Privacy, complaints and telling people what they are talking to
What the sector will not let an agent do.
Support is the one function where the agent may speak to your customer, so the obligations are about disclosure and about knowing when to stop, not only about where the data sits.
- Privacy Act obligations over customer information
- The agent reads only the systems you connect, with the permissions you grant. Australian hosting is available across the deployment options, customer conversations are not used to train any model, and prompts and outputs are not retained by the model provider. Log retention is a setting you choose.
- Complaint handling
- Complaints are a detection and routing job, never a resolution job. When the signals you define appear, automated handling stops on that item, a named person becomes the owner and the timestamp is recorded so the response window can be evidenced.
- Telling the customer what they are dealing with
- Automated replies say so, and every one carries a route to a person. Asking for a human ends the automated exchange straight away. An agent that pretends to be a person is a reputational risk with no upside.
- Vulnerable customers and hardship
- Treated as a stop condition, not a category to be answered. The signals are defined with you during solution design, and the item is handed to the person who is trained to handle it.
- What the customer was told, and when
- Every draft, release, deflection and escalation is logged with the source material behind it, so the record of what was communicated exists without anyone reconstructing it from a mailbox.
This is a description of how the deployment is built, not legal, financial
or compliance advice. Your own obligations should be confirmed with your
own advisers.
The security page
sets out hosting, model choice, retention and access in full.