Privacy Policy

Effective date: 1 July 2026

Last updated: 2 July 2026

WIT SOLUTIONS PTY LTD (ACN 634 805 324)

1. Introduction

WIT SOLUTIONS PTY LTD (ACN 634 805 324), trading as ReelAI ("we", "us", or "our"), operates a business-to-business (B2B) software-as-a-service (SaaS) platform that enables businesses ("Clients") to manage AI-powered voice receptionist services.

This Privacy Policy explains how we collect, use, disclose, and protect information about our business clients who use our platform. This policy does not cover the personal information of your end-users (customers who call your business) — you are responsible for your own privacy practices regarding that data.

We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).

2. Data Controller vs Data Processor

2.1 ReelAI as Data Processor

For call recordings, transcripts, and end-user data processed through our platform:

  • You (the Client) are the Data Controller
  • ReelAI is the Data Processor
  • You determine the purposes and means of processing
  • We process data only on your instructions
  • You are responsible for obtaining consent from your end-users

2.2 ReelAI as Data Controller

For your business account information (company name, email, billing details):

  • ReelAI is the Data Controller
  • We determine how this information is collected and used
  • This Privacy Policy applies to this information

3. Information We Collect About Our Clients

3.1 Account Information

  • Business name and ABN/ACN
  • Contact person name and email address
  • Phone number
  • Billing address
  • Login credentials (password is encrypted)

3.2 Usage Information

  • Platform activity logs (login times, feature usage)
  • Browser type, IP address, device information
  • Pages visited and actions taken within the portal
  • Support tickets and communications

3.3 Payment Information

We do NOT store payment card details. All payment processing is handled securely by Stripe, a PCI DSS Level 1 certified payment processor. Payment card information is entered directly on Stripe's secure payment forms and never touches our servers.

Information we store for billing purposes:

  • Stripe Customer ID and Subscription ID (for account management)
  • Billing history and invoices
  • Tax information (GST registration number if provided)

3.4 End-User Data (Processed on Your Behalf)

We process the following data on your instructions as a Data Processor:

  • Call recordings and transcripts
  • Phone numbers of callers
  • Names and information provided during calls
  • Call metadata (duration, date/time, outcome)
  • Campaign data uploaded by you (CSV imports)

4. How We Use Your Information

4.1 Service Delivery

  • Provide and maintain the ReelAI platform
  • Process voice calls and transcriptions
  • Store and manage call recordings
  • Send you notifications about calls and system events
  • Provide customer support

4.2 Platform Improvement

  • Analyze platform usage to improve features
  • Monitor system performance and reliability
  • Develop new features and services
  • Conduct research and development

4.3 Business Operations

  • Process billing and payments
  • Send account-related communications
  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect against fraud and abuse

5. Data Storage and Security

5.1 Storage Location

We use the following infrastructure providers:

  • Amazon Web Services (AWS) - Sydney, Australia: All permanent data storage including encrypted databases, secure file storage, and email services. AWS Sydney infrastructure is IRAP-assessed at the PROTECTED level.
  • Azure OpenAI - Australia East: AI analysis and processing for call transcripts and data mapping
  • Anthropic (via AWS Bedrock) - Sydney, Australia: AI analysis for call insights. Data is processed within AWS in Australia and is not shared with or retained by Anthropic.
  • Retell AI - United States: Real-time call processing during active calls. Retell retains metadata only (transcripts, recordings, and PII removed) and deletes any retained data within 24 hours; the permanent record is stored in Australia - see Section 6.1 below

5.2 Security Measures

We implement enterprise-grade security measures to protect your data:

  • Military-Grade Encryption at Rest: All data stored in our secure databases and file storage uses AES-256 encryption, the same standard used by governments and financial institutions worldwide
  • Encryption in Transit: All data transmission uses TLS 1.3 protocol with perfect forward secrecy
  • Australian Data Centres: Permanent storage is hosted on AWS Sydney infrastructure, which is IRAP-assessed at the PROTECTED level
  • Multi-Tenant Isolation: Database-level client separation ensures your data cannot be accessed by other clients
  • Zero Payment Card Storage: All payment processing handled by PCI DSS Level 1 certified Stripe
  • Role-Based Access Controls (RBAC): Granular permission system with admin and client roles
  • Secure Password Storage: Industry-standard bcrypt hashing with salt
  • Webhook Security: Rate limiting and endpoint protections on inbound webhook traffic
  • Security Maintenance: Ongoing application of security patches and platform updates

Why Security Matters to Your Business

We've invested in enterprise-grade security infrastructure because your reputation depends on it. When your customers' call data is protected by the same AES-256 encryption used by banks and governments, you can confidently assure them their information is safe.

100% Australian data sovereignty means all permanent storage remains in Sydney data centers, giving you clear answers for privacy-conscious customers and compliance audits.

Hosting on AWS Sydney infrastructure that is IRAP-assessed at the PROTECTED level isn't just a checkbox—it's a competitive advantage that sets you apart from competitors using generic cloud platforms.

5.3 Data Retention

  • Call recordings and transcripts: Retained for 7 years by default (configurable per client)
  • Account information: Retained while your account is active plus 2 years after closure
  • Billing records: Retained for 7 years (Australian tax compliance)
  • Usage logs: Retained for 90 days

5.4 Data Breach Notification

We take data security incidents seriously and have comprehensive protocols in place:

  • Incident Response: We maintain documented incident response procedures designed for rapid assessment and containment
  • Assessment: Any suspected breach is immediately investigated to determine scope, impact, and appropriate response measures
  • Notification: In the event of a data breach that may impact your business or customers, we will:
    • Notify your organization (as Data Controller) immediately
    • Provide detailed information about the nature and scope of the breach
    • Work with you to determine appropriate notification requirements for affected individuals
  • Breach Details: Our notifications will include: nature of the breach, types of information involved, steps taken to mitigate harm, and recommended actions
  • Prevention: Post-incident reviews are conducted to strengthen security measures and prevent recurrence

Where a data breach is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required. Our multi-layered security approach is designed to prevent unauthorized access and detect anomalies before they become incidents.

