Privacy Policy

How Echo Point Labs Pty Ltd collects, holds, uses, discloses and protects personal information.

Effective date: 13 August 2026

Echo Point Labs Pty Ltd (ABN 61 697 773 854), trading as Echo Point Labs, respects individual privacy and is committed to handling personal information responsibly.

This Privacy Policy explains how Echo Point Labs Pty Ltd handles personal information when individuals:

  • Use our website;
  • Communicate with us;
  • Make an enquiry;
  • Engage our services;
  • Interact with a website, form or workflow managed by us; or
  • Otherwise provide personal information to us.

References to Echo Point Labs, EPL, we, us or our mean Echo Point Labs Pty Ltd.

1. Who this policy applies to

This Privacy Policy applies to personal information handled by EPL through:

  • The Echo Point Labs website;
  • Email and direct communications;
  • Sales enquiries and project discussions;
  • Client onboarding and service delivery;
  • Website forms;
  • Automation and enquiry workflows;
  • Hosting and technical systems;
  • Reporting and operational records; and
  • Services managed by EPL on behalf of clients.

EPL may operate or manage website forms, enquiry workflows, automations, hosting or reporting systems for its clients.

When an individual submits information through a client website or workflow managed by EPL, both EPL and the relevant client may handle the information. The client may have its own privacy policy and legal obligations.

Business details

  • Legal name: Echo Point Labs Pty Ltd
  • Trading name: Echo Point Labs
  • ABN: 61 697 773 854
  • Location: Manly, NSW 2095, Australia
  • Privacy contact: hello@echopointlabs.com.au

2. Personal information we may collect

The personal information we collect depends on the relevant interaction and may include:

  • First and last name;
  • Business or company name;
  • Position or role;
  • Telephone number;
  • Email address;
  • Business address or service location;
  • Information contained in an enquiry, message or request;
  • Details about a business problem, project or service requirement;
  • Information contained in emails and other communications;
  • Client onboarding and account information;
  • Billing and transaction records;
  • Information contained in client systems or documents where required to provide services;
  • Website, business, form or campaign through which an enquiry was submitted;
  • Service requested and relevant location;
  • Submission date and time;
  • Referral, campaign, source and workflow information;
  • Enquiry delivery status;
  • Troubleshooting and operational records; and
  • Technical and website-usage information.

Technical and usage information may include:

  • IP address;
  • Browser type;
  • Device type;
  • Operating system;
  • Approximate location derived from an IP address;
  • Referral source;
  • Pages viewed;
  • Links or features used; and
  • Date and time of access.

Client project information

When providing services, EPL may process personal information contained in:

  • Client CRM systems;
  • Enquiry records;
  • Internal business documents;
  • Operational systems;
  • Workflow platforms;
  • Reporting systems;
  • Email or communication tools; and
  • Other client-controlled data sources.

EPL will only access or process this information where reasonably necessary to provide the agreed services or meet applicable obligations.

3. Sensitive information

EPL does not intentionally collect sensitive information through its standard website forms or client enquiry workflows.

Individuals should not submit:

  • Health or medical information;
  • Financial account information;
  • Payment-card details;
  • Government identifiers;
  • Identity documents;
  • Passwords or authentication credentials;
  • Biometric information;
  • Information about racial or ethnic origin;
  • Political, religious or philosophical beliefs;
  • Sexual orientation or practices;
  • Criminal records; or
  • Other sensitive personal information

through a standard website or enquiry form.

If sensitive information is received unexpectedly, EPL may restrict access to, delete, de-identify or return the information where reasonably appropriate and permitted by law.

Services involving the intentional collection or processing of sensitive information require separate assessment and agreement.

4. How we collect personal information

EPL may collect personal information when:

  • An individual visits our website;
  • An individual completes a website form;
  • An individual contacts us by email, telephone or another communication channel;
  • An individual communicates with us during a sales enquiry, project or service engagement;
  • A client supplies information in connection with a project;
  • An enquiry is submitted through a client website or workflow managed by EPL;
  • A service provider supplies information needed to operate a workflow or service;
  • Analytics, hosting, security or similar tools collect technical information; or
  • Information is generated through our business and service-delivery activities.

