PRIVACY

Privacy notice.

A concise account of how we handle personal information across the trusec.ai website, fit check and assessment service.

Effective
13 September 2026
Operator
Trusec.ai Pty Ltd · ABN 44 702 224 155
Privacy contact
hello@trusec.ai
Our position: we do not sell personal information, use it for cross-context behavioural advertising, or ask for live-system access, passwords or secrets. trusec.ai is operated by Trusec.ai Pty Ltd, an Australian company based in Victoria.

1. Scope and our role

This notice applies to website visitors, people completing the assessment fit check, customer and prospective-customer contacts, authorised account users, and people who communicate with us. In this notice, “personal information” includes “personal data” under UK law.

We determine how personal information is used for our website, accounts, contracting, billing, security and customer communications. When a customer submits personal information about other people for an assessment, our role may instead be that of a processor or service provider acting for that customer. Applicable statutory duties and restrictions apply independently of a contract. Additional contract-specific commitments apply only if agreed. Do not submit third-party personal information until any legally required data-processing and transfer terms are in place.

2. Information we collect

  • Identity and business details: name, work email, company, role, account identity and organisation membership.
  • Fit-check details: AI-system type, deployment stage, intended decision, answers, result and the conversation used to produce it.
  • Assessment material: system descriptions, architecture, suppliers, datasets, permissions, controls, risks, assumptions, uploaded files and information included in the resulting reports.
  • Contract and transaction records: accepted terms, order details, invoice or purchase-order information, billing email, amount, currency, status and payment-provider references. Stripe may also collect a billing address on its hosted checkout. trusec.ai does not receive or store full card details from Stripe Checkout.
  • Communications and technical records: emails, support or procurement enquiries, IP address, user agent, session identifiers, access timestamps, security events and diagnostic records.

We collect information from you, your organisation and its authorised users; automatically when you use the service; and from identity, payment and other providers involved in your organisation’s transaction.

Do not submit passwords, API keys, authentication tokens, live-system access, sensitive customer datasets, special-category information or other confidential personal information through the fit check or assessment intake.

Your name and work email are required to provide a recorded fit-check result; company is optional. Account, order and assessment fields marked as required are needed to establish the customer relationship or deliver the assessment. If required information is not provided, we may be unable to provide that function or service.

3. Why we use it

  • Provide, record and send the fit-check result you request.
  • Set up and administer accounts, organisations, orders and assessments.
  • Extract and analyse submitted material and prepare assessment outputs.
  • Authenticate users, enforce tenant boundaries and protect the service.
  • Send transactional, support, procurement and service communications.
  • Meet legal, tax, accounting, dispute-resolution and compliance duties.
  • Diagnose faults and improve the reliability and usability of the service.
  • With your consent, measure public website engagement and marketing attribution.

Where UK data protection law applies, the corresponding lawful bases are:

  • Requested services and contracts: steps taken at your request and performance of a contract for the fit check, accounts, orders, assessments, support and transactional communications.
  • Security and service operation: our legitimate interests in authenticating users, enforcing customer boundaries, preventing misuse, diagnosing faults and maintaining a reliable business service.
  • Business administration: our legitimate interests in managing prospective and customer relationships, procurement enquiries and disputes.
  • Legal records: compliance with tax, accounting, regulatory and other legal obligations.

We do not currently use fit-check contact details for unrelated promotional email. If optional marketing is introduced, it will have a separate choice and unsubscribe mechanism and a documented lawful basis where required.

The fit check uses automated rules to provide a preliminary scope result. It does not make a decision that produces legal or similarly significant effects, and it is not an approval, certification or security conclusion.

4. Who receives information

We disclose only what is reasonably needed to operate the relevant function:

  • Google Cloud for application hosting, databases, storage and assessment jobs.
  • WorkOS for authentication, sessions and organisation membership.
  • Anthropic for configured document extraction, structured assessment analysis and report narration. When those functions run, the submitted files, converted text or assessment content needed for the function are sent to the configured Anthropic service.
  • Microsoft for transactional email delivery and mailbox records.
  • Stripe for hosted card checkout and payment processing when that payment option is enabled.
  • Professional advisers, regulators, courts, law enforcement, transaction counterparties or successors where permitted or required by law.

Provider and transfer details relevant to an enterprise engagement must be confirmed during procurement. We do not sell personal information or share it for targeted advertising.

5. International processing

trusec.ai is operated from Australia. Its production application, database and storage are currently configured in Google Cloud’s us-east1region in the United States. Other providers may process information in the United States, Australia, the United Kingdom and locations where they operate.

UK data protection law may require an adequacy regulation, an International Data Transfer Agreement, a UK Addendum or another permitted basis for a restricted transfer. trusec.ai has not yet documented the mechanisms applicable to each provider and engagement. Before accepting UK assessment material in circumstances involving a restricted transfer, trusec.ai must establish the permitted mechanism and required safeguards. No UK representative has been appointed as at the effective date. Before offering services in circumstances that require one, we will appoint a representative and publish its details here. UK organisations should contact us before submitting assessment material.

