Privacy Policy
Effective date: 29 March 2025
1. Introduction
i imagine ("Company", "we", "us"), a business registered in Victoria, Australia, operates the iimagine pro platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs").
By using the Service, you consent to the practices described in this Privacy Policy.
2. Information We Collect
We may collect the following types of personal information:
- Identity information: name, email address
- Account information: password (stored as a bcrypt hash, never in plain text), role, organisation membership
- Profile information: profile picture, display name
- Usage data: chat messages, conversation history, actions performed within the Service
- Customer data: information you upload about your customers (names, emails, phone numbers, order details, subscription details, claims, payments) for the purpose of AI-assisted support
- Knowledge base content: documents and text you upload for AI retrieval
- Technical data: IP address, browser type, device information, and access logs
- Communication data: information you provide when contacting us (demo requests, contact forms)
3. How We Collect Information
We collect personal information:
- Directly from you when you register, use the Service, upload data, or contact us
- Automatically through your use of the Service (technical and usage data)
- From third-party services we use to operate the platform (authentication providers, email delivery services, AI model providers)
4. How We Use Your Information
We use your personal information to:
- Provide, operate, and maintain the Service
- Process your account registration and manage your subscription
- Facilitate AI-powered customer support conversations and automated actions
- Generate vector embeddings of your knowledge base content for semantic search
- Send transactional emails (verification, invitations, notifications)
- Respond to your enquiries and support requests
- Monitor and analyse usage to improve the Service
- Detect, prevent, and address technical issues or security threats
- Comply with legal obligations
5. Third-Party Service Providers
We use the following categories of third-party service providers to operate the Service. Your data may be processed by these providers in accordance with their own privacy policies:
- Cloud hosting and database services (for storing your data)
- AI model providers (for processing chat and voice conversations — message content is sent to these providers to generate responses)
- Email delivery services (for sending transactional emails)
- File storage services (for profile pictures and uploaded documents)
- Voice and speech services (for real-time voice agent functionality)
We take reasonable steps to ensure our third-party providers handle your data in compliance with applicable privacy laws. Some providers may store or process data outside of Australia. By using the Service, you consent to the transfer of your data to these providers.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. Chat history and audit logs are retained for a minimum of 90 days. If you close your account, we will delete or de-identify your personal information within a reasonable timeframe, except where we are required to retain it by law.
7. Data Security
We implement reasonable technical and organisational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Password hashing using bcrypt
- Role-based access control within the platform
- Organisation-level data isolation (multi-tenant architecture)
However, no method of transmission or storage is completely secure. We cannot guarantee absolute security of your data.
8. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate or incomplete personal information
- Request deletion of your personal information (subject to legal obligations)
- Withdraw consent for direct marketing communications
- Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs
To exercise any of these rights, please contact us at the details provided below.
9. Cookies and Tracking
The Service uses session cookies for authentication purposes. These are essential for the operation of the Service and cannot be disabled. We do not use third-party advertising or analytics cookies.
10. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a revised effective date. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.
12. Contact
If you have any questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, please contact us at:
You may also contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au if you are not satisfied with our response.