Information Protection & Privacy Policy

Smart Reception Pty Ltd T/A TechnoSmart — Last updated 01 June 2026

Company NameSmart Reception Pty Ltd T/A's TechnoSmart
Version1.0
Clauses / Controls No.5.32, 5.33, 5.34
Effective Date01/06/2026
Next Review Date01/06/2027
Prepared ByPritesh Darji (Director & CISO)
StatusApproved
Date of Approval01/06/2026

Revision History

Revision DateVersionRevision Details
03/06/20271.0No Changes

Background

Smart Reception Pty Ltd T/A's TechnoSmart develops and manages AI-based solutions including AI Voice Agents, SMS Agents, APIs, automation workflows, and other AI-powered products. The Organisation processes and stores customer information, communication records, source code, AI prompts, cloud-hosted data, voice recordings, SMS content, email data, contracts, and business records.

The Organisation recognises the importance of protecting intellectual property, maintaining secure records, and safeguarding personal information in compliance with applicable Australian legal, contractual, regulatory, and business requirements.

This policy has been established to ensure organisational information, customer data, records, and intellectual property assets are adequately protected against unauthorised access, disclosure, misuse, alteration, loss, or destruction.

Purpose

The purpose of this policy is to:

  • Protect intellectual property rights associated with organisational assets, software, AI systems, source code, and business information.
  • Ensure organisational records are securely created, retained, protected, and disposed of appropriately.
  • Ensure personal information and Personally Identifiable Information (PII) are handled in accordance with Australian privacy laws and business requirements.
  • Support compliance with ISO/IEC 27001:2022 and applicable Australian legislation.

Scope

This policy applies to:

  • All employees, freelancers, contractors, consultants, interns, and third-party users.
  • All organisational information, customer data, records, AI assets, systems, cloud platforms, and communication systems within the ISMS scope.
  • All physical and electronic records processed, stored, or transmitted by the Organisation, including AI Voice Agent data, SMS Agent data, Email Agent data, customer information, employee information, and source code.

Data & Platforms Covered

Applicable Legal & Regulatory Requirements

The Organisation shall comply with applicable Australian laws and regulations including, but not limited to:

  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles (APPs)
  • Spam Act 2003 (Cth)
  • Telecommunications Act 1997 (Cth)
  • Copyright Act 1968 (Cth)
  • Corporations Act 2001 (Cth)
  • Applicable contractual and confidentiality obligations

The Organisation shall also consider customer contractual requirements and industry obligations relating to protection of information and privacy.


Policy

Protection of Intellectual Property

The Organisation shall protect intellectual property associated with source code, AI models and workflows, APIs, agent configurations, system prompts, technical documentation, business processes, software solutions, and customer deliverables.

Organisational intellectual property shall not be:

  • Copied without authorisation
  • Shared externally without approval
  • Used for unauthorised purposes
  • Modified or distributed unlawfully

Ownership of Intellectual Property

All intellectual property created during employment, during contractual engagement, or using Organisational systems or resources shall remain the property of the Organisation unless otherwise defined contractually. This includes AI solutions, voice agent configurations, SMS workflows, prompt designs, source code, APIs, technical documentation, and automation scripts.

Use of Third-Party Intellectual Property

The Organisation shall use licensed software and authorised tools only, and shall respect copyright, licensing, and usage restrictions while preventing unauthorised installation or use of software, libraries, media, or tools. Developers and employees shall not use pirated software, copy third-party intellectual property unlawfully, or use unapproved AI models or datasets without authorisation.

Records Management

Organisational records shall be securely created, stored, retained, protected, archived, and disposed of based on legal, regulatory, operational, and contractual requirements. Records may include contracts, customer communications, voice recordings, SMS records, email records, audit logs, financial records, incident records, security logs, HR records, and technical documentation.

Records Protection

Records shall be protected against unauthorised access, loss, tampering, destruction, disclosure, and corruption. Security controls may include access restrictions, encryption, backups, multi-factor authentication (MFA), audit logging, secure cloud storage, and role-based access control.

Retention & Disposal

Records shall be retained only for as long as required by business, legal, regulatory, or contractual obligations. Records containing sensitive information or personal data shall be securely deleted or destroyed when no longer required.


Privacy & Protection of PII

Privacy Commitment

The Organisation is committed to protecting personal information and handling Personally Identifiable Information (PII) responsibly, securely, and lawfully in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Collection of Personal Information

The Organisation shall only collect personal information that is required for legitimate business purposes, necessary for service delivery, or authorised by applicable agreements or laws. Personal information collected may include names, phone numbers, email addresses, voice recordings, SMS content, customer communication records, and employee information.

Protection of PII

PII shall be protected against unauthorised access, disclosure, alteration, misuse, loss, or destruction. Security measures may include MFA, encryption, access controls, logging and monitoring, secure APIs, cloud security controls, secure repositories, and restricted access permissions.

AI Voice, SMS & Communication Data

Voice recordings, transcripts, SMS content, email data, prompts, and communication records processed through AI systems shall be treated as confidential and protected information. The Organisation shall restrict access to authorised personnel only, prevent unauthorised sharing or disclosure, avoid using customer information for AI model training without authorisation, and implement secure storage and transfer controls.

Cross-Border & Cloud Data Handling

Where customer information or records are processed using cloud platforms or third-party providers, the Organisation shall use approved providers, implement security controls, review contractual protections, and ensure reasonable protection of customer information.

Data Access & Disclosure

Personal information shall only be disclosed for authorised business purposes, where legally required, or with customer authorisation where applicable. Unauthorised disclosure of customer or employee information is prohibited.

Monitoring & Compliance: Compliance with this policy is monitored through internal audits, security reviews, access reviews, log monitoring, compliance assessments, and incident management activities. Non-compliance or security weaknesses are addressed through corrective actions.

Violations & Disciplinary Actions

Violation of this policy, misuse of intellectual property, unauthorised disclosure of information, or mishandling of records or personal information may result in suspension of access privileges, disciplinary action, contract termination, and/or legal or regulatory action where applicable.

Document Review & Maintenance

This policy shall be reviewed annually, after significant legal or regulatory changes, following major security incidents, and upon changes to technology or business operations. The ISMS Manager is responsible for maintaining and reviewing this policy.