Privacy Policy — Proactive AI
Legal

Privacy Policy

Proactive AI is committed to protecting your personal information in accordance with the Australian Privacy Act 1988, all 13 Australian Privacy Principles, and the Notifiable Data Breaches Scheme.

Last updated: June 2026  ·  Proactive AI  ·  ABN 89 628 778 147

⚠️ Important notice

This Privacy Policy is a working template and does not constitute legal advice. You should seek independent legal advice from a qualified professional before relying on any part of this document. Proactive AI accepts no liability for any loss or damage arising from its use.

Proactive AI ("we", "us", "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy outlines how we collect, use, and safeguard your information when you visit our website or use our AI-powered services. By accessing and using our Website and Services, you agree to the practices described in this Privacy Policy.

1. Information we collect

a. Personal information

When you create an account, sign up for our services, or contact us, we may collect:

  • Name
  • Email address
  • Phone number
  • Business or practice name
  • Billing and payment information

b. Usage data

We may collect information about how you access and interact with our Website, including:

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on each page
  • Referring URL

c. AI interaction data

When you or your patients interact with our AI-powered automations and voice assistants, we may collect:

  • Conversation transcripts and logs
  • Voice call recordings and transcriptions
  • User inputs, queries, and responses provided to AI systems
  • Appointment booking details captured through AI assistants
  • Lead information collected via AI-powered forms and conversations
  • Behavioural data related to AI engagement and interaction patterns

d. Cookies and tracking technologies

We use cookies and similar tracking technologies to collect data on user interactions with our Website. These technologies allow us to remember your preferences and improve your user experience. You can control cookies through your browser settings.

2. How we use your information

We use the information we collect in the following ways:

  • To provide servicesto process your requests, manage your account, deploy and maintain AI automations, and deliver the services you have signed up for.
  • To improve AI performanceto refine and improve our AI automation models and conversational flows for better accuracy and patient experience.
  • To communicateto send transactional emails such as account confirmations, updates about our services, and customer support responses.
  • To generate reportsto provide you with performance analytics, AI engagement metrics, and other insights related to your services.
  • To improve our website and servicesto analyse usage trends and optimise the functionality and experience of the Website.
  • For marketing and promotionsto send you promotional material or updates that may be of interest. You can opt out at any time by following the unsubscribe instructions in our emails.

3. How we share your information

We do not sell or rent your personal information to third parties. However, we may share your information with third parties in the following circumstances:

  • Service providerstrusted third-party vendors who assist in providing our services, including CRM platforms, telephony providers, AI processing services, payment processors, and customer support platforms.
  • AI platform providerscertain data may be processed by third-party AI and machine learning platforms that power our automation services. We ensure appropriate data processing agreements are in place with these providers.
  • Legal requirementswe may disclose your information if required by law or in response to legal processes (e.g. court orders, subpoenas).
  • Business transfersin the event of a merger, acquisition, or sale of assets, your personal information may be transferred as part of the transaction.

4. Australia's AI governance framework — our compliance position

Australia does not yet have a standalone AI Act, but AI is actively regulated through a combination of existing laws and voluntary frameworks. As an AI automation business handling health information, Proactive AI operates in compliance with all applicable frameworks:

🔒

Privacy Act 1988 (Cth) & APPs

All 13 Australian Privacy Principles apply to Proactive AI as a handler of health information. The Privacy and Other Legislation Amendment Act 2024 introduced enhanced enforcement powers, a statutory tort for serious privacy invasions (effective June 2025), and automated decision-making transparency requirements (effective December 2026) — all addressed in this policy.

🤖

Australia's 8 AI Ethics Principles

Voluntary principles published by the Department of Industry, Science and Resources that form the foundational framework for responsible AI in Australia. Our full commitment to all 8 principles is set out in section 15 of this policy.

📋

Guidance for AI Adoption (October 2025)

The National AI Centre's primary guidance for responsible AI governance, setting out six essential practices. This replaced the earlier Voluntary AI Safety Standard and is the current benchmark for responsible AI adoption in Australia. Proactive AI aligns its operations with these six practices.

🗺️

National AI Plan (December 2025)

Australia's whole-of-government AI strategy, confirming that AI will be governed through existing laws rather than a standalone AI Act. The new Australian AI Safety Institute (operational early 2026) supports regulators in managing AI-related risks across the economy.

📡

Spam Act 2003 (Cth) & Telecommunications Act 1997 (Cth)

Our SMS automation services comply with Australia's anti-spam and telecommunications laws as administered by ACMA. All SMS communications require appropriate consent and include clear opt-out mechanisms.

⚖️

Australian Consumer Law (ACL)

Prohibits misleading or deceptive conduct, including through AI outputs. All AI communications are configured to be accurate and truthful. The proposed Unfair Trading Practices Bill 2026 includes AI-enabled manipulation within scope — Proactive AI does not engage in any such practices.

