- Effective
- 13 September 2026
- Operator
- Trusec.ai Pty Ltd · ABN 44 702 224 155
- Privacy contact
- hello@trusec.ai
1. Scope and our role
This notice applies to website visitors, people completing the assessment fit check, customer and prospective-customer contacts, authorised account users, and people who communicate with us. In this notice, “personal information” includes “personal data” under UK law.
We determine how personal information is used for our website, accounts, contracting, billing, security and customer communications. When a customer submits personal information about other people for an assessment, our role may instead be that of a processor or service provider acting for that customer. Applicable statutory duties and restrictions apply independently of a contract. Additional contract-specific commitments apply only if agreed. Do not submit third-party personal information until any legally required data-processing and transfer terms are in place.
2. Information we collect
- Identity and business details: name, work email, company, role, account identity and organisation membership.
- Fit-check details: AI-system type, deployment stage, intended decision, answers, result and the conversation used to produce it.
- Assessment material: system descriptions, architecture, suppliers, datasets, permissions, controls, risks, assumptions, uploaded files and information included in the resulting reports.
- Contract and transaction records: accepted terms, order details, invoice or purchase-order information, billing email, amount, currency, status and payment-provider references. Stripe may also collect a billing address on its hosted checkout. trusec.ai does not receive or store full card details from Stripe Checkout.
- Communications and technical records: emails, support or procurement enquiries, IP address, user agent, session identifiers, access timestamps, security events and diagnostic records.
We collect information from you, your organisation and its authorised users; automatically when you use the service; and from identity, payment and other providers involved in your organisation’s transaction.
Do not submit passwords, API keys, authentication tokens, live-system access, sensitive customer datasets, special-category information or other confidential personal information through the fit check or assessment intake.
Your name and work email are required to provide a recorded fit-check result; company is optional. Account, order and assessment fields marked as required are needed to establish the customer relationship or deliver the assessment. If required information is not provided, we may be unable to provide that function or service.
3. Why we use it
- Provide, record and send the fit-check result you request.
- Set up and administer accounts, organisations, orders and assessments.
- Extract and analyse submitted material and prepare assessment outputs.
- Authenticate users, enforce tenant boundaries and protect the service.
- Send transactional, support, procurement and service communications.
- Meet legal, tax, accounting, dispute-resolution and compliance duties.
- Diagnose faults and improve the reliability and usability of the service.
- With your consent, measure public website engagement and marketing attribution.
Where UK data protection law applies, the corresponding lawful bases are:
- Requested services and contracts: steps taken at your request and performance of a contract for the fit check, accounts, orders, assessments, support and transactional communications.
- Security and service operation: our legitimate interests in authenticating users, enforcing customer boundaries, preventing misuse, diagnosing faults and maintaining a reliable business service.
- Business administration: our legitimate interests in managing prospective and customer relationships, procurement enquiries and disputes.
- Legal records: compliance with tax, accounting, regulatory and other legal obligations.
We do not currently use fit-check contact details for unrelated promotional email. If optional marketing is introduced, it will have a separate choice and unsubscribe mechanism and a documented lawful basis where required.
The fit check uses automated rules to provide a preliminary scope result. It does not make a decision that produces legal or similarly significant effects, and it is not an approval, certification or security conclusion.
5. International processing
trusec.ai is operated from Australia. Its production application, database and storage are currently configured in Google Cloud’s us-east1region in the United States. Other providers may process information in the United States, Australia, the United Kingdom and locations where they operate.
UK data protection law may require an adequacy regulation, an International Data Transfer Agreement, a UK Addendum or another permitted basis for a restricted transfer. trusec.ai has not yet documented the mechanisms applicable to each provider and engagement. Before accepting UK assessment material in circumstances involving a restricted transfer, trusec.ai must establish the permitted mechanism and required safeguards. No UK representative has been appointed as at the effective date. Before offering services in circumstances that require one, we will appoint a representative and publish its details here. UK organisations should contact us before submitting assessment material.
6. Retention and deletion
- The pseudonymous fit-check session cookie expires after 30 days. The related server-side session is not automatically deleted when the cookie expires and may be linked to the contact-bearing result after completion. Starting over deletes the current session record, but does not erase a completed fit-check lead or result.
- Uploaded source files are subject to an automated object-storage deletion rule after 365 days and may be removed earlier while an intake remains editable.
- Removing an uploaded file does not automatically remove facts already extracted into assessment answers, snapshots, findings or released reports.
- Copies of transactional emails, including secure-link URLs, may remain in the intended recipient’s mailbox and trusec.ai’s Microsoft mailbox under the applicable mailbox-retention settings.
- Fit-check sessions, accounts, assessments, reports, contracts, orders, security records and communications do not currently have one general automated deletion schedule. They may remain in the service until deleted following a verified request, decommissioning or a contract-specific process, subject to legal, accounting, security, dispute and backup requirements.
Ask our privacy contact about deletion or contract-specific retention before an assessment begins. We will assess the request against applicable rights, contractual duties, report-integrity requirements and lawful exceptions. A request may not remove records from another party’s mailbox or from backups until those backups expire.
8. How we protect information
We use access controls, organisation-scoped authorisation, encrypted connections, private cloud storage, managed secret storage, bounded upload types and sizes, expiring hashed access tokens, backups and controlled report release. No internet service is risk-free. See our Security page for the current control summary and reporting channel.
9. Your rights and choices
Subject to verification, applicable law and permitted exceptions, you may ask us to provide access, correct inaccurate information, delete information, restrict or object to processing, or provide portable data. You may also withdraw consent and opt out of marketing. We do not discriminate against anyone for exercising a privacy right.
- Australia: you may request access or correction and complain to us first. Where the Privacy Act 1988 applies and a complaint remains unresolved, you may contact the Office of the Australian Information Commissioner.
- United Kingdom: where UK data protection law applies, rights may include access, rectification, erasure, restriction, objection, portability and review of qualifying automated decisions. You may complain to the Information Commissioner’s Office.
- United States: residents of some states may have rights to know, access, correct, delete or obtain a copy of personal information and to opt out of certain disclosures. trusec.ai does not sell personal information or use it for targeted advertising.
Send a request to hello@trusec.ai. State your country or US state and your relationship with trusec.ai. We may ask for information reasonably necessary to verify identity and authority. We aim to respond within 30 days, or within another period required by applicable law. For a complaint, include the conduct, date and outcome sought. We will acknowledge it, investigate the relevant records and explain the outcome or next step within a reasonable period.
10. Children
trusec.ai is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16. Contact us if you believe a child has provided information so we can investigate and take appropriate action.
11. Changes and contact
We will update this notice when our practices or legal obligations materially change and post the revised effective date here. If a change materially affects how existing customer information is used, we will provide additional notice where required.
Privacy questions, requests and complaints can be sent to hello@trusec.ai. Our public business location is Victoria, Australia.