Privacy Policy
Last updated: January 2026
Joist Consulting Pty Ltd (“we”, “us”, “our”) is committed to protecting your privacy and handling personal information in an open and transparent manner. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Scope of this Policy
This Privacy Policy applies to:
Visitors to our website
Clients and prospective clients
Users of our digital tools, including AI-enabled assistants
Stakeholders participating in discovery, analysis, or project activities facilitated by us
2. Personal Information We Collect
We may collect personal information including, but not limited to:
Identity and contact details (e.g. name, email address, organisation, role)
Professional or business information (e.g. business context, project responsibilities)
Communications (e.g. emails, chat messages, meeting notes)
Usage data relating to interactions with our website or digital tools
Conversation content voluntarily provided during interactions with AI-enabled assistants
We do not intentionally collect sensitive information unless it is reasonably necessary for an engagement and provided with consent.
3. How We Collect Personal Information
Personal information may be collected when you:
Contact us via our website or email
Engage us for consulting or advisory services
Participate in workshops, interviews, or discovery activities
Interact with AI-enabled tools or assistants we provide
Use collaboration platforms (e.g. Microsoft Teams or web-based tools) in connection with our services
4. Purpose of Collection
We collect and use personal information for purposes including:
Delivering consulting, project, and advisory services
Conducting discovery, analysis, and stakeholder engagement
Improving service quality and outcomes
Operating and improving digital tools used in client engagements
Communicating with clients and stakeholders
Meeting legal, regulatory, and contractual obligations
5. Use of AI-Enabled Tools (including the Virtual Business Analyst)
Some engagements may involve the use of AI-enabled assistants (such as the Joist Virtual Business Analyst) to facilitate structured conversations, capture insights, or support analysis.
In relation to these tools:
Access is restricted to authenticated and authorised users
Users must sign in using Microsoft Entra ID (formerly Azure Active Directory)
Only users explicitly granted access by Joist Consulting (or the relevant client) may use the tool
AI interactions are used solely for the purposes of the relevant engagement
Outputs are treated as draft working material and are reviewed by the project delivery team
AI tools do not make autonomous decisions affecting clients
We do not use client conversations to train public or general AI models
6. Disclosure of Personal Information
We may disclose personal information to:
Our employees and contractors on a need-to-know basis
Technology service providers supporting our operations (e.g. secure cloud hosting, collaboration platforms, AI tooling)
Professional advisers (e.g. legal or accounting) where required
Regulatory or government authorities where legally required
We do not sell personal information.
7. Overseas Disclosure
Some technology service providers we use (including cloud and AI platforms) may store or process data outside Australia.
Where this occurs, we take reasonable steps to ensure overseas recipients handle personal information in a manner consistent with Australian privacy obligations.
8. Data Security
We take reasonable technical and organisational measures to protect personal information, including:
Identity-based access controls and role-based permissions
Secure cloud-hosted environments
Encryption in transit and at rest where available
Restricted access to AI tools and supporting systems
Regular review of access, security, and retention practices
9. Data Retention
We retain personal information only for as long as reasonably necessary to:
Fulfil the purpose for which it was collected
Meet contractual, legal, or regulatory requirements
When information is no longer required, it is securely deleted or de-identified.
10. Access and Correction
You may request access to, or correction of, personal information we hold about you by contacting us using the details below.
We will respond within a reasonable timeframe and in accordance with applicable law.
11. Complaints
If you believe we have breached the Australian Privacy Principles, you may contact us with details of your complaint.
We will investigate and respond promptly. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
12. Changes to this Policy
We may update this Privacy Policy from time to time.
The latest version will always be published on our website with the effective date noted above.
13. Contact Us
For privacy enquiries, access requests, or complaints, please contact:
Joist Consulting Pty Ltd
If you have any questions about how we use the limited information we collect, please contact us and we will be happy to clarify.
