Privacy Policy

AI Architecture Lab Pty Ltd

Last updated: 13 August 2026

AI Architecture Lab Pty Ltd (“AI Architecture Lab”, “we”, “us” or “our”) respects your privacy and is committed to handling personal information responsibly, transparently and securely.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you visit our website, contact us, submit an enquiry or engage with our services.

AI Architecture Lab is an Australian company and may provide services to organisations in Australia and internationally.

Website:
https://aiarchitecturelab.com

Email:
contact@aiarchitecturelab.com

1. Our approach to privacy

We aim to collect only the personal information reasonably necessary to communicate with you, understand your business requirements and provide our services.

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply to our activities, we intend to handle personal information consistently with those requirements.

Additional privacy or data-protection laws may apply depending on the location of an individual, client, project, service provider or processing activity. We address those requirements where applicable rather than representing that every privacy law in every jurisdiction automatically applies to AI Architecture Lab.

2. Personal information we may collect

When you contact us or use our website forms, we may collect information including:

  • your name
  • business or organisation name
  • job title or role
  • email address
  • telephone number
  • organisation type
  • number of sites or locations, where relevant
  • details you provide about a business problem, operational situation or proposed AI use case
  • correspondence between you and AI Architecture Lab
  • information reasonably required to assess or provide an agreed service

Our website may also process limited technical information required for security and reliable operation, such as IP address and request information used for fraud prevention, form protection and rate limiting.

3. Information you should not submit through our public forms

Our public enquiry forms are intended for general business enquiries.

Please do not submit:

  • patient information
  • resident or care-recipient information
  • medical records
  • health information
  • financial account information
  • government identification information
  • passwords or credentials
  • confidential client records
  • sensitive employee information
  • information about another person unless it is appropriate and authorised to provide it

This is particularly important for organisations operating in aged care, healthcare or other regulated environments.

If a potential project may involve sensitive, regulated or confidential information, those requirements should be assessed separately before such information is provided to AI Architecture Lab.

4. How we collect personal information

We generally collect personal information directly from you when you:

  • submit a website enquiry
  • request the Free 30-Day AI Assistant Experience
  • email us
  • telephone us
  • participate in a meeting or consultation
  • provide information during a discovery process
  • request a proposal or service
  • enter into a business relationship with us

Where relevant, we may also obtain business information from publicly available sources or from an organisation that has authorised us to work with it.

Public availability does not necessarily remove privacy obligations. Where publicly available material contains personal information, we consider the purpose of collection, the proposed use and any applicable privacy requirements.

5. Why we collect and use personal information

We may collect and use personal information to:

  • respond to enquiries
  • communicate with prospective clients
  • assess whether AI Architecture Lab can assist an organisation
  • administer the Free 30-Day AI Assistant Experience
  • understand business requirements
  • arrange meetings and follow-up discussions
  • prepare proposals, recommendations or scopes of work
  • perform discovery and architecture activities
  • analyse appropriate client information using approved AI and technology tools
  • develop and configure ACOS, knowledge bases, operating materials, policies, playbooks and specifications
  • generate drafts and structured outputs for review
  • design, build, test, deploy or govern agreed AI capabilities
  • maintain, troubleshoot, secure and improve the service provided to a client
  • administer client relationships
  • provide support
  • maintain business and legal records
  • protect our systems from misuse or abuse
  • comply with contractual, legal or regulatory obligations

We do not intend to use information submitted through our general website forms to make automated high-impact decisions about individuals.

6. Website enquiry forms

AI Architecture Lab currently operates:

  • a general Contact form
  • a Free 30-Day AI Assistant Experience enquiry form

Successful submissions are transmitted to:

contact@aiarchitecturelab.com

The email address supplied by the visitor is used as the Reply-To address so AI Architecture Lab can respond directly.

Our forms use technical protections including:

  • server-side validation
  • field limits
  • honeypot protection
  • form-completion timing checks
  • same-origin validation
  • request-size limits
  • submission rate limiting

The rate-limiting system does not store the contents of the enquiry.

A one-way hashed value associated with the requesting network address may be retained temporarily to control repeated submissions.

7. Artificial intelligence and submitted information

AI Architecture Lab provides AI consulting, architecture and implementation services.

Submitting an enquiry through our website does not mean that the information you provide is automatically placed into an AI system.

Where an engagement requires information to be processed by an AI system, we aim to determine:

  • what information is actually required
  • where that information comes from
  • which systems or providers may receive it
  • what the AI is permitted to do
  • what it must not do
  • when human review or escalation is required
  • whether personal or sensitive information should be excluded
  • which privacy, security or regulatory obligations may apply

Where appropriate, we seek to minimise personal information used in AI systems and design systems around approved information sources and defined boundaries.

To provide an agreed service, AI Architecture Lab may process appropriate client information through assessed third-party artificial intelligence models, machine-learning systems, automation systems, hosting or runtime platforms, APIs and related technology providers. This may be reasonably necessary to analyse discovery information, understand the client's business, develop and configure ACOS, create client-specific knowledge and operational materials, generate drafts, test and quality-assure assistants, deploy or operate services, and maintain, troubleshoot, secure or improve the service provided to that client.

