Skip to content
Nexus Flow Innovations
Discuss your project
Legal

Privacy Policy

Last updated: September 2026Nexus Flow Innovations Pty Ltd · ABN 96 676 461 626

Nexus Flow Innovations Pty Ltd, ABN 96 676 461 626 ("NFI", "we", "us" or "our") is committed to protecting the personal information entrusted to us. This Privacy Policy explains what personal information we collect, how we collect, hold, use and disclose it, how you can access and correct it, and how to make a complaint. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy applies if you:

Visit our website at nexusflowinnovations.com, our social media pages, or other web pages we operate.

Use any website or application we develop and host.

Interact with an AI agent, assistant, chat, voice or automation system that we built or operate for one of our clients.

Contact us, request a proposal, engage our services, attend an event, subscribe to our content, or apply for a role with us.

1. What Personal Information Do We Collect?

The kinds of personal information we collect depend on how you interact with us.

1.1 Information You Provide Directly

Identity and contact details, such as your name, email address, phone number, job title, company and postal address.

Enquiry, proposal and project information, including the content of forms, emails, calls and meetings, and any materials, data or credentials you share with us to deliver the services.

Creative project materials, such as briefs, brand assets, photographs, footage, audio, voice, likeness, contributor or talent contact details, and records of releases, permissions and production approvals that you or an authorised contributor provides.

Payment and billing details, which are processed by our payment processor; we do not store full card numbers.

Communications, surveys, testimonials and feedback you give us, including recordings and transcripts of calls or meetings where we have told you they are being recorded.

Contact form submissions, which are protected by a bot check (Cloudflare Turnstile) and delivered to us by our email provider (Resend); both receive the technical data needed for that purpose, such as your IP address. The bot check runs invisibly in the background; Cloudflare describes what it processes in its Turnstile Privacy Addendum at cloudflare.com/turnstile-privacy-policy.

Recruitment information, such as your CV, work history, qualifications and referees, if you apply for a role.

1.2 Information Collected Automatically

When you use our website, we and our service providers automatically collect technical and usage information, including IP address, approximate location derived from it, browser and device type, operating system, language, referring pages, pages viewed, time spent, clicks, error logs and interactions with emails we send. See section 6 for cookies and similar technologies.

1.3 Information Processed for Our Clients

If you interact with a business that uses a system we built or operate ("Client"), for example a website assistant, voice agent, booking flow or email automation, the Client may collect and pass to us information such as:

Conversation transcripts, call recordings and voice data, where the Client has told you the interaction is recorded.

Details you provide during the interaction, such as your name, contact details, booking preferences, enquiry details and, where the Client's service requires it, health, dietary or other sensitive information.

Technical information about your device and session.

In these cases the Client controls the information and decides why and how it is used. We process it as the Client's service provider, only on the Client's instructions and under contract. If you have questions about how a Client uses your information, or wish to exercise rights in relation to it, contact the Client directly. Clients may have privacy practices we do not control, and we are not responsible for them.

1.4 Sensitive Information

We only collect sensitive information (such as health information, biometric data, or information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record) with your consent, or where a Client's system is designed and agreed to handle it with appropriate safeguards, or where the law permits. Voice recordings are handled as personal information and, where used to identify you, as biometric information.

1.5 Anonymity and Pseudonymity

You may deal with us anonymously or under a pseudonym where it is lawful and practicable, for example when browsing our website. We may not be able to provide services or respond to enquiries without certain information.

1.6 Unsolicited Information

If we receive personal information we did not ask for and could not have collected under the APPs, we will destroy or de-identify it as soon as practicable, where lawful.

2. How Do We Collect Personal Information?

We collect personal information:

Directly from you, through our website forms, email, phone, meetings, proposals, contracts, surveys, events and job applications.

From authorised creative contributors, talent or representatives who provide project materials and permission or release records.

Automatically, through cookies, pixels, analytics tools, server logs and software development kits when you use our website or emails.

From our Clients, when they engage us to build or operate systems that process their customers' information.

From third parties, including publicly available sources, business networking platforms, referral partners, marketing lists where you have opted in, payment processors, and identity or fraud-prevention services.

From AI and platform providers, in the form of usage logs and metadata generated when our systems call their services.

Where reasonable and practicable we collect personal information directly from you. If we collect it from someone else, we take reasonable steps to make sure you are aware of this policy.

3. How Do We Use Personal Information?

We use personal information for the purposes for which it was collected, for related purposes you would reasonably expect, and for purposes you have consented to or that the law permits, including to:

Respond to enquiries, prepare proposals and enter into and perform contracts with you.

Design, build, test, deploy, operate, monitor, support and improve the services you have engaged.

Produce agreed design, video and other creative deliverables; manage reviews and handover; verify permissions and licence restrictions; and keep records of approvals, releases and consent.

Process payments, issue invoices and manage accounts receivable.

