Ask Sam Privacy Policy
Last Updated: 17th Feb 2025
-
Overview
1.1 We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This policy explains how and why we collect, use, hold and disclose your personal information.
1.2. "We", "us" and "our" means [OMG.AI Pty Ltd ACN 678 328 400].
1.3. You consent to us collecting, holding, using and disclosing your personal information in accordance with this policy.
-
What is personal information?
Personal information is any information or an opinion about an identified individual or an individual who can be reasonably identified from the information or opinion. Information or an opinion may be personal information regardless of whether it is true.
-
What personal information do we collect and hold?
3.1. We collect information about you and your interactions with us, for example, when you use any of our services or purchase any of our products or visit our website. The information we collect from you may include your identity and contact details, your use of and services, information about your health, details of enquiries or complaints you make and any other personal information you provide us.
3.2. We may collect information about how you access, use and interact with our website and mobile application. This information may include:
(a) the location from which you have come to the website or mobile application and the pages you have visited;
(b) technical data, which may include IP address, the types of devices you are using to access the website or mobile application, device attributes, browser type, language and operating system; and
(c) any information you provide while accessing website or mobile application or using our services.
3.3. We use cookies on our website. A cookie is a small text file that the website may place on your device to store information. We may use persistent cookies (which remain on your computer even after you close your browser) to store information that may speed up your use of our website for any of your future visits to the website. We may also use session cookies (which no longer remain after you end your browsing session) to help manage the display and presentation of information on the website. You may refuse to use cookies by selecting the appropriate settings on your browser. However, please note that if you do this, you may not be able to use the full functionality of the website.
-
Why do we collect, hold and use your personal information?
4.1. We collect, hold and use your personal information so that we can:
(a) provide you with services and manage our relationship with you;
(b) contact you, for example, to respond to your queries or complaints, or if we need to tell you something important;
(c) comply with our legal obligations and assist government and law enforcement agencies or regulators;
(d) identify and tell you about other or services that we think may be of interest to you; or
(e) improve our and services.
4.2. If you do not provide us with your personal information, we may not be able to provide you with our services, communicate with you or respond to your enquiries.
-
How do we collect your personal information?
5.1. We will collect your personal information directly from you whenever you interact with us.
5.2. We may collect information from third parties such as third-party businesses involved in any third-party sign-in function.
-
How do we store and hold personal information ?
a. Advanced Encryption: We use AES-256 encryption to protect data at rest and secure communication channels.All PII data stored in database is encrypted.
b. Regulatory Compliance: Ask Sam is fully HIPAA-compliant and adheres to stringent privacy and data protection standards.
c. International Standards: Our platform is ISO 27001-certified, ensuring robust security for company and customer information.
d. Certifications: We have applied for SOC 1 and SOC 2 certifications, which are expected soon, to further strengthen data security and regulatory compliance.
e. Continuous Security Measures: We regularly implement advanced security protocols to protect user information and maintain trust.
f. Ethical Hacking: Our ethical hackers continuously test the platform's firewalls and overall security to identify and address vulnerabilities proactively.
6.1. We store most information about you in computer systems and databases operated by either us or our external service providers. Some information about you is recorded in paper files that we store securely.
6.2. We implement and maintain processes and security measures to protect personal information which we hold from misuse, interference or loss, and from unauthorised access, modification or disclosure.
6.3. These processes and systems include:
(a) the use of identity and access management technologies to control access to systems on which information is processed and stored;
(b) requiring all employees to comply with internal information security policies and keep information secure;
(c) requiring all employees to complete training about information security; and
(d) monitoring and regularly reviewing our practise against our own policies and against industry best practice.
6.4. We will also take reasonable steps to destroy or de-identify personal information once we no longer require it for the purposes for which it was collected or for any secondary purpose permitted under the APPs.
-
Who do we disclose your personal information to, and why?
7.1. We may transfer or disclose your personal information to our group of companies.
7.2. We may disclose personal information to external service providers so that they may perform services for us or on our behalf.
7.3. We may also disclose your personal information to others outside our group of companies where:
(a) we are required or authorised by law to do so;
(b) you may have expressly consented to the disclosure or the consent may be reasonably inferred from the circumstances; or
(c) we are otherwise permitted to disclose the information under the Privacy Act.
7.4. If the ownership or control of all or part of our business changes, we may transfer your personal information to the new owner.
-
Do we disclose personal information to overseas recipients?
8.1. We may disclose your personal information to recipients which are located outside Australia (for example where our servers are located).
8.2. We will only disclose your personal information overseas if:
(a) we have taken reasonable steps to ensure that the overseas recipient of your personal information does not breach the APPs;
(b) the overseas recipient is subject to a law, binding scheme or binding contract that provides substantially similar protection to the APPs which you can access and enforce; or
(c) if the disclosure overseas is otherwise required or authorised by law.
-
Do we use your personal information for marketing?
9.1. We will use your personal information to offer you products and services we believe may interest you, but we will not do so if you tell us not to. These products and services may be offered by us, our related companies, our other business partners or our service providers.
9.2. Where you receive electronic marketing communications from us, you may opt out of receiving further marketing communications by following the opt-out instructions provided in the communication.
-
Access to and correction of your personal information
10.1. You may access or request correction of the personal information that we hold about you by contacting us. Our contact details are set out below. There are some circumstances in which we are not required to give you access to your personal information.
10.2. There is no charge for requesting access to your personal information, but we may require you to meet our reasonable costs in providing you with access (such as photocopying costs or costs for time spent on collating large amounts of material).
10.3. We will respond to your requests to access or correct personal information in a reasonable time and will take all reasonable steps to ensure that the personal information we hold about you remains accurate, up to date, complete, relevant and not misleading.
-
Your rights under the EU GDPR
11.1. Under the European Union (EU) General Data Protection Regulation (GDPR), if you are a data subject, you have the right to: (a) access your data; (b) have your data deleted or corrected where it is inaccurate; (c ) object to your data being processed and to restrict processing; (d) withdraw consent to having your data processed; (e) have your data provided in a standard format so that it can be transferred elsewhere; and (f) not be subject to a decision based solely on automated processing.
(Data Subject Rights)
11.2. We have processes in place to deal with Data Subject Rights requests. Our actions and responsibilities will depend on whether we are the controller or processer of the personal data at issue. Depending on our role as either a controller or processor, the process for enabling Data Subject Rights may differ, and are always subject to applicable law. Please refer to the Contact details section of this policy if you would like to make a Data Subject Rights request.
-
Complaints
12.1. If you have a complaint about the way in which we have handled any privacy issue, including your request for access or correction of your personal information, you should contact us. Our contact details are set out below.
12.2. We will consider your complaint and determine whether it requires further investigation. We will notify you of the outcome of this investigation and any subsequent internal investigation.
12.3. If you remain unsatisfied with the way in which we have handled a privacy issue, you may approach an independent advisor or contact the Office of the Australian Information Commissioner (OAIC) (www.oaic.gov.au) for guidance on alternative courses of action which may be available.
-
Contact details If you have any questions, comments, requests or concerns, please contact us at: Phone:1300375384 Email:contactus@asksam.com.au
-
Changes to this policy
14.1. From time to time, we may change our policy on how we handle personal information or the types of personal information which we hold. Any changes to our policy will be published on our website.
14.2. You may obtain a copy of our current policy from our website or by contacting us at the contact details above.