Specific providers, models, versions and infrastructure may change over time. We may assess providers according to matters such as the purpose and information involved, model-training and data-use settings, confidentiality, security, retention, data location, contractual protections, suitability for sensitive information, availability and operational risk. We may maintain provider and subprocessor information separately rather than publishing an exhaustive permanent list on this website.

Processing client information through an AI provider to deliver that client's service is not the same as intentionally using the information to train a general-purpose or foundation model. AI Architecture Lab does not intend to use Client Confidential Information or Personal Information to train general-purpose or foundation AI models for the benefit of unrelated clients or third parties without appropriate authority, permission or another valid basis.

Standard ACOS implementations are not intended to autonomously make significant decisions about individuals concerning employment, credit, insurance, healthcare, legal rights, eligibility for significant services or benefits, or similarly consequential outcomes. A use case involving such decisions requires specific legal, privacy, security and governance assessment, including appropriate transparency and human oversight.

8. Meeting recording, transcription and AI-assisted note-taking

AI Architecture Lab may use digital recording, transcription or AI-assisted note-taking tools during meetings, discovery sessions, consultations or project discussions.

We currently use PLAUD for this purpose.

Where a meeting is to be recorded, participants will be informed before recording begins and consent will be requested.

We do not intend to record business conversations covertly.

Participants may decline to be recorded. If consent is not provided, AI Architecture Lab will use an alternative method of taking notes.

Recordings, transcripts, summaries and related meeting information may be used to:

  • create accurate meeting notes
  • capture business requirements, decisions and agreed actions
  • reduce the need for manual note-taking
  • allow us to focus more fully on the discussion
  • prepare project documentation, summaries or follow-up actions
  • support discovery, architecture, implementation and governance activities
  • maintain an appropriate record of project requirements and decisions

Recordings and transcripts may contain personal information, confidential business information or commercially sensitive information.

Participants should not provide patient records, medical records, resident or care-recipient information, passwords, financial account credentials, government identification information or other highly sensitive information during a recorded meeting unless AI Architecture Lab has specifically agreed that collection is necessary and appropriate and suitable safeguards have been established.

PLAUD and its technology providers may process audio, transcripts, prompts, summaries and related information in order to provide transcription and AI-assisted note-taking services.

PLAUD states that customer data is not used to train its AI systems or third-party AI models by default unless the customer expressly opts in.

PLAUD may use infrastructure and subprocessors located outside Australia. Depending on service configuration and processing requirements, information may be processed in jurisdictions including the United States, Europe, Singapore, Japan or other locations used by PLAUD or its subprocessors.

AI Architecture Lab seeks to configure recording and note-taking services in a privacy-conscious manner and to retain recordings and transcripts only for as long as reasonably required for the relevant business or project purpose.

Recordings, transcripts and AI-generated summaries are reviewed as appropriate before information is treated as authoritative client or ACOS knowledge. Capturing a conversation does not automatically make every statement approved, accurate or suitable for inclusion.

Where a client supplies a recording or requests that it be processed, the client should have the rights, notices, consents or other authority reasonably required to provide it for that purpose.

Recording practices may also be subject to applicable surveillance, privacy and recording-consent laws in the jurisdiction where participants are located.

9. Sensitive information

We do not intentionally request sensitive personal information through our general website enquiry forms.

Some future client engagements may involve organisations operating in healthcare, aged care, government or other regulated sectors.

If sensitive information may be involved in a project, additional privacy, security, governance and legal controls may be required before the information is accessed, transferred or processed.

Clients should not provide unnecessary highly sensitive information or credentials to AI Architecture Lab or its AI systems. This includes passwords, authentication secrets, private API keys, payment-card credentials, banking login credentials, government identifiers and highly sensitive medical information unless the particular use has been specifically approved as necessary and appropriate safeguards have been established.

10. Disclosure of personal information

We do not sell personal information.

We may disclose personal information where reasonably necessary to:

  • hosting providers
  • email providers
  • cloud or technology providers
  • assessed AI, machine-learning, automation, hosting, runtime and API providers used to deliver an agreed service
  • professional advisers
  • authorised contractors or specialists
  • service providers supporting business operations
  • regulators, government authorities, courts or law-enforcement bodies where required by law
  • another party where you have authorised the disclosure

We seek to limit disclosures to information reasonably necessary for the relevant purpose.

11. International clients and cross-border processing

AI Architecture Lab may provide services to clients located in Australia and other countries.

Personal information may therefore be processed, stored, transmitted or accessed in Australia or overseas.

Technology, hosting, communications, cloud, AI or professional-service providers may operate infrastructure in multiple jurisdictions.

Where the Australian Privacy Principles apply, an APP Privacy Policy must explain whether personal information is likely to be disclosed overseas and, where practicable, identify the countries involved. APP 8 also establishes requirements concerning certain overseas disclosures.

Because infrastructure locations, subprocessors and routing arrangements can change, we do not represent that all information will remain exclusively within Australia.

