AERRIS

Privacy Policy

Last updated: August, 2026

We know that trust is essential when you use AERRIS to work with confidential legal, transaction and business information. AERRIS Pty Ltd (ACN 693 924 533) ( AERRIS, we, us or our) respects your privacy and is committed to handling personal information carefully, transparently and securely.

This Privacy Policy describes how we collect, hold, use and disclose personal information when you visit our website, use the AERRIS platform and related services, request a demonstration or support, communicate with us, or otherwise interact with AERRIS (together, the Services).

This Policy explains our practices under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where another privacy or data protection law applies, we will also handle personal information in accordance with that law.

Specific features, interactions or relationships may also be subject to a collection notice, cookie notice, customer agreement or other supplemental privacy notice. Those documents supplement this Policy and, where they deal with a matter more specifically, apply to that processing to the extent permitted by law.

1. Scope of this Policy and Customer Content

AERRIS is a business-to-business legal technology platform. Our customers may upload documents and data, connect authorised data sources, submit prompts or queries, collaborate within a matter, and generate analyses, dashboards, reports and other outputs ( Customer Content). Customer Content may contain personal information about people who do not themselves use AERRIS.

AERRIS also generates and collects technical, operational and usage information about the operation and use of the Services ( Service Data). Service Data may include information about features used, workflow steps, dashboard and visualisation types, generic information categories selected, system interactions, configuration patterns, the occurrence and type of correction or feedback events, response times, errors and other product-usage or performance information. Service Data does not include Customer Content. AERRIS may process Customer Content where necessary and permitted to provide, support, secure or configure the Services, but such processing does not change its character as Customer Content. Service Data may be generated from interactions involving Customer Content without including the underlying Customer Content itself.

AERRIS may also generate aggregated, statistical or otherwise de-identified information from Service Data and use of the Services ( De-identified Derived Data). De-identified Derived Data is processed so that it does not identify the relevant customer, matter, user or individual and does not contain or reasonably permit reconstruction of Customer Content or confidential customer information.

For clarity, an underlying document, clause, prompt, query, annotation, correction, output, financial value, legal conclusion or other customer-specific information remains Customer Content merely because AERRIS derives Service Data or De-identified Derived Data from an interaction involving that information.

Where we handle personal information in Customer Content to provide the Services, we generally do so under the customer’s instructions and the applicable customer agreement. The customer determines what Customer Content is provided to AERRIS, who may access it and the purposes for which it is used. Detailed terms governing Customer Content, including confidentiality, security, retention and deletion, may be set out in the customer agreement and will apply in addition to this Policy.

In jurisdictions that distinguish between data controllers and processors (or equivalent concepts), AERRIS will generally act as a processor or service provider for personal information in Customer Content where we process it on a customer’s behalf. This allocation depends on the circumstances and applicable law.

Where AERRIS processes Service Data for its own operational, security, analytics and product-improvement purposes described in this Policy, AERRIS may act in its own capacity in relation to that processing, subject to applicable law and the customer agreement.

If your personal information appears in Customer Content provided by an organisation, that organisation may be the most appropriate first point of contact about why the information was collected or how it is being used. We will assist our customers with privacy requests where appropriate and as required by law.

When you or your organisation upload Customer Content, connect a data source, or instruct AERRIS to retrieve or use information from another service, you are responsible for ensuring that you have the necessary rights, permissions and authority to do so, including under applicable privacy, confidentiality, privilege, contractual and third-party access arrangements.

2. Confidential, privileged and professional information

Because AERRIS is used for legal, transaction and other professional work, Customer Content may include confidential client information, legal advice, lawyer work product, commercially sensitive information and material that may be subject to legal professional privilege or other legal protections.

Our generation and use of Service Data or De-identified Derived Data does not authorise AERRIS to disclose, reproduce or make available confidential or privileged Customer Content. De-identified Derived Data used across customers is designed not to identify the relevant customer or matter or reasonably permit Customer Content or confidential customer information to be reconstructed.

