DataMPowered Pty Ltd · ABN 49 632 702 768

Privacy Policy

Last updated: 2026-07-28

DataMPowered Pty Ltd provides IFCEM, a governed AI workspace platform. This Privacy Policy explains how we handle personal information when you visit https://ifcem.com.au, create an account, contact us, or use the platform. It is written for our primary market in Australia and also addresses visitors and customers who may be located in the EU, UK, or United States.

Who we are

DataMPowered Pty Ltd (ABN 49 632 702 768) operates https://ifcem.com.au and the IFCEM platform.

Privacy and data-protection enquiries: privacy@datampowered.com.au.

Our role: responsible entity, controller, or processor

How we describe our role depends on the type of data and how you use IFCEM:

  • Website, contact and lead enquiries, marketing preferences, account administration, support, security, and billing data (where applicable): DataMPowered is generally the organisation responsible under the Australian Privacy Act (APP entity) and, where GDPR applies, the data controller for that processing.
  • Enterprise or team workspace content: your organisation is usually the controller of workspace content and user data processed in that workspace. DataMPowered acts as a processor or service provider on the organisation's instructions, as set out in the customer agreement or Data Processing Addendum (DPA).
  • Professional or individual workspace use: DataMPowered handles personal information in accordance with this Privacy Policy and our Terms of Service, unless a separate written agreement says otherwise.
  • We do not treat DataMPowered as the controller for all platform data in every scenario. If you need role-specific terms, contact us or refer to your organisation's agreement with us.

Individual account holders and pilot access

If you hold a personal IFCEM account (for example through an approved pilot or future Professional subscription), you are the account holder for that account.

For account administration data (identity, contact details, authentication, support, security, and billing where applicable), DataMPowered is generally the responsible organisation under the Australian Privacy Act and, where GDPR applies, the controller.

Workspace content you create as an individual account holder is processed to provide the service under these Terms and this Privacy Policy unless a separate customer agreement applies.

Information we collect

Depending on how you interact with IFCEM, we may collect:

  • Identity and contact details — name, email, phone, organisation, job title, role, industry, and similar profile fields.
  • Account and authentication data — Cognito user identifiers, group membership, session tokens, and sign-in metadata.
  • Lead and contact information — form submissions, selected plan or tier, messages, marketing opt-in choices, and withdrawal requests.
  • Workspace and product data — conversations, prompts, AI outputs, uploaded files, knowledge sources, workflow metadata, governance decisions, and audit events.
  • Technical and security data — IP address, browser and device information, logs, and abuse-prevention signals.
  • Analytics data (with consent) — aggregated site usage events via Google Analytics 4. We do not send names, email addresses, phone numbers, message text, or other contact-field values to GA4.
  • Billing data (if enabled) — limited billing and subscription details from payment providers; we do not store full payment card numbers on our servers.

How we collect information

We collect personal information from sources such as:

  • You directly — forms, account creation, support messages, and other communications.
  • Automatic collection — website and platform logs, cookies, analytics (where consented), and security tools.
  • Organisation administrators — invitations, user management, workspace configuration, and access controls.
  • Integrations you enable — connectors or data sources that you or your organisation authorise.
  • Payment and billing providers — if billing is enabled for your account or plan.
  • AI and workspace interactions — prompts, outputs, files, retrieved knowledge, workflow steps, and audit records generated through governed use of the platform.

How we use information

We use personal information to:

  • Provide, operate, secure, and improve IFCEM and our website.
  • Process sign-up, onboarding, authentication, and support.
  • Apply governance, permissions, workspace isolation, and auditability features.
  • Detect, prevent, and respond to abuse, fraud, and security incidents.
  • Send service and transactional communications, and marketing only where permitted or opted in.
  • Comply with law and respond to privacy, access, and complaint requests.
  • Understand website usage through analytics cookies where you have consented.

Lawful bases and APP purposes

Under the Australian Privacy Act, we collect information that is reasonably necessary for our functions, tell you why we collect it, and handle it in line with the Australian Privacy Principles (APPs).

Where the GDPR or similar laws apply, we rely on one or more of: performance of a contract; legitimate interests (for example security, fraud prevention, and service improvement, balanced against your rights); consent (for example optional analytics and marketing cookies, and certain marketing emails); and legal obligation.

Sensitive information

We do not intentionally collect sensitive information (such as health information, biometric data, or government identifier numbers) through our public website or standard contact forms.

Please do not submit sensitive information unless it is genuinely required for your request and you are authorised to provide it.

If sensitive information is included in workspace content, we process it only to provide the service, subject to your permissions, organisation settings, applicable agreements, and law.

Cookies, analytics, and consent

Strictly necessary cookies and similar storage (for example authentication sessions and your saved cookie preferences) are used to deliver the service and do not require optional marketing or analytics consent.

Functional preferences (such as theme selection) may use local storage. Analytics cookies (Google Analytics 4) and marketing or attribution technologies run only after you consent through our cookie banner or Cookie Settings.

We configure GA4 so that names, email addresses, phone numbers, message text, form field contents, and other contact details are not sent as analytics event parameters. Do not place personal information in UTM campaign parameters or page titles.

For category details and how to change your choices, see our Cookie Policy and use Cookie Settings in the site footer.

