Privacy Policy

Entity: Purposeful Security Pty Ltd · ABN 36 677 972 039 · Website: pursec.com.au · Contact: hello@pursec.com.au

Address: Office 102, 210-218 Boundary Rd, Braeside, Australia

Effective 28 June 2026 · Last updated 1 August 2026 · Version 1.3.

1. About this policy

Purposeful Security Pty Ltd ("Purposeful Security", "we", "us", "our") respects your privacy. This policy explains how we collect, hold, use, and disclose personal information, and how you can access, correct, or complain about how we handle it.

It applies to:

Because these involve different kinds of information, we publish product-specific privacy notices that sit alongside this policy and should be read with it:

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We apply the APPs in full and do not rely on the small-business exemption.

2. What personal information we collect

The personal information we collect depends on how you interact with us. We only collect personal information that is reasonably necessary for our functions and activities as a cyber security consultancy and software publisher (APP 3).

Website enquiries and prospects

When you use our contact form, sign up for our newsletter, or email us, we collect your name, email address, company (if provided), and the content of your message. If you choose to identify yourself only by a pseudonym for an initial enquiry, we will deal with you on that basis where it is lawful and practicable (see Section 12).

Consulting clients and engagement contacts

In the course of providing services, we collect business-contact details of client personnel (name, role, email, phone) and engagement records (notes, agreements, deliverables). We may also be given access to information within a client's environment under the terms of our engagement. Where that information includes personal information, the client remains the entity primarily responsible for it and we handle it on the client's behalf under contract (see Section 6).

Contractors and associates

If you work with us as a contractor, employee, or associate, we collect the information needed to engage and pay you and to manage security and access — for example identity, contact, banking, tax, and background-screening information.

SecArch users

Account and usage information for the SecArch platform — including user name, email address, role, authentication events, audit logs, and usage telemetry. This information is covered by this policy and the SecArch Privacy Notice. Tenant content (the architecture content your organisation puts into SecArch) is handled separately and is governed by your SecArch Customer Agreement (see Section 6A).

My Values users

Account information of the parent/guardian account-holder, and limited information they enter about their family. This includes limited personal information about children, provided by the adult account-holder. Full detail is set out in the My Values Privacy Notice.

Authentication and identity information

Login credentials are stored only in hashed form. We collect authentication events (sign-in time, source IP, device type) for security and audit purposes.

Communications and meeting records

For consulting engagements we may keep records of meetings, emails, and other communications relating to the engagement. We do not record audio or video calls without your knowledge and consent.

Sensitive information

We do not collect sensitive information (as defined in the Privacy Act) unless it is reasonably necessary for our activities, and only with your consent or as otherwise permitted by law.

3. How we collect it

We collect personal information directly from you wherever practicable — when you contact us, enter into an engagement, create an account, or use our products. In some cases, we collect it from a client or employer in the course of an engagement, or from publicly available sources for prospect research.

Website analytics

Our website uses Cloudflare Web Analytics, which is cookieless and does not identify or track individuals across sites. We do not use advertising, behavioural-analytics, or cross-site tracking technologies.

Cookies and similar technologies

We use a small number of strictly-necessary cookies — for example, to keep you signed in to SecArch. We do not use advertising, third-party analytics, or cross-site tracking cookies. Where any third-party embed is added to our website in future (such as a calendar booking widget), it will be disclosed here before it goes live.

4. Why we collect, hold, and use it

We use personal information to:

We only use personal information for the purpose for which it was collected, a directly related purpose you would reasonably expect, or where you have consented or the law permits or requires it.

Automated decision-making

We do not use personal information to make automated decisions that have legal or similarly significant effects on you. The My Values Advisor uses artificial intelligence to generate guidance for parents; it is informational only and does not make decisions about you or your children. If we introduce any system that makes significant automated decisions about individuals, we will update this policy and tell you before doing so.

5. Disclosure

We disclose personal information only as needed to provide our services and run our business, including to:

We do not sell personal information, and we do not disclose it for third-party advertising or profiling.

6. When we act for a client (consulting)

When we deliver consulting services, we often handle personal information that belongs to, and is controlled by, our client. In those cases the client is responsible for that information under its own privacy obligations, and we handle it strictly under the terms of our engagement and our internal security policies.

Our consulting contracts include confidentiality and, where appropriate, data-handling terms governing how we access, use, and return or destroy that information. Purposeful Security personnel with access to client information are bound by confidentiality undertakings.

6A. When we act for a SaaS customer (SecArch)

SecArch is a workspace where our customer organisations (each a "tenant") manage their own security architecture content — patterns, decisions, design reviews, and control mappings.

When your organisation uses SecArch:

Data residency

SecArch hosts customer data in Australia by default. We support storing customer data in the customer's own jurisdiction where the underlying infrastructure region is available; available regions and the process for selecting an alternative region are set out in the SecArch Customer Agreement and the SecArch Privacy Notice.

Sub-processors and changes

A current list of SecArch sub-processors and their hosting regions is published in the SecArch Privacy Notice. We give SecArch customers notice of material changes to sub-processors consistent with the SecArch Customer Agreement.

