Join Our Webinar: See How Audit Pilot Keep You Audit-Ready All Year Round Register Free Now →

Audit Pilot

Privacy Policy

Privacy Policy

Last Updated: May 2026

1. Purpose

This Privacy Policy explains how Audit Pilot Pty Ltd (“Audit Pilot”, “we”, “our”, or “us”) collects, holds, uses, discloses, stores, and protects personal information and sensitive information in connection with the Audit Pilot platform and related services.

Audit Pilot is committed to protecting privacy and handling personal information in accordance with applicable Australian privacy and data protection laws, including:

  • Privacy Act 1988 (Cth)  
  • Australian Privacy Principles (APPs)

2. Purpose

This Privacy Policy applies to:

  • users of the Audit Pilot platform;  
  • healthcare providers and organisations using the platform;  
  • employees, contractors, and representatives of client organisations;  
  • website visitors;  
  • individuals whose information is uploaded to or processed through the platform; and  
  • any other individuals who interact with Audit Pilot.

This Privacy Policy applies to all personal information collected through:

  • the Audit Pilot website;  
  • the Audit Pilot compliance platform;  
  • onboarding and support processes;  
  • integrations and uploaded documents;  
  • communications with users and clients; and  
  • any related services provided by Audit Pilot.

3. Definitions

  • Personal Information: Has the meaning given under the Privacy Act 1988 (Cth), being information or an opinion about an identified individual, or an individual who is reasonably identifiable.  
  • Sensitive Information: Includes information relating to health, disability, racial or ethnic origin, religious beliefs, criminal records, professional memberships, biometric information, and other information classified as sensitive information under the Privacy Act.  
  • Health Information: Information about an individual’s physical or mental health, healthcare services provided, disability status, or other health-related data.  
  • Client: A healthcare provider, organisation, business, or entity that subscribes to or uses the Audit Pilot platform.  
  • Platform: The Audit Pilot software platform, associated systems, dashboards, integrations, applications, and related services.

4. Information We Collect

Audit Pilot may collect and process the following categories of information:

  • Identity and Contact Information
    • full names;
    • business names;
    • position titles;
    • email addresses;
    • telephone numbers;
    • postal addresses; and
    • account login credentials.
  • Organisation and Compliance Information
    • policies and procedures;
    • incident records;
    • audit records;
    • training records;
    • workforce compliance documentation;
    • accreditation records;
    • licences and registrations;
    • service agreements; and
    • governance and operational documentation.
  • Sensitive and Health Information
    Depending on how clients use the platform, uploaded documentation may contain:
    • employee health-related compliance records;
    • worker screening information;
    • vaccination records;
    • disability-related information;
    • patient or participant references contained within uploaded documents; and
    • other sensitive information relevant to healthcare compliance obligations.

      Audit Pilot does not intentionally collect patient clinical records unless uploaded by the client as part of compliance documentation management. We do not collect sensitive information (such as health information, racial or ethnic origin, or political opinions) unless it is directly related to providing our compliance monitoring services and you have provided explicit consent. Any sensitive information collected is handled with additional safeguards as required by the Privacy Act.
  • Technical and Usage Information
    • IP addresses;
    • browser type and device information;
    • login timestamps;
    • system activity logs;
    • usage analytics;
    • session information; and
    • security monitoring data.
  • Communications
    • support requests;
    • enquiries;
    • feedback;
    • onboarding communications; and
    • correspondence with our team.

5. How We Collect Information

WWe collect information through:

  • direct interactions with users and clients;
  • onboarding forms and account registration;
  • integrations with third-party systems authorised by clients;
  • website forms and enquiries;
  • cookies and analytics technologies;
  • support interactions;
  • automated compliance monitoring processes; and
  • publicly available sources where reasonably necessary.

Clients are responsible for ensuring they have lawful authority to upload and process information through the platform.

6. Purpose of Collection

We collect, use, and process personal information for purposes including:

  • providing and operating the Audit Pilot platform;  
  • monitoring regulatory compliance;  
  • identifying compliance gaps and risks;  
  • generating audit readiness insights and remediation guidance;  
  • maintaining platform security;  
  • providing customer support;  
  • onboarding and account management;  
  • improving platform functionality and services;  
  • communicating updates, alerts, and notifications;  
  • meeting legal and regulatory obligations;  
  • conducting internal quality assurance and risk management activities; and  
  • preventing fraud, misuse, or unauthorised access.

We only collect information reasonably necessary for our functions and activities.

7. Use of Artificial Intelligence and Automated Processing

Audit Pilot uses automated systems and artificial intelligence-assisted technologies to analyse uploaded documentation and identify potential compliance gaps, risks, missing evidence, and remediation requirements.

Automated outputs are intended to support compliance monitoring and operational workflows and should not be relied upon as legal advice or as a substitute for independent professional or regulatory advice.

Clients remain responsible for reviewing all outputs and ensuring compliance with applicable laws and regulatory obligations.

8. Disclosure of Information

We may disclose personal information to:

  • authorised employees and contractors;  
  • cloud hosting and infrastructure providers;  
  • IT and cybersecurity service providers;  
  • professional advisers, including legal, accounting, and insurance advisers;  
  • regulators, government agencies, or law enforcement where legally required;  
  • service providers supporting the operation of the platform; and  
  • other parties where authorised or required by law.

We do not sell your personal information to third parties. We do not share your compliance data with other clients or competitors.

