ApplySmarts (applysmarts.com.au) is committed to protecting the privacy and security of your personal and corporate data. This Privacy Policy outlines how we collect, use, disclose, and safeguard information when you visit our website, interact with our public edge utilities, or engage our Governance-as-a-Service (GaaS) architecture.
We operate under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and strict enterprise data sovereignty protocols.
1. The Core Paradigm: In-Tenant Separation
Data Boundary Guarantee: ApplySmarts deploys its core software modules directly within your private enterprise cloud perimeter (Microsoft Azure/Fabric, Google Cloud Platform, or Amazon Web Services). All primary corporate records, client files, personal identification parameters, and operational incident logs reside inside your own cloud tenant. ApplySmarts does not host, replicate, or store your primary business data on our local servers.
This Privacy Policy applies strictly to the data captured by our public-facing website, edge webhook gateways, and administrative operational pipelines.
2. Information We Collect
We collect information that identifies, relates to, describes, or could reasonably be linked with an individual or corporate entity (“Personal Information”).
A. Information You Provide Directly to Us
- Contact & Inquiry Data: Name, business email address, phone number, company name, and job title collected via our contact and consultation forms.
- Diagnostic & Assessment Data: Operational answers, industry selection, and compliance readiness parameters supplied when using our Smart Governance Diagnostic (
/readiness-assessment) or Compliance Risk Matrix Builder. - Discovery & Onboarding Input: Structural metrics, software stack preferences, and operational pain points logged through our conversational Pre-Consultation Context Capture Agent.
B. Automated Telemetry & Edge Interface Data
- Voice Telemetry Streams: When utilizing our voice intake streams, temporary audio fragments and real-time metadata pass securely through our API webhooks to generate text transcriptions before being instantly routed to your secure cloud bucket.
- Device & Usage Metrics: IP addresses, browser types, operating systems, referring URLs, access times, and clickstream paths recorded via our Cloudflare edge shields and standard website performance logs.
3. How We Use Your Information
- Funnel Personalization: Powering the AI Regulatory Navigator and Role-Based Content Feed to show you compliance insights relevant to your jurisdiction.
- Diagnostic Report Generation: Compiling your diagnostic answers into your Personalized Maturity Scorecard delivered as a customized PDF download.
- Service Scoping & Proposal Preparation: Processing form context vectors through our backend script to build tailored, automated integration proposals and technical blueprints.
- Webhook Authentication & Security: Reviewing incoming custom header keys to verify the integrity of data streams and protect our isolated backend architecture.
- Communications: Sending critical regulatory bulletins, framework updates, and operational follow-up items linked to your designated area of interest.
4. How We Share and Disclose Data
ApplySmarts does not trade, sell, or rent your corporate or personal data to external marketing groups. Data disclosures are restricted to the following functional vectors:
- Third-Party Infrastructure Proxies: We share necessary data streams with hardened technical utilities required to execute edge services (such as Twilio for voice routing or Cloudflare for threat mitigation) operating under explicit privacy agreements.
- Enterprise Cloud APIs: Data processed through our intelligent automation layer interacts with private generative and vision processing pipelines hosted in local, secure cloud regions (such as Azure Australia East).
- Legal Mandates: We will disclose information if required by law, subpoena, or direct mandate from an authorized Australian court or regulatory body to protect system safety or legal rights.
5. Data Sovereignty, Retention, and Security
5.1. Data Residency: All processing engines, isolated FastAPI nodes, and metadata caches used by ApplySmarts are deployed strictly within Australian borders to ensure compliance with national data-residency expectations.
5.2. Security Architecture: Our public WordPress ecosystem is entirely separated from our backend calculations. We apply multi-layered protection frameworks, including verification of secure cryptographic header tokens on all inbound API packets, absolute exclusion of master cloud or language model API keys from our front-end databases, and continuous encapsulation of storage nodes behind reverse Nginx proxies within isolated Docker containers.
5.3. Retention Limits: Website lead metadata and diagnostic inputs are preserved for the minimum period required to fulfill administrative engagement tracking or active service contracts, after which they are programmatically scrubbed or anonymized.
6. Your Rights Under Australian Privacy Law
Under the Australian Privacy Principles, you maintain explicit control over your personal data. You may exercise the following rights at any time by contacting our privacy officer:
- The Right to Access: Request an extracted copy of any personal information ApplySmarts holds about you or your organization.
- The Right to Correction: Demand the immediate updating or rectification of inaccurate, outdated, or incomplete data records.
- The Right to Deletion: Request that your contact histories and diagnostic records be permanently scrubbed from our pipeline databases.
- The Right to Lodge a Complaint: If you believe ApplySmarts has breached the APPs, you retain the right to lodge a formal complaint with us directly or escalate the matter to the Office of the Australian Information Commissioner (OAIC).
7. Changes to This Privacy Policy
ApplySmarts reserves the right to modify this Privacy Policy to align with technical modifications, architectural expansions, or updating statutory guidelines from Australian watchdogs. Any amendments will become instantly active upon the publication of the updated text framework to this page.
8. Contact Information
To submit data clearance requests, update your practice profile, or communicate privacy inquiries, please contact our data security team: