Privacy
Privacy policy
This company would hold other organisations' records for fifteen years, so the policy is built around the difference between information we decide about and information we would merely hold. Nothing has been deposited yet.
Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)Australian Privacy Principles 1 to 13
1Two capacities, and which one applies to you
ARCVAULT AI PTY LTD (ACN 696 486 987, ABN 11 696 486 987) would handle personal information in two quite different capacities, and almost every question about your rights depends on which one applies to you. A supplier whose business is holding other organisations' records for fifteen years and does not draw that line clearly has written a policy about a different company.
| Capacity | Whose information | Who decides | Where a request goes |
|---|---|---|---|
| Controller | Our own handling. People who write to us, prospective customer contacts, suppliers, anyone reading this website | Us | Directly to us |
| Processor | Personal information inside a record deposited for retention by a customer organisation, about that organisation's own employees, clients, patients or members | The depositing organisation, not us | To that organisation. We route it if you write to us by mistake |
Why we could not act on a deposited person's request directly
Where we hold a record as processor, we hold it on a customer's documented instructions and for that customer's retention obligation. We have no purpose of our own for it. If somebody named inside a deposited payroll export asked us to delete their record and we did it, we would have destroyed material the customer is required by law to keep, acted against the instruction we were given, and made the customer's compliance position worse without their knowledge. A supplier prepared to do that is a supplier nobody should deposit with.
What we would do instead is route the request to the depositing organisation within 5 business days, tell you that we have done it and who it went to, and act on that organisation's instruction when it arrives. We will not ignore you and we will not pretend to a power we do not have.
Nothing has been released and no organisation has deposited anything. There is no record belonging to anybody else in our possession, and therefore no processor activity at all at the date at the top of this page. The controller half of this policy is live now. The processor half describes how it is being designed to work, and it is published early so that it can be argued with before it matters.
2The law this policy answers to
The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.
Australian Privacy Principle 1, and why this document exists
APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.
The small business threshold, and why it does not get us out of this
Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. ARCVAULT AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.
We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.
If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.
Other Australian law that applies
- Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
- Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
- Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.
3What we hold as controller
Australian Privacy Principle 3 governs collection. It permits an organisation to collect personal information that is reasonably necessary for one or more of its functions or activities, requires that it be collected by lawful and fair means, and requires that it be collected from the individual concerned unless that is unreasonable or impracticable. Sensitive information needs consent as well as necessity, subject to specific exceptions.
This section is what we hold in our own right, where we decide the purpose. It is short, and it is short because the company does not yet do very much.
| Category | Example fields | Source | Why we have it | If you withhold it |
|---|---|---|---|---|
| Correspondence | Your email address, your name if you sign your message, the display name your mail client sends, the content of the thread, message headers and timestamps | You, when you write to us | Answering you, and keeping a record of what was said | We cannot reply. There is no other route in |
| Enquiry context | Your organisation, your role, what you are trying to retain and for how long | You, voluntarily | Giving a useful answer rather than a generic one | The answer is more generic. Nothing else changes |
| Supplier and accounting records | Contact name, business email, invoice and payment details of people we buy from | The supplier | Paying for things, and the statutory obligation to keep financial records | Not applicable. This is not information about visitors |
| Website request data | IP address, user agent string, requested path, response code, timestamp | Your browser, automatically | Serving the page at all, and absorbing malicious traffic | Cannot be withheld while still loading a page. It is held transiently by the host |
What is deliberately not on that table
- No analytics of any kind. No page view counter, no session recording, no heat mapping, no visitor identification service, no advertising pixel. This website measures nothing about you and we would have to change this policy before it could.
- No cookie set by us. The cookie position in full is in its own section below and on the cookie notice.
- No marketing list, no newsletter, no lead capture, and no form anywhere on this site.
- No account system, because there is nothing to sign in to.
- No sensitive information within the meaning of the Privacy Act. We do not ask for health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, or biometric or genetic material, and there is no field anywhere in our systems intended to hold any of it.
Collection from someone other than you
Occasionally a person writes on behalf of a colleague, or copies a colleague into a thread. That is collection from a third party and APP 3.6 permits it where collecting from the individual is unreasonable or impracticable. In that situation we take reasonable steps to notify the person whose information it is, which in practice means replying to all rather than replying privately so that everybody can see what we now hold.
