Legal

Privacy Policy

How Enki.AI collects, uses, protects and shares your information, in plain language, under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated: 29 August 2026 (version 3.0)

1. Who we are and what this policy covers

Enki.AI is a business software platform built and operated by Enkisonics Pty Ltd (ABN 48 688 943 106, ACN 688 943 106) of 80 Fearnley Street, Portsmith QLD 4870, Australia ("Enkisonics", "we", "our", "us"). We are an Australian company; our team is in Cairns and our production infrastructure is in Sydney and Cairns.

This policy covers every way you might deal with us:

  • The websites enki.ai and enkisonics.com, including the contact, Talk To Sales and affiliate enquiry forms.
  • The Enki platform: the web app, the Enki.AI mobile apps for iPhone and Android, the Enki desktop app for Windows, and every business app inside the platform.
  • Enki's communication channels: web chat on your website, WhatsApp, Telegram, SMS, email and AI phone agents.
  • The Enki affiliate program and the affiliate workspace.
  • Support, sales and onboarding conversations with our team.

Two kinds of personal information

We handle personal information in two different roles, and your rights differ depending on which applies:

  • Information about you as our customer, prospect, affiliate or visitor (your name, contact details, account, billing and usage). We decide how this is collected and used, and this policy governs it directly.
  • Information your company stores in its Enki workspace (your customers, suppliers, staff, callers and contacts). Your company decides why that information is collected and how it is used. We process it on your company's behalf, under your company's instructions and our agreement with your company. If you are an individual whose details are held by a business that uses Enki, that business is your first point of contact; section 15 explains what we do to help.

We handle all personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme, whether or not a particular activity is technically covered by the Act.

2. The personal information we collect

Account and identity

  • Name, work email address and mobile phone number. Your mobile number is used for sign-in verification codes by SMS and for number-matching approvals of sign-ins through the Enki app.
  • Password (stored only as a salted cryptographic hash), sign-in history, and identifiers for the devices and browsers you sign in from.
  • Push-notification tokens for the mobile app, so we can deliver reminders, sign-in approvals and messages to your device.
  • Profile details you choose to add, such as a photo, role and time zone.
  • If you unlock the app with Face ID, Touch ID or Android biometrics, that check happens entirely on your device. We never receive your biometric data.

Company and billing

  • Business name, ABN, address, industry, branding and the details of your team members, provided by you or your company administrator during onboarding.
  • Billing contact details, tax invoices, payment history and your prepaid AI usage wallet transactions.
  • Payment card details are collected and stored by our payment gateway, Commonwealth Bank PowerBoard, as a secure token. We keep only the card brand, the last four digits and the expiry date.
  • For the affiliate program: your ABN, bank account details for commission payments, signed agreements (with the signing evidence: time, IP address and the document version signed), commission statements and deal registrations.

Content you and your company create in the platform

  • Conversations with Enki: the messages you send, the replies you receive, the files you attach and the actions you approve.
  • Voice: recordings you make in the app or on desktop are transcribed to text so Enki can respond. Voice sessions and read-aloud replies are generated from Enki's response text.
  • Business data your company keeps in its workspace: contacts, companies, pipelines, quotes, invoices, transactions, bookings, documents, files, notes, to-dos, calendar events and custom app records.
  • Messages your business sends and receives through Enki on WhatsApp, Telegram, SMS, email and website chat, including the phone numbers and addresses of the people you correspond with.
  • Phone agent calls: the audio, transcripts, caller numbers, call outcomes and any bookings or notes created from the call, stored in your company's workspace.
  • Images, videos, documents and websites generated or edited by Enki at your request.
  • Your company's goals, KPIs and standing instructions (the "heartbeat"), and the long-term memory Enki builds about your business and your preferences.

Connected services

  • When you connect a third-party tool (for example Google Workspace, Microsoft 365, Xero, Square, Shopify, HubSpot, Meta or LinkedIn) we store the access token that lets Enki act in that tool on your behalf, encrypted, scoped to your user.
  • Data Enki reads from those tools at your direction (an email thread, a calendar, an invoice) is processed to complete the task and may be kept in your workspace if you ask Enki to save it.

