email is used only for follow-up where interest has been shown, sent from our client's own mailbox.
Who we contact. Our outreach is directed to business contacts, predominantly in the United States. We contact people in a professional capacity, at a business address, about something relevant to the role they hold. We do not contact personal addresses, and we do not contact anyone who has told us not to.
Where we got your details. You are entitled to ask us where we obtained your information, and we will tell you free of charge within a reasonable period. Email [email protected].
How to stop it. Tell us and we will stop. Reply to the message and say so, use the opt-out in any email, submit the form at hummbird.io/do-not-contact, or write to [email protected]. We act on opt-out requests promptly and in any event within ten business days, and we add you to a suppression list so you are not contacted again through our systems. You can also ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. See section 12.
How long we keep it. Campaign data is retained for the duration of the client engagement and for a limited period afterwards for reporting and record-keeping. Suppression records are kept indefinitely, because that is what allows us to keep not contacting you.
8. Who we share information with
We share personal information with service providers who help us run the business. These fall into the following categories:
- AI processing providers (speech recognition, transcription and content generation, currently including Anthropic, OpenAI, Deepgram and Speechmatics)
- Cloud hosting, database and storage providers (currently Supabase on AWS infrastructure in the EU, and Hetzner in Germany, behind Cloudflare)
- Outreach and sequencing platforms
- Business data, enrichment and email verification providers
- Email delivery platforms
- Website hosting, analytics and form processing
- Scheduling and calendar tools
- Internal communication, project tracking and document storage
- Payment processing (Stripe) and accounting
We require these providers to protect the information and to use it only to provide their service to us. We do not sell personal information, and we do not share it for unrelated third-party marketing.
We may also disclose information where required by law, or to establish or defend a legal claim. If our business is reorganised or sold, personal information may be transferred as part of that transaction, subject to this policy.
A current list of the providers we use is available on request from [email protected].
9. Where information is stored
We are an Australian company. Our platform databases and file storage are hosted in the European Union (AWS regions in Frankfurt and Dublin via Supabase, with application servers in Germany). Our clients, the people we contact on their behalf, and some service providers are located overseas, including in the United States, so personal information is likely to be disclosed to recipients outside Australia.
We take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles and, where applicable, use recognised transfer mechanisms such as Standard Contractual Clauses for transfers of European data.
10. How long we keep information
- Website analytics: typically up to 26 months
- Applications: up to 24 months from submission, unless you ask us to delete sooner
- Platform accounts: for as long as your account is active; deleted on verified request, and after account closure following a short grace period for export and reactivation
- Client records: for the duration of the engagement, and afterwards as required for tax, accounting and legal record-keeping
- Campaign and prospect data: for the duration of the engagement and a limited period afterwards
- Suppression and opt-out records: indefinitely
When information is no longer needed we delete it or de-identify it. A written retention and purge schedule is maintained as part of our internal privacy programme.
11. European and UK users (GDPR)
Where the GDPR or UK GDPR applies, North Arrow Pty Ltd is the controller of personal information described in this policy, except client-provided prospect lists and campaign data we process on a client's instruction, for which we act as processor.
Our legal bases are: performance of a contract (providing the platform and service); legitimate interests (operating and improving the business, B2B direct marketing, security); consent where we ask for it (for example optional cookies and promotional use of your content); and legal obligation.
You have the rights of access, rectification, erasure, restriction, portability and objection (including to direct marketing), and the right to withdraw consent at any time. Contact [email protected]. You may complain to your local supervisory authority; we will also always try to resolve concerns directly.
12. Your rights
You can ask us to:
- Tell you what personal information we hold about you and give you a copy
- Correct information that is wrong, incomplete or out of date
- Tell you where we obtained your information
- Delete information we hold about you
- Export your platform data in a commonly used format
- Stop contacting you
Email [email protected]. We respond within 30 days and normally much sooner. We may need to verify your identity first. There is no cost, and we will not ask you to justify an opt-out request.
If we refuse a request for access or correction, we will tell you why in writing and explain how to complain.
California residents. We extend the rights above to you regardless of whether we meet the thresholds set by the California Consumer Privacy Act. That includes the right to know what we collect and why, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under that Act.
13. Data breaches
If a data breach occurs that is likely to result in serious harm, we will assess it promptly and, where the Notifiable Data Breaches scheme requires, notify affected individuals and the Office of the Australian Information Commissioner. Where European data is affected, we will notify the relevant supervisory authority within 72 hours where required.
14. Security
We protect personal information with encryption in transit (TLS) and at rest, per-role database credentials with row-level security, MFA enforced on all administrative systems, segregated databases per product, daily automated backups stored separately from production, and least-privilege access limited to the founders. Stored third-party credentials are encrypted with the key held outside the database. Payments are processed by Stripe; we hold no payment card data. No system is perfectly secure, but we limit who can access what.
15. Cookies
We use essential cookies to make the site work and, with your consent where required, analytics cookies to understand how it is used. You can manage preferences through the cookie banner and block or delete cookies through your browser settings, though some parts of the site may not work as intended.
16. Children
Our platform and service are for businesses. We do not knowingly collect personal information from anyone under 18.
17. Changes to this policy
We may update this policy from time to time. The current version is always on this page with the date it was last updated. If we make a significant change, we will take reasonable steps to let affected people know.
18. Contact
North Arrow Pty Ltd 100 Taylors Road, Mount Macedon, Victoria 3441, Australia [email protected]