Search on this blog

Search on this blog

Privacy Policy

Service Provider: ExpertEase AI/Quantum Pulse Pty Ltd
ABN: 78 671 001 675
Address: Level 21, 25 Grenfell Street, Adelaide, South Australia 5000
Website: https://experteaseai.com
Contact: https://experteaseai.com/contact-us

Effective Date: 21 June 2025
Last Updated: 07 July 2026

COMMITMENT TO PRIVACY

ExpertEase AI (“we,” “us,” “our,” or “the Company”) is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use our artificial intelligence services, autonomous AI agents, and related platforms.

Australian Data Sovereignty: All personal information and data is processed and stored within Australian borders by default. We are proudly Australian-owned and operated, ensuring your data remains under Australian jurisdiction and protection. A complete list of sub-processors and data processing locations is maintained at experteaseai.com/trust/subprocessors.

1. INFORMATION WE COLLECT

1.1 Personal Information You Provide

When you use our services, we may collect:

Account Information:

  • Full name and business contact details
  • Email address and phone number
  • Organisation name and ABN/ACN
  • Business address and industry sector
  • Job title and role within organisation
  • Payment and billing information
  • User credentials and authentication data

Service Usage Information:

  • AI chatbot configurations and customisations
  • Training data and knowledge base uploads
  • Conversation logs and chat histories
  • Voice recordings and transcripts (where Voice AI is used and recording is enabled)
  • Custom automation workflows and integrations
  • Support requests and communications

End User Data (when you deploy our AI services):

  • Chat conversations between your customers and AI agents
  • Personal information shared during AI interactions
  • Customer service inquiries and responses
  • Usage analytics and interaction patterns
  • Any personal or business information disclosed to AI assistants you create

Where Customer operates in the health, aged care, or disability services sector and health information about individuals may be processed through the Service, ExpertEase AI treats such information as sensitive information in accordance with the Australian Privacy Principles and applicable health records legislation.

1.2 Information Automatically Collected

Website Usage Data:

  • IP address and location data
  • Browser type and operating system
  • Device information and screen resolution
  • Pages visited and time spent on our website
  • Referral sources and exit pages
  • Date and time of access

Service Performance Data:

  • System logs and error reports
  • Response times and service availability
  • Feature usage and adoption metrics
  • Security event logs and access patterns

1.3 Information from Third Parties

We may receive information about you from business partners and referral sources, third-party integrations you authorise (CRM systems, etc.), payment processors and financial institutions, and identity verification services.

2. USE OF THE WEBSITE

2.1 Lawful Basis for Processing

We process personal information under the following lawful bases:

  • Consent: Where you have provided explicit consent
  • Contract Performance: To provide services under our Terms and Conditions
  • Legitimate Interests: For business operations, security, and service improvement
  • Legal Compliance: To meet Australian regulatory requirements

2.2 Purpose of Data Collection

We use your personal information to:

Service Delivery: Provide access to AI chatbot and automation services; process and respond to AI training data uploads; enable voice AI and conversational capabilities; facilitate custom integrations and workflows; provide customer support and technical assistance.

Account Management: Create and maintain user accounts; process payments and manage subscriptions; send service notifications and updates; verify identity and prevent unauthorised access; manage user permissions and access controls.

Business Operations: Improve our platform and service performance; develop new features and capabilities; conduct research and analytics for service enhancement; ensure system security and prevent fraud; comply with legal and regulatory obligations. Service improvement does not include using customer content or end-user interaction data to train AI models. AI model improvement uses only anonymised platform performance telemetry.

Marketing and Communications: Send product updates and announcements; provide information about new features; conduct customer satisfaction surveys; share relevant industry insights and content; invite participation in events and webinars.

3. COOKIES AND TRACKING TECHNOLOGIES

3.1 Types of Cookies We Use

Essential Cookies: Authentication and session management; security and fraud prevention; load balancing and performance optimisation; user preference storage.

Analytics Cookies: Website usage and traffic analysis; feature adoption and user behaviour tracking; performance monitoring and error reporting; A/B testing and service optimisation.

Marketing Cookies: Advertising effectiveness measurement; personalised content delivery; social media integration; remarketing and conversion tracking.

3.2 Third-Party Tracking

We may use third-party services for website traffic analysis, service monitoring, customer support platforms, and payment processing.

3.3 Cookie Management

You can control cookies through your browser settings or by contacting our privacy team. Note: disabling essential cookies may impact service functionality.

4. SHARING INFORMATION WITH THIRD PARTIES

4.1 Australian Data Processing Commitment

All personal information and data is processed and stored within Australian borders by default, using Microsoft Azure’s Australian data centres (Sydney and Melbourne). All AI model inference runs within Australia — on Azure OpenAI in Microsoft’s Australian regions, or on ExpertEase AI’s own self-hosted models on Australian infrastructure. No conversation content, documents, or voice audio is transmitted to overseas AI providers.

