EpiqFlo – A subsidiary of Excalibur Contractors Pty Ltd
ABN: 69 614 048 547
Effective Date: 1 July 2026 | Last Reviewed: 20 July 2026
EpiqFlo (“we”, “us”, “our”) is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Privacy and Other Legislation Amendment Act 2024 (Cth). We also acknowledge the Privacy and Responsible Information Sharing Act 2024 (WA) (PRIS Act) as Western Australia’s dedicated privacy framework for public sector entities.
This Privacy Policy explains how we collect, use, store, disclose and protect your personal information, including information processed through our website, quoting tools, artificial intelligence (AI) systems and customer relationship management platforms. We are transparent about our use of automated decision-making technologies and the steps we take to safeguard your data.
By accessing our website, submitting an enquiry, or engaging our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any aspect of this policy, you should not use our services or provide personal information to us.
In this Privacy Policy:
We collect personal information that is reasonably necessary for our business functions and activities. The types of personal information we may collect include:
We do not collect sensitive information about you unless it is reasonably necessary for our services and you have provided explicit consent, or where required or authorised by law.
We collect personal information through the following channels:
At or before the time we collect your personal information, we will take reasonable steps to notify you of the matters required under APP 5, including the purpose of collection, how you may access the information and to whom we may disclose it.
We collect, use and hold your personal information for the following primary purposes:
We will only use your personal information for the purpose for which it was collected (the primary purpose) or for a related secondary purpose that you would reasonably expect, or where you have consented. If we propose to use your information for any other purpose, we will seek your consent first.
We use artificial intelligence and automated systems to enhance our service delivery. In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth), we disclose the following about our automated decision-making processes:
6.1 Types of ADM We Use
6.2 Personal Information Used in ADM
These systems may process your uploaded images, facility details, floor dimensions, contact information and communication history to generate outputs relevant to your project.
6.3 Significant Decisions
Where an automated process substantially informs a decision that could significantly affect your rights or interests — such as a formal quote approval, warranty eligibility determination, or credit assessment — we ensure meaningful human review is available. You may request that a human review any such decision and provide input before the decision is finalised.
6.4 Transparency and Accountability
We take reasonable steps to ensure our AI tools are used responsibly, ethically and in accordance with privacy obligations. We do not rely solely on automated processing for decisions that produce legal or similarly significant effects without human oversight. We regularly review our AI systems to identify and mitigate risks of bias or unintended adverse outcomes.
We use cookies, web beacons and similar tracking technologies to:
You can manage or disable cookies through your browser settings. However, some features of our website may not function correctly if cookies are disabled. For more information, refer to our Cookie Policy available on request.
We do not sell your personal information. We may disclose your personal information to:
Where we disclose personal information to third parties, we take reasonable steps to ensure they handle it in accordance with the APPs and appropriate contractual safeguards.
Some of our service providers may store or process personal information outside Australia, including in the United States, Singapore and the European Union. This may occur through our use of cloud-based CRM systems, AI platforms, analytics tools and email marketing services.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs, including by:
We also take reasonable steps to protect any de-identified information disclosed to overseas recipients, consistent with IPP 9 and IPP 11 of the PRIS Act, to prevent re-identification except in limited and lawful circumstances.
We take the security of your personal information seriously. We implement a range of technical and organisational measures to protect your data from misuse, interference, loss, unauthorised access, modification, or disclosure, including:
Despite these measures, no method of electronic transmission or storage is completely secure. If you have reason to believe your interaction with us is no longer secure, please contact us immediately.
We have procedures in place to detect, assess and respond to data breaches. Under the Notifiable Data Breaches (NDB) scheme, if we become aware of unauthorised access to, or unauthorised disclosure of, personal information we hold and a reasonable person would conclude that the access or disclosure is likely to result in serious harm to any of the individuals to whom the information relates, we will:
“Serious harm” may include physical, psychological, emotional, financial, or reputational harm. Where remedial action is taken before serious harm occurs, notification may not be required.
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, insurance and warranty obligations. Our general retention periods are:
When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it, consistent with APP 11 and the PRIS Act requirements for de-identified information.
Under APP 12 and APP 13, you have the right to:
We will respond to access and correction requests as soon as practicable and, in any event, within 30 days of receiving your request. In certain circumstances permitted by the Privacy Act, we may refuse to grant access or make corrections. If we refuse, we will provide you with written reasons and inform you of your complaint rights.
Where it is lawful and practicable, you may interact with us on an anonymous or pseudonymous basis. For example, you may browse our website without providing personal information. However, if you wish to request a quote, book a site assessment, or engage our services, we will require your identity and contact details to fulfil your request.
We may use your personal information to send you marketing communications about our services, promotions and industry updates where:
Every marketing communication we send will include a clear opt-out mechanism. You may opt out of receiving marketing communications at any time by clicking the unsubscribe link in our emails or contacting us directly. We will honour your opt-out request within 5 business days.
Our website may contain links to third-party websites, platforms and services, including booking systems, social media platforms and external visualisation tools. This Privacy Policy applies only to our own data handling practices. We are not responsible for the privacy practices of third-party websites or services and we encourage you to review their privacy policies before providing any personal information.
Our services are not directed to individuals under the age of 18 and we do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child under 18, we will take reasonable steps to delete that information as soon as possible. If you believe we may have collected information from a minor, please contact us immediately.
In line with best practice and the PRIS Act’s emphasis on privacy governance, we conduct privacy impact assessments (PIAs) when introducing new technologies, systems, or processes that involve the collection or handling of personal information at scale, including the deployment of new AI tools, CRM integrations, or data sharing arrangements. These assessments help us identify and mitigate privacy risks before they materialise.
If you believe we have breached the APPs or mishandled your personal information, we encourage you to contact us first so we can attempt to resolve the matter directly.
Step 1: Contact EpiqFlo
Email your complaint to [email protected] with the subject line “Privacy Complaint”. Please include your contact details, a description of your concern and any relevant supporting information. We will acknowledge receipt within 5 business days and aim to resolve the matter within 30 days.
Step 2: Escalate to the OAIC
If you are not satisfied with our response, or if we have not responded within 30 days, you may lodge a complaint with the Office of the Australian Information Commissioner:
Step 3: WA Information Commissioner
If your complaint relates to services provided under a Western Australian government contract, you may also contact the Office of the Information Commissioner Western Australia. Phone: (08) 6557 7165.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or service offerings. Material changes will be notified by:
We encourage you to review this Privacy Policy periodically. Your continued use of our services after any changes constitutes acceptance of the updated policy.
Privacy Officer – EpiqFlo
A subsidiary of Excalibur Contractors Pty Ltd
ABN: 69 614 048 547
Email: [email protected]
Phone: (08) 6629 6400
Website: www.epiqflo.com
Address: Perth, Western Australia
Contact our Privacy Officer directly for any concerns or requests.
Email Privacy Officer Call (08) 6629 6400