Home/Legal & Trust Centre/Privacy Policy

Privacy & data protection

Privacy Policy

How we collect, use, protect and disclose your personal information

Effective date1 January 2026
Document versionVersion 1.0
Product websitehivenox.com
Operated byAI Solution Technologies Pty Ltd
Registered officeSuite 6, 191 Church Street, Parramatta, Sydney NSW 2150, Australia

This document is published in English. The English text is the governing version.

What personal information we collect, how we use and protect it, and the choices you have.

1. Introduction

Hivenox is a software-as-a-service (“SaaS”) platform — including ERP, CRM, HRMS, finance, service desk, operations and AI agent products — owned and operated by AI Solution Technologies Pty Ltd (“AI Solution Technologies”, “we”, “us” or “our”). This Privacy Policy explains how we collect, hold, use, disclose and protect personal information when you visit hivenox.com (the “Website”), register for or use the Hivenox platform (the “Service”), request a demo, or otherwise interact with us.

We handle personal information in accordance with the Privacy Act 1988 (Cth) (the “Privacy Act”) and the Australian Privacy Principles (“APPs”) in Schedule 1 to that Act. Where we handle the personal data of individuals in the European Union, the United Kingdom, or other jurisdictions, we also take steps to comply with applicable laws, including the EU General Data Protection Regulation (“GDPR”), as described in our GDPR Compliance Statement.

2. Controller and processor roles

It is important to distinguish two kinds of information:

  • Information we handle as controller — personal information about Website visitors, prospects, account administrators, billing contacts and authorised users, which we collect and use for our own purposes (for example, to provide and administer the Service). This Privacy Policy governs that information.
  • Customer Data we process as processor — content that our subscribers (“Customers”) and their users upload to, or generate within, the Hivenox platform, which may include personal information about the Customer’s own employees, contacts, customers and other individuals. We process this Customer Data on behalf of, and under the instructions of, the Customer. Our handling of Customer Data is governed primarily by the Customer’s agreement with us and our Data Processing Agreement, not by this Privacy Policy. If you are an individual whose data is held in a Customer’s Hivenox account, please contact that Customer, who is the controller of that data.

3. The personal information we collect

Depending on how you interact with us, we may collect:

  • Account and identity data — name, job title, organisation, business email address, username and authentication credentials.
  • Contact and enquiry data — information you provide when you request a demo, contact sales or support, or subscribe to communications.
  • Billing data — billing contact, billing address, plan details and transaction records. Card payments are processed by third-party payment processors; we do not store full card numbers.
  • Usage and telemetry data — log data, feature usage, device and browser information, IP address, and diagnostic data generated when you use the Service, used to operate, secure and improve it.
  • Support data — information contained in support requests, correspondence and, where applicable, session records.
  • Cookies and analytics data — collected via cookies and similar technologies on the Website and in the Service (see our Cookies Policy).
  • AI interaction data — prompts, inputs and interactions with Hivenox AI features (such as AI Sales Agent, AI Support Agent, AI Recruiter, Voice AI and Insights AI), used to provide and improve those features consistent with this Policy and our contractual commitments.

4. How we collect personal information

We collect personal information: directly from you when you register, contact us or use the Service; automatically through cookies, logs and telemetry; from your organisation or account administrator; and from third parties such as our partners, resellers, integration providers and publicly available sources. Where reasonable and practicable, we collect personal information directly from the individual.

5. Why we collect, hold and use personal information

We use personal information to:

  • create, administer and secure accounts and provide the Service;
  • process subscriptions, billing and payments;
  • provide customer support and communicate about the Service;
  • operate, maintain, monitor, troubleshoot and improve the Service and its AI features;
  • personalise and develop new features and products;
  • send administrative and, where permitted, marketing communications;
  • detect, prevent and respond to fraud, abuse, security incidents and misuse; and
  • comply with legal obligations and enforce our terms.

We use personal information only for the primary purpose for which it was collected, a directly related secondary purpose you would reasonably expect, or where you consent or the law permits or requires.