4.2 Sub-processors

We engage a limited set of vetted third-party sub-processors to deliver the Service. Each sub-processor is bound by contractual data-protection obligations. A complete and current list, including the data each receives and where it is processed, is maintained at experteaseai.com/trust/subprocessors.

Key sub-processors include:

  • Microsoft Azure — cloud hosting, database, file storage, AI model inference (Azure OpenAI), document processing, speech recognition and synthesis, application monitoring. Location: Australia East (Sydney) and Australia Southeast (Melbourne).
  • Twilio (Voice) — voice calls and phone numbers. Location: Australia (Twilio Australian region AU1) — call audio processed onshore for Australian numbers.
  • Twilio SendGrid — transactional email. Location: United States.
  • Stripe — payment processing. Card data is processed solely by Stripe and never stored on ExpertEase AI systems. Location: United States.
  • io — IP address security screening (VPN/proxy/Tor detection). IP addresses only — no account data or content shared. Location: United Kingdom.

The following tools are self-hosted by ExpertEase AI on Australian infrastructure and involve no third-party processor: Langfuse (AI interaction tracing), Firecrawl (website content retrieval), and Jina (web content processing).

4.3 Overseas Processing — Disclosed Exceptions

The following limited functions involve overseas processing by default and are necessary to deliver the Service. These are disclosed in full on our sub-processor register:

  • SMS message routing — Twilio, United States (SMS content transits US infrastructure)
  • Transactional email — Twilio SendGrid, United States
  • Payment processing — Stripe, United States
  • IP-address security screening — ProxyCheck.io, United Kingdom

Australian customers making payments by EFT pay directly to ExpertEase AI’s Australian bank account — no overseas payment processor is involved in EFT transactions.

All other personal information, including conversation content, documents, voice audio, and AI processing, is handled within Australia.

4.4 Other Disclosure Circumstances

We may disclose personal information where required by law, court order, or regulatory authority; in connection with a merger, acquisition, or sale of business assets (subject to equivalent privacy protections); or to protect the rights, property, or safety of ExpertEase AI, its customers, or others.

4.5 Customer-Directed Integrations

The platform connects to third-party systems at the customer’s direction and under the customer’s own accounts — for example Zoho CRM, Salesforce, Shopify, Cliniko, Google Calendar, Microsoft Outlook, WhatsApp Business, and others. Data flows to these services only when a customer actively connects them, is governed by the customer’s own agreement with each provider, and can be disconnected at any time. These are not sub-processors of ExpertEase AI.

5. DATA SUBJECT RIGHTS

Under the Australian Privacy Principles, you have the right to:

  • Access: Request confirmation of what personal information we hold and obtain copies
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of personal information where appropriate; withdraw consent where consent was the lawful basis
  • Objection: Object to processing for direct marketing; opt-out of non-essential processing
  • Portability: Request personal information in a structured, machine-readable format

To exercise these rights, contact us at:

We will respond within 30 days of receiving your request. If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or call 1300 363 992.

6. DATA PROTECTION MECHANISMS

6.1 Technical Safeguards

Our platform is built on Microsoft Azure’s Australian infrastructure, which is IRAP-assessed and certified to ISO/IEC 27001 and SOC 2. Our own security program is aligned with ISO/IEC 27001 principles; ExpertEase AI’s own ISO 27001 certification is on our roadmap.

Controls include: end-to-end encryption for data in transit and at rest; field-level AES encryption for sensitive credentials; multi-factor authentication and role-based access controls; strict tenant isolation ensuring no cross-customer data access; automated security scanning in our CI/CD pipeline; and centralised monitoring and alerting via Azure Application Insights and Log Analytics. All application logs and security telemetry are retained within Microsoft Azure — no third-party log management service receives customer or operational data.

Full details of our security architecture are published at experteaseai.com/trust/security.

6.2 Operational Safeguards

Staff training, confidentiality agreements, vendor due diligence, data processing agreements with all sub-processors, and regular compliance monitoring.

6.3 Compliance Frameworks

  • Privacy Act 1988 (Cth) and Australian Privacy Principles — compliant
  • Notifiable Data Breaches scheme — compliant
  • Privacy Act ADM transparency requirements (December 2026) — ready ahead of deadline
  • ASD Essential Eight — self-assessed
  • Australian Voluntary AI Safety Standard (VAISS) — adopted, self-assessed
  • OWASP Top 10 / OWASP LLM Top 10 — development baseline
  • ISO/IEC 27001 — aligned (delivered on Azure-certified infrastructure; ExpertEase AI certification on roadmap)
  • ISO/IEC 42001 (AI Management Systems) — aligned, certification on roadmap

7. DATA STORAGE AND RETENTION

7.1 Storage Location

All personal information is stored at rest in Microsoft Azure’s Australian regions — Australia East (Sydney) and Australia Southeast (Melbourne). No offshore storage without explicit written consent.