Collected automatically

  • Technical information: IP address, browser or app version, operating system, device model, language and screen size.
  • Usage information: features used, pages visited, actions taken, timestamps and error reports, used to run, secure and improve the service.
  • Approximate location inferred from your IP address, used for security checks and regional settings. We do not collect precise GPS location.
  • Cost and performance statistics for every AI reply (model used, tokens, time and cost), shown to you under the reply and used for billing.

From other people and sources

  • If an affiliate introduces your business to us, they give us your name, business, contact details and notes about your needs.
  • When you submit a Talk To Sales or contact form, we keep what you tell us about your business, the package you are interested in, and any call booking details.
  • We verify business details against the Australian Business Register (ABN Lookup).
  • Publicly available business information used to prepare for onboarding or support.

Sensitive information

We do not ask you for sensitive information (such as health, biometric, racial, religious, sexual orientation or criminal record information). Your business may choose to store sensitive information about its own customers in its workspace, for example a clinic keeping appointment notes or a gym recording injuries. Where that happens, your company is responsible for having the consent required to collect it, and we handle it only to provide the service to your company, with the protections described in section 11.

3. Mobile and desktop app permissions

The Enki.AI mobile app asks for the following permissions, each only when you use the feature that needs it:

  • Microphone: only when you actively start a recording by tapping the microphone, starting a voice session, or pressing your headset button in walkie mode (which can begin a recording while the app is in the background, always announced by an audible chime). The microphone is never accessed passively.
  • Contacts (read and write): only if you grant it, so you can pick people from your device address book and save contacts Enki creates back to your phone. Your address book is never uploaded without an action from you that requires it.
  • Photos and files: only when you choose to attach an image, video or document to a conversation.
  • Notifications: for reminders, sign-in approvals, messages and agent updates. You can turn these off in your device settings.
  • Exact alarms (Android): so to-do reminders fire at the time you set, even when the app is closed.
  • Biometrics: to unlock the app with your face or fingerprint. The check runs on your device; we receive only a yes or no.

The Enki desktop app can, with the Desktop Tools feature switched on, read and write files in the folders you choose and run actions on your computer that you ask Enki to perform. Every action is logged in your activity trail. The desktop app checks for and installs updates automatically.

4. How we use personal information

  • To provide and operate the platform: generating Enki's responses, running your apps and automations, delivering messages on your channels, and answering or making calls with your phone agents.
  • To secure the platform and your account: verification codes, sign-in approvals, unusual sign-in detection, rate limiting, fraud prevention and abuse monitoring.
  • To bill you: subscription charges, AI usage wallet accounting, tax invoices, receipts and payment reminders.
  • To onboard, support and train you, including reviewing your access application and shaping your Enki to your business.
  • To send service messages: security alerts, billing notices, release notes, changes to these terms and outages.
  • To send marketing about Enki only where you have consented or would reasonably expect it, always with a way to opt out (see section 14).
  • To improve the product: we analyse how features are used, and we may use de-identified or aggregated information to understand performance and plan improvements.
  • To run the affiliate program: attributing introductions, calculating and paying commissions, and enforcing the affiliate agreement.
  • To comply with our legal obligations, resolve disputes and enforce our agreements.

We do not sell personal information, we do not use your conversations or business data to train AI models, and we do not use them for advertising.

5. How AI processing works

Enki is an AI assistant. When you send a message or an automation runs, the request, together with the context needed to complete it (which can include parts of your company's data, your connected tools and your memory with Enki), is processed by one or more AI models. Which model does the work depends on the choice your company has made in the model picker and on the task.

