Privacy Policy
Effective 1 July 2026 · AxiomField Pty Ltd
1. Who we are
AxiomField is operated by AxiomField Pty Ltd (ABN pending), a subsidiary of Quantum Tech Hub. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
2. What we collect
- Account data: name, email, company, role, hashed password.
- Voice recordings submitted by technicians (uploaded audio files).
- Site photos uploaded by technicians.
- Report content: transcripts, structured fields, compliance scores, audit logs.
- Billing data: managed by Stripe; we store only your Stripe customer id, plan, and billing status — not card numbers.
- Usage data: IP address (for rate limiting on the public demo), timestamps of actions.
3. How we use it
We use collected data solely to operate the Service: transcribe voice, analyse compliance, deliver reports to supervisors, and bill your subscription. We do not sell your data. We do not train third-party AI models on your data — voice + photos are sent to OpenAI (Whisper) and Anthropic (Claude) via API in stateless request/response mode; those providers process data under their zero-retention API terms.
4. AI processing partners (international disclosure — APP 8)
- OpenAI (Whisper speech-to-text) — data processed in the United States.
- Anthropic (Claude Sonnet 4.5 text + vision) — data processed in the United States.
- Stripe (subscription billing) — data processed in the United States and Australia.
- Resend (transactional email) — data processed in the United States.
- MongoDB Atlas (application database) — hosted in Sydney AU region.
By using the Service you consent to this international transfer under APP 8.2.
5. How long we keep it
Reports and their attached voice + photo files: for as long as your organisation maintains an active AxiomField subscription, plus 30 days after cancellation to allow export. Audit logs: 7 years, to support compliance-driven use cases (WHS, SOCI). Billing records: 7 years per Australian Taxation Office requirements.
6. Your rights (APP 12 & 13)
You may request access to, correction of, or deletion of your personal information by emailing privacy@axiomfield.io. We will respond within 30 days. If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
7. Security
Data in transit is TLS-encrypted. Passwords are bcrypt-hashed. Multi-tenant isolation is enforced at the database query layer. We follow industry-standard security practices, but no system is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you within 72 hours in accordance with the Notifiable Data Breaches (NDB) scheme.
8. Voice recording consent
You are responsible for obtaining any recording consent required by the Australian state or territory in which the recording is made (see the Terms of Service for detail). We store recordings only for the purpose of report generation and audit.
9. Contact
Questions or requests: privacy@axiomfield.io.