LegalData Security & AI Compliance
We apply technical and operational safeguards to help keep your business data and customer conversations secure, private and handled in line with Australian requirements.
1. Data Encryption and Security
In transit: communications routed through our platform, including web chat, SMS, voice AI and social messages, are protected using industry-standard Transport Layer Security (TLS), version 1.2 or above.
At rest: client databases, customer records and business knowledge bases are stored using AES-256 encryption.
Workspace isolation: each client's workspace is provisioned separately with strict data partitioning. Your data is not visible to other clients.
2. Data Storage and Infrastructure Location
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We deliver our services through enterprise-grade cloud infrastructure, with data centres located in the United States. In line with Australian Privacy Principle 8 (APP 8) on cross-border disclosure, please note that your customer records and AI knowledge base are stored on these US servers. Data is encrypted at rest and in transit wherever it is located, and our partners are bound by contractual data processing obligations.
3. AI Data Privacy
Data isolation: your business data, price lists and customer chat histories are kept separate from other clients' data. Data used to set up your AI Employees is not shared with other clients.
Third-party AI providers: our AI features rely on enterprise-grade AI interface agreements, and data processing is governed by the data processing terms of the relevant third-party providers.
Human oversight: you can view AI conversation histories in real time, step in and take over live conversations, or change AI-made bookings.
4. Telecommunications and Anti-Spam Compliance
Our tools are designed to support compliance with Australian communications law:
Spam Act 2003 (Cth): our marketing automation tools include automatic opt-out keywords (for example, “Reply STOP to opt out”) to help your SMS and email campaigns meet Australian requirements. Responsibility for compliance remains with the sender, which is you.
Do Not Call Register Act 2006 (Cth): you must ensure your outbound calling lists comply with the Do Not Call Register rules and must not make unauthorised marketing calls to registered numbers.
5. Backups and Data Deletion
Backups: your customer database, customer lists and conversation histories are backed up automatically on a regular basis to secure cloud servers, to support disaster recovery. Backup copies are kept for up to 12 months, as described in our Privacy Policy.
Deletion requests: you may ask us to permanently delete your business data and associated records at any time. Verified requests will be actioned within 30 days, subject to the backup and legal retention periods set out in our Privacy Policy.
6. Contact and Compliance Enquiries
For questions about our data security or compliance measures, please contact us at myaiboss.com/contact-us.