Introduction
This document explains how SpectraIQ Pty Ltd (ABN registered in Australia, trading as "SpectraIQ", "we", "us" or "our") approaches the handling of personal information in connection with the SpectraIQ.ai platform. It applies to all use of our website, products and services unless a separately executed agreement says otherwise.
Australian Privacy Principles
We are bound by the 13 Australian Privacy Principles (APPs) set out in Schedule 1 of the Privacy Act 1988 (Cth). This policy describes how we comply with each APP in practice, including the open and transparent management of personal information under APP 1 and the requirement for anonymity and pseudonymity under APP 2 where lawful and practicable.
Information we collect
We collect personal information that you provide directly to us (such as name, email, role, dealership) and information we collect through our services (such as conversation logs you process, dealer system data your dealership configures us to read, technical logs and usage telemetry). We do not collect sensitive information unless you actively configure us to and we have lawful grounds.
How we use information
We use information to provide and improve the services, to authenticate users, to detect and prevent fraud and abuse, to meet legal and regulatory obligations, and for any other purpose disclosed at the time of collection. We do not train shared foundation models on dealership conversation data.
Disclosure
We disclose personal information to our authorised subprocessors (listed at /legal/subprocessors), to your nominated dealership administrators, and to government, regulatory or law-enforcement bodies where required by law. We do not disclose your data for marketing by third parties.
Cross-border data flows
Customer data is hosted in AWS Asia Pacific (Sydney) Region (ap-southeast-2). Limited operational metadata may be processed in other regions for engineering support; in such cases we ensure equivalent protections consistent with APP 8.
Security
We apply administrative, technical and physical safeguards proportionate to the sensitivity of the data, including encryption in transit and at rest, role-based access control, least-privilege provisioning, audit logging, vulnerability management and an active SOC 2 Type II programme.
Access and correction
You may request access to or correction of your personal information at any time by contacting privacy@spectraiq.ai. We will respond within 30 days.
Complaints
If you believe we have breached the APPs, contact our Privacy Officer. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Contact
Privacy Officer, privacy@spectraiq.ai, SpectraIQ Pty Ltd, Sydney NSW Australia.