📌 Evolving regulatory landscape Australia's AI regulatory environment is changing rapidly. Mandatory guardrails for high-risk AI are under active consideration and new obligations are expected through 2026–2027. We monitor these developments closely and will update this policy as requirements come into force. For the latest, visit the OAIC and the Department of Industry, Science and Resources.

5. Data security

We take appropriate technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, or destruction. This includes encryption of data in transit, secure storage of conversation logs, and access controls for AI system administration. However, no method of transmission over the internet or electronic storage is 100% secure, so we cannot guarantee absolute security.

Proactive AI is committed to operating at the security standard defined by SOC 2 (System and Organisation Controls 2) — the internationally recognised security and privacy framework developed by the American Institute of Certified Public Accountants (AICPA). SOC 2 defines rigorous requirements across five Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.

Our commitment to the SOC 2 standard means we operate with the following controls in place:

  • Securitysystems and data are protected against unauthorised access through encryption, access controls, monitoring, and incident response protocols.
  • Availabilityour AI systems are designed for high availability, with processes in place to minimise downtime and notify clients of any disruptions.
  • Processing integrityAI automation outputs are designed to be complete, accurate, and configured exclusively using content approved by you — the client.
  • Confidentialityinformation designated as confidential — including patient data, business information, and conversation logs — is handled with strict access controls and never disclosed without authorisation.
  • Privacypersonal information is collected, used, retained, and disclosed only in accordance with our Privacy Policy and the Australian Privacy Act 1988 (Cth).
🔒 Our security commitment Proactive AI is committed to continuously improving our security practices in alignment with the SOC 2 framework. We treat the protection of your data — and your patients' data — as a non-negotiable responsibility. If you have specific security requirements or questions about our controls, please contact Paul Dorotich CPA directly at [email protected].

6. AI-specific data practices

In relation to our AI-powered services, the following data practices apply:

  • Conversation dataAI voice and SMS automation conversations may be recorded and stored for quality assurance, service improvement, and dispute resolution purposes.
  • AI traininganonymised and aggregated interaction data may be used to improve our AI models and conversational capabilities. Personal identifiers are removed before any data is used for training purposes.
  • Data retentionAI interaction data is retained for the duration of your service agreement plus a reasonable period thereafter, unless you request earlier deletion.
  • End-user disclosureyou are responsible for notifying your patients and customers that they may be interacting with an AI-powered system and that their interactions may be recorded.

7. Your rights under the Australian Privacy Principles (APPs)

Proactive AI handles health information and is therefore subject to the Privacy Act 1988 (Cth) and all 13 Australian Privacy Principles (APPs), regardless of business size. Under Australian privacy law, you have the following rights:

  • Access (APP 12)the right to request access to the personal information we hold about you. We will respond within 30 days.
  • Correction (APP 13)the right to request corrections to any inaccurate, incomplete, or out-of-date personal information we hold.
  • Anonymity (APP 2)where practicable, you may interact with us anonymously or using a pseudonym.
  • Opt-out of direct marketing (APP 7)you can opt out of receiving promotional communications at any time by following the unsubscribe link in our emails or contacting us directly.
  • Deletionyou may request that we delete your personal information, subject to our legal retention obligations.
  • Data portabilityin some cases, you may request a copy of your data in a machine-readable format.
  • AI interaction datayou may request access to or deletion of AI conversation logs and interaction data associated with your account.
  • Complaintif you believe we have breached your privacy, you may lodge a complaint with us first. If unsatisfied, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

To exercise any of these rights, please contact us using the details in section 14.

8. Children's privacy

Our Website and Services are not intended for individuals under the age of 18, and we do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal information from a child, we will take steps to delete that information as soon as possible. A Children's Online Privacy Code is expected to take effect in December 2026, and we will update our practices accordingly when that code is registered.

9. International data transfers (APP 8)

Some of our AI processing services and cloud infrastructure operate outside of Australia. Before transferring personal information to an overseas recipient, Proactive AI takes reasonable steps to ensure the recipient handles that information in accordance with the Australian Privacy Principles — as required by APP 8 of the Privacy Act 1988 (Cth).

You should be aware that if an overseas recipient breaches the APPs, Proactive AI may itself be treated as having breached the APPs and may be liable under Australian privacy law. We mitigate this risk by only engaging overseas service providers who maintain data protection standards consistent with Australian requirements and by entering into appropriate data processing agreements with those providers.

By using our Services, you consent to the transfer of your personal information to these overseas recipients in accordance with the above safeguards.

10. Notifiable Data Breaches (NDB) Scheme

Proactive AI is subject to the Notifiable Data Breaches (NDB) Scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of an eligible data breach — that is, a breach that is likely to result in serious harm to any individual whose personal information is involved — we are required to:

  • Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable, and in any case within 30 days of becoming aware of the breach.
  • Notify all individuals whose personal information was involved in the breach, or whose information is at risk of serious harm, as soon as practicable.
  • Publish a statement on our website describing the breach, the information involved, and the steps we are taking in response.

