Privacy Policy
Last updated: 5 September 2026
1. Introduction
LAIT is operated by Anthony Henry Marquez, trading as Lotus AI Tech (ABN 67 480 566 441) (“we”, “us”, “our”). We are committed to protecting your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy explains how we collect, hold, use, and disclose your personal information when you visit our website at laitapp.com.au (“Website”) and when you use the LAIT platform, including LAIT PM and its participant and provider portals (“Platform”).
LAIT provides the software used by customer organisations. Your plan manager provides your plan management service and is responsible for its own collection, use and disclosure of your service records. We handle those records on its behalf to deliver the Platform, and handle account, security and support information to operate our services. This policy explains our handling of information; your plan manager’s privacy policy also applies to its activities. You can contact us or your plan manager about a privacy request.
2. What Personal Information We Collect
We collect and hold the following types of personal information:
2.1 Information you provide directly
When you use our contact form, we collect your name, email address, organisation name (optional), and your message. When you subscribe to receive our NDIS AI Privacy Guide or other resources, we collect your email address. When you book a demonstration through our scheduling service, we collect your name, email address, and any information you provide in the booking form.
2.2 Information collected through the LAIT Platform
We collect account and contact details, organisation details, roles and information needed to sign you in. In LAIT PM, we also hold participant and representative details, NDIS numbers, plan and budget information, invoices, service descriptions, claims, payment and banking details, messages, documents, and records of consent, authority and invoice approvals. Invoices and other service records may contain sensitive information about a participant’s health, disability and supports. Provider information includes business names, ABNs and contact details. We also hold account activity, security logs and, where notifications are enabled, device and notification identifiers. The information held depends on the services you use.
2.3 Information collected automatically
We use Plausible Analytics, a privacy-focused analytics service, to collect anonymised usage data about how visitors interact with our Website. Plausible does not use cookies and does not collect personally identifiable information. The data collected includes page views, referrer information, browser type, and approximate geographic location (country level). Plausible is operated by Plausible Insights OÜ (based in the European Union), and analytics scripts are loaded from their content delivery network.
3. How We Collect Personal Information
We collect personal information in the following ways:
We collect information directly when you contact us, create or use an account, complete a profile, submit an invoice or document, send a message, request a resource or book a demonstration. We also receive information from your plan manager, service providers, authorised representatives and other people authorised to act for you. For plan management, information may come from the NDIA through claims integrations, existing records supplied by the customer organisation, and public business registers such as ABN Lookup. Our Website also uses the services described in Section 7.
We collect sensitive information with consent where required by law, or where another lawful basis permits collection. A person acting for a participant must have appropriate authority. Reading this policy does not itself give another person authority to access or share your information. If required information is not provided, we or your plan manager may be unable to create an account, respond to a request or complete the relevant service. Ask your plan manager about other ways to provide information.
4. Why We Collect Your Personal Information
We collect, hold, use, and disclose your personal information for the following purposes:
To respond to your enquiries submitted through our contact form. To send you the resource you requested (such as the NDIS AI Privacy Guide). To schedule and conduct product demonstrations. To provide and maintain the LAIT Platform, including user account management, technical support and service improvements. For LAIT PM, to enable your plan manager to manage plans and budgets, receive and check invoices, obtain participant responses, submit and reconcile claims, arrange payments, provide statements and remittances, and communicate with participants, authorised representatives and providers. To verify access and authority, protect accounts and maintain audit records. To communicate with you about your account, service updates, and changes to our terms or policies. To comply with our legal obligations under Australian law. To analyse anonymised Website usage data to improve our Website and services.
We will not use your personal information for direct marketing without your express consent. Requesting a resource does not by itself subscribe you to marketing. You may unsubscribe from marketing communications at any time.
5. How We Store and Protect Your Information
5.1 Website data
We use Microsoft 365 for email correspondence. Contact details and enquiries may also be recorded in operational logs so that we can investigate delivery problems and respond to requests. We limit access to these records to people who need them for those purposes.
5.2 Platform data
Our primary application, database and document hosting uses Australian-region cloud infrastructure. Access is controlled according to the user’s role, organisation and authority. We use encryption at rest and in transit and audit logging to protect Platform information.
For LAIT PM, we use an AI service to read uploaded invoices and extract their details for use within the application. Invoice checks, claims and payments are handled within LAIT PM. Other LAIT products may provide AI features as described within those products. Our managed AI services use Australian-region infrastructure. We do not use your Platform information to train general-purpose AI models.
5.3 Security measures
We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include encryption at rest and in transit, role-based access controls, audit logging, and hosting on Australian-region cloud infrastructure (Google Cloud Platform and AWS) that holds SOC 2 and ISO 27001 certifications.
No method of electronic storage or transmission is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
6. NDIS Participant Data
Participant information is used to provide the services for which it was supplied. Authorised plan-manager staff and representatives may access information relevant to their responsibilities. A provider’s portal access relates to its own dealings with the plan manager; it does not give general access to participant records or other providers’ information. Access by an unrelated customer organisation is not permitted.
Information may be shared with the participant, people authorised to act for them, relevant service providers, the NDIA and claims intermediaries, and financial institutions where needed for plan management and payments. We also use contracted services described below to deliver the Platform. Other disclosures may occur with consent or where required or authorised by law. Please tell your plan manager about changes to representative authority or restrictions on sharing your information.
LAIT is a software platform, not your plan manager or a registered NDIS provider. Your plan manager remains responsible for the services it provides. This does not limit our own privacy obligations. Access, correction and deletion requests are explained in Sections 10 and 11.
