Skip to main content

Policy baseline

Privacy Policy

This policy explains how AI Audit Solutions handles information across audit requests, enquiries, AI-assisted review, service delivery, future uploads, payment workflows, customer records, and support operations.

Legal review required before live reliance.

This MVP baseline should be reviewed before live payment collection, paid audit execution, expanded uploads, customer dashboards, automated delivery workflows, or broader third-party processing are activated.

1. About this Privacy Policy

This Privacy Policy explains how AI Audit Solutions collects, uses, stores, discloses, protects, and manages personal information and business information submitted through our website, audit forms, enquiries, meetings, documents, email communications, payment workflows, customer dashboards, and service delivery processes.

This page is the current MVP policy baseline. It should be reviewed by an Australian privacy or commercial lawyer before live payment collection, paid audit execution, expanded uploads, customer dashboards, automated delivery workflows, or broader third-party processing are activated.

Where the Privacy Act 1988, Australian Privacy Principles, Australian Consumer Law, or other applicable laws apply, nothing in this policy is intended to limit rights that cannot lawfully be excluded.

2. Information we may collect

We may collect contact details, business names, role titles, phone numbers, email addresses, website URLs, business goals, operational context, staff size, industry information, revenue ranges, system details, workflow information, audit answers, submitted documents, uploaded file metadata, payment status information, meeting notes, support records, and customer communications.

We may also collect technical information such as browser type, device information, IP-derived diagnostic data, access logs, form events, error logs, analytics events, security logs, and information needed to operate, secure, improve, and troubleshoot the platform.

You must not submit passwords, private keys, seed phrases, unrestricted API keys, database credentials, payment credentials, production secrets, sensitive third-party data, unlawful material, or information you are not authorised to share.

3. How we collect information

Information may be collected when you complete an audit form, submit an enquiry, book or request a call, send us an email, provide documents, interact with the website, pay an invoice, participate in a project, or communicate with us about an audit or implementation service.

Some information may be collected automatically through website systems, analytics, security tools, hosting logs, payment processors, error monitoring, or other approved operational systems.

If you provide information about another person, business, client, staff member, supplier, or third party, you confirm that you are authorised to provide it and that doing so does not breach any duty, contract, privacy obligation, confidentiality obligation, or law.

4. How we use information

We use information to assess audit requests, prepare internal recommendations, generate audit findings, review business systems, prepare quotes, manage customer relationships, deliver agreed services, support implementation work, improve our products, manage payments, maintain records, prevent abuse, and operate the platform securely.

We may also use submitted information to improve scoring models, templates, service pathways, internal processes, user experience, documentation, quality assurance, and operational reporting, provided this is done in a reasonable and lawful way.

We do not sell customer personal information. We do not use submitted confidential business information to create public case studies, testimonials, or promotional material unless permission is obtained or identifying details are removed.

5. AI-assisted processing

AI Audit Solutions may use AI tools, automation, templates, internal models, scoring systems, and human review processes to support audit analysis, drafting, recommendations, development planning, and service delivery.

AI-assisted systems may process information you provide for the purpose of delivering, improving, checking, or supporting services. Human review and approval should apply where customer-facing outputs, commercial recommendations, or material decisions are involved.

You should not submit highly sensitive personal information, regulated data, privileged legal material, patient data, payment card details, passwords, secrets, or production credentials unless a secure, approved, and purpose-specific process has been agreed in writing.

6. Disclosure to service providers

We may disclose information to trusted service providers that support hosting, databases, analytics, email, payments, project management, development, automation, AI processing, security, storage, document generation, customer support, and business operations.

Third-party providers may have their own terms, privacy policies, data locations, retention rules, and security practices. We aim to use providers that are appropriate for the purpose and the risk profile of the information being handled.

We may disclose information if required by law, regulation, court order, dispute process, professional adviser, payment processor, security investigation, debt recovery process, or where reasonably necessary to protect rights, safety, systems, customers, or business operations.

7. Storage, security, and retention

We take reasonable steps to protect information from misuse, interference, loss, unauthorised access, modification, or disclosure. Security measures may include access controls, authentication, environment separation, logging, backups, secure development practices, and operational review.

No website, email system, AI tool, cloud platform, database, payment processor, or internet transmission can be guaranteed to be completely secure. You should only submit information through approved channels and avoid sending secrets or unnecessary sensitive information.

We retain information for as long as reasonably required for audit delivery, service delivery, legal compliance, dispute handling, accounting, record-keeping, security, quality assurance, and business administration. Retention periods may vary based on the type of information and the service provided.

8. Access, correction, and deletion requests

You may contact us to request access to, correction of, or deletion of personal information we hold about you, subject to identity checks, legal obligations, record-keeping duties, dispute needs, security requirements, and technical limitations.

We may need to retain some records for accounting, legal, contractual, security, fraud prevention, audit trail, or legitimate business purposes even if a deletion request is made.

If you believe information we hold is inaccurate, outdated, incomplete, irrelevant, or misleading, contact us with enough detail for us to review the issue.

9. Marketing and communications

We may contact you about audit requests, enquiries, quotes, project updates, service delivery, support issues, policy changes, payment matters, and related business services.

We may send marketing or educational communications where permitted by law or where you have shown interest in our services. You can request to opt out of marketing communications, although operational, transactional, legal, security, and service messages may still be sent where necessary.

We do not guarantee that every communication channel is secure. Do not send passwords, private keys, API secrets, payment credentials, or confidential production access through ordinary email or unapproved forms.

10. Overseas processing and cloud providers

Some service providers, cloud systems, AI tools, analytics platforms, payment processors, or support tools may store or process information outside Australia.

Where overseas or third-party processing is used, we aim to take reasonable steps to assess the purpose, provider, data type, and risk involved. Additional controls may be required before sensitive uploads, customer dashboards, or expanded delivery workflows are activated.

If your business has strict data residency, confidentiality, government, health, financial, legal, or regulated-data requirements, you must tell us before submitting data or starting an audit or project.

11. Contact

Questions about privacy, data handling, information access, correction, deletion, AI-assisted processing, third-party providers, or security should be sent to AI Audit Solutions using the contact details published on the website.

Before public launch, this page should be updated with the final legal entity name, ABN or ACN, business address, privacy contact email, and any required disclosures confirmed through legal review.

12. Google Sign-In and customer authentication

Where Google Sign-In is offered, AI Audit Solutions requests only the standard identity scopes required for authentication: openid, userinfo.email, and userinfo.profile.

We use the resulting verified email address and basic profile information to establish an authenticated session and to match the identity to an existing authorised AI Audit Solutions customer record. Authentication does not itself grant access to customer records.

The current Google Sign-In configuration does not request access to Gmail message content, Google Drive files, Google Calendar data, Google Contacts, or other Google service content.

We do not sell Google user data or use Google authentication data for advertising. Google and our authentication provider may process authentication information in accordance with their own applicable terms and privacy policies.

Related policies

Review the connected policy pages for terms, security, service standards, refunds, data handling, and launch-readiness boundaries.