SECURITY & PRIVACY

Your accounts.
Clear responsibilities.

Useful AI starts with sensible access, protected information and a team that knows what to check. We agree those boundaries before connecting your business systems.

Updated 19 September 2026

01 / OWNERSHIP & ACCESS

You retain control of your business account.

We help you set up the chosen AI service in an account owned and controlled by your business, using your business email and billing arrangements. You approve the provider’s terms and retain owner access, account recovery and subscription control.

Your business

Owns the account, approves users and integrations, sets internal information-sharing rules and appoints the person responsible for security and ongoing administration.

Our access

Is through a separate named user or supported delegated role, only when needed. We agree the permissions and purpose, use appropriate sign-in protection, and remove our access when the agreed work or support ends.

Keep control of the owner account. Give us the minimum access needed for the task, rather than sharing your main password. Some platforms charge for an additional user; we identify that cost in the scope.

Client ownership does not remove our responsibilities. We remain responsible for carrying out our agreed work with due care and skill and for appropriately handling information and access entrusted to us.

02 / YOUR WIDER IT ENVIRONMENT

AI security is one part of business security.

We strongly recommend an appropriate business IT security programme, supported by a suitably qualified IT provider. It should cover your devices, email, network, cloud services, staff access, backups and incident response independently of the AI platform.

You are responsible for maintaining your wider IT environment and your business’s security procedures. Our onboarding and development service does not replace a managed IT service, a security audit, continuous cyber monitoring or disaster recovery. Any such work must be expressly included in a separate agreed scope.

Agree controls proportionate to the information and consequences involved. If a required safeguard is missing, address it with your IT provider or use non-sensitive demonstration data before granting live access. Our own agreed security tasks remain our responsibility.

The Australian Signals Directorate’s Essential Eight is a useful starting point for a discussion with your IT provider. It is a baseline, not a guarantee or a complete security programme for every business.

03 / BEFORE AND DURING AN ENGAGEMENT

Steps to protect your business.

Use this checklist with your IT provider and the person approving the project. Confirm responsibilities in the proposal before we connect to live records.

01

Protect your devices and network

Use supported, regularly updated operating systems and applications, suitable endpoint protection and a properly configured firewall. Apply device encryption and screen locks. For phones and tablets used on site, consider remote wipe and device management with your IT provider.

02

Secure every account

Use unique passwords in a password manager, multi-factor authentication and single sign-on where suitable. Protect recovery methods. Use named staff accounts, restrict administrator rights and remove access promptly when people leave.

03

Keep independent, recoverable backups

Keep backups of important records and configurations separate from the working system. Limit who can delete them and test restoration. Before migration or bulk changes, agree who makes the backup, how it is checked and how to roll back.

04

Approve the information being shared

Identify confidential, personal and commercially sensitive records before connecting a tool. Confirm your authority to use customer, employee and project information. Start with sample or appropriately de-identified data and share only what the agreed task needs.

05

Limit connections and permissions

Approve each folder, mailbox, system and integration. Start with read-only access where practical. Store API keys securely, set usage limits and review access regularly. Keep different clients and projects appropriately separated.

06

Keep people responsible for important decisions

Check names, figures, quantities, calculations and source documents. Require an authorised person to approve payments, significant client commitments, bulk deletions and issued engineering work. Automatic routine actions need a separately agreed scope, limits and a way to stop them.

07

Train your team and recognise suspicious instructions

Set a short policy on approved tools, permitted data and output checks. Train staff to recognise phishing and instructions hidden in emails or documents that try to make AI reveal information or take unauthorised actions. Strong sign-in does not prevent these risks on its own.

08

Test the workflow before going live

Use representative cases and agree acceptance checks, permissions, error handling and a manual fallback. Custom apps need their own security review proportionate to the data and exposure. An AI provider’s security certification does not certify the app built around it.

09

Plan for incidents and ongoing changes

Nominate a business owner and an IT contact. Keep suitable activity logs, agree retention and deletion rules, and review changes to tools and integrations. If access is compromised, contact your IT provider and us promptly, contain affected access and preserve relevant records.

At handover, review account ownership, outstanding permissions, operating instructions, backup arrangements, support limits and who handles future changes. Remove temporary accounts, tokens and exports when no longer needed, subject to agreed and lawful retention requirements.

04 / OPENAI & ANTHROPIC CLAUDE

Choose the setup for the work.

Our focus is OpenAI and Anthropic Claude. We normally recommend one primary platform for each business to keep training, administration and reusable workflows consistent. Other tools can be used where there is a clear reason and their data arrangements are approved.

OpenAI’s business offerings and Anthropic’s commercial services do not use business inputs and outputs for model training by default. Optional feedback, opt-ins, product features and third-party connections need separate checking. Business and personal plans have different terms.

No training does not mean no storage. Retention, access, data location and deletion depend on the selected plan and services. We check those requirements before setup; we do not promise that every tool keeps all data in Australia or that any system is risk-free.

05 / PRIVACY & DATA HANDLING

Agree what information is needed.

Work Site AI is a service of Kontain Pty Ltd, ABN 70 675 603 719. Privacy questions, access or correction requests and complaints can be sent to ben.lewis@worksiteai.com.au. We will assess the request, verify identity where necessary and respond in accordance with applicable requirements.

Enquiries and website use

When you contact us, we receive the details you provide, such as your name, contact information, company and enquiry. We use them to respond, prepare a proposal and administer agreed services. Email links open your email app; call links open your calling app. This website does not itself record calls or upload your project files.

Website hosting and communications providers may process connection and service information, such as IP addresses and browser details, to deliver and protect their services. External links take you to services with their own privacy arrangements.

Project records and financial information

Our approach is to work in your approved systems and limit access to the agreed purpose. Receipt capture, invoices, CRM records and emails can contain personal or financial information. We agree the data, authorised uses, any temporary copies, providers and retention requirements before access. Do not send passwords, bank login details or payment-card details in an initial enquiry.

Providers, storage and retention

Hosting, email, AI and integration providers may process information outside Australia. The providers and locations relevant to your project must be checked against your confidentiality and client requirements. We use enquiry and project information for the agreed work and associated business, legal and record-keeping purposes, and limit retention to what is needed for those purposes. Project-specific deletion, backup and export arrangements belong in the agreed scope; deletion from a live system may not immediately remove provider backups.

Do not assume that information already held in a company system can automatically be shared with AI. Check the purpose, confidentiality commitments and any required authority or consent first. The OAIC’s guidance on using AI explains relevant privacy considerations.

Optional website analytics

If you choose “Allow analytics”, we use Google Analytics to understand visits, traffic sources, pages viewed, scrolling, outbound links, downloads and clicks on our call and email links. Analytics cookies recognise a browser across visits. Google may process this usage and device information outside Australia. We do not send your enquiry text, email address or telephone number as part of our contact-click events, and advertising personalisation is disabled.

Analytics does not load until you opt in. Choose “No thanks” to browse without these analytics cookies, or use “Cookie settings” at any time to change your choice. Declining does not prevent you using the website or contacting us. A click on a call or email link does not tell us whether a call connected or an email was sent.

See how Google uses information from sites that use its services for further details.