Where the models run

  • Our own infrastructure in Australia. We operate a private GPU cluster in Cairns that runs open-weight language, speech and embedding models. Speech-to-text (Whisper), dictation clean-up, memory search, translation and a number of chat models run here, and the data does not leave our environment.
  • Frontier AI providers under business terms. Anthropic (Claude), OpenAI (GPT), Google (Gemini) and xAI (Grok) are accessed through their commercial APIs, whose terms prohibit the provider from using your content to train their models. These providers may retain inputs for a short period (typically up to 30 days) to monitor for abuse, then delete them.
  • Optional value-tier models. Some models in the picker are supplied by other providers, including DeepSeek, Moonshot AI (Kimi), Zhipu AI (GLM) and Alibaba Cloud (Qwen). Their terms differ from the frontier providers' and may permit the provider to use inputs to improve its services, and the provider may be located outside Australia (see section 10). These models are labelled in the model picker, your company administrator can disable them for your company, and no request is sent to them unless that model has been selected.

Other AI services

  • Mixture of Agents sends your question to several models at once and a further model combines the answers; each model's provider receives the question.
  • Voice: transcription runs on our own cluster, with Deepgram (USA) available as an alternative for phone calls. Spoken replies are generated on our own cluster or by ElevenLabs (USA), depending on the voice chosen.
  • Images and video are generated through fal.ai (USA) and Google.
  • Web search and page reading use Brave Search and Firecrawl, which receive the search query or the page address, not your business data.
  • Phone agents run on our own voice engine, with calls carried by Twilio and Telnyx and SMS by Twilio and SMSGlobal.

Providers receive the content of the request, not your account identity. Your company can see which model handled every reply, and what it cost, under the reply.

6. Automated decision-making

From 10 December 2026 the Privacy Act requires every organisation to say, in its privacy policy, what personal information its computer programs use to make decisions that could reasonably be expected to significantly affect a person's rights or interests, which of those decisions are made entirely by a program, and which a program substantially helps a person to make. Enki is built around automation, so we set this out in full here. Enki makes these decisions using the information your company holds and the instructions your company has given it; every action is recorded in the workspace activity trail, and a person can always ask for a decision to be reviewed by a human.

The personal information these programs use

  • Contact and identity details of the people a business deals with: names, phone numbers, email addresses, postal addresses, business names and roles.
  • The content of conversations: chat messages, emails, SMS and WhatsApp messages, and the transcripts and recordings of calls handled by AI phone agents.
  • Appointment, booking and job history, including availability, no-shows and cancellations.
  • Quotes, invoices, payments, payment methods on file (as tokens, never card numbers) and outstanding balances.
  • Lead and deal information: where an enquiry came from, what was asked for, pipeline stage, notes, and when the person was last contacted.
  • Your own account, device, sign-in and usage information, and the AI spending limits your company administrator has set for you.
  • Affiliate lead records: which affiliate introduced a lead, when, and whether it has converted.

Decisions made entirely by automated processes

These run without a person approving each one. Your company chooses which of them are switched on.

  • Answering and handling inbound contact. AI phone agents answer calls, take messages, book, confirm and reschedule appointments and send confirmation texts; Enki replies to web chat, email and messaging enquiries and decides which enquiries to flag or prioritise for a person.
  • Scheduled communications. Appointment reminder calls and messages, payment reminders and invoice follow-ups are sent when they fall due.
  • Security and abuse controls. Automated systems may block or challenge a sign-in, rate-limit an account, or hold a message or payment that looks like fraud or abuse, using your account, device and usage information.
  • AI spending controls. When a person reaches a spending or model limit set by their company administrator, the platform automatically switches them to a lower-cost model or pauses AI use until the limit is raised or the wallet is topped up.
  • Affiliate lead pool. A lead that an affiliate has not converted within 30 days is released automatically to the shared affiliate pool. This affects the affiliate's commission opportunity; it does not change anything for the person who made the enquiry.

None of these automated decisions refuses a person a product or service, credit, employment, insurance, housing or a legal right. Our Terms require a person to stay in the loop for any decision of that kind, and Enki asks a person before anything irreversible unless your company has explicitly automated it.

Decisions where automation substantially helps a person decide

  • Sales and service. Enki drafts replies, quotes and proposals, scores and orders leads, suggests who to follow up and when, and recommends when an overdue account should be escalated. A person at the business reviews and decides.
  • Business operations. Business audits, scheduling suggestions, rostering and cover suggestions, and marketing audience and campaign recommendations are prepared by Enki for a person to accept, change or reject.
  • Our own decisions about you. Whether we accept your access or affiliate application, your pricing, refunds, and whether an account is suspended or closed are decided by people at Enkisonics. Automated checks (for example ABN verification, payment status and fraud signals) inform those people; they do not decide.

