Privacy Policy
Aligned to the Australian Privacy Principles (Privacy Act 1988 (Cth)). Effective date on publication · Version 2.1 (draft — pending legal review; v2.0 of 3 August 2026 remains current)
Flowmatix builds workplace software for Australian business: visitor and contractor sign-in, maintenance and works management, and AI Reception, an AI phone receptionist that answers calls for businesses. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs).
- Information we collect
- Why we collect it
- Consent at sign-in
- AI processing & phone calls (AI Reception)
- How we use & disclose it
- Direct marketing & our emails
- Where it is processed (overseas disclosure)
- Payments & billing
- Who can access it
- Security & data breaches
- Keeping it accurate
- Retention
- Your access & correction rights
- This website (cookies & analytics)
- Children's information
- Links to other websites
- Complaints
- Contact us
- Changes to this policy
1. Information we collect · APP 3 & 5
We collect only what is reasonably necessary to run the service for our customers:
- Visitor sign-in records: name, organisation, host/person visited, purpose, time in and out, and — where the site requires it — vehicle details, a typed or drawn signature, and an optional sign-in photo.
- Contractor records & inductions: name, company, contact details, licences/clearances a site requires, and versioned, timestamped acceptance of the site's induction and agreements (site rules, SWMS, NDA).
- Maintenance & works data: work requests, suppliers and quotes, and related operational records our customers enter.
- Phone call records (AI Reception): when AI Reception answers a call for one of our business customers, we collect the caller's phone number, a text transcript of the conversation, the details the caller chooses to leave — for example a name, a callback number, a message, a booking request or an enquiry — and a summary of the enquiry that the AI assembles from the conversation (the message or booking details passed to the business). Because those summaries are AI-generated, they can contain errors; see Keeping it accurate. We do not keep audio recordings of calls; see AI processing & phone calls for exactly how call audio is handled.
- Account data for users who sign in: name, email, role, and sign-in activity (for security and audit).
- Enquiries and demo requests: if you contact us or request a demo through this website, we collect what you submit — name, email, phone, organisation, role and your message.
- Technical & security logs: actions taken in the app, timestamps, and an audit trail of changes.
We collect personal information at the point of sign-in (from the visitor or contractor), on phone calls AI Reception answers (from the caller), and from records our customers enter. We make this policy available and tell people who we are, why we are collecting the information, and how to reach us (APP 5).
2. Why we collect it · APP 3
- To operate site sign-in, emergency roll-call and evacuation lists, and a defensible record of who was on site and when.
- To manage contractor compliance — inductions, agreements and required clearances.
- To run maintenance and works — logging jobs, quoting and supplier coordination.
- To answer our customers' phone calls with AI Reception — taking messages, capturing enquiries and booking requests, and giving the business a transcript of every call so nothing is lost.
- To respond to your enquiries and demo requests.
- To troubleshoot problems, support administrators and maintain an audit history for accountability and security.
We do not collect more than we need to run the service.
3. Consent at sign-in · APP 3 & 5
Before a visitor or contractor's details are recorded, the sign-in screen presents the site's collection notice and — where the site requires it — an induction briefing and agreement that the person must accept to continue. Each acceptance is stored as versioned, timestamped evidence against the sign-in. Where an optional photo is captured, it is taken with the person's on-screen consent and can be disabled by the site. This is how we ensure a person is told about, and agrees to, the collection before it happens.
4. AI processing & phone calls (AI Reception) · APP 5 & 8
AI Reception is an AI receptionist. Being straight about how it works matters to us, so here it is in full:
- What happens on a call. When AI Reception answers, the call audio is streamed in real time to AI speech and language services so it can understand the caller and reply. We use commercial AI providers for this — currently OpenAI and Anthropic (speech recognition and conversation) and ElevenLabs and Microsoft Azure (voice synthesis). This processing may occur on servers outside Australia, and is an overseas disclosure for the purposes of APP 8.
- What we keep. The text transcript, the caller's number, the details the caller leaves, and the enquiry summary the AI assembles are stored on Flowmatix infrastructure in Australia, visible only to the business that received the call. We do not store audio recordings of calls.
- Provider terms. We use these providers' business APIs — not their consumer products — under service terms that restrict how the data may be used and retained. We only send the audio and text needed to handle the call.
- Transparency on the call. AI Reception answers on behalf of the business and confirms it is an AI assistant when asked. Callers can always ask for a human, and businesses using AI Reception remain responsible for telling their callers how their information is handled.
- No training, no profiling by us. We do not use call content to build profiles of callers, and we do not sell it or use it for advertising.
Elsewhere in the platform — visitor sign-in, maintenance and works — records are processed on our own servers in Australia without AI services, unless a feature clearly tells you otherwise.
5. How we use & disclose it · APP 6
We use and disclose personal information only for the purposes above (the primary purpose for which it was collected), for directly related purposes you would reasonably expect, or where required or authorised by law (for example, providing an evacuation roll to emergency services). We do not sell personal information, and we do not disclose it to third parties for their own marketing. We use a small number of service providers strictly to operate the service — hosting, message delivery, payments and the AI services described above (see Where it is processed). Each is bound to use the data only to provide the service to us.
6. Direct marketing & our emails · APP 7
We never use visitor sign-in records, contractor records, AI Reception call records or other operational data for direct marketing — those records belong to the business that collected them, full stop.
If you ask us for a demo, download a resource or enquire through this website, we will reply, and we may follow up with a small number of emails about the thing you asked about. Every one of those emails tells you how to opt out — replying to say "no thanks" is enough — and we stop promptly. If we send service or product updates to a customer contact, the same applies.