Security verification (reCAPTCHA)

We use Google Cloud reCAPTCHA on protected forms (such as contact and sign-up flows) to help detect fraud, spam, and abuse.

When you use a protected form, Google may process technical information (such as device and interaction signals) for security purposes. Google may act as a separate controller or processor for that processing under its own terms and privacy notices.

DataMPowered uses reCAPTCHA results to decide whether to accept or challenge a submission. We do not use reCAPTCHA to profile you for unrelated marketing.

Security

We design IFCEM around trust, governance, and privacy by design. No online service can be completely secure, but we use measures that include:

  • Encryption in transit (TLS) and encryption at rest where supported for stored data.
  • AWS-hosted infrastructure, primarily in ap-southeast-2 (Sydney) where configured for our environment.
  • Role-based access controls and least-privilege access for internal operations.
  • Workspace isolation so customer and workspace data is logically separated within the platform architecture.
  • Audit and security logging, monitoring, and abuse-prevention controls.

Sharing and subprocessors

We share personal information with service providers who process data on our instructions, and where required with regulators, professional advisers, or parties involved in a business transaction subject to confidentiality. Key subprocessors include:

  • Amazon Web Services — hosting, authentication (Cognito), databases, storage, compute, and AI runtime services (primarily ap-southeast-2 where configured).
  • Google — Google Analytics 4 (with consent) and Google Cloud reCAPTCHA on protected forms.
  • Postmark or similar providers — transactional and operational email delivery.
  • Marketing and attribution providers — only where enabled, disclosed, and consented to through cookie preferences.
  • Payment providers — if billing is enabled for your account.

International transfers

Our primary hosting region is AWS ap-southeast-2 (Sydney) where configured. Some subprocessors may process data in Australia, the United States, the EU, the UK, or other regions depending on service configuration, support operations, or model provider routing.

We do not represent that all data stays in Australia for every feature, integration, or model path.

Where required by law, we use appropriate safeguards such as data processing terms, vendor security commitments, or Standard Contractual Clauses.

Retention

We retain personal information only for as long as needed for the purposes described, unless a longer period is required or permitted by law. Typical periods include:

Data typeTypical retention
Lead and contact enquiriesWhile the request is active and for up to 24 months afterwards, unless you request earlier deletion or we must retain longer by law.
Account and admin recordsWhile the account is active and for periods required for legal, tax, billing, and dispute resolution.
Workspace contentAccording to your plan, workspace settings, organisation configuration, or customer agreement.
Audit and security logsFor security, abuse prevention, compliance, and audit purposes; enterprise retention may be configurable where offered.
Analytics dataAccording to Google Analytics 4 retention settings and your cookie consent choices.
Support communicationsAs needed to resolve issues and maintain reasonable business records.

Your rights, requests, and complaints

Depending on your location, you may ask us for access to, correction of, or deletion of your personal information, or to withdraw consent where processing is based on consent.

Send requests to privacy@datampowered.com.au. We may need to verify your identity before actioning a request. We will respond within a reasonable period and in accordance with applicable law.

If you are concerned about how we have handled your personal information, contact us first so we can try to resolve the issue. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) or, where applicable, your local data protection supervisory authority.

You can change cookie preferences at any time through Cookie Settings in the site footer. Our approach to selling and sharing data is explained in our Cookie Policy under Do Not Sell or Share.

AI processing

IFCEM uses AI to process prompts, workspace content, retrieved knowledge, workflow metadata, and your instructions to generate outputs and run governed workflows.

AI outputs may be inaccurate or incomplete. You should review outputs before relying on them, especially where decisions have legal, safety, financial, or operational consequences.

IFCEM is designed to support accountable use through governance checks, audit trails, permissions, and human review points in workflows.

We do not use workspace content to train public foundation models without a separate written agreement.

Enterprise customers may be able to configure model providers, retention, and data-handling settings where those features are supported in their agreement.

IFCEM does not make solely automated legally significant decisions about you unless that is clearly disclosed and agreed for a specific feature.

Optional PA learning and memory

IFCEM may offer optional personal-assistant (PA) learning or memory features that retain context to help with future tasks in your workspace.

PA learning is optional and is not enabled by default unless you opt in through in-product settings where that feature is available.

When enabled, retained learning is scoped to your account and workspace as described in product settings. You can opt out, withdraw or re-enable consent, and clear retained PA learning from account settings where the feature is offered.

We do not use optional PA learning data to train public foundation models without a separate written agreement.

Closing your account

You may stop using IFCEM at any time. Where account deletion or closure is offered in product settings, you can initiate closure from your account.

You may also contact us at privacy@datampowered.com.au to request access, correction, or deletion of your personal information.

After closure, we delete or de-identify personal information when no longer needed for the purposes described in this policy, except where we must retain records for legal, tax, billing, dispute resolution, security, or audit purposes as described in Retention.

Deletion from live systems may not immediately remove data from encrypted backups; backup retention follows our infrastructure retention schedules.

Children

IFCEM is not directed at children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. Changes apply from the updated date shown at the top of this page. Where required by law, we will seek consent or provide additional notice.

Questions? Contact privacy@datampowered.com.au

Manage cookies: