Privacy Policy

Effective Date: 31 July 2026

1. Introduction

Welcome to Northern Beaches AI ("we," "us," or "our"). We are the trading name of Interview Management Solutions Pty Ltd (ABN 65 166 406 015). We provide AI-powered services to Australian organisations, including:

  • The Lucent Edge platform ("Platform"), a sovereign AI digital workforce platform that provides secure access to frontier AI models on Australian infrastructure, together with governed digital employees and related capabilities.
  • AI automation and voice AI solutions, including voice automation systems, workflow automation, and integrated AI tools designed for small and medium businesses.

Together, these are referred to as our "Services."

Your privacy is important to us. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal information in compliance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs").

Important note regarding customer data: This Privacy Policy primarily describes how we handle the personal information of prospective and existing users and administrative contacts for our Services. Where our Services process data on behalf of customers (for example, documents, files, or client materials uploaded to the Platform by a customer or its users), that processing is governed by our agreements with those customers and the relevant provisions of this Privacy Policy, including Sections 6, 7, and 8. We do not use customer data processed through our Services for any purpose other than delivering the Services, except as described in this Privacy Policy.

2. Scope

This Privacy Policy applies to:

  • Our website: northernbeaches.ai
  • The Lucent Edge platform and any related portals, tools, or interfaces
  • Our AI automation and voice AI solutions, including any third-party platforms or integrations used to deliver those services
  • Any other platforms, products, or services offered by Northern Beaches AI that link to or otherwise reference this policy

By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.

3. Information We Collect

We may collect various types of information from or about you depending on how you engage with us:

Personal Information

  • Contact details, such as your name, email address, phone number, and mailing address.
  • Business information, such as company or practice name, job title, professional role, and related details if you are using our Services on behalf of an organisation.
  • Communications data, based on our exchanges with you, including when you contact us through our website, email, phone, social media, or otherwise.
  • Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
  • Account data, such as the username and password you may set to establish an account on the Platform, and any account configuration or preferences.
  • Payment data, needed to complete transactions. Payment card information is collected and processed directly by our payment processor, Stripe, in accordance with its privacy policy at https://stripe.com/privacy. We do not store your full payment card details on our systems.

Platform Interaction Data (Lucent Edge)

  • Chat and workflow activity conducted through the Lucent Edge platform, including interactions with digital employees.
  • Documents, files, or other content you upload to or generate through the Platform.
  • Email drafts and communications initiated or supported through the Platform's integrated tools (such as Microsoft 365 Outlook or other connected services).
  • Workflow event logs, approval records, and audit trail data generated during your use of the Platform.

Voice and Audio Data (AI Automation Services)

  • Any audio recordings or voice data captured during interactions with our AI voice automation systems. This data is used solely to provide and improve our voice-related services.
  • Call metadata, including call duration, timestamps, and routing information.

Automation and Integration Data

  • Data processed through our workflow automation services, including information passed between integrated third-party tools (such as CRM systems, scheduling tools, payment platforms, or communication services) as part of delivering our automation solutions.

Technical Information

  • Device and browsing information, such as IP address, browser type and version, operating system, device type, screen resolution, unique identifiers, and language settings.
  • Usage data, such as pages visited, time spent on pages, navigation paths, links clicked, and access times.

Cookies and Similar Technologies

We may use cookies or similar tracking technologies to enhance your experience on our website. For more information, please see Section 11 of this Privacy Policy.

4. How We Collect Information

We collect information in the following ways:

  • Directly from you: When you voluntarily provide it, such as when filling out forms on our website (including early access or waitlist applications), subscribing to our updates, contacting us via email or phone, or entering information into the Platform.
  • Through the Platform: When you use the Lucent Edge platform, including interactions with digital employees, document uploads, email drafting, and workflow activity.
  • Through voice AI systems: When you interact with our AI voice automation systems, including inbound and outbound voice calls and related call handling.
  • Through automation workflows: When data is processed through our automation services and integrated third-party tools on your behalf.
  • From third parties: We may receive information from third parties that assist us in providing our Services (for example, software providers, voice AI platform providers, integration partners, or marketing partners).
  • Automatically: Through the use of cookies, web beacons, and other tracking technologies on our website and in our communications.

