Encompass Blue Privacy Policy

Last updated: 27 August 2026

Who we are and what this policy covers

Encompass Blue is a building-monitoring platform operated by Blue IoT Pty Ltd (ABN 59 635 172 066) ("Blue IoT", "we", "us"). Our business address is Level 1, 30–32 Compark Circuit, Mulgrave VIC 3170, Australia.

This policy explains how we handle personal information through the Encompass Blue website, web console, mobile app, connected building services, and related support activities.

Encompass Blue is provided to business customers and their authorised staff. There is no public account sign-up. Accounts are created and managed by Blue IoT or by authorised administrators of a customer organisation under that organisation's agreement with us.

You can contact us about privacy at info@blueiot.com.au or +61 3 9566 7288.

The information we collect and hold

Depending on how Encompass Blue is configured and used, we may collect and hold the following information.

Account and profile information: your name, work email address, phone number if provided, user identifier, organisation, role, profile photo, bio, account status, and profile preferences.

Authentication information: credentials and session information managed through Amazon Web Services (AWS) Cognito, including multi-factor authentication settings. Blue IoT does not have access to your password in readable form.

Content and communications: alert acknowledgement reasons and rectification notes, messages and conversation history in Encompass AI, generated reports, voice-input transcripts, support requests, privacy or account-deletion requests, and other information you choose to provide.

Website enquiries: information submitted through an Encompass Blue contact form, such as your name, work email address, country or region, organisation, role or department, and enquiry.

Activity and audit records: records of actions performed in the platform, including who performed an action, what was changed, when it occurred, request and response details, and the outcome.

Technical and security information: IP address, login and request timestamps, request identifiers, browser or device type, operating system and app version, update information, network and security logs, and crash or diagnostic information.

-Web console analytics and session diagnostics: information about how the web console is used. Where enabled, diagnostic tools may record page interactions and visible page content to help reproduce errors and improve the service. We do not use this information for advertising or cross-service tracking.

Building and operational information: site and building names and addresses, equipment and device details, sensor readings, status history, alerts, occupancy or activity indicators, and other information produced by or entered about the buildings monitored by a customer.

Building camera information: where a customer has configured a camera integration, video feeds and related device information from cameras installed in that customer's own buildings. These are the customer's building cameras. Encompass Blue does not access the camera on your phone, tablet or computer.

Voice input information: live microphone audio, where a user chooses to use voice input in the Encompass Blue web console. Audio is streamed for transcription and is not intentionally retained by Blue IoT as an audio recording. The resulting transcript may be retained as content entered into the service.

Information about other people: information a customer or authorised user enters about emergency contacts, building occupants, contractors or other individuals. This may include names, contact details, and location or safety information. See "Sensitive information" below.

Building and device data generally relates to buildings and equipment. In some circumstances, however, it may be associated with a user action or may identify or allow inferences to be made about occupants or activity at a location.

What the mobile app does not do

Voice input is currently available through the Encompass Blue web console and is not available through the mobile app. The mobile app does not request access to the microphone.

The mobile app also does not request access to your device location, contacts, camera, photo library, Bluetooth or local network, and it does not include third-party advertising, analytics or tracking SDKs. It does not use advertising identifiers for advertising or cross-app tracking. The mobile app and its service providers may nevertheless receive the technical and security information described above when the app connects to our services or checks for updates.

Sensitive information

Some information handled through Encompass Blue may be sensitive information under Australian privacy law. Examples include health, disability or accessibility information recorded about a building occupant, and safety information that reveals such details.

Blue IoT only collects sensitive information where it is reasonably necessary for the relevant service and where the individual has consented, or where the collection is otherwise permitted or required by law.**

We do not require customers or users to enter sensitive information into Encompass Blue. Where a service genuinely requires it — for example an accessibility or evacuation-assistance requirement recorded against a building — only the minimum necessary information should be entered.

Where a customer or authorised user provides personal or sensitive information about another person, that customer or user is responsible for ensuring that they are authorised to provide it and that any required notice or consent has been obtained. This is particularly important for schools, hospitals, emergency contacts and accessibility information.

