Privacy Policy
Last updated: 1 January 2026
This Privacy Policy describes how Praktor AI Pty Ltd ("we", "us", "our") collects, uses, stores, and discloses your personal information when you use Praktor (the "Service") and when you visit our website. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who we are
Praktor AI Pty Ltd provides Praktor, a B2B platform for multi-persona customer-facing teams to capture, analyse, and act on client interactions. We are the entity that collects and holds the personal information described in this policy. If you have any questions about this policy or how we handle your information, contact us at [email protected].
2. What we collect
We collect the following categories of personal information:
- Account information: your name, email address, password (hashed), role within your organisation, profile picture (if provided), and timezone preference.
- Organisation information: organisation name, billing address, billing contact, and subscription tier.
- Client and log content: the text and voice recordings you record about your clients, including interaction notes, client quotes, and any attachments. This content is provided by you and may include personal information about third parties (your clients and their contacts).
- AI analysis outputs: the structured insights our AI generates from your logs — summaries, sentiment ratings, risks, opportunities, action items, and derived search data used to power semantic search.
- Usage metrics: counts of logs created, voice minutes consumed, AI assistant questions asked, and similar metrics used for billing and product analytics.
- Technical information: IP address, browser type, operating system, page views, and error events — collected automatically to operate the Service and diagnose issues.
- Session recordings: we record a sample of sessions to understand how the Service is used and to diagnose problems. A recording captures the pages you visit and the actions you take, and may include content shown on your screen. Passwords and form fields are always hidden from these recordings.
- Website enquiries: if you contact us through the enquiry form on our website, we collect your first and last name, your work email address, your company name (where you provide it), and the content of your message, so that we can respond to you. This information is held by our enquiry-management provider, which is located in the United States.
- Website usage: when you visit our public website we measure page views using a privacy-preserving analytics method that sets no cookies, stores no identifier in your browser, and does not track you across other websites.
3. How we use your information
We use your information to:
- Provide, maintain, and improve the Service
- Run the AI analysis pipeline on logs you submit
- Process billing and manage your subscription
- Respond to enquiries you send us through our website
- Send transactional emails (account invitations, security alerts, billing notices)
- Monitor for errors, debug issues, and measure product usage (via our analytics and error-monitoring providers)
- Comply with our legal obligations and respond to lawful requests
- Detect, prevent, and respond to fraud, abuse, or security incidents
We do not sell your personal information. We do not use your content to train third-party AI models (see Section 4).
4. How AI is used with your content
Your logs are processed by AI models to generate insights. The specific providers and safeguards:
- AI analysis provider: classification and extraction of risks, opportunities, and action items. The provider does not train its models on data sent via the API.
- AI search provider: powers semantic search across your logs. The provider does not train on API inputs.
- Voice transcription provider: voice-to-text transcription only. The provider does not train on API inputs.
AI outputs are labelled as such in the interface and are intended as a starting point for your own judgement. They are not a substitute for professional advice.
5. Third-party providers
We use a small number of third-party providers to run the Service and our website — for hosting and data storage, AI analysis and transcription, search, product analytics, error monitoring, email, background processing, payments, website analytics, and management of enquiries sent through our website. Each receives only the information its function requires.
Your database records, voice recordings and file uploads are stored in Sydney, Australia. Some processing happens overseas — in the European Union and the United States.
If you need the specific providers we use and what each one handles, email us at [email protected] and we will provide the list.
6. Data storage, security and breach notification
Your database records are stored in Sydney, Australia. Voice recordings and file uploads are stored with the same provider, in the same region. All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
We enforce strict per-organisation isolation at the database layer so that one organisation's data is never returned to another. Within your organisation, access is restricted to authenticated users with the appropriate roles.
We take reasonable steps to protect your information from misuse, interference, loss, unauthorised access, modification, and disclosure. No system is perfectly secure, and we cannot guarantee absolute security.
Our access to your content. A small number of authorised Praktor personnel can access customer content where it is necessary to operate the Service — to investigate a fault you have reported, to diagnose an error our monitoring has flagged, or where we are required to by law. We do not access your content to browse it, and we do not use it to train AI models (see Section 4).
Notifiable Data Breaches. If an eligible data breach occurs, we will assess it without undue delay and notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988 (Cth)). Where we process data on behalf of a business customer, we will promptly notify that customer and reasonably assist with its own notification obligations.
7. How long we keep your information
- Account and client data: retained for as long as your plan allows — 6 months on Free, 18 months on Pro, 3 years on Business, and 5 years on Enterprise, measured from the date of each note. We email you 30 days and again 7 days before anything is removed, so you can export it or move to a longer plan. If you change to a plan with a shorter retention period, notes already outside that shorter window are notified at the time you make the change rather than 30 days ahead — we always tell you how many will be removed. Deletion is permanent. Your account itself is kept for as long as it is open, plus a 7-day grace period after you ask us to delete it. You can export your data at any time from Settings → Export Data. Account deletion is available from Settings → Delete Account.
- Audit logs: retained for 2 years (for security investigation + compliance).
- Background job events: retained for 7 days (background-job event retention).
- Database backups: retained for 7 days (daily database snapshots).
After account deletion plus the grace period, your personal information is permanently removed from our live systems. Copies may remain in rolling backups until those backups age out.
8. Your rights under the Privacy Act 1988
You have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Withdraw consent to certain processing (where consent was the lawful basis)
- Lodge a complaint with us or with the Office of the Australian Information Commissioner (OAIC)
To exercise these rights, email [email protected]. We will respond within 30 days.
If you are not satisfied with our response, you can contact the OAIC at oaic.gov.au.
9. Rights for users outside Australia
If you are based in the European Economic Area, the United Kingdom, or another jurisdiction with data protection laws, you may have additional rights under those laws (for example, GDPR Articles 15, 16, 17, 18, 20, and 21 — access, rectification, erasure, restriction, portability, and objection).
You can exercise the access and erasure rights directly from the app: Export your data produces a portable archive, and Delete account triggers full deletion with a 7-day grace period for cancellation.
10. Cookies and local storage
In the Service, we use strictly-necessary cookies for authentication (session management) and browser local storage for analytics, theme preferences, and draft content. We do not set advertising, social-media, or cross-site tracking cookies.
Our public website sets no cookies at all. It measures page views using a cookieless analytics method that stores no identifier in your browser and does not track you across other websites.
For full detail see our Cookie Policy.
11. Children
The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided personal information to us, contact us and we will delete it.
12. International data transfers
Some of the providers we use are based outside Australia. When your personal information is transferred overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles — we choose providers that publish their own privacy and security commitments, and we send them only the information their function requires.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page.
For material changes — what we collect, how we use it, where it goes, or who we share it with — we will notify you by email at least 30 days before the change takes effect, and we will tell you plainly what is changing.
14. Contact
For privacy-related questions or requests, contact [email protected].