AERRIS treats Customer Content as confidential in accordance with the applicable customer agreement and applies access, security and data-handling controls designed to protect that information. Nothing in this Privacy Policy is intended to alter the legal status of Customer Content, including any confidentiality obligation or claim of legal professional privilege. Whether privilege or another legal protection applies or is maintained will depend on the relevant circumstances and applicable law.

Customers remain responsible for ensuring they have the necessary rights and authority to provide Customer Content to AERRIS and for managing access to, use and disclosure of that information consistently with their legal, professional and confidentiality obligations.

3. Personal information we collect and hold

Personal information” has the meaning given in the Privacy Act and generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true.

The kinds of personal information we may collect and hold include:

Account and identity information – such as your name, business contact details, organisation, role, account credentials, authentication information and user permissions.

Customer Content – documents, datasets, prompts, queries, annotations, comments, outputs and other material provided to or generated through the Services, including personal information that may be extracted, summarised, classified, inferred or otherwise generated from that content. Depending on what a customer provides, this may include information about employees, contractors, directors, shareholders, counterparties or other individuals, including contact, employment, remuneration, financial, identity, signature, legal or commercial information.

Sensitive information – Customer Content may contain sensitive information, such as health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record information or biometric information We only collect or handle sensitive information where permitted by law, including where any required consent has been obtained or an applicable exception applies.

Usage, interaction, device and log information– such as IP address, browser and device information, login and access records, timestamps, feature and workflow usage, query volumes, dashboard and visualisation types, generic information categories selected, configuration and interaction patterns, the occurrence and type of correction and feedback events, diagnostic information, performance information, security events and audit logs. This may include information about how users interact with features and move through workflows, but does not include the underlying Customer Content associated with those interactions Usage and interaction information may constitute personal information while it remains linked to an identifiable user.

Communications, feedback and support information – including information you provide when you contact us, request a demonstration, submit feedback or ratings, participate in surveys, interact with our website(s), seek technical support or otherwise communicate with us.

Commercial and billing information – such as customer account, contract, invoicing and transaction information, where applicable.

Recruitment information – if you apply to work with us, such as your employment history, qualifications, references and other information relevant to your application.

We do not seek to collect more personal information than is reasonably necessary for our functions and activities. Where we receive unsolicited personal information, we will assess whether we could lawfully have collected it and, where required, destroy or de-identify it.

4. How we collect personal information

We may collect personal information:

directly from you when you create or use an account, contact us, request a demonstration, provide support information, attend an event or apply for a role;

from the customer or organisation that gives you access to AERRIS, including account administrators;

through Customer Content uploaded to AERRIS or made available through customer-authorised integrations, virtual data rooms, document repositories or other connected services;

automatically when you use our website or Services, including through logs, cookies, similar technologies and product telemetry that records technical, performance and interaction information about how features, dashboards, visualisations and workflows are used; and

from service providers, business partners or other lawful sources where reasonably necessary for our functions or activities.

Where it is lawful and practicable, you may interact with us without identifying yourself or by using a pseudonym. However, we generally need to know who you are to provide secure platform access, administer a customer account, provide support, enter into contracts or respond to certain requests.

5. How we use personal information

We use personal information to operate, provide, secure, support and improve the Services. Depending on the circumstances, these purposes include:

providing the AERRIS platform and its functionality, including document ingestion, indexing, classification, search, analysis, extraction, comparison, summarisation, issue identification, question-and-answer functionality and generation of draft outputs;

creating and administering accounts, authenticating users, managing permissions and providing customer and technical support;

performing our contracts, managing customer relationships, billing and business administration;

monitoring performance, troubleshooting, fixing errors, improving usability and developing the Services using service telemetry, feedback and aggregated or de-identified usage information where appropriate;

communicating with you about the Services, security, support, product updates, events or other matters relevant to our relationship with you;

protecting AERRIS, our customers and others, including detecting, preventing and investigating fraud, misuse, security threats, unauthorised activity and breaches of our terms;

maintaining records, resolving disputes, exercising or defending legal rights, and complying with legal, regulatory, professional or contractual obligations; and

assessing employment applications and managing recruitment.