4What we would hold as processor
This section covers material deposited by a customer organisation for long term retention. It is written as a commitment to those organisations as much as to the people whose information sits inside a deposit, because a processor's obligations are contractual first and the contract should not contradict the public page.
What a deposit would consist of
| Part | What it is | What we do with it | What we deliberately do not do |
|---|---|---|---|
| The payload | The exported records themselves. Documents, structured exports, images, correspondence archives. It may contain personal information about the customer's own people | Verify the digest, identify the format, store it, recompute the digest on schedule, migrate the format when instructed | Open it to look at the content, index the text, extract entities, profile it, or use it to improve anything |
| Technical metadata | Byte size, format identification, character encoding, digest value and algorithm, deposit timestamp | Hold it beside the payload as the fixity and format record | Derive anything about individuals from it |
| The index | The finding aid the customer writes. Origin system, arrangement, field meanings, code lists, the retention rule and its expiry date | Hold it, keep it readable, return it with the payload on exit | Edit its substance. Corrections come from the customer |
| Operator contact | Name, role and business email of the people at the customer authorised to give instructions | Verify that an instruction came from an authorised person | Market to them, or reuse the contact for anything else |
| Instruction log | Who instructed what, when, and what we did about it | Keep it for the life of the relationship, because a chain of custody with a gap in it is not a chain of custody | Delete it on request, since it is the evidence that the record was handled correctly |
Not looking inside is a design decision, not a courtesy
A retention service that indexes content for search has to read every deposit, has to hold the index somewhere, and has to secure a second body of derived material that is often more sensitive than the original because it is easier to query. We have chosen not to build that, which is the reason the non-goal appears on the approach page as well as here. The practical consequence is that we usually cannot tell you whether a particular person appears in a particular deposit. The customer can, and that is the correct division.
What we would commit to as processor
- Instructions only. We would process deposited material only on the customer's documented instructions, including for any transfer, unless an Australian law requires otherwise, in which case we tell the customer before processing unless the law forbids that.
- No secondary use. Not for product development, not for benchmarks, not for an aggregate report about what organisations retain, and not for training any model. An archive that mines its holdings has stopped being an archive.
- Confidentiality. Everyone with access would be under a confidentiality obligation that survives the end of their engagement, and access would be limited to those who need it to operate the service.
- Assistance. We would assist the customer to answer access, correction and deletion requests, and to meet its own obligations after a breach.
- Sub-processors. Named in the recipients table below, with at least 30 days notice before one is added or replaced, and a right for the customer to object.
- Return or destruction. At the end of a contract, and at the customer's election, we return or destroy the deposit within 30 days and destroy remaining copies, unless a law requires retention. Return means the payload and the index together, in the formats they are held in, because a return that omits the index is not a return.
- Audit. We would make available the information needed to demonstrate compliance and allow a reasonable audit by the customer or its auditor, on reasonable notice and no more than once a year unless a breach has occurred.
- Notification to the customer. If we became aware of unauthorised access to, unauthorised disclosure of, or loss of deposited material, we would notify the affected customer without undue delay and in any event within 24 hours, with what we know at the time, and keep updating as we learn more. The customer, being the entity accountable under Part IIIC of the Privacy Act, decides whether the incident is an eligible data breach and makes any notification to the Commissioner and to affected individuals. We assist and we do not obstruct.
5Notification at the point of collection
Australian Privacy Principle 5 requires us to tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. What we have to tell you includes who we are, the fact and circumstances of collection, the purpose, the consequences of not providing the information, how to get access and correction, how to complain, and whether the information goes overseas and where.
Where notice actually happens, in each capacity
- As controller, here. This document is linked from the footer of every page of this website, including the page you would have been reading before you wrote to us. There is no collection point on this site other than the mail link, and the mail link goes to an address that is published in plain text beside it rather than hidden behind a script.
- As controller, in the reply. Where a thread turns into something that will be kept for longer than an answer, for example an ongoing discussion with a prospective customer, we say so in the thread rather than relying on you having read this page.
- As processor, through the customer. We would have no relationship with the people described inside a deposit and no way to contact them. Notice to them is the depositing organisation's obligation under its own APP 5 duty, and the contract would require it to have given that notice, or to be relying on a lawful basis for not doing so, before it deposits anything.
