Privacy Policy
Privaproof Pty Ltd (ABN 57 699 856 794) ("Privaproof", "we", "us") respects your privacy and is committed to handling personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the same standards our product helps other businesses meet.
This policy explains what we collect, why, how we handle it, and your rights. It applies to privaproof.com.au and our services.
Last updated: 6 July 2026 · We may update this policy; the current version always lives at privaproof.com.au/privacy.
What we collect
We collect only what we need:
- Information you give us: your email address, and if you provide them, your name and agency name, when you join our founding list, ask us for the audit fix list, or contact us.
- If you subscribe: when you become a member, we (through our membership provider, Ghost) hold your name, email, login details and subscription status, so we can give you access to the Kit and support you.
- Payment information: if you buy from us, payments are processed by Stripe; we receive confirmation of payment but we do not collect or store your card details.
- Business identity, when you activate a licensed copy: when you download documents from your Kit, we collect your business's registered name and ABN (and ACN, if you have one) to create and personalise your licensed copy. We add a visible licence line to each document and record the same details in the document's file metadata, so each copy is identifiable to the licensed business. This is business-identity information, used only to licence and mark your documents, never for marketing.
- Information collected automatically: when you visit, our infrastructure provider (Cloudflare) processes standard server information, including your IP address, device/browser type, and the pages you request, to deliver and secure the site.
Your self-audit answers stay on your device. Our free self-audit is scored entirely in your browser. Your answers to the audit questions are not sent to us and not stored by us. If you ask us for the fix list, we collect only your email address, your overall score and band, and how many areas need attention, never your individual answers. We also record the consent wording you agreed to, the date, a salted one-way hash of your IP address and its country, as evidence of that consent. We de-identify the score signal after 90 days (see How long we keep it).
Consent to emails, minimally recorded. When you opt in to hear from us, we keep a record of that consent (the wording you agreed to, the date, and the page) so we can show it was genuine. As part of that record we store a one-way, salted hash of your IP address (never the raw address), because we hold ourselves to the same data-minimisation we ask of others.
Cookies and analytics
We run no analytics product at all, and no advertising or cross-site tracking cookies. We do not build advertising profiles of you. Because we set no tracking cookies, you won't find a cookie-consent banner here, by design.
The one exception, and it is a count rather than a record: on our free Am I covered? checker we add one to a daily tally of how many people reach each of the five possible results. That tally is all that is kept. It holds no email address, no cookie, no device or session identifier and no IP address, so there is nothing in it that can be traced back to you, and nothing to ask us to access or correct.
Why we use your information
We use personal information to:
- provide the self-audit and send you the fix list you asked for;
- create and manage your membership account and give you access to the Kit;
- licence and personalise the documents you download, and identify licensed copies;
- keep you informed about Privaproof and privacy-compliance updates, where you've asked us to (see Marketing, below);
- respond to your enquiries and provide our services;
- process payments and manage your subscription;
- operate, secure and improve our website; and
- meet our legal obligations.
We use your information only for these purposes, or a directly related purpose you'd reasonably expect, unless you consent otherwise (APP 6).
When we share it
We don't sell your personal information. We share it only with:
- Service providers who help us operate: our infrastructure/hosting provider (Cloudflare), our membership and login provider (Ghost), our email/mailing provider (EmailOctopus), and our payment processor (Stripe), and only so they can perform those services for us; and
- others where required or authorised by law.
We list our current providers, what each handles, and where, on our sub-processor page.
Overseas disclosure
Some of our service providers store or process data outside Australia. Our infrastructure provider (Cloudflare) and payment processor (Stripe) are United States-based and operate globally; our membership provider (Ghost) hosts data in the Netherlands (EU); our email/mailing provider (EmailOctopus) hosts data in Ireland (EU) and is incorporated in the United Kingdom; and our business email provider (Proton Mail) is based in Switzerland. Where we disclose your information overseas, we take reasonable steps to ensure it is handled consistently with the APPs, including through data-processing agreements (APP 8). By providing your information, you understand it may be handled as described here.
How we protect it
We take reasonable steps to protect personal information from misuse, loss, and unauthorised access, including data minimisation (we collect and keep as little as we can), access controls and multi-factor authentication on our administrative accounts, encryption in transit and at rest through our providers, and secure deletion. No system is perfectly secure, but we hold ourselves to the standard we help others meet.
If something goes wrong: data breaches
We have procedures to detect, contain and assess suspected data breaches. If a breach involving your personal information is likely to result in serious harm and we can't prevent that harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in line with the Notifiable Data Breaches scheme under the Privacy Act.
How long we keep it
We keep personal information only as long as we need it for the purposes above or as the law requires, then delete or de-identify it:
- Self-audit score signal: de-identified after 90 days (we keep it only long enough to send you the fix list that matches your result).
- Founding-list / marketing contacts: removed after 24 months of no engagement, or sooner if you ask.
- Account and billing records: kept while you're a member and for at least 7 years afterwards, to meet our tax and company record-keeping obligations.
You can ask us to delete your information at any time (see below), and we'll do so unless we're required to keep it.
Your rights: access, correction and unsubscribe
- Access and correction (APP 12–13): you can ask for a copy of the personal information we hold about you, and ask us to correct it if it's wrong or out of date. Contact us using the details below; we aim to respond within 30 days, at no charge.
- Deletion: you can ask us to delete your information, and we will unless we're required to keep it.
- Marketing: we only send marketing where you've opted in. Every marketing email has an unsubscribe link, and you can opt out at any time; we action opt-outs promptly, consistent with the Spam Act 2003 (Cth). Account and service messages (like receipts and login links) aren't marketing and will still be sent while you hold an account.
Complaints
If you think we've mishandled your personal information, please contact us first. We'll take it seriously and aim to resolve it quickly, within 30 days. If you're not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
Contact us
Privacy enquiries: privacy@privaproof.com.au · by post: PO Box 101, Randwick NSW 2031, Australia · Privaproof Pty Ltd (ABN 57 699 856 794).
This is Privaproof's own privacy policy. It reflects our current practices and will be kept up to date as our service evolves.