Communicate with you about projects, services, changes to terms and policies, security and service notices.

Send you marketing, newsletters, case studies and event invitations where you have opted in or would reasonably expect it, with an easy way to unsubscribe at any time.

Analyse usage, measure performance, run analytics, diagnose problems and develop new features and services.

Train and enable our team, and maintain records of our work and decisions.

Protect our rights, property and safety and those of our clients and others, including detecting and preventing fraud, abuse and security incidents.

Comply with our legal and regulatory obligations, resolve disputes and enforce our agreements.

Assess job applications and manage recruitment.

AI Model Training

We do not use your personal information, or personal information we process for Clients, to train AI models. Where our AI providers offer them, we use enterprise, API or zero-data-retention configurations under which the provider does not use inputs or outputs to train its models. Where a provider or feature does not offer that control, we limit the data shared to what the feature needs and tell affected Clients.

Direct Marketing

We may use your business contact details to send you information about our services that we think will interest you, in accordance with the Spam Act 2003 (Cth) and the APPs. Every marketing message includes an unsubscribe option, and you can opt out at any time by using that option or by contacting us. We do not sell personal information and do not use sensitive information for marketing.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the APPs. Where the EU or UK General Data Protection Regulation applies, we rely on one or more of the following legal bases: your consent; performance of a contract with you or steps taken at your request before entering one; compliance with a legal obligation; and our or a third party's legitimate interests, such as operating and improving our business, securing our systems and marketing to business customers, where those interests are not overridden by your rights. Individuals in those jurisdictions have the additional rights described in section 8.

5. AI and Automated Processing

We use AI technologies to deliver our services. This section explains how, and what it means for you.

Providers We Use

Depending on the solution, your information may be processed by third-party AI and platform providers, which may include OpenAI, Anthropic, Google (Gemini), Voiceflow, ElevenLabs, Retell AI, Vapi and Groq, and by cloud, telephony, messaging and analytics providers. We choose providers that offer contractual data protection commitments and, where available, no-training and limited-retention settings.

How AI Processes Your Information

AI systems we build or operate may process your information to understand and respond to enquiries, qualify and route requests, book appointments, transcribe and summarise conversations, classify and file documents and emails, generate personalised content and recommendations, and automate routine tasks. Inputs and outputs may be logged for quality, debugging, safety and security purposes for a limited period.

Voice Agents and Recordings

Before we enable recording or transcription for a Client solution, we and the Client agree who is responsible for giving any notice, obtaining any consent required for the expected jurisdictions and context, and providing a refusal pathway. Where we control the recording, we provide the notice and seek consent required for that use. Recordings and transcripts are used only for the purposes disclosed for that deployment, such as completing your request or agreed quality assurance, and are retained for the period agreed with the Client. We do not reuse them for publicity, unrelated model training or synthetic voice or likeness creation unless that separate use has been specifically authorised and is lawful. You may ask the Client, or us where we are the controller, for a copy or for deletion, subject to legal retention requirements.

Disclosure That You Are Interacting With AI

Our AI agents identify themselves as automated where the law requires it and, as a matter of practice, will tell you they are an AI assistant if you ask.

Automated Decision-Making

Our systems are designed to assist and inform, not to make decisions with legal or similarly significant effects on you without human involvement. Where a Client's solution involves automated decisions that significantly affect you, you have the right to request human review, to express your point of view, to contest the decision and, where the law provides, to opt out. To exercise these rights, contact the Client, or contact us at [email protected] if we are the controller.

Accuracy of AI Outputs

AI outputs can be inaccurate or incomplete. We and our Clients apply human oversight proportionate to the use case. You should not rely on AI outputs as the sole basis for important decisions.

6. Cookies and Similar Technologies

We use cookies, pixels, local storage and similar technologies on our website to make it work, remember your preferences (such as your theme and cookie choices), measure performance and understand how they are used.

Strictly necessary: required for the site to function, including security, load balancing, your cookie choices and settings you set yourself, such as the site theme. These cannot be switched off.

Functional: remember choices you make on our website, such as form progress.

Analytics and performance: help us understand which pages and features are used, and diagnose errors. We use Google Analytics and similar tools, which set their own cookies and are subject to their providers' privacy policies.

Our content delivery network also reports aggregate, cookieless traffic and page performance measurements (page views, referrers, countries and load times). It does not store anything on your device, does not track you across sites and cannot identify you, so it runs without a consent choice.

Marketing: measure the effectiveness of our campaigns and, where you consent, show you relevant content on other platforms.

When you first visit our website you can accept or decline non-essential cookies in the consent banner, and you can change your choice at any time using "Cookie settings" in the footer. Analytics scripts are not requested until you accept performance cookies, and they are disabled, with their cookies cleared, when you withdraw that choice. You can also control cookies through your browser settings; refusing cookies may affect some features. We do not currently respond to browser "Do Not Track" signals because there is no agreed standard for them.