Consequences of not providing information
Set out against each row of the collection table above rather than described in general terms, because "we may not be able to provide our services" is a sentence that tells nobody anything. In practice the only consequence that arises is that without an email address we cannot reply to you.
What this page is not allowed to do
A privacy notice that reserves a right to change what it collects without telling you defeats the point of APP 5. Where we begin collecting a category of personal information that is not in the table above, this policy changes first and the notice provisions in the changes section apply.
6Dealing with us anonymously
Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.
Reading this website is anonymous in every sense we can control. There is no account, no cookie of ours, no analytics and no fingerprinting script, so nothing here attempts to work out who you are or to recognise you if you come back.
Writing to us can be pseudonymous. A message from an address that does not carry your name is answered on its merits. We will not insist on a real name, a company domain or a telephone number as a condition of a reply, and we will not treat a pseudonymous enquiry as less serious than one from a corporate address.
The option genuinely falls away in two places. The first is a request to access or correct personal information, because to answer it we have to be reasonably satisfied you are the person the information is about. The second is a contract. An organisation depositing records has to be identified, because the whole service rests on knowing whose records they are and who is authorised to instruct us about them.
7Information we did not ask for
Australian Privacy Principle 4 deals with personal information we receive without having asked for it.
For a company in this line of work the obvious route is a sample. Somebody wanting to know whether a format can be preserved attaches a real export rather than a synthetic one, and a real export from a payroll system, a case management tool or a clinical record contains a great many people who were never asked. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
Practically, an unsolicited attachment containing other people's personal information is deleted from the mailbox, disappears from the ordinary backup rotation as those copies age out, and the technical question it was sent to illustrate is written down without it. We then reply saying what we deleted, because a sender usually does not realise what was in the file.
The contact page asks you to describe a file before sending it, for exactly this reason. It is not a formality.
8Use and disclosure
Australian Privacy Principle 6 governs what may be done with personal information once it is held. The rule is that information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.
As controller
- Replying to you, and continuing a thread you started.
- Keeping a record of what was said, so that a later question about an earlier answer can be resolved by looking rather than remembering.
- Improving what this website says. Where several people ask the same question, the fix is usually a paragraph on a page rather than nine identical replies. We use the substance of a question that way. We do not quote you, name you or reproduce your organisation.
- Meeting statutory obligations, principally the requirement to keep financial records.
- Establishing, exercising or defending a legal claim, if one ever arises.
As processor
Operating the retention service on the customer's documented instructions, and nothing else. There is no secondary purpose, because a processor that develops one has become a controller of that material and would have to say so on this page.
What we do not do, in either capacity
- We do not sell personal information. Not to a data broker, not to an advertiser, not as an audience, not bundled into anything.
- We do not use anything you send us for advertising. There is no advertising on this website and none in anything the company has built.
- We do not train a model on your correspondence or on any deposited material. The company name contains the letters AI and that makes this worth stating rather than assuming. Nothing that arrives here becomes training data.
- We do not enrich what you send us against a third party dataset to work out more about you or your organisation than you told us.
Disclosure to law enforcement, courts and regulators
We may disclose personal information where the Act permits it. That covers disclosure required or authorised by or under an Australian law or a court or tribunal order, a permitted general situation under section 16A including a serious threat to life, health or safety, and disclosure to an enforcement body where reasonably necessary for an enforcement related activity.
Where we make such a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you a request was made, we will. Where a request relates to material we hold as processor, we tell the customer before responding unless the law forbids it, because the customer is the party accountable for that material and may have standing to object that we do not.
We do not have a policy of volunteering material we have not been compelled to produce.
9Recipients, sub-processors and where they are
The complete list. Where a recipient would touch material held as processor it is marked as a sub-processor, which triggers the notice obligation described earlier.