7. Third-Party Services
We use the following third-party services that help us handle personal information:
7.1 Plausible Analytics
Plausible is a privacy-focused, cookieless analytics service operated by Plausible Insights OÜ (Estonia, EU). It collects anonymised website usage data only. Plausible does not track individual users, does not use cookies, and does not collect personally identifiable information. Analytics scripts are loaded from Plausible’s content delivery network, which may involve a request to servers outside Australia.
7.2 Calendly
When you book a demonstration through our Website, you interact with Calendly, a scheduling service operated by Calendly LLC (United States). Information you enter into the Calendly booking form (such as your name and email address) is processed under Calendly’s own privacy policy. This data may be processed and stored in the United States. We recommend reviewing Calendly’s Privacy Policy before booking a demonstration.
7.3 Cloud infrastructure providers
Our Website and Platform are hosted on Australian-region cloud infrastructure. Primary application and database hosting is provided by Google Cloud Platform in the Sydney region (australia-southeast1). Managed AI processing is provided by Google Cloud Vertex AI and AWS Bedrock, both within the Sydney region. Microsoft 365 supports our email correspondence. These providers process data on our behalf in accordance with their respective privacy policies (Google Cloud, AWS, Microsoft).
7.4 Plan management and communications services
LAIT PM uses claims integration services, including QuickClaim, to exchange plan and claims information with the NDIA. Microsoft 365 supports email correspondence and invoice receipt, and ClickSend supports SMS delivery. Where mobile push notifications are enabled, Expo and the Apple or Google push notification service handle device identifiers and notification delivery. These services receive the information needed to perform their role. An email or SMS sent to you or another authorised recipient is also handled by that recipient’s email or telecommunications provider.
8. Overseas Disclosure of Personal Information
In accordance with APP 8, we disclose that your personal information may be disclosed to overseas recipients in the following circumstances:
Calendly (United States) — if you book a demonstration through our Website. Plausible Analytics (European Union) — anonymised website analytics data only (no personally identifiable information). Expo (United States) — device identifiers and notification payloads when mobile push notifications are enabled.
ClickSend identifies possible overseas recipients in the United States, United Kingdom, New Zealand, Brazil, Vietnam and the Philippines in its privacy policy, and its service-provider list also identifies access in Sweden and other EU locations. The locations involved depend on the service and delivery arrangements.
Australian hosting describes where our primary Platform records and managed AI workloads are hosted. It does not describe the location of every email, telecommunications or notification service used to deliver information to you. Delivery through these services may involve overseas infrastructure. Contact us for information about the services involved in your use of the Platform. We take reasonable steps required by Australian privacy law in relation to overseas disclosures.
9. Cookies and Tracking Technologies
Our Website does not set first-party cookies for tracking purposes. Plausible Analytics, our analytics provider, does not use cookies.
If you book a demonstration, the Calendly scheduling widget (loaded on our demo page) may set its own cookies. These cookies are governed by Calendly’s cookie policy.
The Platform uses essential cookies and similar technologies for sign-in, sessions and security. These are separate from Website analytics. Disabling them may prevent you from signing in or using portal features.
10. Data Retention and Deletion
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Contact enquiries are kept for responding to you and necessary record-keeping. Account and service records are kept while needed to provide the service, meet applicable legal and record-keeping obligations, resolve disputes and maintain necessary financial and audit records. Closing a portal account or ending a subscription does not automatically erase invoices, claims, payments or other service records that still need to be retained.
You may ask us or your plan manager about access, export or deletion. We assess deletion requests against the purpose for retaining the information and applicable obligations, and explain any information that needs to remain. When information is no longer needed and retention is not required by law, we take reasonable steps to securely destroy or de-identify it. This includes addressing archived and backup copies through the applicable retention and backup processes; removal from an active account does not mean every copy is immediately erased.
11. Your Rights Under the Privacy Act
You can request access to your personal information, ask for corrections and make a privacy complaint as explained below.
For plan-management service records, your plan manager can help with access and correction. You may also contact us directly; we will help identify the appropriate organisation and coordinate the request where needed. We may verify your identity and a representative’s authority before providing information. You can ask for this policy or assistance with a request in an accessible format.
Access your personal information. You may request access to the personal information we hold about you. We will respond to your request within 30 days. In some circumstances, we may refuse access if permitted or required by law, and we will provide reasons for any refusal.
Correct your personal information. If you believe the personal information we hold about you is inaccurate, incomplete, or out-of-date, you may request that we correct it. We will take reasonable steps to correct the information and respond within 30 days.
Complain about a breach of your privacy. If you believe we have breached the APPs, you may lodge a complaint with us (see Section 14). We will acknowledge your complaint within 7 days and investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
12. Marketing Communications
We will only send you marketing communications with your express consent, in accordance with the Spam Act 2003 (Cth). Every marketing communication will include an unsubscribe mechanism. You may opt out of marketing communications at any time by clicking the unsubscribe link in any email or by contacting us directly.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. We encourage you to review this page periodically. For material changes, we will make reasonable efforts to notify affected individuals directly (for example, via email to Platform users).
14. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights under the APPs, or wish to make a privacy complaint, please contact us:
Privacy Officer
Anthony Henry Marquez
Lotus AI Tech
Email: hello@lait-app.com.au
Location: Queensland, Australia
If you are not satisfied with our response to your complaint, you may contact the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
This Privacy Policy was last updated on 5 September 2026.