We do not use Customer Content for general advertising or marketing and do not use Customer Content to train or improve AI models for the benefit of other customers or the public.

We may use Service Data to operate, secure, support, analyse, evaluate and improve the Services. Where Service Data contains personal information, we handle that information in accordance with this Policy and applicable law.

We may generate and use De-identified Derived Data to understand use of the Services and develop and improve AERRIS, including its taxonomies, classification methods, dashboard and visualisation structures, analytical workflows, evaluation methods, system prompts, model selection and routing, user experience and other proprietary technology.

For example, AERRIS may learn that users commonly analyse particular generic information categories together, frequently create a particular type of dashboard, commonly correct one generic classification to another, or follow particular analytical or workflow sequences, without using the underlying contract text, customer-specific values, legal advice or matter-specific conclusions for cross-customer training.

We do not attempt to re-identify De-identified Derived Data or use it to reconstruct Customer Content.

Customer Content may be used to configure, evaluate or improve the Services for the relevant customer, including through customer-specific configurations, corrections, thresholds, playbooks and institutional learning, in accordance with the applicable customer agreement.

If a customer separately agrees that specified Customer Content may be contributed for broader model development, evaluation or training, that use will be governed by a separate express written agreement identifying the information and permitted purpose. Our standard Services do not require customers to contribute Customer Content for shared model training.

If you voluntarily provide feedback, examples, screenshots or other material to help us improve the Services, we may use that feedback for support, quality and product-improvement purposes. Customer Content included in that material remains subject to the restrictions described in this Policy and the applicable customer agreement.

We may also use or disclose personal information for another purpose where you have consented, where you would reasonably expect that use or disclosure and it is related to the primary purpose (or directly related for sensitive information), or where otherwise permitted or required by law.

6. How AERRIS uses AI

AERRIS uses artificial intelligence and related technologies to assist professional users to review and work with documents and data. AI-assisted functionality may classify and organise documents, extract and compare information, identify potential issues, summarise content, answer questions about source material, generate analyses and reports, and assist users to create dashboards, visualisations and other outputs.

Privacy obligations apply to personal information used as an input to AI-assisted functionality and to AI-generated or inferred output where it is personal information. Information generated or inferred by AI can be incomplete or inaccurate, and information about an identified or reasonably identifiable individual may be personal information even if it is incorrect.

Our approach to Customer Content, AI and improvement of the Services includes the following:

No training of shared models on Customer Content. We do not use Customer Content, including uploaded documents, contract or clause text, matter-specific data, financial information, customer-specific outputs or confidential user inputs, to train or improve AI models for the benefit of other customers or the public. We do not authorise our third-party AI providers to use Customer Content to train or improve their public or shared models.

Customer Content may be processed as necessary to provide, configure, evaluate, secure, support and improve the Services for the relevant customer. This may include indexing, retrieval, extraction, classification, analysis, generation of outputs, evaluation of results and customer-specific configuration or learning. Customer-specific configurations, corrections, playbooks, thresholds and other institutional knowledge derived from Customer Content remain within the customer's environment unless the customer expressly agrees otherwise.

Service and usage data. AERRIS may collect and use Service Data as described in sections 1 and 5. Service Data does not include Customer Content. Where Service Data is generated from an interaction involving Customer Content, the underlying Customer Content remains Customer Content and is subject to the protections described in this Policy.

De-identified and derived data. AERRIS may generate and use De-identified Derived Data as described in sections 1 and 5 to operate, analyse, evaluate and improve AERRIS and its functionality.

De-identified Derived Data may include, for example, information about commonly used dashboard or chart types, generic information categories that users commonly analyse together, commonly used issue or attribute categories, workflow and analysis sequences, correction and error patterns, generic recommendation or action categories, feature usage and product-performance information.

De-identified Derived Data will not include contract or clause text, customer-specific financial values, legal advice or conclusions, party names or other Customer Content and will be processed so that it does not identify the relevant customer, matter, user or individual and does not reasonably permit Customer Content to be reconstructed.

