The short version. We don't store your clients' documents. We don't sell data. We never use client information to train AI models. Where our systems process information overseas, we say so below and name the countries. If you want the full technical detail, ask us for our data flow map — we'll send it.
1. Who we are
Avaris [full legal entity name and ABN to be inserted] is an Australian business providing AI automation and customer success services to mortgage brokers and brokerages.
We are bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles, and — because our services touch credit-related information — Part IIIA of that Act and the Privacy (Credit Reporting) Code 2014.
2. Two kinds of information
This distinction matters, so we've kept the rest of the policy split along it.
| Type | Whose information | Our role |
|---|---|---|
| Business information | Brokers and prospects who contact us, visit the site or book a call | We decide how it's used — see sections 3 to 6 |
| Client data | The borrowers and referral partners of brokerages we work for | We process it only on the brokerage's instructions — see section 7 |
3. Business information we collect
- Name, email address, phone number and business name when you book a call, email us, or complete a form
- Information you share during an Ops Audit or in the course of an engagement, including details about your business processes and systems
- Technical information when you visit avarisagency.com — IP address, browser type, pages viewed, referring site
- Correspondence between us
We collect this directly from you in almost every case. If we obtain your details from a referral or a public source, we'll tell you when we first make contact.
4. Why we collect it
- To respond to your enquiry and arrange an Ops Audit
- To provide, run and improve the services you engage us for
- To produce your reporting and performance reviews
- To send you information about our services, where you've agreed to receive it
- To meet our legal and record-keeping obligations
You can opt out of marketing communications at any time — every message includes an unsubscribe, or email us and we'll action it.
5. Who we share it with
We share business information only with service providers who help us operate — scheduling, email, hosting, accounting — and only to the extent they need it. We do not sell personal information, and we do not disclose it for anyone else's marketing.
We will disclose information where required by law, or to protect our legal rights.
6. Cookies and analytics
Our website uses a small number of cookies to make the booking widget work and to understand how the site is used in aggregate. You can block cookies in your browser; the site will still function, though the booking calendar may not.
7. Client data — how we handle information about your borrowers
When we deliver services to a brokerage, we act as a service provider processing information on that brokerage's behalf. The brokerage remains the entity responsible for their clients' information under the Privacy Act. They obtain the consents, they hold the relationship, and we act on their documented instructions.
What we process
| Category | Examples |
|---|---|
| Contact | Name, phone, email |
| Qualification | Employment type, deposit position, property stage, timeline |
| Interaction | Chat transcripts, call recordings and transcripts, message logs |
| Status | Which documents are outstanding, which milestone a file has reached |
What we deliberately do not process
We do not receive, store or read your clients' documents. Payslips, bank statements, identity documents and credit reports are uploaded directly to your own systems. Our document workflows track what is outstanding and chase it — they never see the contents. This is an architectural decision, not a policy preference: we designed it this way so that credit information never enters our systems.
Call recording
Where our systems make or answer calls, those calls are recorded and transcribed. Every call opens with a clear statement that the caller is speaking with an automated assistant and that the call is being recorded, and offers the option to speak with a person instead.
Outbound contact
Outbound campaigns run only to contacts who have an existing relationship with the brokerage and have not opted out. We screen against the Do Not Call Register and honour opt-out requests immediately and permanently.
8. Overseas disclosure
Some of the technology we use to deliver our services processes information outside Australia — principally in the United States. This applies to our conversational AI, voice, telephony and workflow platforms.
We take reasonable steps to ensure these providers handle information consistently with the Australian Privacy Principles, including by contract. We require in writing that no provider uses client information to train or improve AI models.
A current list of the providers we use, what each one processes and where, is available to any client on request, and forms part of our client agreements.
9. How we protect information
- Encryption in transit and at rest
- Multi-factor authentication on every system holding personal information
- Role-based access on a least-privilege basis, with no shared accounts
- Logging of access to client information
- Automated deletion when retention periods expire
- Separation of each client's data from every other client's
- A documented breach response plan
10. How long we keep it
| Information | Retention |
|---|---|
| Chat transcripts and call recordings | 90 days |
| Call transcripts | 12 months |
| Qualification and status data | Term of engagement, plus 30 days |
| Message and campaign logs | 24 months — needed to honour opt-outs |
| Reporting data | De-identified after 12 months |
| Client documents | Not held |
When an engagement ends, we delete or return all client information within 30 days and confirm it in writing.
11. Data breaches
If we become aware of unauthorised access to, disclosure of, or loss of information, we notify the affected brokerage within 24 hours — regardless of how serious we initially assess it to be. We then assist them with their assessment and any notification required under the Notifiable Data Breaches scheme.
We commit to 24 hours because the brokerage carries the legal obligation to assess and notify, and they cannot start that process if we sit on the information.
12. Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it's wrong. Email us and we'll respond within 30 days. There's no charge for a reasonable request.
If you're a borrower whose information we process on behalf of a brokerage, please direct your request to that brokerage — they're the entity responsible for it. We'll support them in responding to you.
13. Complaints
If you think we've mishandled your personal information, email us first at info@avarisagency.com. We'll acknowledge within 5 business days and aim to resolve it within 30.
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
14. Changes to this policy
We'll update this page when our practices change and revise the date at the top. If a change materially affects how we handle client information, we'll notify affected clients directly rather than relying on you to check.
15. Contact
Avaris
Email: info@avarisagency.com
Web: avarisagency.com