What we do not do

We do not profile people for advertising, we do not make automated decisions about employment, credit, insurance, health or legal rights, and we do not use conversations or business data to train AI models.

Your rights

You can ask us, or the business that uses Enki, for an explanation of any automated decision that affects you and for a person to review it. Use the contact details in section 21. If your business uses Enki to make decisions about its own customers, your business is responsible for describing those decisions in its own privacy policy; you are welcome to reuse the wording in this section.

7. Data isolation between companies

Every company on Enki runs in its own sealed environment: its own AI runtime, its own dedicated databases, its own private file storage and its own AI memory. Nothing in one company's workspace is visible to, used for, or reachable from another company's Enki, and Enki never surfaces one company's information when working for another. Affiliates who introduce a business have no access to that business's workspace or data.

8. Who we share personal information with

We share personal information only with the categories of recipients below, each limited to what they need, and each bound by contract or law to protect it. We do not sell, rent or trade personal information.

Infrastructure and securityCloudflare (network security, content delivery, DNS, file storage and website hosting); our Sydney data-centre provider for the servers that run the platform; our own hardware in Cairns.
AI model providersAnthropic, OpenAI, Google, xAI; and, only when selected, DeepSeek, Moonshot AI, Zhipu AI and Alibaba Cloud. See section 5.
Voice, telephony and messagingTwilio, Telnyx and SMSGlobal (calls and SMS), Deepgram (speech-to-text), ElevenLabs (text-to-speech), Meta (WhatsApp Business), Telegram.
EmailBrevo (transactional and marketing email delivery); our own mail servers for email hosted with Enki.
PaymentsCommonwealth Bank PowerBoard (card tokenisation and processing).
Connected toolsComposio (secure connection layer for many third-party integrations) and the providers of the tools you connect, such as Google, Microsoft, Xero, Square, Shopify, HubSpot, Meta, LinkedIn and TikTok. Data flows to them only at your direction and under their own privacy policies.
Creative and content servicesfal.ai and Google (image and video generation), Brave Search and Firecrawl (web search and page reading), Unsplash, Giphy and Klipy (stock media), Google Maps.
Apps and notificationsApple (App Store, push notifications), Google (Play Store, Firebase push notifications), Expo (app updates).
Business verificationThe Australian Business Register (ABN Lookup).
AffiliatesIf an affiliate introduced your business, we tell them the status of that deal (registered, onboarded, active, ended) so commissions can be calculated. They do not receive your workspace data.
Professional advisersOur accountants, lawyers, insurers and auditors, where needed to run the business, handle a claim or meet an obligation.
AuthoritiesWhere the law requires it, under a warrant, subpoena or court order, or where necessary to prevent serious harm or to protect our rights.
A successorIf Enkisonics is merged, acquired or restructured, personal information may transfer to the successor. We will tell you before your information becomes subject to a different privacy policy.

9. Where your information is stored

Your company's workspace and databases are stored on servers in Sydney, Australia, and AI processing on our own infrastructure happens in Cairns. Backups are kept in Australia. Files are stored in your company's own private storage bucket on Cloudflare's network, and Cloudflare's global network is used to deliver the sites and apps quickly and securely, which means encrypted traffic passes through edge locations around the world.

10. Overseas disclosure

Some of the providers in section 8 operate outside Australia. When we send personal information to them, we take reasonable steps to ensure it is protected to a standard consistent with the APPs, through contract terms, security requirements and limits on what they may do with it. The countries involved are:

  • United States: Anthropic, OpenAI, Google, xAI, Deepgram, ElevenLabs, fal.ai, Composio, Twilio, Telnyx, Cloudflare, Apple, Meta, Brave, Firecrawl and Expo.
  • European Union (France): Brevo.
  • China and Singapore: DeepSeek, Moonshot AI, Zhipu AI and Alibaba Cloud, only when your company has selected one of those models.
  • Wherever the tools you connect are hosted: the providers of your connected services, under their own policies.

