Privacy policy

Last updated 7 September 2026

⚠ Draft under legal review. This policy reflects an initial review by an Australian privacy lawyer and will be finalised before public launch.

1. Who we are

Compliantly (“we”, “us”, “our”) is an Australian software product, operated by Compliantly Software (ABN 59 769 213 043), that helps small and medium businesses build and operate an ISO 9001:2015 quality management system. We handle personal information in line with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). Where customers or users are covered by other privacy laws (such as the New Zealand Privacy Act 2020), we take reasonable steps to accommodate those requirements.

2. What information we collect

  • Account information — your name, email address, encrypted password, optional profile photo, time zone, and language preference.
  • Workspace information — your company name and ABN, industry, location, employee count, scope statement, suppliers, equipment, staff records, training records, customer feedback, audit findings, and the other registers you build inside the product. Your workspace data belongs to you or your organisation. You control the content you add to the service and, subject to our legal, security and operational obligations described in this policy, you may request its deletion.
  • Operational information — server logs, IP addresses, browser metadata, error reports, and product analytics generated as a byproduct of using the service. We use these to keep the service secure and improve reliability.

Information about your staff, suppliers and customers

Workspace data often includes personal information about people who are not Compliantly users — for example your employees (training records, induction records, performance reviews), supplier contacts, and customer contacts. We process this information on behalf of your organisation, which remains responsible for collecting it lawfully and for how it is used. Specific rules and exemptions can apply to employee records held by employers under Australian law. If you are an employee or contact of a Compliantly customer and have questions about information held about you, we suggest contacting that organisation first; we will assist them (and you) with any request.

3. How we use your information

  • To provide the Compliantly service to you and your team.
  • To send you transactional notifications and digest emails — these are part of the service. Marketing emails are separately opt-in and you can unsubscribe at any time from your profile settings.
  • To provide AI features. We configure our AI provider not to use your inputs to train its models. AI requests are processed by the provider to generate the requested output and are subject to the provider's applicable data-handling terms and our contractual arrangements with the provider.
  • To meet our legal obligations and respond to lawful requests.

4. Who we share information with (including overseas)

We never sell your information. We share it only with the sub-processors that operate the service, with law enforcement when compelled by a valid legal request, and with professional advisors (lawyers, accountants) under confidentiality.

Some of these providers process information outside Australia. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure they handle it consistently with the APPs — through contractual data-processing terms — and we remain accountable for those disclosures under Australian privacy law. The countries involved are listed below and this table is kept current:

ProviderFunctionInformation potentially processedCountry / region
SupabaseDatabase, authentication, file storageWorkspace and account dataHosting region of our production deployment — being confirmed; this table will be updated
AnthropicAI inference (suggestions, document generation)Prompts and the relevant workspace inputs for each requestUnited States
ResendTransactional emailRecipient email addresses and email contentJapan (Tokyo sending region) and United States (provider infrastructure)
VercelHosting and content deliveryRequest and technical metadataApplication functions run in Sydney, Australia; global edge network for content delivery
StripePayments (when paid plans launch)Billing name, email, address, payment methodUnited States and other countries

5. Where your data is stored

Your workspace data is stored at rest in our Supabase-hosted database. Some processing occurs outside Australia as set out in the sub-processor table above. Backups are retained for 30 days and encrypted at rest. Audit logs are retained for 90 days.

6. How long we keep your data

We keep personal information only for as long as it is reasonably needed for the purposes described in this policy — providing the service, security and fraud prevention, resolving disputes, and meeting legal obligations (for example, Australian tax record-keeping). When information is no longer needed for any of those purposes, we take reasonable steps to delete or de-identify it.

In practice: when you delete your account, deletion is scheduled with a 14-day cooling-off period during which you can cancel. After that, your workspace data is removed from production systems, and backups containing it age out within 30 days. Operational logs with minimal identifiers (IP addresses, request paths) are retained for 90 days for security analysis. Limited billing records may be kept longer where the law requires it.

7. Access, correction and your choices

The product gives you direct self-service tools:

  • Export your available account and workspace data via the “Export your data” button on the Security page.
  • Edit your information directly in your profile or workspace.
  • Delete your account via the “Delete account” flow on the Security page.
  • Marketing choices — opt in or out of product update emails at any time in your profile settings.

Separately from those tools, you can always contact us directly to request access to, or correction of, personal information we hold about you — you are not required to use any particular feature or procedure to make a request. We will respond within a reasonable time and, if we ever refuse a request (for a reason the Privacy Act permits), we will tell you why in writing.

8. Data breaches

If a data breach occurs that is likely to result in serious harm to individuals, we will assess it promptly, take steps to contain and remediate it, and notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme — as soon as practicable, targeting notification to affected customers within 72 hours of confirming an eligible breach.

9. Complaints

If you have a privacy complaint, please contact us first at privacy@compliantly.com.au. We will acknowledge and investigate your complaint and aim to respond within 30 days. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (oaic.gov.au).

10. Security

We protect your data with TLS in transit, AES-256 at rest, scoped row-level security in the database, optional two-factor authentication on your account, and routine security review. See our Security page for more.

11. Children

Compliantly is for business use. We do not knowingly collect information from anyone under 18.

12. Changes to this policy

We may update this policy as the service evolves. Material changes will be communicated via email and a notice in the application. The “last updated” date at the top reflects the most recent revision.

13. Contact us

Questions or requests? Email privacy@compliantly.com.au or use our contact form.