Privacy Policy
(Covers Lisi — branded as AgedCareAI in the aged-care sector — across web, iOS and Android)
Version 7.0 • Effective: May 2026 • Aligned with MSPLA
Innovation Philosophy – I.P. Pty Ltd (ABN 25 652 243 484) (Innovation Philosophy, we, us, our) is committed to protecting and respecting your privacy and the privacy of the individuals whose personal information is processed through our products and services.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information when you:
-
visit our websites (www.i-p.com.au, www.agedcareai.com.au or any related domains);
-
correspond with us or enquire about our products;
-
use Lisi (our underlying artificial intelligence platform), whether through a web browser or through our iOS or Android mobile application. In the aged-care sector, Lisi is provided under the brand AgedCareAI. In all other sectors, Lisi is provided under the name "Lisi". References in this Policy to "Lisi", "the Platform", "AgedCareAI" or "the App" all refer to the same underlying platform; or
-
are an individual whose personal information is processed by us on behalf of an organisation that uses Lisi (for example, an aged-care resident, an NDIS participant, a patient, a client, a student, a policyholder, or a member of staff of an organisation that uses the Platform).
This Policy is aligned with the Master Service & Platform Licence Agreement (the MSA) under which we provide Lisi to organisations. Where personal information is processed through Lisi (whether under the AgedCareAI brand for aged-care customers or under the "Lisi" brand for other sectors) on behalf of an organisation, that organisation is the data controller and is responsible for its own privacy notice to its data subjects. Innovation Philosophy acts as a data processor (or, where the organisation hosts Lisi itself, as a software supplier with no access to personal information). Refer to your organisation for its specific privacy notice.
This Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), together with any State or Territory privacy and health-records legislation that applies to a particular customer or data subject (including, without limitation, the Health Records and Information Privacy Act 2002 (NSW), the Health Records Act 2001 (Vic), the Health Records (Privacy and Access) Act 1997 (ACT) and equivalent legislation in other Australian States and Territories), as well as any sector-specific privacy laws applicable to the Customer organisation’s industry (such as the Aged Care Act 2024 (Cth) for aged-care customers).
1. Scope of This Policy
This Policy covers two distinct contexts in which we may handle personal information:
1.1 Website, direct communications, and individual enquiries
When you visit our websites, fill in a form, request a demo, attend an event, or otherwise interact with us directly, we act as the data controller for the personal information you provide.
1.2 Platform usage (acting on behalf of an organisation)
When an organisation (for example, an aged-care provider, NDIS service provider, healthcare practice, insurer, education provider or consultancy) uses Lisi (our underlying platform, branded as AgedCareAI in the aged-care sector and as Lisi in all other sectors) to support its operations, that organisation is the data controller for the personal information it processes through the Platform. We act as a data processor (or, where the organisation has selected "Your Cloud" hosting, we have no access to personal information at all). Our handling of that personal information is governed by the MSA between us and the organisation.
If you are an end user, resident, participant, patient, client, student or other data subject of an organisation that uses Lisi or AgedCareAI: please refer to that organisation for its own privacy notice. We act on its instructions and any rights you have over your personal information should be exercised first through that organisation.
2. Information We Collect
2.1 Information you provide to us directly
When you visit our websites, contact us, request a demo, or correspond with us, we may collect:
-
contact information: name, job title, organisation, email address, phone number;
-
enquiry information: messages you send us, your interest in particular products, attendance at events;
-
account information: where applicable, login credentials and authentication factors;
-
marketing preferences: your opt-in preferences for receiving updates from us.
2.2 Information we collect automatically through our websites
When you visit our websites, we may automatically collect:
-
technical information: IP address, device type, browser, operating system;
-
usage information: pages visited, time on page, referring URL, search terms;
-
cookie information: as set out in section 8 (Cookies).
2.3 Information we collect through the mobile application (iOS and Android)
When you download, install or use our mobile application (the App), we may collect or process the following types of information, in addition to anything you submit through the App’s interface:
-
Device and technical information: device model, operating system version, unique device identifiers (such as advertising identifiers where applicable), app version, language and time-zone settings, and connectivity status.
-
Authentication information: login credentials and multi-factor authentication factors. Where you elect to use biometric authentication (Face ID, Touch ID or fingerprint), the biometric data itself is processed by your device’s operating system and is not transmitted to or stored by us; we only receive confirmation that authentication succeeded.
-
Usage and diagnostic information: feature usage, screens viewed, in-app events, crash reports and performance data, used to operate, secure, troubleshoot and improve the App.
-
Permissions you grant: content captured through device features you explicitly grant permission to (for example, microphone audio for voice-to-text features, camera/photo content for capturing forms or documents, photos uploaded for incident reports, and approximate location where used for an Application feature). We do not access these features without your express permission. You can revoke any permission in your device’s settings at any time.
-
Push notifications and in-app messages: we send operational and security-related notifications through the relevant operating-system push notification service (Apple Push Notification service or Google Firebase Cloud Messaging). You can disable non-critical push notifications in your device settings.
-
Local storage: the App may cache content locally on your device to support offline or low-bandwidth use. If you uninstall the App, reset your device, or are de-provisioned from your organisation, cached data may be deleted from your device.
We do not use the App’s permissions to: track you for advertising purposes; collect your contacts; access your private messages; access your location continuously in the background; or access content for purposes other than the Platform features you are using.
2.4 Information processed through the Platform on behalf of an organisation
(The actual scope is set out in Schedule 4 of the MSA between us and the organisation, as adapted to that organisation’s sector.)
-
For aged-care providers (AgedCareAI): resident information (name, date of birth, contact details, next of kin, health and clinical records, care plans, medication records, incident reports); staff information (names, qualifications, rostering data, training records).
-
For NDIS and disability service providers: participant information (name, date of birth, NDIS number, support plans, goals, health and disability information, incident reports); staff and screening data.
-
For other sectors (healthcare, insurance, education, consulting, etc.): client, patient, student, policyholder or claimant records; staff and contractor records; and any other categories agreed in writing with the organisation.
Sensitive information: depending on the sector and the organisation’s use case, the Platform may process sensitive information (including health information). The organisation is responsible for ensuring it has obtained any consents required by Applicable Laws before providing such information to the Platform.
2.5 Aggregate metrics and de-identified data
In accordance with our agreement with each Customer organisation, we may also collect aggregate metrics about the use and performance of the Platform, and may generate de-identified data from data processed through the Platform. The way we use this information is set out in section 3.3 below. Once data has been irreversibly de-identified, it is no longer "personal information" under the Privacy Act 1988 (Cth).
3. How We Use Personal Information
3.1 Information collected directly
We use personal information collected directly from you to:
-
respond to your enquiries, provide demonstrations, and follow up on your interest;
-
manage our customer relationships, including contracting, onboarding and support;
-
improve and personalise your experience on our websites and our App;
-
send you marketing communications about our products, services and events, where you have opted in (you may opt out at any time);
-
analyse aggregated, de-identified usage patterns to improve our products, websites and App;
-
comply with our legal and regulatory obligations.
3.2 Information processed through the Platform
When we process personal information on behalf of an organisation through the Platform, we use that information only:
-
to provide the Platform and the Services described in the MSA;
-
to integrate and serve third-party artificial intelligence services on behalf of the organisation;
-
for technical operations such as hosting, monitoring, security, support, maintenance, updates and backups;
-
on the documented written instructions of the organisation; and
-
as otherwise required by law.
We do not sell personal information processed through the Platform, and we do not use identifiable personal information to train artificial intelligence models.
3.3 Aggregate metrics and de-identified data
In accordance with the Master Service & Platform Licence Agreement we hold with each Customer organisation, we may collect, generate, retain and use:
-
aggregate metrics derived from the operation of the Platform — for example, usage statistics, performance metrics, error rates, response times, feature uptake, query volumes and system health data; and
-
de-identified data derived from data processed through the Platform, where such data has been irreversibly de-identified so that no individual is reasonably identifiable from it (whether alone or in combination with other information reasonably available to us), in accordance with the Privacy Act 1988 (Cth) and the Office of the Australian Information Commissioner’s de-identification guidance.