In the event of a data breach, we will act promptly to contain the breach, assess its severity, and notify affected individuals and the OAIC in accordance with our legal obligations. If you believe your personal information may have been involved in a data breach, please contact us immediately at [email protected].

For more information about the NDB scheme, visit the OAIC website at oaic.gov.au/privacy/notifiable-data-breaches.

11. Automated decision-making disclosure

Proactive AI uses AI-powered automation to assist with patient communications, appointment scheduling, call handling, and enquiry responses. Some of these automated processes may produce outputs that affect individuals — for example, classifying an enquiry as routine or urgent, or determining the appropriate response to a patient question.

In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth), which introduces mandatory automated decision-making transparency requirements taking effect on 10 December 2026, we disclose the following:

  • We use substantially automated processes to handle patient and customer communications on behalf of our clients.
  • These automated systems operate using content and instructions approved by our clients — they do not independently make clinical or medical decisions.
  • All AI systems are configured to escalate to a human where the situation requires judgement beyond their programmed scope.
  • Individuals interacting with our AI systems are informed that they are speaking with an AI at the start of every interaction.
  • If you wish to understand how an automated decision was made, or to challenge an automated outcome, you may contact us at [email protected].

We will review and update this section as the December 2026 requirements come into force.

12. Statutory tort for serious invasions of privacy

From 10 June 2025, under Schedule 2 of the Privacy and Other Legislation Amendment Act 2024 (Cth), individuals have the right to bring a legal action against any person or organisation that has seriously invaded their privacy — including through the misuse of personal or health information. This right exists independently of any complaint to the OAIC.

Proactive AI takes this obligation seriously. We are committed to handling all personal and health information in a manner that respects the privacy of every individual, and we will not use or disclose information in ways that could constitute a serious invasion of privacy. If you believe your privacy has been seriously invaded, you may seek legal advice about your rights under this statutory tort in addition to any complaint process through the OAIC.

13. Changes to this privacy policy

We reserve the right to update this Privacy Policy from time to time to reflect changes in the law, our services, or our data practices. Any changes will be posted on this page with the updated date. We encourage you to review this Privacy Policy periodically. Where changes are material, we will notify you by email or prominent notice on our website.

14. Contact us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us at:

Proactive AI

Contact: Paul Dorotich CPA

Website: proactiveai.pro

Email: [email protected]

ABN: 89 628 778 147

Mildura, Victoria, Australia

By using our Website and Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described.

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC): oaic.gov.au · Phone: 1300 363 992

15. Our commitment to Australia's 8 AI Ethics Principles

Proactive AI's approach to privacy is underpinned by Australia's 8 AI Ethics Principles. Here is how each principle shapes how we handle your data and your patients' data:

🤝

Human, societal & environmental wellbeing

Data collected through our AI systems is used solely to improve patient care outcomes, reduce administrative burden, and support your practice — never for purposes that could harm individuals, communities, or the environment.

⚖️

Human-centred values

Patients always have the right to speak with a human and to withdraw from AI interactions at any time. Our systems respect individual autonomy and are never used to manipulate, deceive, or surveil patients without their knowledge.

🔍

Fairness

Our AI systems are designed to treat all patients equitably regardless of age, language, background, or ability. Our multilingual capability ensures patients from diverse communities receive the same quality and accuracy of response. We do not use data in ways that could result in discrimination.

🔒

Privacy protection & security

All personal and health-related data is handled in strict accordance with the Australian Privacy Act 1988. Data is encrypted in transit and at rest, never sold or shared with unauthorised third parties, and retained only for as long as necessary. You retain full ownership of your data at all times.

🛡️

Reliability & safety

AI systems are tested before deployment and monitored continuously. All AI responses are based exclusively on content approved by you — the client. We maintain incident response protocols and will notify you promptly of any issue affecting patient communications or data security.

💡

Transparency & explainability

All Proactive AI systems are required to identify themselves as AI at the start of every patient interaction. Patients are never misled into believing they are speaking with a human. Clients receive full documentation of how their AI system operates and how responses are generated.

Contestability

Patients and clients have the right to question or challenge any AI-generated response or data-related decision. A human contact — Paul Dorotich CPA — is always available to review concerns. Clients may request access to any AI interaction log at any time by contacting [email protected] (see section 13).

🏛️

Accountability

Proactive AI — and specifically Paul Dorotich CPA — accepts full accountability for the responsible handling of all data processed through our AI systems. Clients are accountable for ensuring the accuracy of content they provide. Our data handling responsibilities are clearly documented and auditable.

These commitments are consistent with the Australian Government's AI Ethics Principles published by the Department of Industry, Science and Resources. Read the full principles →