05

Privacy & Security

Your Business Security Is Our Number One Focus

We design systems with privacy controls, access controls, and data minimisation. The actual data handling model depends on the deployment you select, and the practical data flows — including any cloud, AI, support, email, payment, backup, or integration services — are documented before your system launches. This page summarises our approach and sets out our full privacy policy below.

Data Minimisation by Design

We aim to collect only the information a system needs to do its job, and we design access controls around it. Where a deployment stores your business data on your own infrastructure, it stays under your control; where cloud, backup, or integration services are used, those flows are disclosed in your deployment agreement.

No Sale of Your Information

We do not sell your personal information. Where a system relies on third-party providers — such as hosting, email, AI, or payment services — those providers are disclosed and used only to deliver the agreed functionality. See "Third-party providers and overseas disclosure" below.

Australian Owned & Operated

Nesso is an Australian business and handles personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth) where they apply. Some deployments use overseas providers (for example cloud, AI, or email); any such disclosure is identified before launch.

Security-Hardened Builds

Privacy is not an afterthought. We design systems with data minimisation, access controls, and security hardening as core requirements. The specific security measures for your deployment are described in your deployment documentation.

Privacy Policy

1. Who we are

We build custom AI assistants, business automation, access-control systems, and web platforms. The data handling for any given product depends on the deployment model selected for that engagement.

2. What personal information we may collect

Depending on how you interact with us and which products you use, we may collect:

  • Website enquiry data — the name, business name, email, phone number, and message you provide through our contact channels.
  • Product support data — information you share with us while we scope, build, deploy, or support a system, which may include operational data held within that system.
  • AI assistant data — where an AI assistant is deployed, voice or text input you provide to it, and any transcripts or responses generated. What is processed locally versus sent to third-party AI or text-to-speech providers is disclosed for each deployment.
  • Biometric data — only where you engage Nesso AccessIQ. Biometric information (such as facial or fingerprint templates) and access/attendance logs are treated as sensitive information and are only collected with consent and appropriate notices in place. See section 3.
  • Payment and integration data — information required to configure integrations you request (for example accounting, email, or payment providers). Payment card processing, where used, is handled by the relevant third-party provider.

3. Biometric and access-control information (Nesso AccessIQ)

Nesso AccessIQ can process biometric information and access logs. This is sensitive information. Where AccessIQ is deployed, biometric enrolment is consent-based, a non-biometric fallback (such as card, PIN, or QR) is available, collection notices and signage are provided, and retention/deletion settings are configured — including deletion on staff or member exit. The customer operating the system must obtain site-specific legal, privacy, and HR approval before biometric enrolment or workplace monitoring begins.

4. How your information is stored and secured

We design systems with access controls, data minimisation, and security hardening. The specific storage location, security controls, encryption, and backup arrangements depend on the deployment model (local-first, private server, or cloud) and are documented in your deployment agreement.

5. Third-party providers and overseas disclosure

Some deployments rely on third-party services to function — for example hosting, content delivery, fonts, email delivery, AI and text-to-speech providers, payment processing, and accounting integrations. Where personal information flows through such a provider, this is identified before launch. Some of these providers may store or process data outside Australia. Any overseas disclosure relevant to your deployment is disclosed to you before launch.

6. Retention and deletion

We retain personal information only for as long as needed for the purpose it was collected, or as required by law. Retention periods for product data — including biometric templates and access logs where AccessIQ is used — are configured per deployment. You can ask us to delete enquiry data we hold about you (see section 8).

7. Automated decision-making

Where a system makes or supports automated decisions that could significantly affect an individual, this is disclosed for that deployment.

8. Access, correction, and complaints

You can request access to, or correction of, the personal information we hold about you, and you can make a privacy complaint, by contacting us using the details below. We will respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

9. Contact us

Privacy enquiries: operations@nesso.net.au · 0429 534 706 · Berri, South Australia 5343.

This policy is provided for transparency and is not legal advice.