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Cloudflare, Inc. | Controller side | Serving and protecting this website. Request data passes through the edge and is held transiently | Global edge network, including Australia. Company incorporated in the United States |
| Google LLC | Neither. Your browser contacts them directly | Delivering the two web fonts this site uses. Your IP address and browser characteristics reach them because your browser makes the request, not because we forward anything | United States and global edge |
| Our email provider | Controller side | Receiving, sending and storing correspondence | Australia and the United States |
| Our accountant | Controller side | Statutory accounts, business activity statements and tax | Australia |
| Storage and compute for the retention service | Would be a sub-processor | Holding deposits. Not yet contracted, because there is no service and nothing deposited | To be named here before any deposit is accepted, with the region stated |
Not on that list
No analytics vendor, no advertising network, no data broker, no customer data platform, no visitor identification service, no marketing automation, no chat widget, no session recorder, no error tracking service that receives your browser state, and no artificial intelligence provider of any kind. A retention company adding a vendor that can see deposited material would be exactly the change that should be announced rather than absorbed, so it would go through the sub-processor notice process even where a strict reading might not require it.
Business transfer
On a sale of the company, personal information held as controller may transfer to the buyer. Material held as processor would transfer subject to the customer contract, which we will not sidestep by structuring a deal differently. Where we are lawfully able to, we give notice before such a transfer completes.
Insolvency
This one is usually left out and it is the case that actually worries a depositor. If the company failed, deposited material would be dealt with under the customer contract and under insolvency law, and neither of those is something a website can promise its way around. The honest mitigation is structural rather than contractual, which is why the design keeps a complete copy in the customer's own hands, in open formats, with the index, throughout.
10Direct marketing and the Spam Act
Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime: consent, accurate sender identification, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.
Our position
We do not run a marketing list. We have never sent a marketing email under this company name. If that changes, it will be opt in, the consent will be recorded with a timestamp and the wording you agreed to, and the first message will say where the address came from.
Writing to our support address does not subscribe you to anything. That is the most common way small companies quietly build a list, and we do not do it.
There is no advertising anywhere in this
This website carries no advertising, no sponsored content and no affiliate link, and nothing the company has built carries any either. There is no advertising network involved in this site, so there is no personalised advertising to switch off and no advertising identifier of any kind in play. The section exists to say that plainly rather than to leave a gap somebody has to interpret.
What a future announcement list would look like
If the company ever publishes a specification and people ask to be told when it changes, that would be a list, and the Spam Act would apply to it in full. It would be opt in from a page that does nothing else, the consent record would carry a timestamp and the exact wording agreed to, every message would identify the sender and carry a working unsubscribe link, and an unsubscribe would be actioned immediately rather than within the five working days the Act allows.
Writing to our support address would not put you on it. That is the most common way a small company quietly builds a list and we do not do it.
11Sending personal information overseas
Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.
We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".
How we meet APP 8
Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.
We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.
Where the data actually goes
The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.
12Government related identifiers
Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.
We do not collect any government related identifier. There is no account, no age check and no identity verification step anywhere in what we do, and no field in any system we operate is intended to hold one.
If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.
The processor position, which is different
A record deposited for retention may well contain government related identifiers belonging to the depositing organisation's own people. A superannuation record contains tax file numbers. A clinical record contains Medicare numbers. That is not us adopting an identifier within the meaning of APP 9, because we do not use it to identify anybody and we do not look inside the deposit at all. It does mean that a deposit has to be treated as sensitive by default, which is the assumption the retention design starts from rather than one it reaches later.
13Keeping information accurate
Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.
Almost everything we hold as controller is something you wrote to us, which is accurate in the narrow sense that it faithfully records what was said and is the category most likely to go stale. Roles change, addresses change, and a thread from two years ago describes an organisation that may no longer be arranged that way. We do not periodically re-verify any of it, because doing so would mean contacting people who had finished dealing with us in order to ask them to confirm details they never asked us to keep.
The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.
As processor the principle bites differently and it is worth being exact about it. We do not correct the content of a deposited record, ever. An archive whose supplier edits the holdings is not an archive, and a record that has been silently improved is no longer evidence of anything. Where a depositing organisation instructs a correction, the corrected version is deposited as a new version, the instruction is recorded, and the superseded version is retained unless the instruction is to destroy it. That is the difference between correcting a record and falsifying one.
14Security, and what we do not hold
Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.
What "reasonable steps" means for a company this size
- Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address is carried over TLS wherever the sending server offers it.
- Encryption at rest for stored data, provided by the underlying platform.
- Multi-factor authentication on every account that can reach the mailbox, the domain registration, the hosting account or the code repositories. Those four are the entire attack surface today, and there is no console behind any of them that holds anybody's records.
- Access on a need to know basis. The number of people who can reach the mailbox is small and is reviewed whenever anyone joins or leaves.
