Legal

Privacy Policy

How Novareck AI handles personal information, written to the Australian Privacy Principles under the Privacy Act 1988 (Cth).

1. Who we are

Novareck AI ("Novareck", "we", "us", "our") is an independent AI risk and governance consultancy operating in Australia. This policy explains how we collect, hold, use, disclose and protect personal information.

We are committed to handling personal information in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). Where a small business exemption may apply to us, we have chosen to comply with the APPs as a matter of practice, because we consider it inconsistent with our work to do otherwise.

2. What information we collect

The personal information we collect depends on your relationship with us. It may include:

CategoryExamples
Contact detailsName, work email address, phone number, organisation, job title
Enquiry contentInformation you provide in a contact form, email or during a call
Engagement recordsCorrespondence, meeting notes, deliverables, invoices and payment records
Subscription detailsEmail address and preferences if you subscribe to our updates
Technical dataIP address, browser type, device type, pages visited, referring page

We do not seek to collect sensitive information as defined in the Privacy Act (such as health information, racial or ethnic origin, political opinions, or religious beliefs). Please do not send us sensitive information unless we have specifically requested it for a defined purpose.

3. How we collect it

We collect personal information:

  • Directly from you, when you contact us, submit a form, subscribe to updates, or engage us for services
  • During the course of delivering an engagement
  • Automatically, through standard web server logs and any analytics we operate
  • From publicly available sources, such as a company website or a professional networking profile, where we are researching a potential client organisation

Where it is reasonable and practicable, we collect personal information directly from you.

4. Why we collect it and how we use it

We collect and use personal information to:

  • Respond to your enquiry and arrange a discovery conversation
  • Prepare proposals and deliver our consulting, training and advisory services
  • Communicate with you about an active engagement
  • Issue invoices and maintain financial and tax records
  • Send updates you have subscribed to
  • Improve our website and understand which content is useful
  • Meet our legal, regulatory, insurance and record-keeping obligations

We will not use your personal information for a purpose unrelated to those above unless you would reasonably expect it, you have consented, or we are required or authorised by law.

5. Client data during an engagement

Our work frequently involves reviewing an organisation's systems, tools, policies and processes. In doing so we may be given access to information that includes personal information about your employees, contractors or customers.

Our commitments

  • We treat all client information as confidential and use it only for the purposes of the engagement
  • We seek to work with de-identified, sampled or minimised data wherever the engagement objective can still be met
  • We do not use client data to train any machine learning model
  • We do not disclose client identities publicly without written agreement
  • Where we handle personal information on your behalf, we do so subject to the engagement terms and any additional data handling requirements you specify

Specific arrangements including confidentiality, data handling, retention and return or destruction of materials are set out in the engagement agreement for each project.

6. Who we disclose information to

We may disclose personal information to:

  • Service providers who support our operations, such as email and cloud hosting providers, accounting software, and payment processors
  • Delivery partners, where an engagement includes development or specialist work delivered by a third-party partner. Where this applies, the partner is disclosed to you before work begins and is bound by confidentiality obligations
  • Professional advisers such as our accountant, insurer or lawyers, where reasonably required
  • Government agencies or regulators, where required or authorised by law

We do not sell, rent or trade personal information. We do not disclose your information to advertisers.

7. Overseas disclosure

Some of the service providers we rely on, including cloud hosting and email providers, may store or process data outside Australia. Where this occurs, we take reasonable steps to ensure the recipient handles the information in a manner consistent with the Australian Privacy Principles.

If you would like to know the countries in which our current providers store data, contact us at info@novareck.com and we will tell you.

8. Artificial intelligence tools

Given the nature of our work, we think you are entitled to a direct answer on this.

  • We use AI tools internally to support research, drafting and analysis
  • We do not input client confidential information or personal information into consumer AI tools
  • Where AI tools are used on engagement material, they are configured so that inputs are not used to train the provider's models, and their use is disclosed and agreed with the client
  • A human reviews and is accountable for every deliverable we issue
  • We do not use AI to make automated decisions that have a legal or similarly significant effect on any individual

9. Cookies and website analytics

Our website may use cookies and similar technologies to make the site function correctly and to understand how it is used in aggregate.

You can configure your browser to refuse cookies or alert you when cookies are being sent. Some parts of the site may not function as intended if you do.

If we operate analytics, we do so on an aggregate basis and do not attempt to identify individual visitors.

10. Direct marketing and email

If you subscribe to our updates, we will use your email address to send those updates and nothing else. Every message includes an unsubscribe link that works, and we action unsubscribes promptly.

We may send commercial electronic messages to business contacts where permitted under the Spam Act 2003 (Cth). All such messages identify us clearly and include a functional unsubscribe facility.

You can opt out at any time by using the unsubscribe link or emailing info@novareck.com.

11. How we store and secure information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include:

  • Access controls and multi-factor authentication on business systems
  • Encryption of data in transit and, where supported by the provider, at rest
  • Limiting access to information to those who need it to perform the engagement
  • Confidentiality obligations on any partner or contractor we engage
  • Periodic review of the tools and providers we rely on

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.

12. How long we keep it

We keep personal information only as long as it is needed for the purposes described in this policy, or as required by law. Financial and tax records are generally retained for at least five years as required under Australian tax law.

Engagement materials are retained, returned or destroyed in accordance with the relevant engagement agreement. Where information is no longer needed and we are not required to keep it, we take reasonable steps to destroy or de-identify it.

13. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

Email info@novareck.com with your request. We will respond within a reasonable period, ordinarily within 30 days. We may need to verify your identity before providing access.

There is no charge for making a request. If a request is complex we may charge a reasonable cost of providing access, and we will tell you before we do. If we refuse access or correction, we will explain why in writing and tell you how to complain.

14. Complaints

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please tell us first. Email info@novareck.com with the details.

We will acknowledge your complaint, investigate it, and respond in writing, ordinarily within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

15. Data breaches

We maintain a data breach response process. If a data breach occurs that is likely to result in serious harm to any individual whose personal information is involved, we will assess it and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the OAIC as required under Part IIIC of the Privacy Act 1988 (Cth).

16. Changes to this policy

We may update this policy from time to time. The current version is always available at this page, and the effective date is shown at the top. Material changes will be communicated to active clients directly.

Contact us

Novareck AI
Email: info@novareck.com
Melbourne, Victoria, Australia