AERRIS may use Service Data to operate, secure, support, evaluate and improve the Services. Where information about usage across customers is used to develop or improve generally available AERRIS functionality, AERRIS uses De-identified Derived Data that do not identify the relevant customer, matter, user or individual. AERRIS may use De-identified Derived Data to improve its standard taxonomies, classification methods, workflows, dashboard templates, analytical sequences, evaluation methods, system prompts, model selection and routing, product features and other proprietary technology, including by identifying model failure modes and creating synthetic or independently sourced evaluation and training examples.

We apply technical and organisational controls appropriate to the nature and intended use of De-identified Derived Data and may reassess de-identification and aggregation measures where relevant circumstances, available information or technology change.

User feedback and corrections. Where a user corrects, accepts, rejects or modifies an AI-generated classification, tag, recommendation, dashboard, workflow or other output, AERRIS may use the resulting non-content signal to evaluate and improve the Services. Where such signals are used for cross-customer product improvement, they are used as De-identified Derived Data so that they do not identify the relevant customer, matter, user or individual. For example, AERRIS may record that one generic clause category was corrected to another or that particular generic information categories are commonly analysed together, without retaining the underlying clause text, financial information or customer-specific conclusion for cross-customer training.

AERRIS will not use underlying Customer Content from such feedback to train shared models unless the customer has expressly agreed to a separate data-contribution arrangement permitting that use.

Data minimisation and purpose limitation. We seek to limit the personal information and Customer Content used or generated by AI-assisted functionality to what is reasonably necessary for the relevant Service, customer-directed task, security, support and permitted product-improvement purposes. Customers should avoid providing personal or sensitive information that is not needed for the matter or workflow.

Customer segregation and controlled access. Within AERRIS, Customer Content is maintained in segregated customer environments and access is limited according to permissions and legitimate need. Customer Content may also be processed by authorised technology providers where required to provide, support or secure the Services.

Third-party AI and technology providers. Where we use third-party AI or technology providers, they may process Customer Content only for purposes permitted under our arrangements with them, including providing and securing the relevant services, complying with applicable law and preventing misuse or abuse. We do not authorise those providers to use Customer Content to train or improve public or shared models or for their independent advertising or marketing purposes.

Human review and control. AERRIS is designed to support professional judgement, not replace it. AI-generated outputs should be reviewed by an appropriately qualified person before they are relied on for legal, commercial, employment or other significant decisions.

Accuracy, evaluation and correction. We take reasonable steps appropriate to the context to support the quality and accuracy of information processed through AERRIS. This may include source-linked review, user verification and correction processes, testing, evaluation of model performance and analysis of de-identified error and correction patterns.

Source traceability and explainability. Where the relevant functionality supports it, AERRIS links extracted information, findings or outputs back to underlying source material so authorised users can review the basis for the result and apply professional judgement.

AERRIS does not, as part of its ordinary business operations, allow computer programs to independently implement decisions using personal information that could reasonably be expected to significantly affect an individual's rights or interests. Customers may use AERRIS outputs within their own decision-making processes and are responsible for their use and approval of those outputs and for complying with applicable legal obligations.

If our practices change, we will update this Policy and provide any additional disclosures or obtain any additional permissions required by law or the applicable customer agreement.

7. When we disclose personal information

Personal information is an important part of the trust placed in AERRIS. We do not sell personal information. We disclose personal information only where reasonably necessary for the purposes described in this Policy, as directed by a customer, with consent, or as otherwise permitted or required by law.