Where practical, EPL will collect personal information directly from the individual concerned.

In some circumstances, EPL may receive personal information from:

  • A client;
  • An individual’s employer or representative;
  • A publicly available business source;
  • A website or form managed for a client;
  • A connected software service;
  • A referral source; or
  • Another party authorized to provide the information.

5. Why we collect and use personal information

EPL may collect, hold and use personal information to:

  • Respond to enquiries and requests;
  • Assess whether we can assist with a project or business problem;
  • Communicate with prospective and current clients;
  • Prepare proposals, agreements and project documents;
  • Provide website, hosting and management services;
  • Provide automation, integration, AI-enabled, reporting and dashboard services;
  • Operate website forms and enquiry workflows;
  • Deliver enquiries to the relevant client;
  • Confirm and troubleshoot enquiry delivery;
  • Prevent spam, fraud, abuse and security incidents;
  • Maintain operational and service records;
  • Prepare reporting agreed with a client;
  • Manage client relationships and service delivery;
  • Process payments and maintain financial records;
  • Monitor and improve website performance and functionality;
  • Improve our services and internal processes;
  • Protect EPL, its clients, systems and users;
  • Resolve complaints and disputes;
  • Meet contractual obligations; and
  • Meet legal, regulatory, taxation, insurance and recordkeeping requirements.

If requested information is not provided, EPL may be unable to respond to an enquiry, assess a project, provide a service, operate a workflow or complete an engagement.

6. Client website enquiries

EPL may operate website forms and enquiry workflows for its clients.

When an individual submits an enquiry through a client website managed by EPL, the information may pass through systems operated, managed or configured by EPL before being delivered to the relevant client.

EPL may retain enquiry information and related operational information where reasonably necessary to:

  • Deliver the enquiry to the client;
  • Confirm or troubleshoot delivery;
  • Prevent spam, fraud or misuse;
  • Protect the security of the website and workflow;
  • Maintain operational records;
  • Prepare reporting agreed with the client;
  • Resolve complaints or disputes; and
  • Meet legal or contractual obligations.

The relevant client is responsible for its subsequent use of the enquiry information, including:

  • Responding to the enquiry;
  • Contacting the individual;
  • Protecting the information it receives;
  • Using the information lawfully; and
  • Complying with its own privacy obligations.

Individuals should review the relevant client’s privacy information where available.

A standard client website form must not be used to submit sensitive information.

7. Website analytics and cookies

EPL may use analytics, cookies and similar technologies on its own website to understand:

  • How visitors reach the website;
  • Which pages are viewed;
  • How visitors interact with the website;
  • Whether website functions operate correctly; and
  • How website performance and user experience can be improved.

These technologies may collect technical and usage information such as IP address, browser type, device information, referral source, pages viewed and interaction data.

The availability and effect of browser controls depend on the browser and technology used. Disabling cookies may affect some website functionality.

EPL’s standard client website package does not include ongoing analytics monitoring, reporting or interpretation. Client websites may use their own analytics or cookies where separately selected, configured or controlled by the client.

8. How personal information may be disclosed

EPL may disclose personal information where reasonably necessary to:

  • Provide an agreed service;
  • Deliver an enquiry to the relevant client;
  • Operate a website, workflow or integration;
  • Process a payment;
  • Obtain technical or professional support;
  • Protect systems and users;
  • Meet a legal obligation; or
  • Respond to a lawful request.

Recipients may include:

  • The client associated with an enquiry;
  • Cloud-hosting and infrastructure providers;
  • Website and database providers;
  • Email and communication providers;
  • Automation and workflow platforms;
  • AI and machine-learning service providers;
  • Analytics providers;
  • Payment providers;
  • Project-management and business software providers;
  • Contractors and technical-support providers;
  • Accountants, lawyers, insurers and other professional advisers;
  • Government agencies, regulators or law-enforcement bodies where required or permitted by law; and
  • Other parties authorized by the individual or client.

EPL does not sell personal information.

