Privacy Policy

Last updated: January 2026

Joist Consulting Pty Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling personal information in an open and transparent manner. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).


1. Scope of this Policy

This Privacy Policy applies to:

  • Visitors to our website

  • Clients and prospective clients

  • Users of our digital tools, including AI-enabled assistants

  • Stakeholders participating in discovery, analysis, or project activities facilitated by us


2. Personal Information We Collect

We may collect personal information including, but not limited to:

  • Identity and contact details (e.g. name, email address, organisation, role)

  • Professional or business information (e.g. business context, project responsibilities)

  • Communications (e.g. emails, chat messages, meeting notes)

  • Usage data relating to interactions with our website or digital tools

  • Conversation content voluntarily provided during interactions with AI-enabled assistants

We do not intentionally collect sensitive information unless it is reasonably necessary for an engagement and provided with consent.


3. How We Collect Personal Information

Personal information may be collected when you:

  • Contact us via our website or email

  • Engage us for consulting or advisory services

  • Participate in workshops, interviews, or discovery activities

  • Interact with AI-enabled tools or assistants we provide

  • Use collaboration platforms (e.g. Microsoft Teams or web-based tools) in connection with our services


4. Purpose of Collection

We collect and use personal information for purposes including:

  • Delivering consulting, project, and advisory services

  • Conducting discovery, analysis, and stakeholder engagement

  • Improving service quality and outcomes

  • Operating and improving digital tools used in client engagements

  • Communicating with clients and stakeholders

  • Meeting legal, regulatory, and contractual obligations


5. Use of AI-Enabled Tools (including the Virtual Business Analyst)

Some engagements may involve the use of AI-enabled assistants (such as the Joist Virtual Business Analyst) to facilitate structured conversations, capture insights, or support analysis.

In relation to these tools:

  • Access is restricted to authenticated and authorised users

  • Users must sign in using Microsoft Entra ID (formerly Azure Active Directory)

  • Only users explicitly granted access by Joist Consulting (or the relevant client) may use the tool

  • AI interactions are used solely for the purposes of the relevant engagement

  • Outputs are treated as draft working material and are reviewed by the project delivery team

  • AI tools do not make autonomous decisions affecting clients

  • We do not use client conversations to train public or general AI models


6. Disclosure of Personal Information

We may disclose personal information to:

  • Our employees and contractors on a need-to-know basis

  • Technology service providers supporting our operations (e.g. secure cloud hosting, collaboration platforms, AI tooling)

  • Professional advisers (e.g. legal or accounting) where required

  • Regulatory or government authorities where legally required

We do not sell personal information.


7. Overseas Disclosure

Some technology service providers we use (including cloud and AI platforms) may store or process data outside Australia.

Where this occurs, we take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with Australian privacy obligations.


8. Data Security

We take reasonable technical and organisational measures to protect personal information, including:

  • Identity-based access controls and role-based permissions

  • Secure cloud-hosted environments

  • Encryption in transit and at rest where available

  • Restricted access to AI tools and supporting systems

  • Regular review of access, security, and retention practices


9. Data Retention

We retain personal information only for as long as reasonably necessary to:

  • Fulfil the purpose for which it was collected

  • Meet contractual, legal, or regulatory requirements

When information is no longer required, it is securely deleted or de-identified.


10. Access and Correction

You may request access to, or correction of, personal information we hold about you by contacting us using the details below.

We will respond within a reasonable timeframe and in accordance with applicable law.


11. Complaints

If you believe we have breached the Australian Privacy Principles, you may contact us with details of your complaint.

We will investigate and respond promptly. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).


12. Changes to this Policy

We may update this Privacy Policy from time to time.
The latest version will always be published on our website with the effective date noted above.


13. Contact Us

For privacy enquiries, access requests, or complaints, please contact:

Joist Consulting Pty Ltd

If you have any questions about how we use the limited information we collect, please contact us and we will be happy to clarify.