Prime AI · Legal & privacy

Privacy Policy

Last updated 22 September 2026

Plain English summary:

  • We collect only what we need to run the platform.
  • We never sell your data or use it for advertising.
  • We do not use your operational data to train AI models.
  • Data you connect is used solely to generate findings and reports for your organisation.
  • You can export or request deletion of your data at any time.

1. Overview

Prime AI is a product of Ensemble Solutions Pty Ltd (ABN 41 650 430 765) ("Ensemble Solutions", "Prime AI", "we", "us"). We are committed to protecting your privacy and complying with applicable Australian and US privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This notice explains how we handle personal information across the Prime AI marketing website (this site) and the Prime AI application used by our customers and their users (together, the "Services").

Prime AI is a B2B platform used by warehousing, 3PL and distribution operators ("Customers") to connect their operational systems, run governed AI-assisted analysis, and coordinate the resulting findings and actions. This policy applies to Customers and to their employees and contractors who use the Services.

By creating an account or using the Services, you agree to the practices described in this policy. If you do not agree, please do not use the Services.

Where a Customer connects their own operational data to Prime AI, that data may include personal information about the Customer's own staff, drivers, customers or suppliers. In that context, the Customer is the data controller for that personal information and Ensemble Solutions processes it on the Customer's behalf. If you are an individual whose information has reached us this way, please direct data-subject requests to the Customer you deal with; we will assist them in responding.

2. Information We Collect

Account and organisation information

When you create an account we collect your name, work email address, a securely hashed password, and your organisation's name and billing details. If you invite team members, we collect their email addresses and their role within your organisation.

Connected operational data

When you connect a source system, we receive the operational data made available through that connection — for example accounting data from Xero, QuickBooks Online or MYOB, order and sales data from Shopify, files from Microsoft or Google, data extracted through the Prime Data Gateway, or files you upload directly. This data is used to standardise, analyse and report on your operation, as described in your Terms of Service.

AI analysis outputs

We store the outputs of AI-assisted analysis — findings, confidence scores, evidence references, recommended actions, and the audit trail of approvals and follow-up checks associated with them.

Billing information

Payments are processed by Stripe. We do not see or store your full card number.

Usage and technical data

We collect standard server logs (IP address, browser type, pages or endpoints visited, timestamps) and aggregate usage metrics used to operate and secure the Services.

3. How We Use Your Information

We use information to:

  • authenticate users and maintain secure sessions;
  • run AI-assisted analysis of the operational data you connect, and generate findings, reports and recommended actions;
  • provide support and troubleshoot issues;
  • manage subscriptions and process billing via Stripe;
  • maintain the security, integrity and tenant isolation of the Services;
  • debug and develop new features; and
  • comply with our legal obligations.

We do not sell your information, share it with third parties for their own marketing purposes, use it for advertising, or use it to train AI models.

4. Operational & Customer Data

Prime AI processes operational data, which may include personal information, on behalf of our Customers. Customers are the data controllers for that data — they decide which systems to connect and for what purpose. Operational data connected by one Customer is scoped strictly to that Customer's account and is not accessible to other Customers. Customers are responsible for ensuring they have a lawful basis to connect and process that data, including any personal information about their own staff, drivers, customers or suppliers, and for providing appropriate notices to those individuals.

5. Data Retention

  • Account data: retained while your account is active. Following account closure (including a Permanently Closed Company Account), you may request deletion of your account data by contacting us. Verified deletion requests will be processed subject to applicable legal, security, billing, fraud-prevention, backup and audit retention requirements.
  • Connected operational data: retained until you disconnect the relevant source or close your account, at which point it is deleted in the ordinary course, subject to a limited window to allow export as described in our Terms of Service.
  • AI analysis outputs and audit trail: retained until deletion is requested, or until the underlying account is closed.
  • Billing records: retained for 7 years as required under the Taxation Administration Act 1953 (Cth).
  • Server and access logs: retained for up to 90 days for security and debugging purposes.

You may request deletion of your personal data at any time by contacting us using the details below.