We may disclose personal information to:

the customer, its authorised administrators and users, and other people or organisations the customer directs us to make information available to. Customer administrators may be able to manage accounts and permissions and access account, usage or Customer Content information according to the customer’s configuration;

other authorised users within the same customer workspace or matter where collaboration features are used. For example, comments, assignments, review status or other collaborative actions may be visible to users who have been granted access to that workspace or matter;

service providers that perform functions for us, including cloud hosting and data storage providers, AI and machine-learning service providers, analytics and product-performance providers, and other technology and operational providers we engage to provide, secure, support, administer, evaluate or improve the Services;

third-party services, plug-ins or integrations that a customer or user chooses to connect to AERRIS. Depending on the integration, AERRIS may transmit authorised queries, instructions or information needed to perform the requested function and may retrieve information from the connected service. Some connections may continue until the customer or authorised user disables or disconnects them. The third party may process information under its own terms and privacy policy, and customers are responsible for ensuring they have authority to enable the connection and disclose or retrieve the relevant information;

government authorities, regulators, courts, law enforcement or other third parties where required or authorised by law, or where reasonably necessary to protect the rights, property, safety or security of AERRIS, our customers, users or others.

Where a service provider processes Customer Content, we do not authorise that provider to use Customer Content to train or improve its public or shared models or for its own independent product-development, advertising or marketing purposes. Service providers are given access only to information reasonably needed to perform their functions and are required to handle that information consistently with their obligations to us.

If we receive a legally binding demand for Customer Content, we will handle it in accordance with applicable law and the relevant customer agreement. Where legally permitted and practicable, we will seek to notify the affected customer before disclosure and limit disclosure to information reasonably required by the demand.

8. Overseas disclosure and processing

Some of our service providers may be located in, or process personal information from, countries outside Australia. Depending on the Services and customer configuration, these may include the United States, Singapore, Ireland and United Kingdom. Our service-provider arrangements and processing locations may change from time to time.

Privacy and data protection laws vary between countries. Before disclosing personal information overseas, we take steps that are reasonable in the circumstances to protect the information and address our obligations under applicable law, including through contractual, technical and organisational safeguards where appropriate.

An overseas recipient may also be subject to foreign laws that permit or require disclosure of information to government authorities, courts or law-enforcement bodies. Where relevant, we address these risks through our contractual, technical and organisational safeguards and our assessment of overseas providers.

Some technical routing, remote access or storage arrangements may involve infrastructure in another country without necessarily constituting a disclosure under Australian privacy law. We nevertheless apply the security and privacy controls described in this Policy to personal information handled through our Services.

9. Product analytics, cookies and similar technologies

We use technical logs, product telemetry, cookies and similar technologies to operate and secure the Services, recognise browsers and devices, maintain sessions, authenticate users, remember preferences, diagnose problems, measure performance and understand how our website and Services are used.

Product telemetry may record information such as features used, workflow steps, dashboard or visualisation types, generic information categories selected, configuration patterns, the occurrence and type of corrections and feedback events and other interactions with the Services. This information helps us understand which functionality is useful, where users encounter difficulties and how the Services can be improved. Product analytics used for cross-customer improvement does not include the underlying Customer Content associated with those interactions.

We may aggregate or de-identify this information and use the resulting De-identified Derived Data as described in sections 5 and 6.

If we use cookies and similar technologies, you can control cookies through your browser or device settings. Blocking some cookies may affect the availability or operation of certain features. Where required, we will provide additional information or choices about non-essential cookies at the point they are used.

10. Security and confidentiality

We design our systems with security and privacy in mind.

We take reasonable technical and organisational measures designed to protect personal information and Customer Content from misuse, interference and loss, and from unauthorised access, modification or disclosure. Depending on the information and service, these measures include segregated customer environments, role-based and least-privilege access controls, authentication controls, encryption in transit and at rest, logging and monitoring, secure administrative access, vendor security controls, backup and recovery measures, and incident-response procedures.

Access by AERRIS personnel is limited to authorised personnel with a legitimate need and is subject to confidentiality and security obligations. We assess and manage third-party providers according to the nature of the services they provide and the information they may handle.

We may request information to verify your identity before providing access to personal information or acting on a privacy request. Users are responsible for protecting their credentials and devices and for using the Services in accordance with their organisation’s security and professional requirements.

No internet, cloud or email transmission is completely secure or error-free. If a data breach occurs, we will take steps to contain, assess and respond to it and will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme or other applicable law.