Declining to provide information: We need to collect certain personal information to provide our Services. If you choose not to provide information we identify as required, we may not be able to provide you with those Services or certain features of them.

5. Use of Your Information

We use the information we collect for purposes including but not limited to:

  • Service delivery: To provide, maintain, and improve the Lucent Edge platform, our AI automation and voice AI solutions, and our related Services, including the operation of governed digital employees, voice automation systems, and integrated workflows.
  • Customer support: To respond to your inquiries, requests, or complaints.
  • Business operations: For internal record-keeping, business analytics, platform and service performance monitoring, and operational purposes.
  • Communication: To send you updates, marketing materials, or other information you have opted to receive. You can opt out at any time by emailing datacontrol@northernbeaches.ai or using the unsubscribe mechanism provided in any communication. Even if you opt out of marketing communications, you may continue to receive necessary service-related and non-marketing communications.
  • Platform governance and auditability: To maintain audit trails, support human oversight of AI-assisted outputs, and enable governance, review, and compliance activities.
  • Voice AI service improvement: To monitor and improve the quality, accuracy, and performance of our voice AI systems, including for quality assurance purposes where applicable.
  • Research and development: To analyse and improve our Services and our business operations. As part of these activities, we may create aggregated, de-identified, or otherwise anonymised data from administrative or usage information. Strict Exemption for Customer Data: We explicitly exclude and strictly prohibit the use, aggregation, de-identification, or anonymisation of any Customer Data (including user prompts, uploaded files, proprietary documents, and AI-generated outputs) processed via the Lucent Edge platform for internal AI research, product development, or any form of AI model training or fine-tuning. Your confidential data is never used to train our AI models.
  • Compliance and protection: To comply with applicable laws, regulations, court orders, or other legal obligations; to protect our or your rights, privacy, or safety (including by making and defending legal claims); to enforce the terms and conditions that govern our Services; and to prevent, identify, investigate, and deter fraudulent, harmful, unauthorised, or illegal activity.

6. Automated Decision-Making

Our Services utilise artificial intelligence models, machine learning, and pre-programmed computer processes to assist with a variety of operational tasks. These tools are designed to augment and support human judgment, not to replace it.

In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth) and the transparency obligations under APPs 1.7, 1.8, and 1.9 (commencing 10 December 2026), we disclose the following:

Scope of Our Role:

This section describes automated decision-making in two contexts:

  1. Our own operations: How we manage waitlists, waitlist applications, and administrative contacts. We do not arrange for computer programs to make any decisions that significantly affect the rights or interests of individuals in these areas.
  2. Our Platform and Services: Where our business customers use our Services to process their own materials. In these scenarios, our customers are the primary APP entities responsible for arranging the decision-making processes. We provide the transparency details below to assist our customers in meeting their compliance obligations and to clarify how our platforms operate.

Applicable Decisions (APP 1.9):

These disclosures apply to decisions that could reasonably be expected to significantly affect the rights, interests, or circumstances of an individual. This includes decisions that are beneficial or adverse, as well as any refusal or failure to make a decision or take action.

Kinds of Personal Information Used (APP 1.8(a)):

Our Services process personal information including names, business details, contact information, voice/audio data, and the text of documents, communications, or workflow interactions provided or generated through the Services.

Kinds of Decisions Made Solely by Computer Programs (APP 1.8(b)):

Our autonomous agents may execute predefined, routine operational actions (such as routing a query, formatting data, or triggering a scheduling API) solely via computer programming. However, we do not arrange for computer programs to make any decisions that could reasonably be expected to have a significant beneficial or adverse effect on an individual’s rights, interests, or circumstances without human review.

Kinds of Decisions for which a Substantially and Directly Related Thing is Done by Computer Programs (APP 1.8(c)):

Our computer programs perform key preparatory tasks that are directly connected to, and serve as key factors in facilitating, human decisions:

  • Lucent Edge Platform: Our digital employees conduct research, analyse data, draft emails, and summarise materials. These outputs are key inputs used by authorised human operators to make final, manual determinations.
  • AI Automation & Voice AI Solutions: Our voice systems capture caller details, route enquiries, and trigger automated workflows. These systems operate within defined guardrails and automatically escalate to a human operator before any decision of significant effect can occur.