7.2 Data Retention Periods

  • Account information (active accounts): Duration of service relationship
  • Conversation logs and transcripts: Retained for the life of the customer’s account; customers can delete their own interaction history at any time through their account dashboard
  • Voice recordings: Retained only if recording is enabled by the customer; customers can disable recording and delete existing recordings through the account dashboard at any time
  • Closed accounts: Personal information deleted from production systems within 30 days of account closure or verified deletion request; residual backup copies purged within 90 days
  • Billing records: 5 years as required by Australian tax law
  • Security logs: As required for audit and compliance purposes

Free plan accounts that have had no login or API activity may be subject to removal at ExpertEase AI’s discretion.

7.3 Data Disposal

When retention periods expire, secure deletion using industry-standard methods is applied across all data stores including database, file storage, vector search indexes, and AI tracing logs.

8. END USER DATA PROCESSING

8.1 Roles

When you deploy our AI services that interact with your end-users: you are the data controller for your end-users’ personal information; ExpertEase AI is the data processor acting on your instructions.

8.2 Your Responsibilities for End User Data

You must: obtain appropriate consents from your end-users; maintain your own privacy policy covering end-user interactions; comply with privacy laws applicable to your end-user relationships; inform end-users that they are interacting with an AI system; and respond to end-user privacy requests and complaints.

8.3 Our Commitments for End User Data

We commit to: apply the same security standards to all customer data; prevent cross-contamination between different customers’ data through strict tenant isolation; process end-user data only as instructed by you; and never use end-user data for AI model training without explicit written consent.

9. AUTOMATED DECISION-MAKING

9.1 What Is Automated

Our platform uses AI systems that generate responses and take actions automatically. In accordance with the Privacy Act’s ADM transparency requirements (commencing December 2026), we disclose:

  • What is automated: AI digital employees generate conversational responses, answer questions from a customer-controlled knowledge base, capture leads, schedule appointments, and execute customer-configured workflows (e.g. creating a CRM record).
  • What information is used: The end-user’s messages in the conversation, the business’s uploaded knowledge content, and — where connected — records from the business’s own integrated systems.
  • Kinds of decisions: Conversational routing and workflow steps configured by the business. Our platform does not itself make automated decisions about credit, employment, insurance, or legal entitlements. Where a business configures a digital employee in a way that could significantly affect individuals, that business is responsible for its own ADM disclosures.
  • Human review: Every digital employee supports escalation to a human. Businesses can review full transcripts of all interactions. Individuals may request human review of any interaction outcome by contacting the business they interacted with, or us at privacy@experteaseai.com.

9.2 Safeguards

We implement regular algorithm review, human oversight of significant automated decisions, full interaction traceability, and mechanisms for challenging and reviewing decisions. Details are published at experteaseai.com/trust/ai-safety.

10. CROSS-BORDER DATA TRANSFERS

10.1 Default Australian Processing

All personal information is processed and stored within Australia using Microsoft Azure’s Australian data centres. All AI processing — including model inference for chat, voice, and document processing — is performed within Australia.

10.2 Disclosed Offshore Exceptions

The following functions involve overseas processing as a necessary part of service delivery: SMS message routing (Twilio, United States), transactional email (Twilio SendGrid, United States), payment processing by credit card (Stripe, United States), and IP-address security screening (ProxyCheck.io, United Kingdom). Australian customers paying by EFT transact directly with ExpertEase AI’s Australian bank account with no overseas processing. All disclosed exceptions are governed by contractual data-protection terms.

For customers in Turkey: ExpertEase AI processes personal data as a data processor under the Turkish Personal Data Protection Law (KVKK). Customers operating under KVKK are responsible for their own registration and compliance obligations under that law.

11. SECURITY INCIDENT RESPONSE

11.1 Incident Response

We maintain monitoring and incident response capabilities including automated threat detection, rapid containment procedures, forensic investigation, and communication protocols.

11.2 Breach Notification

We participate in the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm, we will notify affected individuals and the OAIC as required by law, and notify affected business customers so they can meet their own obligations to their end-users.

12. CHILDREN’S PRIVACY

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have done so, we will take steps to delete such information promptly.

13. UPDATES TO THIS PRIVACY POLICY

We may update this Privacy Policy to reflect changes in our services, privacy laws, or security practices. We will provide 30 days’ advance notice for material changes via our website and by email to registered account holders.

14. CONTACT AND COMPLAINTS

Privacy Officer ExpertEase AI / Quantum Pulse Pty Ltd Level 3, 97 Pirie Street, Adelaide, South Australia 5000 Email: privacy@experteaseai.com Website: https://experteaseai.com

We will acknowledge your inquiry within 3 business days and respond fully within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: oaic.gov.au
  • Phone: 1300 363 992
  • Mail: GPO Box 5218, Sydney NSW 2001

ACKNOWLEDGMENT

By using our services, you acknowledge that you have read, understood, and agree to this Privacy Policy.

Document Version: July2026-2 Last Updated: July 2026

ExpertEase AI – Proudly Australian. Your Privacy. Our Commitment.