When EPL handles information for a client, it may act as a contracted service provider following the client’s lawful instructions. The client may have separate responsibilities for that information under its own privacy policy and applicable law.

9. AI-assisted services

EPL may use hosted artificial-intelligence or machine-learning services to assist with:

  • Drafting and editing;
  • Automation;
  • Classification;
  • Summarisation;
  • Information extraction;
  • Workflow routing;
  • Reporting;
  • Technical development; and
  • Related service functions.

Personal information will only be submitted to an AI service where EPL considers it reasonably necessary and appropriate for the relevant task.

EPL aims to:

  • Minimise the personal information submitted;
  • Avoid submitting sensitive information through standard services;
  • Use appropriate account and privacy settings where available;
  • Review AI-generated output before relying on it for material work; and
  • Select service providers appropriate to the nature of the information and task.

AI-generated output may contain errors. Human review may be required before output is used or published.

EPL does not intentionally use client enquiry information to independently train its own publicly available AI model.

Third-party AI providers may process information according to their own contractual terms and privacy practices.

10. Overseas storage and processing

EPL uses third-party cloud, hosting, communication, automation, analytics, payment and artificial-intelligence service providers. Some of these providers operate through global or distributed infrastructure.

As a result, personal information may be stored, processed, backed up or accessed outside Australia. The countries or regions involved may vary according to:

  • The service provider used
  • The provider’s infrastructure and subcontractors
  • The processing region selected
  • The location of support personnel
  • Service availability
  • Changes made by the provider from time to time

Where practicable, EPL will identify the countries or regions in which overseas recipients are likely to be located. Based on EPL’s current service-provider arrangements, these may include Malaysia, Australia and the United States of America.

Where it is not practicable to identify every location, personal information may be processed through infrastructure located in regions including Asia-Pacific, North America and the European Union, depending on the relevant provider and service.

Where Australian privacy law applies to an overseas disclosure, EPL will take reasonable steps appropriate to the circumstances to protect the information and address applicable cross-border disclosure obligations. These steps may include:

  • Reviewing provider privacy and security information
  • Using available contractual protections
  • Limiting the information provided
  • Applying access controls
  • Selecting suitable processing regions where available
  • Using providers with security measures appropriate to the relevant information

Overseas privacy laws and protections may differ from those applying in Australia.

11. Direct marketing

Where permitted by law, EPL may use business contact information to communicate about:

  • EPL services;
  • Relevant updates;
  • Related offers; or
  • Information EPL reasonably believes may be relevant to the recipient’s business.

Marketing communications will include a method to unsubscribe where required.

An individual may opt out of direct marketing at any time by:

EPL will process an opt-out request within a reasonable period.

Operational communications concerning an enquiry, active project, account, payment, security issue or service are not marketing communications.

EPL does not use information collected through a client website enquiry to market EPL’s own services to the individual unless separately authorized or otherwise permitted by law.

12. Security

EPL takes reasonable steps appropriate to its activities to protect personal information from:

  • Misuse;
  • Interference;
  • Loss;
  • Unauthorized access;
  • Unauthorized modification; and
  • Unauthorized disclosure.

These measures may include:

  • Access controls;
  • Multi-factor authentication;
  • Secure credential-management practices;
  • Encryption where supported and appropriate;
  • Restricted access to systems and information;
  • Software and platform updates;
  • Backup and recovery processes;
  • Service-provider assessment;
  • Contractual protections;
  • Monitoring and logging; and
  • Internal handling procedures.

No method of internet transmission or electronic storage is completely secure. EPL cannot guarantee absolute security.

Clients and users must promptly notify EPL if they become aware of a suspected security or privacy incident involving an EPL-managed website, form, workflow or service.

13. Data breaches

EPL will assess suspected data breaches affecting personal information it controls or manages.

Where required by applicable law, EPL will take appropriate steps which may include:

  • Containing the incident;
  • Investigating the circumstances;
  • Assessing the risk of harm;
  • Notifying affected clients;
  • Notifying affected individuals;
  • Notifying the Office of the Australian Information Commissioner or another relevant authority; and
  • Taking corrective action.