How we collect information

We collect information:

- directly from you when you sign in, complete or update your profile, acknowledge an alert, use Encompass AI or voice input, submit an enquiry, or contact us;

- from your organisation and its authorised administrators when they create or manage your account or enter information into the platform;

- automatically when you use the website, web console, mobile app or related services;

- from sensors, gateways, cameras, equipment and other systems connected to your organisation's Encompass Blue environment; and

- from service providers and integration partners where this is necessary to operate, secure or support the service.

Cookies and local storage

The Encompass Blue website and web console use cookies and similar browser storage, including local storage and session storage. We use them to:

- keep you signed in and maintain your session;

- remember display preferences, such as your selected site, dashboard layout and theme; and

- collect web analytics and diagnostic information about how the web console is used and where it fails.

We do not use cookies or browser storage for advertising or cross-site tracking. You can block or delete cookies through your browser settings. If you block the cookies and storage needed for sign-in, the web console will not work correctly.

The mobile app does not use cookies. It stores authentication tokens and display preferences in protected storage on your device.

How we use information

We use information to:

- establish and administer accounts and authenticate users;

- provide building monitoring, alerting, reporting, analytics and operational services;

- deliver notifications by email, SMS or other configured channels;

- provide voice transcription and Encompass AI features;

- respond to enquiries, provide support and process privacy or deletion requests;

- send sales and relevant business communications, including following up an enquiry you submit and telling you about services related to those we provide to your organisation. You can opt out at any time using the unsubscribe option in the message or by contacting us;

- maintain security, audit activity, investigate incidents and prevent misuse;

- diagnose faults, maintain and improve the service; and

- comply with legal obligations and establish, exercise or defend legal claims.

We do not sell personal information. We do not use personal information for third-party advertising or cross-app tracking.

Encompass AI

When you use Encompass AI, your messages, relevant conversation history, and relevant operational context—such as site, building and equipment names, sensor readings and analysis results—are sent to our AI provider, Anthropic, to generate a response. Anthropic processes this information in the United States.

We do not deliberately add your account name or email address to the information sent to Anthropic. They may nevertheless be included if you enter them in a message or if they appear in content or operational context submitted to the assistant. You should not enter personal, sensitive or confidential information unless it is necessary and you are authorised to do so.

Under Anthropic's terms for commercial services, API inputs and outputs are not used to train its models by default unless the customer expressly opts in or submits relevant material as feedback. Under Anthropic's standard API settings, inputs and outputs may be retained by Anthropic for up to 30 days, subject to its terms, misuse monitoring, legal requirements, and any different retention arrangement that applies to Blue IoT.

Conversation history is stored on Blue IoT's systems so that you can return to it. You can request deletion of an individual conversation from the service. Deletion removes the conversation from active systems through an automated or manual process, but backup copies may remain beyond ordinary use until the relevant backup expires.

Encompass AI can make mistakes. Its responses are provided as operational assistance and should not be treated as a substitute for professional judgment, safety procedures or verification of critical readings.

Who we disclose information to

We may disclose personal information where necessary to:

- AWS, which provides cloud hosting, authentication, storage, logging, email delivery and voice-transcription services;

- Anthropic, which provides AI processing as described above;

- communications providers that deliver email and SMS messages;

- error-monitoring, diagnostic and web analytics providers;

- mapping and address-search providers;

- mobile app build, distribution and update providers;

- camera, equipment and other integration providers selected or configured for a customer;

- alarm monitoring centres and response providers where the customer has arranged for alarms to be escalated;

- the customer organisation that provides and administers your access, including its authorised administrators;

- professional advisers, insurers and contractors where reasonably necessary; and

- government authorities, regulators, courts or other parties where required or authorised by law.

We take reasonable steps to select and manage service providers appropriately, limit the information disclosed to what is reasonably necessary, and use contractual and security protections where appropriate.

Overseas processing

Our core platform is hosted with AWS in Australia, in the Sydney region.

Some service providers process limited information in the United States. These are the providers used for Encompass AI, error monitoring, web analytics, SMS delivery, mapping, camera integrations, and mobile app distribution and updates.

Encompass Blue is also deployed for customers outside Australia. Taking our current service providers and customer deployments together, personal information is likely to be processed in the following countries and regions:

- Australia

- the United States

- the United Kingdom

- the European Union

- the Middle East

- South East Asia

Information may also be processed in a country in which a customer-selected integration provider, or an approved subprocessor of one of our service providers, operates. We maintain an internal inventory of our service providers and their processing locations. We review that inventory and will update this policy if the likely countries in which personal information is processed materially change.

Before disclosing personal information to an overseas recipient, we take the reasonable steps required by applicable Australian privacy law to ensure that it will be handled appropriately, subject to any applicable exception.

Retention

We retain personal information only for as long as it is reasonably needed for the purposes described in this policy, to provide services to our customers, or to meet legal, security and legitimate operational requirements.

- Account information is generally retained while the relevant customer relationship and account remain active. It is deleted or de-identified when no longer needed, subject to the exceptions below.

- Audit logs are scheduled to expire 12 months after they are created. They may include a user identifier, email address, request details and information changed through the relevant request.

- Encompass AI conversations are kept until the user deletes them, the account is deleted, or they are otherwise no longer needed.

- Technical, security, support, analytics and diagnostic records are retained according to internal schedules and applicable provider settings, and are deleted or de-identified when no longer needed.

Operational and building records

Alert history and alert acknowledgement notes may be retained for up to 10 years. These are our customers' building, maintenance, safety and accountability records, and they are retained for that purpose rather than as a record about any individual.

These records may include the name, email address or identifier of the person who acknowledged an alert. That identifier is the point of the record: an acknowledgement that cannot be attributed to a person does not establish that anyone responded to a safety or equipment event. For that reason we do not remove it while the record is required. Where a long-term operational record does not need to identify an individual, we do not add or keep an identifier in it.

Backups

Backups exist only to restore the service after data loss, corruption or a security incident. They are not a records archive. They are not used for reporting, analytics or any other ordinary business purpose.

Backups are retained on a rolling schedule:

| Backup | Retained for |

| Hourly | 7 days |

| Daily | 35 days |

| Weekly | 90 days |

| Monthly | 5 years |

The monthly tier exists because the building, maintenance and safety records described above have a 10-year life, and corruption or unauthorised alteration of an old record can go undetected for a long time. The monthly tier gives a multi-year recovery window for those records. It is deliberately shorter than the life of the records themselves. Personal information in a monthly backup is incidental to this purpose; it is not the reason the backup is kept.

Backups are encrypted, and access is restricted to authorised staff performing recovery activities. We do not open a backup to read or extract an individual's information. If a backup is restored, we take reasonable steps to reapply completed deletion requests. Personal information in a backup is removed when that backup expires.

Access, correction and deletion

You can view and update certain profile details through the web console. To request access to, or correction of, other personal information we hold about you, contact us using the details below.

To request deletion of your account, use the **Request account deletion** link on the Profile screen of the mobile app, follow the instructions at [encompassblue.com/account-deletion](https://encompassblue.com/account-deletion), or email info@blueiot.com.au. Account-deletion requests are processed manually by authorised Blue IoT staff. We may ask you to verify the request using the email address registered to the account, and may consult your organisation's administrator to identify customer operational records that must be retained.

We aim to acknowledge a deletion request within 5 business days and complete it within 30 days after verification. If more time is reasonably required, we will explain the reason and provide an updated timeframe.

When a request is approved, we delete or de-identify the account and associated personal information from active systems, except information that we are required or reasonably need to retain for legal, security, customer operational-record, contractual or dispute-resolution purposes. Retained information is not used to recreate the account, and remains subject to appropriate access controls and the retention periods described above. Backup copies are removed as the relevant backups expire.

In some circumstances, applicable law may permit or require us to refuse or limit an access, correction or deletion request. If this occurs, we will explain the reason where we are permitted to do so.

Security

We use technical and organisational safeguards designed to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include encryption in transit and at rest for core cloud data, authenticated access through AWS Cognito, multi-factor authentication support, role and permission controls, access logging, staff access restrictions, backups, monitoring and incident-response procedures.

No service or transmission method is completely secure. We review and improve our safeguards based on the nature of the information, identified risks and changes to the service.

Where a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.

Automated systems and decisions

Automated systems use account identifiers, organisation membership, assigned roles, authentication status and, for some network-operations accounts, IP address information to permit or refuse access to platform functions. The platform also uses rules and analytics to generate alerts, equipment-status information and operational recommendations.

These systems generally make or support decisions about platform access, buildings and equipment. Encompass AI outputs are advisory, and Blue IoT does not use them by themselves to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. We will update this section if our use of automated systems materially changes.

Children and building occupants

Encompass Blue accounts are intended for authorised staff of business customers and are not directed at children.

The platform may be deployed at schools, public facilities or other locations used by children and other occupants. Operational information from those locations may indirectly indicate occupancy or activity. Customers must configure and use the service lawfully, provide required notices, obtain any required consents, and avoid entering unnecessary personal or sensitive information about children or other occupants.

Additional information for UK and EU users

This section applies where the UK GDPR or the EU GDPR applies to our handling of your personal information. Where this section conflicts with the rest of this policy, this section applies.

Controller and processor. Where we handle personal information to operate, secure and improve Encompass Blue and to run our own business, Blue IoT is the controller. Where we handle personal information on behalf of a customer organisation and on that organisation's instructions, Blue IoT is a processor and the customer organisation is the controller. Direct your request to that organisation in the second case; we will assist it as its agreement with us requires.

Legal bases. We rely on the following legal bases:

- Performance of a contract — to create and administer accounts, authenticate users, deliver monitoring, alerting and reporting services, and provide support.

- Legitimate interests — to secure the platform, audit activity, investigate incidents, prevent misuse, diagnose faults, improve the service, and send business communications to business contacts. We balance these interests against your rights and freedoms.

- Consent — for optional analytics and similar cookies, for voice input, and for any other purpose where we ask for it. You may withdraw consent at any time, without affecting processing carried out before withdrawal.

- Legal obligation — to meet obligations that apply to us.

- Vital interests — in rare cases involving a threat to the life or safety of a person, such as an alarm escalation.

Your rights. Subject to the conditions and exceptions in the applicable law, you may request access to your personal information, correction of inaccurate information, erasure, restriction of processing, and portability. You may object to processing based on our legitimate interests, and you may object at any time to direct marketing. To exercise a right, contact us using the details below.

International transfers. Personal information may be transferred outside the United Kingdom and the European Economic Area, including to Australia and the United States. Where this happens we rely on an adequacy decision, on standard contractual clauses together with the UK international data transfer addendum where applicable, or on another lawful transfer mechanism. You can ask us for information about the mechanism used for a particular transfer.

Supervisory authorities. You may complain to your local supervisory authority. In the United Kingdom this is the Information Commissioner's Office ([ico.org.uk](https://ico.org.uk)). In the European Union this is the data protection authority for your country.

Privacy questions and complaints

We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.

If you have a question, concern or complaint about how we have handled personal information, contact us using the details below. Please provide enough information for us to understand the issue. We will acknowledge a complaint promptly, investigate it fairly, and aim to respond within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):

- Online: [oaic.gov.au/privacy/privacy-complaints](https://www.oaic.gov.au/privacy/privacy-complaints)

- Phone: 1300 363 992

- Post: GPO Box 5218, Sydney NSW 2001

Changes to this policy

We may update this policy when our services, providers, information-handling practices or legal obligations change. We will publish the updated policy and revise the date above. Where appropriate, we will also notify users or customer administrators of material changes.

Contact

Privacy Officer — Blue IoT Pty Ltd (ABN 59 635 172 066), Level 1, 30–32 Compark Circuit, Mulgrave VIC 3170, Australia. Email: info@blueiot.com.au. Phone: +61 3 9566 7288.