6. Third-Party Sub-processors

We use the following categories of sub-processors to deliver the Services:

Sub-processorPurposeLocation
OpenAI, Anthropic, GoogleGenerate AI-assisted analysis, summaries and recommendations from data submitted to those features, via our own gateway infrastructure.US-based
StripeSubscription billing. We do not see or store your card number.US-based
Oracle Cloud InfrastructureApplication hosting and encrypted backups.Australia (or your selected region)
SentryError and exception monitoring, to diagnose and fix technical faults.US-based
MetabaseOptional embedded reporting, where a Customer connects their own Metabase instance.As configured by the Customer
Xero, QuickBooks Online, MYOB, Shopify, Microsoft, GoogleRetrieve data from accounts you explicitly connect and authorise, for standardisation and analysis within the Services.As operated by each provider

AI analysis calls are made under our own API arrangements. Data sent to a model provider is used only to generate the output returned to you as part of the Services, and is not used to train models for other customers.

7. Cookies & Sessions

The Prime AI application uses a small set of session cookies to keep you signed in: an access-token cookie, a refresh-token cookie used to renew your session without requiring you to log in again, and a non-sensitive CSRF-protection cookie. These cookies are HTTP-only where they carry a token (not accessible to JavaScript on the page), transmitted only over HTTPS, and scoped to limit cross-site use. We do not use third-party advertising cookies, social-media tracking pixels, or analytics cookies that track you across other sites. See our Cookie & Tracking Disclosure for the technologies used on the public marketing website specifically.

8. Your Rights

Subject to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may ask us to:

  • Access: request a copy of the personal information we hold about you.
  • Correction: correct inaccurate, out-of-date or incomplete personal information.
  • Deletion: request deletion of your account and associated personal data, where we are not otherwise required to keep it for legal, accounting or record-keeping reasons.
  • Portability: request an export of your organisation's data in a machine-readable format.
  • Opt-out: unsubscribe from non-essential notifications at any time.

We aim to respond to requests within 30 days. If your information reached us through an organisation you deal with (rather than directly), we may direct your request to that organisation, who remains responsible for it. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

9. International Transfers

Prime AI operates from Australia. Some of our sub-processors (including OpenAI, Anthropic and Stripe) are primarily based in the United States. By using the Services, you acknowledge that personal information may be transferred to and processed in the United States or other jurisdictions in which our sub-processors operate. We take reasonable steps to ensure such transfers are consistent with Australian Privacy Principle 8, including through contractual protections with our sub-processors.

10. Data Security

We maintain technical and organisational measures designed to protect personal information, including:

  • encryption of data in transit (HTTPS/TLS);
  • passwords hashed with bcrypt — never stored in plain text;
  • optional multi-factor authentication (TOTP authenticator app) for user accounts;
  • short-lived, HTTP-only session tokens with refresh-token rotation;
  • tenant-level data isolation between customer accounts, and role-based access control within an account; and
  • audit logging of governance-relevant actions within the Prime AI application.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches (NDB) scheme.

11. Children's Privacy

Prime AI is a professional platform intended for use by adults in a business context. We do not knowingly collect personal information from anyone under the age of 18.

12. California Residents (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the right to know what personal information we hold about you, the right to request deletion of that information, the right to opt out of the sale of personal information (we do not sell personal information, so this right does not apply), and the right to non-discrimination for exercising these rights. You can submit a request using the contact details below; we aim to respond within 45 days.

13. Changes to This Policy

We may update this policy from time to time to reflect changes to our practices, technology, legal requirements, or the marketing website. We will post a notice in the Prime AI application, and where the change is significant, notify account administrators by email, at least 14 days before the change takes effect. Continued use of the Services after that date constitutes acceptance of the updated policy. If analytics, marketing or other non-essential tracking is introduced on the marketing website, we will also update our Cookie & Tracking Disclosure and deploy consent controls before those technologies execute where consent is required.

14. Contact

For privacy questions, or to exercise any of the rights above:

Ensemble Solutions Pty Ltd
ABN 41 650 430 765
Email: support@ensemblesolutions.com.au
Subject line: "Privacy Request — [your name and request type]"

Office of the Australian Information Commissioner (OAIC): oaic.gov.au