6. Use of data to improve the Service and AI features

We may use aggregated and de-identified data derived from use of the Service to operate, secure, analyse and improve Hivenox. We do not use Customer Data to train generative AI models for the benefit of other customers except where permitted by the applicable Customer agreement or where the data has been aggregated and de-identified so that it no longer identifies any individual or Customer. Any third-party AI model providers we use are engaged as sub-processors under contractual confidentiality and data protection terms.

7. Direct marketing

We may send you marketing about Hivenox where permitted under the Privacy Act and the Spam Act 2003 (Cth). Each commercial electronic message identifies us and includes an unsubscribe facility. You can opt out at any time via the unsubscribe link or by contacting info@hivenox.com.

8. Disclosure of personal information

We may disclose personal information to:

  • our personnel, related entities and offices (including in the United Arab Emirates and the Kingdom of Saudi Arabia) on a need-to-know basis;
  • sub-processors and service providers who host, support and help operate the Service (including cloud infrastructure, analytics, communications, payment and AI model providers);
  • your organisation and its administrators, where you use the Service under a Customer account;
  • professional advisers, and parties to a proposed or actual business sale, merger or reorganisation; and
  • government, regulatory or law enforcement bodies where required or authorised by law.

We require our sub-processors and service providers to protect personal information consistently with this Policy and applicable law. We do not sell personal information.

9. Overseas disclosure

The Service is delivered using cloud infrastructure and providers (such as Microsoft Azure and Amazon Web Services) that may store or process data outside Australia, including in the United States, the European Union, the United Arab Emirates and the Kingdom of Saudi Arabia. Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, or we rely on another basis permitted under APP 8, such as your consent. Customers may, where offered, select a preferred data hosting region for their account.

10. Security and storage

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our controls include encryption in transit and at rest, access controls and multi-factor authentication, network security, monitoring, secure development practices, personnel training, and information security and AI governance aligned with ISO/IEC 27001 and ISO/IEC 42001. No system is completely secure, and we cannot guarantee absolute security.

We retain personal information for as long as necessary to provide the Service, comply with legal, tax and accounting obligations, resolve disputes and enforce our agreements. Customer Data is retained and deleted in accordance with the applicable Customer agreement and our Data Processing Agreement.

11. Notifiable data breaches

We maintain a data breach response plan. Where an eligible data breach likely to result in serious harm occurs, we will notify affected individuals and the Office of the Australian Information Commissioner (“OAIC”) as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a breach affects Customer Data, we will notify the relevant Customer in accordance with our Data Processing Agreement.

12. Access and correction

You may request access to, and correction of, the personal information we hold about you as controller. To make a request, contact us using the details below; we may need to verify your identity. If your personal information is held within a Customer’s Hivenox account, please direct your request to that Customer. We will respond within a reasonable period, and where we decline a request as permitted by law, we will explain why.

13. Cookies

The Website and Service use cookies and similar technologies. For details and how to manage them, see our Cookies Policy.

14. Children

Hivenox is a business platform intended for organisations and their authorised users. It is not directed to children, and we do not knowingly collect personal information from children.

15. Complaints

If you believe we have breached the APPs or mishandled your personal information, please contact our Privacy Officer using the details below. We will acknowledge and investigate your complaint and aim to respond within 30 days. If you are not satisfied, you may complain to the OAIC at www.oaic.gov.au, on 1300 363 992, or at GPO Box 5288, Sydney NSW 2001.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The current version is always available on the Website and takes effect from the date shown. This Privacy Policy is effective from 1 January 2026.

Contact Us

If you have any questions about this document, or wish to exercise any of your rights, please contact us using the details below.

Hivenox — operated by AI Solution Technologies Pty Ltd

Also in the Trust Centre

The other documents

Talk to HIVENOX

Questions about how we would run it for you?

The policies set out the rules. The team can walk you through how they apply to your data, your contracts and your markets.