Overseas providers may be subject to the laws of their own country, including laws that allow government access to data. If that is a concern for your business, use the models and voices that run on our own Australian infrastructure and keep the optional overseas models disabled; Enki works fully that way.

11. Security and data breaches

We take security seriously because our own business depends on it. The measures we use include:

  • Encryption in transit (TLS 1.3) for every connection, and encryption at rest for files, databases and backups.
  • Two-factor authentication on every account, with number-matching approvals through the Enki app, and optional enforcement by your company administrator.
  • Per-company isolation of runtimes, databases, storage and memory, so a fault in one workspace cannot reach another.
  • Access tokens for connected services encrypted with keys specific to your company; every secret held in a vault, never in code.
  • Cloudflare DDoS protection, web application firewall and Zero Trust access in front of every service.
  • Least-privilege access for our staff, with access to customer workspaces only for support you have asked for, security investigation or a legal requirement, and logged when it happens.
  • Version control over every change to your system, with the ability to roll back in minutes; full audit trails of the actions Enki takes.
  • Professional indemnity and cyber liability insurance, underwritten by Australian insurers.

The security page describes the architecture in more detail. No system is perfectly secure, and we cannot guarantee that unauthorised access will never occur, but we work to prevent it and to detect it fast.

If a data breach happens

If we become aware of a data breach that is likely to result in serious harm to any individual, we will contain it, assess it, notify the Office of the Australian Information Commissioner and the affected individuals as the Notifiable Data Breaches scheme requires, and tell the administrators of any affected company promptly with what happened and what we recommend they do. Where the breach involves information your company holds about its own customers, we will give your company the information it needs to meet its own notification obligations.

12. How long we keep information

Account and company informationFor the life of the account, then deleted or de-identified within 90 days of closure, except records we must keep for up to 7 years under Australian tax, corporations and anti-money-laundering law.
Workspace content (conversations, files, business data, memory)Until you delete it or the company closes its account. After closure it is available for export for 30 days, then deleted within 90 days. Backups roll off within a further 35 days.
Phone agent recordings and transcriptsKept in your workspace under your company's settings; by default, recordings 90 days and transcripts for the life of the account. Your company can shorten this.
Message logs on WhatsApp, Telegram, SMS and emailFor the life of the account, or as your company configures.
Billing, invoices and wallet transactions7 years, as required by law.
Affiliate agreements, statements and payment records7 years after the agreement ends.
Sign-in, security and audit logsUp to 24 months.
Sales and support enquiriesUp to 3 years from the last contact, unless you become a customer.
Usage analyticsDe-identified within 24 months.

13. Your rights and choices

Under the Australian Privacy Principles you can:

  • Access the personal information we hold about you. Most of it is visible in your profile and workspace; we will provide the rest on request.
  • Correct anything inaccurate, incomplete or out of date. You can edit your own profile at any time.
  • Export your information and your company's data in a portable format. Company administrators can request a full workspace export.
  • Delete your information, subject to the retention periods above and to your company's rights over its workspace. Your company administrator can close the company account; you can ask us to delete your individual account.
  • Opt out of marketing at any time, without affecting service messages.
  • Deal with us anonymously or under a pseudonym for general enquiries where that is practical. We cannot provide an account, billing or support for a specific workspace without knowing who you are.
  • Withdraw consent where we rely on it, for example by disconnecting a connected tool or turning off a permission.
  • Complain to us, and if you are not satisfied with our response, to the Office of the Australian Information Commissioner (section 21).

To exercise any of these, use the details in section 21. We will need to verify your identity, we will respond within 30 days, and we will not charge for access requests except where the law allows a reasonable charge for unusually large or complex ones.

14. Marketing and communications

We send marketing email and SMS only in accordance with the Spam Act 2003 (Cth): with your consent, or to existing customers about the platform they use, always identifying Enkisonics as the sender and always with a working unsubscribe. You can opt out by using the unsubscribe link in any message, by changing your notification preferences in your profile, or by contacting us; we action opt-outs within 5 business days.

