POLICIES

Cyber Security & Liability


Last updated: 15 July 2026

We take the security of your information seriously. This policy sets out the measures we maintain, how we respond to incidents, what we ask of you, and how security-related risk and liability are allocated. It works together with our Terms of Service, MSA and Data Processing Addendum.

Our measures

  • Encryption of data in transit;
  • Encrypted, per-client rooms in our client portal, each linked to that client's own asset library;
  • Access controls on a least-privilege basis — people can access only what they need;
  • Multi-factor authentication on core systems;
  • Vetting of the sub-processors and specialist partners we work with;
  • A standing rule against using client confidential material to train publicly available AI models.

Incident response

If we identify a security incident affecting your information, we will contain it, assess its scope and impact, remediate, and notify affected clients without undue delay. Where the incident is an eligible data breach, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). Where the GDPR applies to a client, we will also meet the notification timeframes in the Data Processing Addendum.

Your responsibilities

  • Keep your access codes, portal credentials and account details confidential;
  • Secure your own systems, devices and accounts, and keep them up to date;
  • Promptly report to us any suspected compromise, phishing or unusual activity relating to your engagement.

Allocation of risk

No system is perfectly secure, and we do not guarantee absolute security. We maintain the measures above and act in good faith to protect your information. Our liability for security-related matters is subject to the liability caps and exclusions in the Terms of Service or MSA, and to the consumer guarantees under the Australian Consumer Law that cannot be excluded.

Insurance

Details of Jewell's relevant insurance cover are available to clients on request.

How these terms work

These service terms sit under Jewell's Terms of Service, which govern every engagement unless a signed Master Services Agreement or Statement of Work says otherwise. Where the two differ, the more specific document controls. In short:

  • Partner delivery: Jewell leads and remains responsible for the work. We may engage vetted specialist partners and subcontractors, and we stand behind their work as if it were our own. Your contract is with Jewell alone.
  • AI-assisted delivery: we use AI tools under human direction and review to work faster and pass the value to you. A qualified person reviews and remains accountable for every deliverable, and we do not use your confidential material to train publicly available AI models. See the AI Disclosure page.
  • Intellectual property: on payment in full, you own the final deliverables created specifically for you. Jewell keeps its pre-existing methods, frameworks (including the 3D Process), tools, code and know-how, and licenses them to you as embedded in the work.
  • Case studies: unless you tell us otherwise in writing, we may reference non-confidential work — including your name, logo and factual outcomes — in our portfolio, proposals and marketing. You can opt out or restrict this at any time.
  • Australian Consumer Law: nothing in these terms excludes the consumer guarantees you have under the ACL.
  • Liability: our liability is capped and certain losses are excluded, as set out in the Terms of Service.

For the full clause set — fees and payment, confidentiality, privacy, termination, disputes and governing law — see the Terms of Service.


Jewell Group Pty Ltd. These terms may change without notice; the current version lives here. Questions? hello@jewellai.com.


LEGAL LIBRARY

All of Jewell's terms, in one place.

Business details, policies, service terms by discipline and the agreements behind each engagement.