We may use this aggregate and de-identified data to:
-
operate, maintain, secure, monitor, troubleshoot and support the Platform;
-
develop, test, validate, benchmark and improve the Platform, its features, models, prompts, prompt templates, configurations and underlying analytical capabilities;
-
train, fine-tune and evaluate artificial intelligence models used by, or in connection with, the Platform;
-
generate industry research, benchmarks, insights and reports (provided that no Customer or individual is identified); and
-
any other lawful business purpose.
Important: aggregate metrics and de-identified data are not "personal information" once the de-identification process is complete, because they cannot be used to identify any individual. We will not (and will not permit any third party to) attempt to re-identify any individual from such data, and we will not disclose any aggregate or de-identified data in a form that identifies any Customer organisation without that organisation’s prior written consent.
4. How We Share Personal Information
We do not sell, trade or rent personal information. We may share personal information in the following limited circumstances:
4.1 Our service providers and AI partners
We use trusted third-party service providers to operate the Platform and our business. These include:
-
Cloud hosting and infrastructure: Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform.
-
Artificial intelligence services: OpenAI, Anthropic (Claude), Google (Gemini), Microsoft (Co-Pilot), xAI, DeepSeek, and other AI providers used by the Platform from time to time. The specific AI services used by an organisation depend on the configuration set out in its MSA.
-
Mobile-platform services: Apple Inc. (for iOS distribution and Apple Push Notification service) and Google LLC (for Android distribution and Firebase Cloud Messaging). These providers may collect technical information about app installation, crashes and notifications in accordance with their own privacy policies.
-
Payment and invoicing: Xero (or another electronic invoicing platform agreed with the organisation).
-
Operational and analytics tools: CRM, support, monitoring, analytics, security and similar tools necessary to operate our business.
All third-party service providers are bound by contractual obligations of confidentiality and security, and are required to use personal information only for the purposes for which we engaged them.
4.2 Hosting selection, "Our Cloud" or "Your Cloud"
The MSA between us and each Customer organisation specifies which hosting option applies to that organisation:
-
Our Cloud: we host the Platform and any personal information processed through it on our cloud infrastructure in Australia, applying technical and organisational security measures consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Under this option we act as a data processor on behalf of the Customer organisation.
-
Your Cloud: the Platform is deployed within the Customer organisation’s own cloud or on-premises environment. In that case, Innovation Philosophy does not host personal information; the Customer organisation is solely responsible for the hosting environment, security and any associated data-protection obligations. Our access in those circumstances is limited to support, maintenance and updates as agreed in writing with the Customer organisation.
Both hosting options are fully supported by us. The option that applies to you is set out in your organisation’s MSA and (for end users) in your organisation’s own privacy notice.
4.3 Cross-border data flows
Personal information processed through the Platform may be processed by AI providers and cloud infrastructure that is located outside Australia (for example, in the United States, the European Union, the United Kingdom or other jurisdictions). Where personal information is sent overseas, we take reasonable steps to ensure that the recipient handles it consistently with the Australian Privacy Principles (in particular APP 8). The specific cross-border arrangements applicable to a given organisation are set out in the MSA.
4.4 Legal disclosures
We may disclose personal information where required by law, including to comply with a court order, subpoena or lawful direction of a government agency, or to protect our legal rights. Where lawful, we will notify the affected organisation before making such a disclosure.
4.5 Business transactions
In the event of a sale, merger, acquisition or restructure of part or all of our business, personal information may be transferred to the acquirer or successor entity, subject to confidentiality and the same protections as set out in this Policy.
5. Data Security
We implement appropriate technical and organisational security measures designed to protect personal information from unauthorised access, use, disclosure, alteration or destruction. These include:
-
encryption of data in transit and at rest;
-
role-based access controls and multi-factor authentication for our personnel;
-
biometric and multi-factor authentication options for end users of the App;
-
network security, perimeter defences and endpoint protection;
-
regular security monitoring, logging and audit trails;
-
secure software development practices and vulnerability management;
-
App-store-aligned security practices (code signing, secure transport, App Sandbox / Android keystore use, biometric integration via OS-provided APIs);
-
contractual security and confidentiality obligations on our service providers;
-
staff training on privacy and information security.
No method of transmission over the internet or electronic storage is entirely secure. While we strive to protect personal information, we cannot guarantee absolute security.