9. Overseas Disclosure

We primarily store and process data within Australia. However, Audit Pilot may use third-party technology providers or cloud infrastructure providers that store or process data outside Australia.

Where overseas disclosure occurs, we take reasonable steps to ensure information is protected in accordance with Australian privacy laws and that providers maintain appropriate security and confidentiality standards.

Clients acknowledge that some data processing infrastructure may involve overseas hosting environments.

10. Data Storage and Security

Audit Pilot implements reasonable technical, administrative, and organisational safeguards to protect information from misuse, interference, loss, unauthorised access, modification, or disclosure.  

Security measures may include:

  • encryption;  
  • role-based access controls;  
  • multi-factor authentication;  
  • audit logging;  
  • secure cloud hosting;  
  • vulnerability management;  
  • access monitoring;  
  • backup and disaster recovery processes; and  
  • cybersecurity monitoring.

Despite reasonable safeguards, no system can guarantee absolute security.  

Users are responsible for maintaining the confidentiality of their login credentials and access permissions.

11. Data Retention

We retain personal information only for as long as reasonably necessary to:

  • provide services;  
  • comply with legal obligations;  
  • resolve disputes;  
  • maintain audit and compliance records; and  
  • enforce agreements.

Generally, we retain client records for a minimum of 7 years after the end of our business relationship, in line with Australian regulatory requirements. Compliance data and audit trails may be retained longer if required by healthcare regulations applicable to your sector.

When information is no longer needed, we securely destroy or de-identify it.

12. Your Rights

Audit Pilot is committed to ensuring individuals are able to access and exercise their privacy rights in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and other applicable Australian privacy and health records legislation.

12.1. Subject to applicable legal requirements and permitted exceptions, individuals may exercise the following rights in relation to their personal information.

12.1.1. Access to Personal Information

You may request access to personal information that Audit Pilot holds about you.

This may include:

  • confirmation of whether we hold your personal information;
  • the categories of information held;
  • the purposes for which the information is used; and
  • access to copies of personal information where appropriate.

Requests for access must be submitted in writing using the contact details provided in this Privacy Policy.

Audit Pilot will respond to access requests within a reasonable timeframe and in accordance with applicable legal requirements.

Where reasonably practicable, access will be provided in the manner requested by the individual.

12.1.2. Correction of Personal Information

You may request correction of personal information that is inaccurate, incomplete, misleading, or outdated. Audit Pilot will take reasonable steps to correct information where appropriate.

If we refuse a correction request, we will provide written reasons for the refusal and information regarding available complaint mechanisms where required by law.

12.1.3. Requests for Deletion or De-identification

You may request that Audit Pilot review whether personal information can be deleted or de-identified.

Audit Pilot will assess such requests in consideration of:

  • legal obligations;
  • healthcare and compliance record retention requirements;
  • contractual obligations;
  • legitimate business requirements;
  • evidentiary obligations; and
  • regulatory requirements.

In some circumstances, Audit Pilot may be legally or operationally required to retain certain information and may therefore be unable to delete records.

Where appropriate, information may instead be securely de-identified.

12.2. Verification of Identity

To protect privacy and maintain platform security, Audit Pilot may require individuals to verify their identity before:

  • providing access to information;
  • making corrections;
  • processing requests; or
  • responding to privacy-related enquiries.

Verification requirements may include:

  • confirmation of account ownership;
  • identification documents;
  • business authorisation evidence; or
  • other reasonable verification measures.

Where a request is made by an authorised representative, evidence of authority may be required.

12.3. How to Exercise Your Rights

To exercise these rights, contact us using the details provided below. We will respond to access requests within 30 days. There is no fee for making a request, though we may charge a reasonable fee for providing copies of information.

Requests should include:

  • the individual’s full name;
  • contact details;
  • details of the request; and
  • sufficient information to identify the relevant records.

We may request additional information where reasonably necessary to process the request.

13. Cookies and Analytics

Our website uses cookies and similar technologies to improve your experience and analyse website usage. These include:

  • Essential cookies: Required for the website to function properly
  • Analytics cookies: Help us understand how visitors interact with our website (Google Analytics)
  • Marketing cookies: Used to deliver relevant advertisements (Google Ads, Meta Pixel)

You can control cookies through your browser settings. Disabling certain cookies may affect website functionality. By continuing to use our website, you consent to our use of cookies as described.

14. Marketing Communications

You may opt out of receiving marketing communications from Audit Pilot at any time by:

  • using the unsubscribe functionality included in communications; or
  • contacting us directly.

Operational, compliance, security, and account-related communications may still be sent where necessary for service delivery or legal compliance.

15. Notifiable Data Breaches

Audit Pilot maintains internal procedures for identifying, assessing, managing, and responding to eligible data breaches in accordance with the Notifiable Data Breaches Scheme under the Privacy Act 1988 (Cth).

Where required by law, affected individuals and the Office of the Australian Information Commissioner (OAIC) will be notified.

16. Children’s Privacy

Audit Pilot is intended for use by businesses, healthcare providers, and authorised personnel. We do not knowingly collect personal information directly from children.

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated policy on our website with a new “Last Updated” date. For significant changes, we may notify you directly via email.

We encourage you to review this policy periodically.

18. Contact Us

If you have questions about this Privacy Policy, wish to exercise your privacy rights, or want to make a complaint, please contact us:

Audit Pilot Pty Ltd
Email: privacy@auditpilot.com.au
Website: https://auditpilot.com.au/contact/

If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992