11. Retention and deletion

We retain personal information only for as long as needed to provide the Services or for other legitimate business, security, dispute-resolution, contractual or legal purposes. Retention periods depend on the type of information, the purpose for which it is held, contractual requirements, sensitivity and risk, and applicable legal requirements.

Customer Content is retained and deleted in accordance with the applicable customer agreement, customer instructions and our legal obligations. Where a customer requests deletion or its service ends, we will delete or return Customer Content in accordance with those arrangements, subject to any lawful retention requirement, legal hold, security requirement or limited backup retention process.

When personal information is no longer required for a purpose for which we may lawfully use or disclose it, we take reasonable steps to destroy it or de-identify it, unless we are required or authorised by law to retain it. Information in backup or archival systems may remain for a limited period until it is securely overwritten or deleted in the ordinary course.

Deletion or return of Customer Content does not require AERRIS to delete De-identified Derived Data generated in accordance with this Policy, subject to the applicable customer agreement and law.

Service Data that remains linked to an identifiable user or customer will be retained only for as long as reasonably required for the purposes described in this Policy or as otherwise permitted by law. De-identified Derived Data may be retained and used for the purposes described in this Policy after the underlying Customer Content has been deleted, provided it continues to satisfy the applicable de-identification requirements.

12. Your choices, access and correction

You may request access to personal information we hold about you and ask us to correct information that is inaccurate, out-of-date, incomplete, irrelevant or misleading. You may also ask questions about our handling of your personal information or request deletion where applicable.

Depending on where you live and the law that applies, you may have additional rights, such as rights to object to or restrict certain processing, withdraw consent, request deletion or portability, or complain to a privacy or data protection authority. These rights are subject to applicable exceptions and limitations and apply to the extent AERRIS is responsible for the relevant processing.

To make a request, contact our Privacy Officer using the details below. We may need to verify your identity before responding. In some circumstances, the law permits or requires us to refuse or limit a request; if that occurs, we will generally explain the reason and available complaint mechanisms.

Where the information is contained in Customer Content that we hold on behalf of a customer, we may refer your request to, or coordinate our response with, that customer.

Where personal information is contained in a source document, public record or third-party source that AERRIS does not control, we may be unable to alter the source itself. Where appropriate and legally required, we may correct or annotate information within our control, update derived information, or refer the request to the relevant customer or source.

You can opt out of marketing communications at any time by using the unsubscribe mechanism in the communication or contacting us. You may still receive service, security, legal or administrative communications that are necessary for your account or relationship with us.

13. International privacy rights

AERRIS is based in Australia and primarily handles personal information in accordance with Australian privacy law. Depending on where you are located and the circumstances in which we handle your personal information, additional privacy or data protection laws may apply and you may have additional rights in relation to your personal information.

Where applicable, we will handle personal information and respond to requests in accordance with those laws. Additional jurisdiction-specific information may be provided in this Privacy Policy, a supplemental privacy notice or the applicable customer agreement.

14. Privacy complaints

If you have a concern or complaint about how AERRIS has handled your personal information, please contact our Privacy Officer with enough information for us to understand and investigate the issue.

We will acknowledge and investigate privacy complaints and aim to respond within a reasonable period, generally within 30 days where practicable. If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or another applicable privacy authority.

15. Children

The AERRIS Services are designed for business and professional use and are not directed to children. We do not knowingly create user accounts for children. If Customer Content contains personal information about a child, we will handle that information in accordance with this Policy, the customer’s instructions and applicable law.

16. Changes to this Policy

Our business, technology and legal obligations may change over time, and we may update this Privacy Policy to reflect changes in our personal information practices. We will publish the current version and indicate when it was last updated. Where appropriate, we will provide additional notice of material changes.

17. How to contact us

AERRIS Pty Ltd (ACN 693 924 533)

Privacy Officer: Roger Ouk

Email: roger@aerris.ai

Postal address: Level 3, 530 Collins St, Melbourne VIC 3000, Australia

Stay in the loop

Sign up with your email address to receive news and updates.

For more information about the handling of your customers' personal data visit our Privacy Policy.