7. Overseas disclosure

Some of our service providers and product sub-processors store or process information outside Australia. Before disclosing personal information overseas we take reasonable steps to ensure it is handled consistently with the APPs (APP 8).

Current overseas processing arrangements

ServicePurposeLocation
CloudflareDNS, CDN, website hosting, web analyticsGlobal edge (data minimised; no personal information stored at edge)
GoogleGoogle Sign-inUnited States
AppleApple Sign-inUnited States
SupabaseMy Values app — database, authentication, storageAustralia (Sydney)
AnthropicMy Values Advisor — generates answers (de-identified question only)United States
OpenAIMy Values Advisor — routes questions (de-identified question only)United States
ResendMy Values app — account emails (sign-up confirmation, password reset)United States
AzureSecArch hosting — Australia by default; customer-jurisdiction options as configuredAustralia (default)

A current list of overseas sub-processors for each product is maintained in the relevant product privacy notice. Where SecArch customer data is stored in a jurisdiction outside Australia at customer request, the customer remains the controller and is responsible for the cross-border implications under its own legal regime.

8. Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11). As a cyber security consultancy, security is the core of what we do.

Our information security program

Our information security program covers, at minimum:

We align our practices with ISO/IEC 27001:2022 and the Australian Cyber Security Centre's Essential Eight. No system is perfectly secure, but security is the discipline our business is built on.

9. Data breaches

We comply with the Notifiable Data Breaches scheme under the Privacy Act. If we become aware of a data breach that is likely to result in serious harm, we will assess it and, where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with our Data Breach Response Plan.

10. How long we keep it

We keep personal information only for as long as we need it for the purposes set out in this policy, or as required by law, and then de-identify or securely destroy it. Indicative retention periods (defaults — actual periods may be shorter):

CategoryRetention
Website enquiries (no engagement follows)2 years from last contact, then deletion
Consulting engagement records7 years from engagement close (tax + limitation period)
Contractor / employee records7 years from end of engagement
Marketing contacts (after unsubscribe)Suppression list kept indefinitely; all other data deleted
SecArch user accountsWhile account is active + 30 days, then deletion. Tenant content per Customer Agreement.
My Values user accountsWhile account is active. Children's task history: 12 weeks rolling. See My Values notice.
Authentication and security logsUp to 2 years for security investigation; aggregated thereafter
Records we are required by law to keepAs required by the relevant legislation

Specific retention periods for each product are also set out in the product notices and our Data Retention and Disposal Policy.

11. Direct marketing

If we send you marketing communications (such as our newsletter, event invitations, or product updates), we do so only where you have consented or where it is permitted under the Privacy Act and the Spam Act 2003 (Cth). Every marketing message includes a clear unsubscribe option. You can also opt out at any time by emailing hello@pursec.com.au. Operational and security communications (for example, account or security notices) are not marketing and are not subject to opt-out.

12. Anonymity, pseudonymity, and identifiers

Dealing with us anonymously or by pseudonym

You may make a general enquiry through our website without giving us your name, by using a pseudonym or pseudonymous email address (APP 2). For consulting engagements and product purchases we need to know who we are dealing with for contract, billing, and security reasons, but for enquiries, blog comments, or other casual contact you don't need to identify yourself.

Government identifiers

Where we collect any government-issued identifier (such as a driver's licence number used to verify the identity of a contractor), we use it only for the limited purpose for which it was collected. We do not adopt a government identifier as our own identifier of you (APP 9).

13. Children's information

One of our products, My Values, collects limited personal information about children, provided by the child's parent or guardian. We handle children's information with particular care and in accordance with applicable Australian law (including, once in force, the Children's Online Privacy Code). The detail is set out in the My Values Privacy Notice.

14. Accessing and correcting your information

You can ask us for access to the personal information we hold about you, and to correct it if it is inaccurate, out of date, or incomplete (APP 12, APP 13). Contact us at hello@pursec.com.au.

We will respond to your request within 30 days. If we need longer (for example, because the request is complex or covers a large volume of information), we will tell you why and agree a revised timeframe with you. We may need to verify your identity before disclosing or correcting personal information. If we refuse access or correction, we will give you reasons in writing.

15. Complaints

If you believe we have breached the APPs, contact us at hello@pursec.com.au and we will investigate and respond.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

16. Changes to this policy

We may update this policy from time to time. If we make a material change (for example, a new category of information, a new sub-processor with cross-border implications, or a change to how we use personal information), we will publish the updated policy at pursec.com.au and, where you are an account-holder, notify you in the product or by email at least 14 days before the change takes effect. Minor wording changes are reflected by updating the "Last updated" date at the top of this policy. The current version is always available at pursec.com.au.

17. Contact us

Privacy enquiries: hello@pursec.com.au

Purposeful Security Pty Ltd, Melbourne, Australia · ABN 36 677 972 039

Version 1.3 · Status: Approved · Owner: Director, Purposeful Security Pty Ltd · Approval date 1 August 2026 · Effective date 28 June 2026 · Next review: effective date + 12 months, or on any material change to data handling.