Service messages (verification codes, sign-in approvals, billing, security and changes to terms) are not marketing and continue while you have an account.

15. Information your business holds about its own customers

When your company stores the personal information of its customers, staff, suppliers or callers in Enki, your company is the organisation responsible for that information under privacy law, and we act on your company's instructions. In practical terms:

  • Your company needs its own privacy policy and collection notices, and the consents its industry requires, for the information it puts into Enki and the messages and calls Enki sends on its behalf.
  • Your company must have consent to send marketing by SMS, email or messaging apps through Enki, and must not use phone agents to call numbers on the Do Not Call Register for marketing.
  • If one of your customers asks your company for access to or correction of their information, the tools in Enki let your company find, export, correct and delete it. We will help your company respond within the legal time limits.
  • We only access your company's workspace to provide the service, at your company's request for support, for security, or where the law requires.

If you are an individual whose information is held by a business using Enki, please contact that business first. If you contact us, we will pass your request to that business and help them respond, and we will act directly where the law requires us to.

16. Phone agents and call recording

Enki phone agents answer and make calls for your business using an AI voice. Calls are transcribed so the agent can act on them, and recordings and transcripts are stored in your company's workspace for the periods in section 12.

The Telecommunications (Interception and Access) Act 1979 (Cth) and state and territory surveillance-device laws govern the recording of calls, and several states require every party to a call to be told, or to consent, before a private conversation is recorded. The phone agent greeting your company configures must therefore tell callers that they are speaking with an AI assistant and that the call is recorded, and your company is responsible for that notice being appropriate for the states its callers are in. Where a caller objects, the agent can continue without recording or hand the call to a person.

Callers can ask your business for a copy of their transcript or for it to be deleted, and your company can do both from the workspace.

17. Cookies and similar technologies

We use cookies and browser storage that are necessary to run the service: keeping you signed in, protecting against cross-site request forgery, remembering your theme and preferences, and Cloudflare's security cookies that distinguish people from bots. We do not use third-party advertising cookies, and we do not run third-party analytics or tracking scripts on enki.ai or in the platform. You can clear or block cookies in your browser; blocking the necessary ones will prevent sign-in.

18. Children, and people outside Australia

Children

Enki is built for businesses and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.

If you are outside Australia

Enki is designed for Australian businesses and is operated from Australia under Australian law. If you use the platform from another country, your information will be transferred to and processed in Australia and, as described above, by our providers elsewhere. If you are in the United Kingdom or the European Economic Area, you may have additional rights under the UK GDPR or GDPR, including the rights to restrict or object to processing and to lodge a complaint with your local supervisory authority; we rely on the performance of our contract with you, our legitimate interests in operating and securing the service, and your consent where we ask for it, as our lawful bases. Contact us to exercise those rights.

19. Affiliates

If you take part in the affiliate program we collect your identity, business and ABN details, bank account details for commission payments, the agreements you sign electronically and the evidence of signing, your deal registrations, the details of the businesses you introduce, and your commission statements. We use this to run the program, pay you, meet our tax obligations and enforce the affiliate agreement, and we keep it for 7 years after the agreement ends. Your affiliate workspace holds only your own pipeline and earnings; it never holds the workspace data of the businesses you introduce.

20. Changes to this policy

We will update this policy as the product, the law or our providers change. Every change carries a new "last updated" date at the top of this page, and we will tell account holders about material changes by email or in the app at least 14 days before they take effect, or immediately where a change is required by law. The previous version is available on request.

21. Contact us and complaints

Enkisonics Pty Ltd (ABN 48 688 943 106), 80 Fearnley Street, Portsmith QLD 4870, Australia. The fastest way to reach us about privacy is the contact form; mark your message "Privacy". You can also ask your Enki to raise a privacy request with us on your behalf.

If you have a complaint about how we have handled your personal information, tell us and we will acknowledge it within 5 business days, investigate, and respond in writing within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: www.oaic.gov.au, 1300 363 992, GPO Box 5288, Sydney NSW 2001.