6. Retention and deletion

  • The pseudonymous fit-check session cookie expires after 30 days. The related server-side session is not automatically deleted when the cookie expires and may be linked to the contact-bearing result after completion. Starting over deletes the current session record, but does not erase a completed fit-check lead or result.
  • Uploaded source files are subject to an automated object-storage deletion rule after 365 days and may be removed earlier while an intake remains editable.
  • Removing an uploaded file does not automatically remove facts already extracted into assessment answers, snapshots, findings or released reports.
  • Copies of transactional emails, including secure-link URLs, may remain in the intended recipient’s mailbox and trusec.ai’s Microsoft mailbox under the applicable mailbox-retention settings.
  • Fit-check sessions, accounts, assessments, reports, contracts, orders, security records and communications do not currently have one general automated deletion schedule. They may remain in the service until deleted following a verified request, decommissioning or a contract-specific process, subject to legal, accounting, security, dispute and backup requirements.

Ask our privacy contact about deletion or contract-specific retention before an assessment begins. We will assess the request against applicable rights, contractual duties, report-integrity requirements and lawful exceptions. A request may not remove records from another party’s mailbox or from backups until those backups expire.

7. Cookies and tracking

The trusec.ai application uses cookies or equivalent storage needed for the fit check, authentication, security and session continuity. Where enabled, optional PostHog Cloud analytics operates only after you select “Accept analytics”. Rejecting or withdrawing consent does not prevent use of the website or fit check. You can change your choice using “Analytics preferences” on public pages.

With consent, we collect a random browser identifier, public page paths, approved campaign tags, broad referral source, public-page click coordinates and scroll milestones, and fit-check step identifiers and successful submissions. Campaign attribution is also saved with your submitted lead in trusec.ai’s database. We do not send your name, email, form contents, fit-check answers, evidence, reports, authentication tokens or URL query strings to PostHog. Account, assessment, authentication and payment pages are excluded. Session replay is disabled.

PostHog is our analytics service provider. Our project uses its US Cloud region in the United States. The free plan has a one-year event-retention period; PostHog is rolling out enforcement by project, so this is not a guarantee that events are automatically deleted after one year. Contact us about deletion. Network requests necessarily expose connection information to the provider; IP-based geolocation and person profiles are disabled in our integration. The consent-choice cookie lasts six months. Analytics identifiers and campaign attribution use browser session storage, cleared when the browser tab’s session ends. Withdrawal stops future collection and clears that stored attribution; it does not automatically delete previously collected events or the submitted lead. Contact our privacy contact to request deletion. Optional analytics relies on consent.

We have not configured providers to collect personal information over time and across unrelated websites for advertising while you use trusec.ai. WorkOS and Stripe may use their own technologies when you visit their authentication or hosted-payment pages, under their notices. Optional analytics is disabled when a browser sends “Do Not Track” or Global Privacy Control. trusec.ai does not sell or share personal information for cross-context behavioural advertising.

8. How we protect information

We use access controls, organisation-scoped authorisation, encrypted connections, private cloud storage, managed secret storage, bounded upload types and sizes, expiring hashed access tokens, backups and controlled report release. No internet service is risk-free. See our Security page for the current control summary and reporting channel.

9. Your rights and choices

Subject to verification, applicable law and permitted exceptions, you may ask us to provide access, correct inaccurate information, delete information, restrict or object to processing, or provide portable data. You may also withdraw consent and opt out of marketing. We do not discriminate against anyone for exercising a privacy right.

  • Australia: you may request access or correction and complain to us first. Where the Privacy Act 1988 applies and a complaint remains unresolved, you may contact the Office of the Australian Information Commissioner.
  • United Kingdom: where UK data protection law applies, rights may include access, rectification, erasure, restriction, objection, portability and review of qualifying automated decisions. You may complain to the Information Commissioner’s Office.
  • United States: residents of some states may have rights to know, access, correct, delete or obtain a copy of personal information and to opt out of certain disclosures. trusec.ai does not sell personal information or use it for targeted advertising.

Send a request to hello@trusec.ai. State your country or US state and your relationship with trusec.ai. We may ask for information reasonably necessary to verify identity and authority. We aim to respond within 30 days, or within another period required by applicable law. For a complaint, include the conduct, date and outcome sought. We will acknowledge it, investigate the relevant records and explain the outcome or next step within a reasonable period.

10. Children

trusec.ai is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16. Contact us if you believe a child has provided information so we can investigate and take appropriate action.

11. Changes and contact

We will update this notice when our practices or legal obligations materially change and post the revised effective date here. If a change materially affects how existing customer information is used, we will provide additional notice where required.

Privacy questions, requests and complaints can be sent to hello@trusec.ai. Our public business location is Victoria, Australia.