Where an engagement involves material overseas processing or disclosure, AI Architecture Lab may assess matters including:

  • the client's jurisdiction
  • the location of relevant individuals
  • service-provider locations
  • processing locations
  • subprocessors
  • applicable transfer requirements
  • contractual safeguards
  • technical safeguards
  • data minimisation
  • access controls
  • retention requirements

12. International privacy laws

Privacy and data-protection rights vary between jurisdictions.

For example, the UK GDPR can apply to organisations outside the UK when they offer goods or services to individuals in the UK, and the EU GDPR contains its own territorial-scope provisions.

We do not claim that every international privacy law automatically applies to AI Architecture Lab.

Where a particular privacy or data-protection law applies to our activities, we will seek to address the requirements relevant to that processing activity.

13. Your privacy rights

Depending on where you are located and which law applies, you may have rights relating to your personal information.

These may include rights to request:

  • access
  • correction
  • deletion
  • restriction of processing
  • withdrawal of consent where processing relies on consent
  • objection to certain processing
  • information about how your personal information is handled

These rights are not absolute and may be subject to legal exceptions.

We may need to verify your identity before responding to a request.

Privacy requests can be sent to:

contact@aiarchitecturelab.com

14. Security

We take reasonable steps to protect personal information from misuse, loss, interference and unauthorised access, modification or disclosure.

Depending on the system involved, security measures may include:

  • HTTPS/TLS encryption
  • authenticated email delivery
  • access controls
  • private configuration storage
  • server-side validation
  • request-size limits
  • anti-abuse controls
  • rate limiting
  • data minimisation
  • controlled information sources
  • defined AI boundaries
  • human oversight
  • limiting unnecessary collection
  • restricting credentials from publicly accessible website files

No internet-connected system can be guaranteed to be completely secure.

We maintain processes for assessing and responding to suspected security incidents or data breaches. Where applicable, this may include investigation, containment, remediation and notification in accordance with relevant legal and contractual requirements.

15. Retention

We retain personal information only for as long as reasonably required for:

  • the purpose for which it was collected
  • providing an agreed service
  • managing a business relationship
  • legitimate business administration
  • legal or regulatory requirements
  • resolving disputes
  • record keeping

Where appropriate and legally permitted, information that is no longer required should be securely deleted or de-identified.

Retention may differ across prospect or demonstration information, active client information and information held after an engagement ends. Subject to the applicable service agreement, scope and technical capability, client-owned knowledge or data may be returned or made available for reasonable export at exit. We may retain information where reasonably necessary for legal, regulatory, dispute-resolution, security, backup or legitimate business-operational purposes.

Deletion from backup systems may occur through normal backup rotation cycles rather than immediately. AI Architecture Lab may retain its underlying reusable ACOS methodology, frameworks, templates, generic processes and know-how, but this does not transfer ownership of client materials to us.

Australian privacy principles include obligations concerning destruction or de-identification where information is no longer required and no exception applies.

16. Access and correction

You may contact us if you would like to request access to personal information we hold about you or ask us to correct inaccurate or outdated information.

Where Australian privacy law applies, the Australian Privacy Principles contain specific rights and obligations concerning access and correction.

17. Cookies, analytics and advertising

At the date of this policy, AI Architecture Lab does not use third-party advertising tracking or website analytics on the public website.

The website may use technical functionality required to operate and secure the service.

If we introduce analytics, advertising, marketing pixels, consent technologies or other tracking tools in the future, this policy should be reviewed and updated before or when those technologies are introduced.

18. Marketing communications

Submitting a general website enquiry does not automatically add you to a marketing mailing list.

If we introduce email marketing or newsletters in the future, appropriate consent, identification and unsubscribe processes should be implemented.

19. Third-party websites and services

Our website may contain links to external websites, platforms or services.

We are not responsible for the privacy, security or information-handling practices of third parties.

You should review the privacy policies of external services before providing them with personal information.

20. Client projects

A website Privacy Policy does not replace project-specific privacy, security or contractual requirements.

Where AI Architecture Lab works with a client, the project may require additional documents or controls such as:

  • confidentiality obligations
  • data-processing provisions
  • security requirements
  • access restrictions
  • information-classification rules
  • cross-border transfer arrangements
  • processor or subprocessor terms
  • project-specific retention rules
  • incident-response responsibilities

These requirements should be determined according to the nature of the engagement.

21. Privacy enquiries and complaints

If you have a question or concern about how we have handled personal information, please contact us.

AI Architecture Lab Pty Ltd

Email:
contact@aiarchitecturelab.com

Website:
https://aiarchitecturelab.com

We will aim to investigate and respond within a reasonable period.

Where Australian privacy law applies and you are not satisfied with our response, you may also have the right to contact the Office of the Australian Information Commissioner.

22. Changes to this Privacy Policy

We may update this Privacy Policy as our:

  • services change
  • technology changes
  • service providers change
  • international operations expand
  • information-handling practices change
  • legal or regulatory obligations change

The latest version will be published on our website with an updated revision date.