Human Oversight:

We maintain strict "Human-in-the-Loop" checkpoints for our AI systems. While autonomous agents may assist with drafting or workflow automation, all outputs that lead to a significant determination are subject to mandatory human review, defined authority limits, and manual escalation pathways. No decision of significant consequence is finalised without meaningful human intervention and judgment.

7. Disclosure of Your Information

We do not sell or rent your personal information to third parties. We may share your information in the following circumstances:

  • Service providers: With trusted third-party companies that perform ancillary services on our behalf (for example, cloud hosting, analytics, email delivery, voice AI platform providers, telephony services, or integration partners) and who are subject to strict confidentiality and data protection obligations.
  • AI model and voice AI providers: For the Lucent Edge platform, we access frontier AI models via sovereign Australian infrastructure. We maintain binding agreements with our third-party AI model providers that explicitly prohibit them from using your data to train, improve, or develop their AI models, and mandate zero data retention beyond the instantaneous generation of the requested output. For our voice AI solutions, we may utilise third-party platforms which are subject to rigorous privacy assessments and cross-border transfer controls under APP 8.
  • Payment processors: Any payment card information you provide is collected and processed directly by our payment processor, Stripe, in accordance with its privacy policy at https://stripe.com/privacy.
  • Professional advisers: With lawyers, auditors, or insurers, where necessary in the course of the professional services they provide to us.
  • Business transfers: If we are involved in a merger, acquisition, or asset sale, your personal information may be transferred. We will notify you of such changes in accordance with applicable laws.
  • Legal requirements: If required to do so by law, court order, or when necessary to protect our rights or the rights of others. In such cases, we will give you prompt notice of the demand or order (to the extent permitted by law) and reasonably cooperate with you in any effort to seek a protective order or otherwise contest such disclosure.

8. Data Sovereignty and Cross-Border Transfers

Core Lucent Edge Inference (Sovereign Processing): The Lucent Edge platform is architected to ensure that core AI inference and data processing occur strictly on sovereign Australian infrastructure (AWS Sydney region, ap-southeast-2). Customer Data submitted for AI processing within the platform remains within Australian-hosted environments at rest, in transit, and during active inference. We do not route core generative AI workloads through offshore data centres, providing you with verifiable data sovereignty for your sensitive materials.

Ancillary Services and Third-Party Integrations: While our core AI inference is 100% onshore, we utilise certain third-party ancillary services to support our operations (for example, web analytics, email delivery, customer support ticketing, or optional integrations like Microsoft 365). These ancillary systems, as well as our AI automation and voice AI solutions, may process or store limited personal information on servers located outside Australia (for example, in the United States). These transfers do not include Customer Data submitted for core sovereign AI processing, unless explicitly configured by the customer (e.g., routing an AI output to an external email service).

Compliance with APP 8: Before transferring any personal information overseas via our ancillary services or integrations, we take reasonable steps to ensure that the overseas recipient handles the information in accordance with the APPs, typically by implementing robust contractual safeguards and assessing the recipient's privacy practices, in compliance with APP 8.1.

9. Data Storage and Security

We have implemented technical, administrative, and physical safeguards to protect your personal information from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These safeguards include:

  • Encryption of data at rest and in transit.
  • Role-based access controls limiting access to personal information to authorised personnel on an as-needed basis.
  • Regular review and updating of security practices to protect against reasonably foreseeable internal and external risks.
  • Incident response procedures for the detection, investigation, and remediation of data security incidents.

However, no security system is impenetrable, and we cannot guarantee the absolute security of your data.

10. Data Breach Notification

In the event of an eligible data breach involving your personal information that is likely to result in serious harm, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. This means we will:

  • Take reasonable steps to contain the breach and assess the risk of serious harm.
  • Notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable after becoming aware of the breach.
  • Include in any notification a description of the breach, the kinds of information involved, and recommendations about the steps you should take in response.