7. Where it is processed (overseas disclosure) · APP 8
Customer records — sign-in data, operational records, AI Reception call transcripts and account data — are stored on servers in Australia. Some processing involves overseas providers:
- AI speech and language processing (AI Reception calls): OpenAI, Anthropic, ElevenLabs and Microsoft Azure, as described in section 4. Call audio and conversation text may be processed outside Australia during a call.
- Payments: Stripe processes subscription payments, which may involve processing outside Australia (see section 8).
- Website analytics: Google Analytics on this marketing website (see section 14).
- Notification delivery: where we use sub-processors to deliver email or SMS notifications, the minimum data needed to send them may be processed in or outside Australia.
We take reasonable steps to ensure any overseas recipient handles the information consistently with the APPs, including using providers' business-grade services under contractual data-protection terms.
8. Payments & billing
Subscription payments are processed by Stripe. When you start a trial or subscribe, your card details are collected by Stripe directly — Flowmatix never stores your card number on our servers. We keep the billing records we need (plan, invoices, payment status). Stripe's own privacy policy covers its handling of payment data, which may include processing outside Australia.
9. Who can access it
- Our customer's authorised administrators — for their site/business only. That includes AI Reception call transcripts and messages, which are visible only to the business that received the call.
- Authorised Flowmatix support personnel — only where required to operate or troubleshoot the service; support access is recorded in the audit log.
- Each customer's data lives in its own isolated database — one customer can never see another's records.
10. Security & data breaches · APP 11 & NDB scheme
- Encrypted connections (HTTPS) and role-based access control — users only see what their role allows.
- Sign-in throttling, idle session timeout, optional two-factor authentication, and an audit trail of changes.
- AI Reception runs on dedicated infrastructure, separate from the rest of the platform.
- We do not store passwords, API keys, session tokens or raw authentication data alongside operational records.
If a data breach is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme, and support customers' own notification obligations.
11. Keeping it accurate · APP 10
Authorised users can view and correct most records directly in the app. We take reasonable steps to keep the personal information we hold accurate, up to date and complete for the purpose it is used. One honest caveat: AI transcription and summarisation are very good but not perfect — a call transcript, and the enquiry summary the AI assembles from it, are working records of a call and may occasionally mishear or misstate a word, a name or a detail. Businesses confirm important details (like bookings) with a human before acting on them.
12. Retention
- Sign-in and operational records are retained for the period each customer configures, or as required by their own record-keeping and safety obligations, then deleted or de-identified.
- AI Reception call transcripts and messages are retained for 12 months, then deleted, so the business can review its recent calls. We delete them earlier at the customer's request, and on request from a caller via the business they called.
- Enquiry and demo-request details are kept as long as needed to follow up, and deleted on request.
- Action and audit logs are kept separately, for longer, to meet operational record requirements.
- On termination, data is returned or deleted as agreed in the services agreement.
13. Your access & correction rights · APP 12 & 13
You may ask to access the personal information we hold about you, or to correct or delete it. If you signed in at a site or called a business that uses AI Reception, the fastest path is that business — it controls the record. You can also contact us (below); we will respond within a reasonable time and, if we cannot give access or make a correction, we will explain why.
14. This website (cookies & analytics)
This marketing website uses Google Analytics 4 to understand how visitors find and move through the site. Google Analytics sets cookies (named _ga and _ga_*) holding a randomly generated identifier, and records the pages you view, your approximate location derived from your IP address, and your device and browser type. That information is processed by Google LLC, including on servers outside Australia — an overseas disclosure for the purposes of Australian Privacy Principle 8. We do not send Google your name, your email address, or anything you type into a form. You can opt out across all sites using Google's browser add-on at tools.google.com/dlpage/gaoptout, or by blocking third-party scripts in your browser. Alongside this we keep a first-party visit count that uses a daily-rotating one-way hash, honours your browser's Do Not Track setting, and cannot identify you or follow you across days. We set no advertising or re-targeting cookies. The signed-in app uses a single, strictly-necessary session cookie to keep you logged in and does not run Google Analytics.
15. Children's information
Our services and this website are directed at businesses, not at children. We do not knowingly collect personal information directly from children, and nothing on this website is designed to attract them. If you believe a child has provided personal information to us directly — for example through a form on this website — contact us (below) and we will delete it.
16. Links to other websites
This website links to external sites we don't operate — for example the OAIC, Google's opt-out tools, and our providers' policies. This policy covers only Flowmatix. We are not responsible for the privacy practices or content of external sites; check their own privacy policies before providing personal information to them.
17. Complaints
If you believe we have mishandled your personal information, please contact our Privacy Officer (below). We will acknowledge your complaint and aim to resolve it within a reasonable time. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, 1300 363 992.
18. Contact us · APP 1
Privacy Officer, Flowmatix
Email: [email protected] or [email protected]
Flowmatix Aus Pty Ltd · Registered in Australia · ABN 31 701 379 731
19. Changes to this policy
We may update this policy from time to time. The effective date and version at the top show the current version; material changes will be notified to customers. Continued use of the service after an update means the updated policy applies.
Version 2.1 (draft) adds: children's information, links to other websites, and AI-assembled call and enquiry summaries. Version 2.0 (3 August 2026) replaced Version 1.0 (7 July 2026). What changed in 2.0: added AI phone reception — call transcripts, the AI providers involved and where they process data — plus payments (Stripe), demo-enquiry follow-up emails, and updated retention. The earlier statement that Flowmatix does not use AI processing no longer applies and has been removed.