Search on this blog

Search on this blog

Privacy & Data Protection | ExpertEase AI Trust Centre

← Trust Centre

Privacy & Data Protection

Australian Privacy Principles — Fully Disclosed

We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and where applicable the GDPR. Last updated: 07 July 2026

Australian Privacy Principles Notifiable Data Breaches Scheme December 2026 ADM Ready No Data Sold. Ever. No AI Training on Your Data

How We Handle Personal Information

ExpertEase AI ([LEGAL ENTITY NAME], ABN [ABN]) handles personal information in two distinct roles depending on whose data it is.

Role 1 — Controller

Your Business Account Data

Account details, billing information, and platform usage data belonging to the businesses that sign up for ExpertEase AI. We decide how and why this is processed, and this policy governs it.

Role 2 — Processor

End-User Interaction Data

When a business deploys a digital employee, the people who chat, call, or message it share information with that business. We process this data solely on the business's instructions. The business is the controller and is responsible for its own privacy notices to its end-users.

What We Collect

👤

Account Data

Name, business name, email, phone, hashed login credentials, plan and billing records.

📄

Customer Content

Documents, websites, and knowledge sources uploaded to train your digital employees.

💬

Interaction Data

Chat transcripts, voice call audio and transcripts, SMS and messaging content, and leads captured by digital employees.

🖥️

Technical Data

IP addresses, device and browser information, and usage logs for security and platform operation.

🔗

Integration Data

Where you connect a third-party system (CRM, calendar, e-commerce), data accessed from that system under your OAuth authorisation.

🚫

What We Never Do

We do not sell personal information. We do not use your content or conversations to train shared or third-party AI models.

Why We Process It

PurposeLegal basis (GDPR where applicable)
Providing and operating the platformContract performance
Billing and account managementContract performance / legal obligation
Platform security, fraud and abuse prevention (including IP reputation screening)Legitimate interests — network and information security (Recital 49)
Service improvement and analyticsLegitimate interests
Legal compliance and dispute resolutionLegal obligation / legitimate interests

December 2026 ADM Transparency — Already Met

Ahead of the Privacy Act's automated decision-making transparency requirements commencing December 2026, we already disclose what our platform automates, what information it uses, and how any outcome can be reviewed by a human.

Automated Decision-Making Disclosure

Our platform uses AI systems that generate responses and take actions automatically. In accordance with the Privacy Act's ADM transparency requirements (commencing December 2026):

🤖

What Is Automated

AI digital employees generate conversational responses, answer questions from a customer-controlled knowledge base, capture leads, schedule appointments, and execute customer-configured workflows (e.g. creating a CRM record).

📊

What Information Is Used

The end-user's messages in the conversation, the business's uploaded knowledge content, and — where connected — records from the business's own integrated systems.

⚖️

Kinds of Decisions

Conversational routing and workflow steps configured by the business. Our platform does not itself make automated decisions about credit, employment, insurance, or legal entitlements.

🙋

Human Review

Every digital employee supports escalation to a human. Businesses can review full transcripts of all interactions. Individuals may request human review at privacy@experteaseai.com.

Overseas Disclosure (APP 8)

All personal information is stored at rest in Australia, and — unusually for an AI platform — all AI processing is also performed in Australia, on Microsoft Azure's Sydney and Melbourne regions or on our own Australian infrastructure. Conversation content, documents, and voice audio are not disclosed to overseas AI providers.

A limited set of functions involve overseas transmission: SMS message routing, transactional email, and payment processing (United States) and IP-address security screening (United Kingdom).

→ Full sub-processor register with locations

Data Stays in Australia

AI Processing — onshoreAzure OpenAI, Sydney & Melbourne
Voice Audio — onshoreTwilio Australian region
SMS Content — offshore exceptionTransits Twilio US infrastructure

Retention & Deletion

  • Chat and voice transcripts retained for the life of your account — deletable by you at any time
  • On closure or verified deletion request: production systems cleared within 30 days
  • Residual backup copies purged within 90 days
  • Billing records retained 5 years as required by Australian tax law

Your Rights

  • Access or correction of your personal information
  • Object to or restrict certain processing (GDPR)
  • Request deletion
  • Lodge a complaint with the OAIC at oaic.gov.au
  • GDPR-covered individuals: complain to your local supervisory authority

Contact: privacy@experteaseai.com

Data Breaches

We participate in the Notifiable Data Breaches scheme. If a breach is likely to result in serious harm, we notify affected individuals and the OAIC as required by law, and notify affected business customers so they can meet their own obligations.

→ Security controls and incident response

Privacy Questions?

Contact our privacy team directly — we respond to all access, correction, and deletion requests.

privacy@experteaseai.com →

Trust Centre  ·  Security  ·  AI Safety  ·  Sub-processors