Privacy Policy
Effective Date: 6 Feb 2025
1. Introduction
Welcome to Pikola.AI. This Privacy Policy outlines how we collect, process, and protect your personal information when using our services. By accessing or using Pikola.ai, you agree to the terms set forth in this policy. If you do not agree, please discontinue using our services.
This Privacy Policy applies to all users globally. We ensure compliance with applicable data protection laws, but Pikola.AI assumes no liability for compliance with specific regional regulations such as GDPR or CCPA.
2. Information We Collect
- Registration Information: Name, email, password, and optional profile picture.
- Usage Information: Access times, session duration, and feature interactions.
- Device Information: IP address, device model, browser type, and OS details.
- Payment Information: Processed securely via Stripe; we do not store payment details.
- Cookies & Tracking Data: Used for analytics, functionality, and security purposes.
3. How We Use Your Information
- To create and manage user accounts.
- To provide, optimize, and secure our services.
- To analyze service usage and improve performance.
- To comply with legal and regulatory obligations.
- To send service-related communications, updates, and notifications.
4. Data Sharing & Third-Party Services
- We do not sell or trade personal information.
- Payment transactions are handled by Stripe, following their privacy policies.
- We may share data with law enforcement when required by law.
5. Data Retention & Security
- User login information is retained for three months after account deactivation.
- Audio files and processed data are deleted after one month.
- We implement industry-standard security but assume no liability for unauthorized access.
6. Your Rights & Choices
- You can request access, modification, or deletion of your personal data.
- Opt-out options are available for marketing emails.
- To exercise your rights, please contact us.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted here, and we encourage users to review the policy periodically.
For any questions, please contact us.
Data Storage Policy
Effective Date: 6 Feb 2025
1. Purpose
This Data Storage Policy outlines how Pikola.AI securely stores, retains, and protects user data to ensure compliance, security, and user trust.
2. Data Storage Location
- All data is securely stored in Microsoft Azure (Australia East).
- Data is encrypted at rest and in transit to ensure security and confidentiality.
3. Data Retention Policy
- Audio Files & Transcriptions: Retained for 1 month and automatically deleted.
- User Login Data: Retained for 3 months after account deactivation.
- Meeting Records & Metadata: Configurable by the user, default retention is 1 month.
- Customer Support Data: Retained for 6 months for service improvements.
4. Data Access & Security
- We enforce Role-Based Access Control (RBAC) to limit access to authorized users only.
- Multi-Factor Authentication (MFA) is used for sensitive data access.
- Users can request data deletion in compliance with applicable regulations.
6. Data Breach Response
At Pikola.AI, we take data security seriously. While we implement strong security measures, we recognize that data breaches can still occur. If a breach happens, we follow a structured Data Breach Response Plan to minimize impact and protect our users.
- Detection & Containment: We monitor our systems for unauthorized access and take immediate action to contain any breach.
- Risk Assessment: Our team investigates the breach to determine the extent of the impact and affected data.
- User Notification: If required by law, we will notify affected users and regulatory bodies (e.g., OAIC in Australia) with clear guidance on next steps.
- Remediation: We take corrective actions, enhance security measures, and update our policies to prevent future breaches.
We are committed to transparency and will provide updates to affected users as needed. If you have any security concerns or suspect unauthorized activity, please contact us.
7. Policy Updates
This policy may be updated periodically to reflect changes in security, regulations, or business needs. Users will be notified of any significant updates.
For any questions, please contact us.
Privacy & Data Security
Your Data, Protected with Industry-Standard Security
Our Approach to Privacy
At Pikola.AI, we take data privacy and security seriously and are committed to protecting personal and sensitive information with the highest standards. While we are a growing startup, we strive to align our practices with regulatory frameworks, including the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Additionally, we recognize the importance of compliance with relevant State and Territory laws, such as the Health Records Act 2001 (Vic), Health Records (Privacy and Access) Act 1997 (ACT), and the Health Records and Information Privacy Act 2002 (NSW).
We are continuously improving our policies, security measures, and data protection practices to ensure compliance to the best of our ability. While we may not yet fully meet all regulatory requirements, our commitment is to safeguard your data, maintain transparency, and follow industry best practices to uphold your privacy and security.
How We Protect Your Data
- Hosted on Microsoft Azure (Australia East) – Your data is stored on one of the world's most secure cloud platforms, benefiting from Microsoft's enterprise-grade security and compliance frameworks.
- Zero Trust Security Model – We enforce strict authentication and access controls, ensuring that only the data owner can access their information.
- No Unauthorized Access – We do not share, sell, or access your data unless explicitly requested for operational support.
- Role-Based Access Control (RBAC) – No one, including Pikola.AI staff, has access to your data except in cases where customers request issue investigation or technical support.
- Data Encryption – All stored and transmitted data is encrypted to prevent unauthorized access.
- Data Retention & Deletion – Audio files are deleted after one month, and user login data is retained for three months post-deactivation.
Our Commitment
As we grow, we plan to further enhance our privacy policies, compliance measures, and certifications to meet industry and regulatory requirements. In the meantime, our focus is on delivering a secure, reliable, and efficient AI-powered transcription service that respects user data privacy.
For any questions, please contact us.