Smart Reception Pty Ltd T/A TechnoSmart — Last updated 01 June 2026
| Company Name | Smart Reception Pty Ltd T/A's TechnoSmart |
|---|---|
| Version | 1.0 |
| Clauses / Controls No. | 5.32, 5.33, 5.34 |
| Effective Date | 01/06/2026 |
| Next Review Date | 01/06/2027 |
| Prepared By | Pritesh Darji (Director & CISO) |
| Status | Approved |
| Date of Approval | 01/06/2026 |
| Revision Date | Version | Revision Details |
|---|---|---|
| 03/06/2027 | 1.0 | No Changes |
Smart Reception Pty Ltd T/A's TechnoSmart develops and manages AI-based solutions including AI Voice Agents, SMS Agents, APIs, automation workflows, and other AI-powered products. The Organisation processes and stores customer information, communication records, source code, AI prompts, cloud-hosted data, voice recordings, SMS content, email data, contracts, and business records.
The Organisation recognises the importance of protecting intellectual property, maintaining secure records, and safeguarding personal information in compliance with applicable Australian legal, contractual, regulatory, and business requirements.
This policy has been established to ensure organisational information, customer data, records, and intellectual property assets are adequately protected against unauthorised access, disclosure, misuse, alteration, loss, or destruction.
The purpose of this policy is to:
This policy applies to:
The Organisation shall comply with applicable Australian laws and regulations including, but not limited to:
The Organisation shall also consider customer contractual requirements and industry obligations relating to protection of information and privacy.
The Organisation shall protect intellectual property associated with source code, AI models and workflows, APIs, agent configurations, system prompts, technical documentation, business processes, software solutions, and customer deliverables.
Organisational intellectual property shall not be:
All intellectual property created during employment, during contractual engagement, or using Organisational systems or resources shall remain the property of the Organisation unless otherwise defined contractually. This includes AI solutions, voice agent configurations, SMS workflows, prompt designs, source code, APIs, technical documentation, and automation scripts.
The Organisation shall use licensed software and authorised tools only, and shall respect copyright, licensing, and usage restrictions while preventing unauthorised installation or use of software, libraries, media, or tools. Developers and employees shall not use pirated software, copy third-party intellectual property unlawfully, or use unapproved AI models or datasets without authorisation.
Organisational records shall be securely created, stored, retained, protected, archived, and disposed of based on legal, regulatory, operational, and contractual requirements. Records may include contracts, customer communications, voice recordings, SMS records, email records, audit logs, financial records, incident records, security logs, HR records, and technical documentation.
Records shall be protected against unauthorised access, loss, tampering, destruction, disclosure, and corruption. Security controls may include access restrictions, encryption, backups, multi-factor authentication (MFA), audit logging, secure cloud storage, and role-based access control.
Records shall be retained only for as long as required by business, legal, regulatory, or contractual obligations. Records containing sensitive information or personal data shall be securely deleted or destroyed when no longer required.
The Organisation is committed to protecting personal information and handling Personally Identifiable Information (PII) responsibly, securely, and lawfully in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
The Organisation shall only collect personal information that is required for legitimate business purposes, necessary for service delivery, or authorised by applicable agreements or laws. Personal information collected may include names, phone numbers, email addresses, voice recordings, SMS content, customer communication records, and employee information.
PII shall be protected against unauthorised access, disclosure, alteration, misuse, loss, or destruction. Security measures may include MFA, encryption, access controls, logging and monitoring, secure APIs, cloud security controls, secure repositories, and restricted access permissions.
Voice recordings, transcripts, SMS content, email data, prompts, and communication records processed through AI systems shall be treated as confidential and protected information. The Organisation shall restrict access to authorised personnel only, prevent unauthorised sharing or disclosure, avoid using customer information for AI model training without authorisation, and implement secure storage and transfer controls.
Where customer information or records are processed using cloud platforms or third-party providers, the Organisation shall use approved providers, implement security controls, review contractual protections, and ensure reasonable protection of customer information.
Personal information shall only be disclosed for authorised business purposes, where legally required, or with customer authorisation where applicable. Unauthorised disclosure of customer or employee information is prohibited.
Violation of this policy, misuse of intellectual property, unauthorised disclosure of information, or mishandling of records or personal information may result in suspension of access privileges, disciplinary action, contract termination, and/or legal or regulatory action where applicable.
This policy shall be reviewed annually, after significant legal or regulatory changes, following major security incidents, and upon changes to technology or business operations. The ISMS Manager is responsible for maintaining and reviewing this policy.