Where an incident involves information handled for a client, EPL and the client will cooperate in accordance with their respective responsibilities and applicable agreements.

14. Retention and deletion

EPL retains personal information only for as long as reasonably required for the purpose for which it was collected or for another lawful purpose.

Retention periods vary according to the type of information and the reason it is held.

Enquiry and workflow information

Enquiry and workflow records may be retained:

  • While the relevant client service remains active; and
  • For a reasonable period afterwards where required for reporting, troubleshooting, security, dispute resolution, insurance, legal or operational purposes.

Client and project information

Client project information may be retained for the duration of the engagement and afterwards where reasonably required for:

  • Service continuity;
  • Project records;
  • Contract administration;
  • Taxation and accounting;
  • Insurance;
  • Legal compliance;
  • Dispute resolution; and
  • Legitimate business records.

Closed website projects

Available website project materials may be retained for up to 90 days following closure or transfer where this is consistent with the relevant client agreement.

This project-retention period does not necessarily apply to invoices, contracts, communications, enquiry records or information that must reasonably be retained for longer.

Deletion and de-identification

When personal information is no longer reasonably required, EPL will take reasonable steps to destroy or de-identify it, subject to:

  • Legal retention obligations;
  • Contractual requirements;
  • Insurance requirements;
  • Reasonable backup cycles;
  • Security and fraud-prevention needs; and
  • Ongoing or anticipated disputes.

Deletion from active systems may not result in immediate removal from encrypted backups. Information stored in backups will remain protected and will be overwritten or deleted through the normal backup cycle.

15. Access and correction

An individual may request access to personal information EPL holds about them.

An individual may also request correction of information that is:

  • Inaccurate;
  • Out of date;
  • Incomplete;
  • Irrelevant; or
  • Misleading.

Requests should be sent to hello@echopointlabs.com.au.

EPL may need to verify the requester’s identity before providing access or making a correction.

EPL may refuse or limit access where permitted or required by law. If access or correction is refused, EPL will explain the reason where legally permitted and provide information about available complaint options.

Where information is held on behalf of a client, EPL may refer the request to the relevant client or coordinate with that client.

16. Deletion requests

An individual may request deletion of personal information by contacting hello@echopointlabs.com.au.

Deletion requests are subject to any legal, contractual, security, insurance or operational requirement to retain the information.

Where deletion is not possible or appropriate, EPL may:

  • Restrict further use;
  • De-identify the information;
  • Retain only the information reasonably required; or
  • Explain why the request cannot be fully completed.

If the information is controlled by an EPL client, the request may need to be directed to or handled jointly with that client.

17. Privacy complaints

An individual who believes EPL has mishandled personal information or breached an applicable privacy obligation may submit a written complaint to:

Email: hello@echopointlabs.com.au

The complaint should include enough information for EPL to understand and investigate the issue.

EPL will:

  • Acknowledge the complaint;
  • Review the relevant circumstances;
  • Request additional information where necessary; and
  • Aim to provide a response within 30 days.

If more time is reasonably required, EPL will explain the reason and provide an updated timeframe.

If the complainant is not satisfied with EPL’s response and the Privacy Act 1988 applies, they may contact the Office of the Australian Information Commissioner:

Individuals may also have other complaint or legal rights depending on the circumstances.

18. Third-party websites and services

EPL websites and services may contain links to third-party websites, software or services.

EPL is not responsible for the privacy, content or security practices of third parties that EPL does not control.

Individuals should review the privacy policies and terms of third-party services before using them or supplying personal information.

19. Changes to this Privacy Policy

EPL may update this Privacy Policy to reflect changes in:

  • Business practices;
  • Services;
  • Technology;
  • Service providers;
  • Privacy risks; or
  • Legal obligations.

The current version will be published on the EPL website with its effective date.

Material changes may also be communicated through other reasonable means where appropriate.

20. Contact

For privacy questions, access requests, correction requests, deletion requests or complaints, contact:

Echo Point Labs Pty Ltd
Trading as Echo Point Labs
ABN 61 697 773 854
Manly, NSW 2095, Australia
hello@echopointlabs.com.au