Home/Legal & Trust Centre/GDPR Compliance Statement

Privacy & data protection

GDPR Compliance Statement

Our commitment to the EU General Data Protection Regulation

Effective date1 January 2026
Document versionVersion 1.0
Product websitehivenox.com
Operated byAI Solution Technologies Pty Ltd
Registered officeSuite 6, 191 Church Street, Parramatta, Sydney NSW 2150, Australia

This document is published in English. The English text is the governing version.

Our commitment under the EU and UK GDPR: lawful bases, data subject rights and transfers.

1. Introduction

AI Solution Technologies Pty Ltd (“AI Solution Technologies”, “we”, “us” or “our”), operator of the Hivenox platform, is committed to protecting the personal data of individuals in the European Economic Area (“EEA”) and the United Kingdom. This Statement explains how we comply with Regulation (EU) 2016/679 (the “GDPR”) and the UK GDPR where they apply. It supplements our Privacy Policy.

2. When the GDPR applies

The GDPR applies where we offer the Service to individuals in the EEA or UK, monitor their behaviour there, or process personal data on behalf of Customers subject to the GDPR. Where the GDPR does not apply, we handle personal information under the Australian Privacy Act 1988 (Cth) and the APPs.

3. Controller and processor roles

Controller — we act as controller for personal data of our website visitors, prospects, account administrators and billing contacts, and for our own business operations.

Processor — we act as processor for Customer Data processed within the Hivenox platform on behalf of Customers. That processing is governed by our Data Processing Agreement.

4. Principles

We process personal data lawfully, fairly and transparently; for specified, legitimate purposes; limited to what is necessary; accurately; for no longer than necessary; and securely — and we can demonstrate our compliance (accountability).

5. Lawful bases (controller)

  • Consent — for specific purposes where you have given clear consent;
  • Contract — to provide the Service and administer your subscription;
  • Legal obligation — to comply with law;
  • Legitimate interests — to operate, secure, improve and market the Service, where not overridden by your rights.

6. Data subject rights

Where the GDPR applies to us as controller, you have rights to be informed, access, rectification, erasure, restriction, data portability, objection, and rights relating to automated decision-making. Where your data is processed as Customer Data, please contact the relevant Customer (controller); we will assist that Customer as required under our Data Processing Agreement.

To exercise rights against us as controller, contact info@hivenox.com. We respond within one month, subject to permitted extensions.

7. International transfers

We may transfer personal data outside the EEA and UK, including to Australia, the United States, the United Arab Emirates and the Kingdom of Saudi Arabia. Where required, we use an appropriate transfer mechanism such as the European Commission’s Standard Contractual Clauses (with the UK Addendum or IDTA where applicable), together with any necessary supplementary measures.

8. Security

We implement appropriate technical and organisational measures — including encryption, access controls, multi-factor authentication, monitoring, secure development and governance aligned with ISO/IEC 27001 and ISO/IEC 42001 — to ensure a level of security appropriate to the risk.

9. Personal data breaches

As controller, where a breach is likely to risk individuals’ rights and freedoms, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, and notify affected individuals for high-risk breaches. As processor, we notify the relevant Customer without undue delay.

10. Sub-processors and AI providers

We engage sub-processors (including cloud hosting, analytics, communications, payment and AI model providers) under contractual data protection terms consistent with the GDPR. Our processing as a processor, and our sub-processor arrangements, are described in our Data Processing Agreement.

11. Supervisory authority

If you are in the EEA or UK and consider our processing infringes data protection law, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concerns first.

12. Changes

We may update this Statement from time to time. It is effective from 1 January 2026.

Contact Us

If you have any questions about this document, or wish to exercise any of your rights, please contact us using the details below.

Hivenox — operated by AI Solution Technologies Pty Ltd

Also in the Trust Centre

The other documents

Talk to HIVENOX

Questions about how we would run it for you?

The policies set out the rules. The team can walk you through how they apply to your data, your contracts and your markets.