6. Third-Party Sub-Processors (APP 8 Disclosure)

Important Cross-Border Disclosure (APP 8): During active calls, call audio is processed in real time by Retell AI in the United States. Retell is configured to store metadata only — call transcripts, recordings, and other personal information are removed and permanently deleted within 24 hours. The permanent transcript and recording are stored on our Australian infrastructure.

6.1 Essential Service Providers

Retell AI (United States)

  • Purpose: Real-time voice call processing and transcription
  • Data: Call audio processed in real time during active calls
  • Retention: Metadata only retained by Retell; transcripts, recordings, and PII removed and permanently deleted within 24 hours
  • Location: United States
  • Necessity: Required for core AI voice functionality

Amazon Web Services (Australia)

  • Purpose: Secure data storage and infrastructure services
  • Data: All platform data including recordings
  • Retention: As per your data retention settings (7 years default)
  • Location: Australia
  • Security: Encrypted at rest (AES-256) and in transit (TLS)

Azure OpenAI (Australia East)

  • Purpose: AI-powered call analysis, sentiment detection, CSV mapping
  • Data: Call transcripts, customer names, campaign data
  • Retention: Not used to train AI models. Content may be retained transiently (up to 30 days) for abuse monitoring in accordance with Microsoft's terms, unless a zero-retention exception applies
  • Location: Australia (East region)

Anthropic (via AWS Bedrock, Sydney, Australia)

  • Purpose: AI-powered call insights and analysis
  • Data: Call transcripts and related call data
  • Retention: Processed within AWS in Australia; not shared with or retained by Anthropic, and not used to train models
  • Location: Australia (AWS Sydney region)

Email Service Provider (Australia)

  • Purpose: Email notifications and communications
  • Data: Email addresses, call summaries
  • Retention: Email delivery logs retained for 14 days
  • Location: Australia

6.2 Your Consent to Cross-Border Disclosure

By using our services, you acknowledge and consent to:

  • Real-time processing of call audio in the United States by Retell AI (metadata-only retention, deleted within 24 hours)
  • The overseas disclosure described in this section (APP 8)
  • The privacy and data protection practices of our sub-processors

7. When We Share Your Information

We do not sell your personal information. We only share information in these circumstances:

7.1 With Your Consent

  • When you explicitly authorize us to share information
  • With third-party integrations you choose to enable

7.2 Service Providers

  • Sub-processors listed in Section 6
  • Payment processors for billing
  • Customer support tools

7.3 Legal Requirements

  • To comply with court orders, subpoenas, or legal process
  • To respond to government or regulatory requests
  • To protect our rights, property, or safety
  • To enforce our Terms of Service

7.4 Business Transfers

If ReelAI is acquired or merged with another company, your information may be transferred to the new owners (you will be notified beforehand).

8. Your Privacy Rights (Australian Privacy Principles)

Under the Australian Privacy Act 1988, you have the following rights:

8.1 Access (APP 12)

  • Request a copy of your personal information we hold
  • View your account information in the portal at any time

8.2 Correction (APP 13)

  • Update your account details through the portal
  • Request correction of inaccurate or outdated information

8.3 Deletion

  • Request deletion of your account and data
  • Some data may be retained for legal compliance (e.g., billing records)

8.4 Data Portability

  • Export your call recordings and transcripts
  • Download reports and analytics data

8.5 Complaint

If you have a privacy concern or complaint:

  1. Contact us at support@reelai.com.au
  2. We will investigate and respond within 30 days
  3. We will work with you to resolve the matter to your satisfaction

9. Cookies and Tracking Technologies

We use cookies and similar technologies for:

9.1 Essential Cookies

  • Session management (login authentication)
  • Security features (CSRF protection)
  • These cookies are necessary for the platform to function

9.2 Preference Cookies

  • Remember your theme selection (dark/light mode)
  • Store your notification preferences

9.3 Analytics Cookies

  • Understand how you use the platform
  • Improve features and performance
  • Where possible this data is aggregated; it may include identifiers such as IP address and device information as described in Section 3.2

10. Children's Privacy

ReelAI Portal is a B2B service intended for business use only. We do not knowingly collect information from individuals under 18 years of age. If you become aware that a child has provided us with personal information, please contact us immediately.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our services
  • Legal or regulatory changes
  • Changes to our data practices

We will notify you of significant changes by:

  • Email to your registered address
  • In-app notification
  • Updating the "Last Updated" date at the top of this page

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal information:

Privacy Officer

WIT SOLUTIONS PTY LTD (ACN 634 805 324)

Trading as: ReelAI

Email: support@reelai.com.au

General Inquiries: support@reelai.com.au

Response Time: Within 30 days

Privacy Policy Summary

  • ✓ We are a Data Processor for your end-user call data
  • ✓ You are the Data Controller responsible for end-user consent
  • ✓ All data stored in Australia (except temporary US processing during calls)
  • ✓ Strong encryption and security measures
  • ✓ 7-year retention by default (configurable)
  • ✓ You have full access, correction, and deletion rights
  • ✓ Compliant with Australian Privacy Act 1988

© 2026 WIT SOLUTIONS PTY LTD (ACN 634 805 324)trading as ReelAI