Data breaches: we maintain a documented incident response process. Where a data breach occurs that affects personal information processed through the Platform, we will notify the affected organisation without undue delay so that the organisation can comply with its obligations under the Notifiable Data Breaches scheme. The MSA sets out the specific breach notification obligations between us and each organisation.
6. Your Rights
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the following rights in relation to personal information we hold about you:
-
Access: to request access to your personal information that we hold;
-
Correction: to request correction of any inaccurate or incomplete personal information;
-
Complaint: to make a complaint about how we have handled your personal information;
-
Marketing opt-out: to opt out of marketing communications at any time, by following the unsubscribe link in any marketing email or contacting us directly;
-
Anonymity / pseudonymity: to deal with us anonymously or under a pseudonym where lawful and practicable.
Important — for personal information processed through the Platform: if you are a resident, participant, patient, client, student or other data subject of an organisation that uses the Platform, the organisation (not Innovation Philosophy) is the data controller and the primary point of contact for your privacy rights. Please contact that organisation first. If we receive a request directly from you, we will, where lawful, refer it to the organisation for handling.
To exercise your rights or make a complaint, contact us using the details in section 10 below. We will respond within 30 days of receiving a valid request. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
7. Children’s Privacy
The Platform is a business tool intended for use by professional staff of organisations that subscribe to it. The Platform is not directed at, or intended for use by, children. We do not knowingly collect personal information directly from children. If you believe a child has provided us with personal information in error, contact us using the details in section 10 and we will take reasonable steps to delete the information.
8. Cookies and Similar Technologies
Our websites may use cookies and similar tracking technologies to enhance your experience, analyse traffic and remember your preferences. Cookies are small text files placed on your device. We use the following categories of cookies:
-
Strictly necessary cookies: required for the operation of our websites and cannot be switched off in our systems.
-
Performance and analytics cookies: help us understand how visitors interact with our websites by collecting anonymised information.
-
Functionality cookies: enable enhanced functionality and personalisation.
You can choose to accept or decline cookies through your browser settings. Disabling some cookies may affect website functionality. The Platform itself (web and App) does not place tracking cookies for advertising purposes. The App does not use advertising identifiers for cross-app tracking.
9. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including for legal, accounting, regulatory, contractual or reporting requirements.
For personal information processed through the Platform, retention is governed by the MSA between us and the organisation. Typically:
-
during the term of the MSA, the personal information is retained for the purpose of providing the Services;
-
on termination or expiry of the MSA, the organisation has up to 90 days to retrieve its data;
-
after the retrieval period, we will return or securely delete the data in accordance with the MSA, unless we are required by law to retain it.
Local data on your device (for example, cached content or files downloaded by the App) is managed by the App and can be cleared by signing out, uninstalling the App, or using your device’s storage management tools.
10. Contact and Complaints
If you have any questions, concerns or complaints about this Policy or our handling of personal information, please contact us:
Innovation Philosophy – I.P. Pty Ltd
ABN 25 652 243 484
Three International Towers, Level 24
300 Barangaroo Avenue, Sydney NSW 2000, Australia
Email: enquiries@i-p.com.au
Phone: (+61) 2 8776 8740
We will respond to all reasonable requests and complaints within 30 days. If you are not satisfied with our response, you may also lodge a complaint with the Office of the Australian Information Commissioner:
Website: www.oaic.gov.au
Phone: 1300 363 992
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. The latest version will be posted at https://www.i-p.com.au/privacy-policy and made available through the App, with an updated effective date. Where changes are material, we will take reasonable steps to notify affected parties (for example, by email to organisations, or by in-App notification to users).
12. Governing Law
This Privacy Policy is governed by the laws in force in New South Wales, Australia, together with any Commonwealth (federal) laws that apply throughout Australia. Where you are located in another Australian State or Territory, any mandatory consumer-protection, privacy or health-records laws of that State or Territory continue to apply to you. Disputes are subject to the non-exclusive jurisdiction of the courts of New South Wales and the courts of any other Australian State or Territory in which you are located.
Document version: 7.0 | Effective: May 2026 | Aligned with Master Service & Platform Licence Agreement
.png)