Where a Client uses our systems on its own website, the Client is responsible for obtaining any cookie consent required and for its own cookie notice.

7. Who Do We Disclose Personal Information To?

We do not sell personal information. We may disclose it to:

Our Clients, where you interact with a system we built or operate for them, and to their nominated systems (for example their CRM, booking or practice-management platform).

Service providers who help us operate our business and deliver our services under contract, including cloud hosting and infrastructure providers, AI and model providers, telephony, messaging and email providers, analytics, payment processors, customer support, document signing, accounting and professional advisers. They may only use personal information to provide services to us.

Subcontractors and partners who work on our engagements under confidentiality obligations.

Related bodies corporate and successors, including in connection with a merger, acquisition, financing, restructure or sale of assets, in which case we will require the recipient to honour this policy.

Regulators, law enforcement and courts, where required or authorised by law, to respond to lawful requests, or to establish, exercise or defend legal claims.

Others with your consent or at your direction.

We may also disclose information if we believe it is reasonably necessary to protect the rights, property or safety of NFI, our clients, our users or the public.

8. Your Rights: Access, Correction and Choices

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We will respond within 30 days. We may need to verify your identity, and in limited circumstances permitted by law we may refuse access or correction, in which case we will tell you why and how to complain.

You may also, at any time: opt out of marketing; withdraw consent where our handling relies on it; ask us to delete personal information we no longer need; and ask us to restrict or object to certain processing. Where the GDPR or UK GDPR applies, you additionally have a right to data portability. If we hold information on behalf of a Client, we will refer your request to the Client and assist them in responding.

To exercise any right, email [email protected]. We will not charge you for making a request, although we may charge a reasonable fee for providing access where the law allows.

9. How Do We Protect Personal Information?

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including:

Encryption of data in transit and at rest, and secure cloud infrastructure with reputable providers.

Access controls, least-privilege permissions, multi-factor authentication and audit logging for our systems.

Contractual data protection commitments from our providers and subcontractors, and no-training or limited-retention configurations with AI providers where available.

Secure development practices, testing, monitoring and regular review of our security measures.

Staff confidentiality obligations and training.

If a data breach occurs that is likely to result in serious harm to individuals, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme, and support our Clients in meeting their own notification obligations. No system is completely secure, and we cannot guarantee absolute security.

10. How Long Do We Keep Personal Information?

We keep personal information only for as long as needed for the purposes described in this policy, including to provide services, maintain business records, comply with legal, tax and accounting obligations (generally 7 years for financial records), resolve disputes and enforce agreements. Information processed for a Client is kept for the period set out in our agreement with the Client and then returned or securely deleted. Conversation and call logs, raw creative media and working files are kept for the project-specific periods agreed with the Client; release, consent and approval records may be retained as long as reasonably needed to evidence permitted use or meet legal obligations. When information is no longer needed we securely destroy or de-identify it, subject to routine encrypted backups, which are overwritten on their normal cycle.

11. Overseas Disclosure

We use cloud, AI and communications providers whose servers may be located outside Australia, including in the United States, the European Union and other countries where our providers operate. Personal information may therefore be stored or processed overseas. Before disclosing personal information to an overseas recipient we take reasonable steps under APP 8 to ensure it will be handled in accordance with the APPs, including by using providers with contractual data protection commitments, standard contractual clauses where required, and appropriate security. We do not rely on your consent alone for these disclosures. We keep a register of our providers and their processing countries, available on request, and we tell Clients before a new provider or country is introduced for their solution.

12. Government Identifiers

We do not use or disclose government-related identifiers, such as tax file numbers or driver licence numbers, except where required or authorised by law, and we do not use them as our own identifiers.

13. Third-Party Websites and Public Forums

Our website may link to third-party websites, platforms and services, including social media, technology partners and our Clients' sites. This policy does not apply to them, and we are not responsible for their privacy practices. Information you post in public forums, comments, communities or social media is publicly accessible and may be read, collected and used by others. Please take care before sharing personal information publicly.

14. Children

Our website and services are intended for business users and adults. We do not knowingly collect personal information from anyone under 16 without parental or guardian consent. If you believe a child under 16 has provided us with personal information, contact us at [email protected] and we will delete it where required.

15. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, services, technology or the law. The current version is always available on our website with its "last updated" date. For material changes we will take reasonable steps to notify you, for example by email or a notice on our website, and we will seek consent where the changed handling requires it by law.

16. Complaints and Contact

If you have a question, concern or complaint about how we have handled your personal information, contact our Privacy Officer:

Nexus Flow Innovations Pty Ltd

ABN 96 676 461 626

Email: [email protected]

Website: www.nexusflowinnovations.com

We will acknowledge your complaint within 7 days, investigate it and respond in writing within 30 days.

Questions about this document: [email protected]Terms of Service