Legal

Privacy Policy

Last updated: 14 June 2026

Future Gen AI Pty Ltd · ABN 60 447 071 932 · trading as autoplexity.ai

1. About this policy

This Privacy Policy explains how Future Gen AI Pty Ltd (“we”, “us”, “our”) collects, uses, stores, and discloses personal information when you use the autoplexity.ai platform. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

We also acknowledge the importance of data sovereignty for Aboriginal and Torres Strait Islander peoples and communities. We are committed to handling cultural and community data with respect and care consistent with the AIATSIS Code of Ethics and, where relevant, the First Nations Data Sovereignty principles.

2. What personal information we collect

We collect information you provide directly and information generated through your use of the platform:

  • ·Account information: name, email address, phone number, and password (stored hashed).
  • ·Profile information: organisation name, role, address, ABN, and any other details you enter.
  • ·Member register data (PBC/secretary portal): names, dates of birth, family relationships, clan groups, voting eligibility, and contact details for native title members you manage.
  • ·Documents and files: any documents you upload, including ILUAs, COA letters, meeting minutes, and other native title or business records.
  • ·Communications: emails, SMS messages, calendar events, and correspondence you manage through the platform.
  • ·Financial information: invoice data and Stripe-processed payment information (we do not store full card numbers — Stripe handles card data directly).
  • ·Usage data: pages visited, AI actions taken, features used, and time spent on the platform.
  • ·AI interactions: the content of your conversations with the AI agent, including prompts, responses, and any documents shared with the AI.

3. How we use your information

We use personal information to:

  • ·Provide, operate, and improve the autoplexity.ai platform and its AI features.
  • ·Authenticate your identity and secure your account.
  • ·Process payments and manage subscriptions.
  • ·Send transactional communications (verification codes, billing receipts, platform notifications).
  • ·Generate AI-assisted content — such as COA letters, ILUA summaries, and meeting minutes — on your instruction.
  • ·Calculate and display your 'hours saved' metric based on AI actions.
  • ·Comply with legal obligations including tax, anti-money-laundering, and regulatory requirements.
  • ·Investigate and resolve security incidents or disputes.

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

4. Where your data is stored

Your data is stored in Australia. Our primary database infrastructure (Supabase) operates on servers located in the ap-southeast-2 (Sydney) region of Amazon Web Services. We do not transfer your personal data to servers outside Australia except as described in section 5 below.

5. Third-party service providers

We use trusted third-party services to operate the platform. Each receives only the data necessary for their specific function:

Anthropic (Claude AI) United States
Purpose: Powers the AI agent, content generation, and document analysis features.
Data shared: The content of your AI conversations and any documents you share with the AI are sent to Anthropic's API for processing. Anthropic does not use API data to train its models by default. See Anthropic's Privacy Policy at anthropic.com/privacy.
Supabase Australia (ap-southeast-2 Sydney)
Purpose: Database, authentication, and file storage.
Data shared: All platform data including user accounts, member records, documents, and settings.
Vercel Australia and global edge network
Purpose: Application hosting and serverless functions.
Data shared: Request metadata and application logs. Does not store personal data beyond what is necessary for hosting.
Stripe United States (compliant with PCI-DSS)
Purpose: Payment processing.
Data shared: Name, email address, and payment card details (Stripe handles card data directly — we receive only a customer token).
Twilio United States
Purpose: SMS sending and phone number management.
Data shared: Phone numbers and SMS message content for verification codes and outbound messages you send.
Google (Gmail / Calendar) United States
Purpose: Email and calendar integration (only when you connect your Google account).
Data shared: Email content and calendar events you choose to sync. We store OAuth tokens; Google processes your email data under their Privacy Policy.
Microsoft (Outlook / Entra ID) United States
Purpose: Email integration and secretary portal authentication.
Data shared: Email content for connected Outlook accounts; authentication tokens for secretary portal users.
Xero New Zealand / global
Purpose: Accounting integration (when connected).
Data shared: Invoice, contact, and financial data you choose to sync.

Where data is processed outside Australia, we take reasonable steps to ensure it is handled in accordance with the Australian Privacy Principles.

6. Aboriginal and Torres Strait Islander data

We recognise that information about Aboriginal and Torres Strait Islander community members — including genealogy, cultural affiliations, eligibility determinations, and native title records — is sensitive in a specific and important way beyond standard privacy law.

We commit to:

  • ·Storing all member register data within Australia (Sydney, AWS ap-southeast-2).
  • ·Not using community member data for any purpose other than operating the platform on your instruction.
  • ·Not disclosing community member data to any government body, researcher, or third party without the explicit written consent of the PBC or their authorised representative.
  • ·Providing PBCs with the ability to export their complete member data in machine-readable format at any time.
  • ·Permanently deleting all community data within 30 days of account closure on request.

7. AI-generated content disclaimer

The autoplexity.ai AI agent generates content including ILUA summaries, COA letters, compliance guidance, and other documents. This content is generated by artificial intelligence and:

  • ·Is not legal advice and should not be relied upon as such.
  • ·Must be reviewed and verified by a qualified professional before use in legal or compliance contexts.
  • ·May contain errors, omissions, or inaccuracies.
  • ·Does not substitute for advice from your legal team, ORIC, or a qualified accountant.

8. Your rights

Under the Privacy Act 1988 and Australian Privacy Principles, you have the right to:

  • ·Access the personal information we hold about you.
  • ·Request correction of inaccurate or incomplete information.
  • ·Request deletion of your account and personal data.
  • ·Opt out of non-essential communications.
  • ·Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

To exercise these rights, contact us at privacy@autoplexity.ai. We will respond within 30 days.

9. Security

We implement technical and organisational security measures including:

  • ·Row-level security (RLS) on all database tables — your data is logically isolated from other users.
  • ·All data encrypted in transit (TLS 1.3) and at rest.
  • ·API keys and service credentials stored only in server-side environment variables — never in client-side code or public repositories.
  • ·Audit logging of all significant actions within the platform.
  • ·Passkey (WebAuthn) support for passwordless authentication.
  • ·Rate limiting on all public-facing API endpoints.

10. Cookies and tracking

We use session cookies for authentication and security (e.g. OTP verification). We do not use third-party advertising trackers or behavioural analytics cookies. Usage analytics, where collected, are aggregate and non-identifying.

11. Data retention

We retain your data for as long as your account is active or as necessary to provide our services. On account closure:

  • ·Your data is deleted within 30 days of a verified deletion request.
  • ·Billing records are retained for 7 years as required by Australian tax law.
  • ·Anonymised, aggregate usage statistics may be retained indefinitely.

12. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notification at least 14 days before taking effect. Continued use of the platform constitutes acceptance of the updated policy.

13. Contact us

Privacy enquiries: privacy@autoplexity.ai

General enquiries: hello@autoplexity.ai

Entity: Future Gen AI Pty Ltd, ABN 60 447 071 932

OAIC: oaic.gov.au

© 2026 Future Gen AI Pty Ltd · ABN 60 447 071 932