How we think about your data.
Plain English. No compliance theatre, no fine-print hedging. This is how ProjxAI actually approaches privacy and security when building AI systems for Australian businesses.
What this page is not: This is not a legal compliance statement, a formal data processing agreement, or a privacy policy. It's a transparent description of how we approach these issues. Our formal Privacy Policy is available separately.
Our working principles
These aren't aspirational values hanging on a wall. They are the decisions we make on every project.
Your data stays yours
We do not sell or monetise your business data. Project delivery can require approved tools to process or store working data, so we document what data a workflow touches, where it goes, who can see it and the agreed retention approach before we build anything.
Humans stay in the loop
We don't build fully autonomous AI systems that make consequential decisions without a person checking the output. Every workflow we design has defined approval points, escalation paths, and clear handoff to a human where it matters. AI handles the repetitive work — your team keeps control of what counts.
We choose tools that match your risk profile
Not every AI tool is right for every business. Before recommending any platform or API, we consider what data it will process, whether that data is sensitive, what the provider's data handling policy is, and whether a private or local deployment makes more sense. We'll tell you clearly when a tool is not appropriate for your situation.
We design for least-privilege access
AI systems only get access to the data they actually need to do the job. We don't connect tools to full databases when a subset of records will do. We scope API permissions tightly, use read-only access where write access isn't required, and document what each integration can and cannot touch.
Sensitive industries get extra care
If your business operates in health, legal, financial services, or another regulated sector, we apply a higher level of scrutiny to every tool and workflow we recommend. We'll be upfront about what we can and can't help with, and we'll point you to appropriate specialists when your situation requires it.
Private deployment when it matters
Where data sovereignty is a hard requirement, we can assess private or client-controlled deployment options. The appropriate design depends on the models, integrations, hosting environment and assurance standard required; any remaining third-party data flows are documented rather than assumed away.
Questions we get asked
Straight answers to the things risk-conscious buyers want to know before they engage.
Do you share our data with AI companies?
Are you ISO 27001 or SOC 2 certified?
What happens to our data after a project ends?
Can AI workflows comply with the Australian Privacy Act?
What if we're in a regulated industry?
Have a question we haven't answered?
If you have specific security or compliance requirements, bring them to the Clarity Call and we'll give you a direct answer.