top of page

Privacy Policy

Effective date: 01/12/2025

1. About this policy

This policy explains how Axion Solutions Pty Ltd (ABN 38 693 335 296), trading as Axion Solutions (Axion, we, us or our), handles personal information.

It applies when you visit our websites, contact us, apply for a role, engage our services, or use a product that Axion operates or maintains, including FoodFlow ERP and the FoodFlow Operations mobile app. It also applies to personal information we handle while designing, building, integrating, hosting or supporting software for clients.

A particular product or project may have an additional privacy notice. Where that notice describes a feature in more detail, read it alongside this policy.

​

2. Our role when we work for a client

Our clients decide what information to put into their business systems, who may use those systems and how their organisations use the information. Axion may handle that information to provide the product or services agreed with the client.

For example, a FoodFlow customer organisation manages its users and enters its own customer, supplier, order and delivery records. If Axion builds or maintains a system owned or operated by another client, that client’s privacy policy may explain its collection and use of information about the system’s end users. Axion’s handling of that information is also covered by this policy and our agreement with the client.

We handle information for our own purposes when we manage enquiries, contracts, billing, recruitment, support, security and our business communications.

​

3. Information we collect and hold

The information depends on how you deal with us. It may include:

  • Identity and contact details: name, employer, role, business address, email address and phone number.

  • Client and supplier relationship details: enquiries, proposals, contracts, billing contacts, invoices, correspondence and support history.

  • Recruitment information: application details, résumé, work history, qualifications, references, interview notes and any files, photographs or videos you choose to submit.

  • Product account details: user ID, organisation membership, role, permissions, account status, authentication and session information.

  • Information in products and client systems: records entered, imported or generated by authorised users. In FoodFlow, these may include customer and supplier contacts, addresses, orders, invoices, delivery instructions, warehouse activity and audit history. Information about a sole trader may also be personal information.

  • Mobile operations information: where an enabled feature is used, barcode scans, work assignments, delivery receiver names, signatures, photographs, delivery times and location points.

  • Communications and content: messages, documents, files, feedback, support requests, and content submitted to an enabled AI or voice feature.

  • Technical information: IP address, device and browser details, cookies, application usage, security events, diagnostic data and error reports.

Some client projects may involve sensitive information. We handle it only as needed for the authorised service, subject to the client’s instructions and applicable law. Users should avoid putting unnecessary personal or sensitive information into notes, prompts, uploads or other free-text fields.

​

4. How we collect information

We collect information directly when you use a website or product, complete a form, communicate with us or apply for a role. We may receive information from your employer or organisation, a client, a referee, a connected business system, or another person authorised to provide it.

Our websites and products also collect some technical information automatically. An app may request access to a camera, photo library or location when you choose to use a feature that needs it.

You may contact us without a product account. If information needed for a requested service, account or transaction is not provided, we may be unable to complete it.

​

5. Why we handle information

We collect, hold, use and disclose personal information as reasonably needed to:

  • respond to enquiries and provide proposals;

  • deliver, maintain, secure and support our products and services;

  • authenticate users and apply access permissions;

  • carry out transactions and workflows directed by clients and their authorised users;

  • provide integrations and AI-assisted features that a client enables;

  • manage contracts, billing and supplier relationships;

  • assess job applications and manage recruitment;

  • monitor performance, investigate incidents and prevent misuse;

  • keep business, security and audit records;

  • improve our products and services using information appropriate for that purpose;

  • send service communications and permitted marketing; and

  • comply with legal obligations or protect our legal rights.

We do not use a client’s operational contact lists as Axion marketing lists. Messages a client sends through a product are sent for that client’s purposes.

​

6. FoodFlow-specific information

FoodFlow is a business operations product used by customer organisations for food distribution operations. An organisation’s authorised users may enter or generate information about staff, customers, suppliers, contacts, orders, payments, stock movements and deliveries.

The FoodFlow Operations app can use a camera to scan barcodes and capture delivery photographs. A user may choose a photograph from the device library. For relevant delivery actions, the app may record a location point when the device provides one. Proof of delivery may contain a receiver’s name, signature, photographs, time and location point. The organisation’s authorised users can access this evidence for delivery operations and recordkeeping.

Where supported, delivery work completed while offline may be held on device storage until it is synchronised or explicitly discarded. Device settings control access to the camera, library and location. Denying access may affect the related feature.

​

7. Who we disclose information to

Depending on the service, we may disclose personal information to:

  • the relevant client organisation and its authorised users;

  • providers that help us operate our business, websites and products, including hosting, database, identity, communications, mapping, monitoring and AI LLM providers;

  • systems a client chooses to integrate with a product;

  • our professional advisers, insurers and contractors;

  • a buyer or successor if part of our business is transferred, with appropriate safeguards; and

  • regulators, courts, law enforcement or others where required or permitted by law.

The providers used by another Axion project may differ. We take steps appropriate to the service to limit access and protect information disclosed to providers.

​​

8. Cookies and similar technologies

Our hosted website and our products may use cookies and similar technologies for essential operation, sign-in, security, preferences, diagnostics and, where enabled, analytics or marketing.

You can manage cookies using your browser and any controls provided on the relevant website. Blocking essential cookies may prevent a site or product from working properly. We will keep this section and any cookie notice aligned with the technologies actually enabled on our sites.

​​

9. Marketing

We may send information about Axion’s products and services to business contacts where permitted by law. You can opt out using the method in a message or by contacting us. An opt-out does not prevent necessary security, account, support or service communications.

​​

10. Security and retention

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our measures vary by service and may include authentication, access controls, separation of client data, secure communications, monitoring and audit records.

We retain information for as long as needed for the service, our agreements, legitimate business and audit purposes, dispute resolution and legal obligations. Retention periods vary between enquiries, recruitment files, accounts, transaction records, delivery evidence, logs and backups. When information is no longer needed for a permitted purpose, we take reasonable steps to destroy or de-identify it, subject to applicable requirements.

We assess data breaches and notify affected people and the Office of the Australian Information Commissioner when the Notifiable Data Breaches scheme requires it.

​​

11. Access, correction and deletion requests

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may verify your identity before responding. If we cannot meet a request, we will explain why where required by law.

If your information is held in a client’s system, the client may be best placed to verify it and decide how to correct it. You may contact that organisation directly, or contact us and we will work with the client where appropriate.

You may also ask about deletion. Whether a record can be deleted depends on the client’s instructions, the type of record, legal obligations and other lawful reasons to retain it. Closing an account does not necessarily remove historical transactions or audit records.

​​

12. Changes to this policy

We may update this policy as our services, products, providers or legal obligations change. We will show the effective date of the current version on this page and provide additional notice when appropriate for a material change.

A new product or feature that handles information in a materially different way may also have a specific privacy notice

bottom of page