We maintain a data breach response plan and will take all reasonable steps to minimise the impact of any breach on affected individuals.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and use data about you, including to improve our Services and your online experience. These technologies may include:

  • Cookies: Small text files stored on your device that allow us to recognise your browser and remember your preferences.
  • Web beacons: Small graphic images (also known as pixel tags or clear GIFs) used to determine whether a webpage or email has been accessed or opened, or whether certain content has been viewed or clicked.
  • Local storage: Technologies that provide cookie-equivalent functionality but may store larger amounts of data on your device.

You may adjust your browser settings to refuse cookies or to alert you when cookies are being sent. However, certain website features may not function properly without cookies.

12. Retention and Destruction of Your Information

In accordance with APP 11.2, we only retain your personal information for as long as is strictly necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is mandated or permitted by Australian law. Once personal information is no longer required, we take prompt and reasonable steps to securely destroy or permanently de-identify it.

Audit Trail and Log Retention Framework: To balance our governance and compliance obligations with privacy minimisation principles, we have implemented a defined retention schedule for platform interaction data and system logs:

  • Standard System Logs: General platform interaction data, temporary workflow state, and standard operational logs are retained for a default period of 90 days before being automatically securely destroyed.
  • Compliance and Legal Hold: Specific audit trail records relating to governed digital employee actions, authorised determinations, or security incidents may be escalated to a retention period of up to 7 years solely where required to satisfy mandatory legal, regulatory, or verifiable enterprise compliance obligations (such as litigation holds or statutory auditing requirements).

Voice and audio data captured through our AI automation services is retained only for the transient period necessary to process the immediate interaction and improve system accuracy, after which it is securely deleted.

13. Third-Party Links and Integrations

Our Services may contain links to, or integrations with, websites, applications, and other online services operated by third parties. We do not control third-party websites, applications, or services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access or use.

Strict Minimisation of Integrated Data (APP 3): Where our Services integrate with third-party tools at your direction (such as Microsoft 365 Outlook, CRM systems, or other connected operational platforms), we adhere strictly to the principle of data minimisation in accordance with APP 3 (Collection of solicited personal information). We configure OAuth scopes and API access controls to ensure we collect only the absolute minimum metadata and explicit operational inputs strictly necessary for the specific integration to function. We do not engage in broad, peripheral, or "just-in-case" data harvesting from your connected third-party accounts.

14. Your Rights and Choices

Under Australian privacy laws, you have the right to:

  • Access and correction: Request access to, or correction of, the personal information we hold about you. We will respond to access and correction requests within a reasonable period and in accordance with the APPs.
  • Withdraw consent: Where you have provided consent to our processing of your personal information, you may withdraw that consent at any time by emailing datacontrol@northernbeaches.ai. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
  • Opt out of marketing: You may opt out of marketing-related communications by following the unsubscribe instructions in any marketing email, or by contacting us at datacontrol@northernbeaches.ai. Even if you opt out of marketing communications, you may continue to receive necessary service-related and non-marketing communications.
  • Request deletion: You may request that we delete personal information we hold about you, subject to any legal or contractual obligations that require us to retain it.
  • Lodge a complaint: If you believe we have breached your privacy rights, you may lodge a complaint with us (see Section 16) or with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

How we handle complaints: If you lodge a privacy complaint with us, we will acknowledge your complaint within 7 days and investigate it promptly. We will provide you with a written response within 30 days, outlining the outcome of our investigation and any steps we have taken or propose to take. If you are not satisfied with our response, you may escalate your complaint to the OAIC.

15. Children's Privacy

Our Services are not directed at individuals under the age of 16. We do not knowingly collect or solicit personal information from anyone under 16. If you believe we have inadvertently collected personal information from a minor, please contact us so we can promptly delete it.

16. Contact Us

If you have any questions, comments, or concerns about this Privacy Policy or our practices, or if you wish to make a complaint or exercise any of your rights, please contact us at:

If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner:

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will revise the "Effective Date" at the top of this page. If we make material changes that reduce your rights or protections, we will take reasonable steps to notify you (for example, by posting a notice on our website or emailing you directly). Any changes will become effective when we post the revised Privacy Policy.


Disclaimer: This Privacy Policy is provided as a general guide and does not constitute legal advice. For specific legal advice tailored to your situation, you should consult with a legal professional familiar with the Australian Privacy Principles and relevant privacy regulations.