- Nothing live to breach. There is no hosted service, no account system, no customer database and no administrative interface behind this site. What has to be defended is a set of static files, one mailbox and a code repository.
- Collecting less. The most reliable security control available to a company of this size is not holding the data, which is why the collection tables earlier on this page are as short as they are.
What we do not have, stated plainly
ARCVAULT AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.
We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.
What a retention service would have to add, and has not been built yet
Everything above describes a company that holds correspondence. A company holding other organisations' records for fifteen years needs a materially stronger position, and the honest statement is that it does not have one yet because there is nothing to protect. The design being written towards includes deposits encrypted with keys the customer can hold, an append only custody log so that a deletion cannot be made to look like it never happened, separation between the credential that can read a deposit and the credential that can destroy one, and destruction that requires a second authorised person. None of that is running. None of it should be believed until it is, and it will be described here in the present tense only when it is true.
Why an archive fails differently
The security failure that worries most companies is a breach that becomes public in a week. The one that should worry an archive is a slow corruption or a quiet deletion that nobody notices for eight years, by which time every copy that could have contradicted it has been rotated out. That is the reason fixity checking runs on a schedule and the custody log is designed to be append only. Confidentiality is the loud risk. Integrity is the one that actually loses the record.
15Retention, and a conflict of interest worth naming
Australian Privacy Principle 11.2 requires that personal information be destroyed or de-identified once it is no longer needed for any purpose for which it may be used or disclosed under the Act, unless it is contained in a Commonwealth record or a law requires it to be kept. For a company whose entire subject matter is long retention, this principle deserves more than a sentence, because our interests and yours point in opposite directions here and it is better to say so.
| Category | Period | Reason |
|---|---|---|
| General correspondence, no ongoing matter | 24 months from the last message in the thread | Long enough that a follow up two years later has context. Short enough that an inbox does not become an archive of everybody who ever wrote in |
| Correspondence about a prospective engagement | 7 years from the end of the discussion | Precontractual dealings can matter to a later dispute, and the general limitation period in New South Wales for a contract claim is 6 years |
| Privacy requests and complaints, and what we did about them | 7 years from closure | Evidence that we handled the request properly. Deleting the record of a deletion is how an organisation loses the ability to show it complied |
| Security reports and incident records | 7 years | Pattern recognition across years, and the record required if a notification is ever assessed |
| Financial and supplier records | 7 years | Section 286 of the Corporations Act 2001 (Cth), and tax record keeping requirements |
| Website request data at the edge | Days, set by the host, not by us | Transient operational logging. We do not copy it into anything of our own |
| Deposited material held as processor | The period the customer instructs, and no longer | The customer's retention obligation is the only reason the material exists here |
| Instruction and custody log for a deposit | 7 years after the deposit itself is destroyed | Proof of what was held and how it was disposed of, which outlives the thing it describes |
The conflict of interest, stated openly
A company paid to store things has an obvious incentive to store them for longer than necessary. Three things are meant to hold against that. Retention is instructed by the customer and recorded, not inferred by us. Every deposit carries a stated expiry date in its index from the day it arrives. And a disposal that is due runs on the schedule rather than waiting for somebody to ask, with a report to the customer either way.
Backups and the awkward gap
Deleting something from a live system does not immediately delete it from the copies taken before the deletion. That is true here as everywhere, and a policy claiming otherwise is describing an imaginary system. Where we delete personal information, it is removed from the live system immediately and disappears from the ordinary backup rotation as those copies age out. Until then it is not used for anything, and a restore that would reinstate deleted information is followed by re-applying the deletion.
16Access and correction, in both capacities
Australian Privacy Principle 12 gives you the right to ask for access to the personal information held about you. Australian Privacy Principle 13 gives you the right to ask that it be corrected. Which door to knock on depends on the capacity, so it is set out twice.
| Capacity | Information | What to do |
|---|---|---|
| Controller | Your correspondence with us, enquiry context, supplier records | Email [email protected] with "Privacy request" in the subject line. We respond within 30 days, access is free, and a refusal comes with written reasons, the ground relied on, and how to complain |
| Processor | Personal information inside a record deposited by an organisation | Ask that organisation. It decides, it holds the index that connects a record to a person, and it is accountable for the material. If you write to us instead we route it within 5 business days and tell you where it went |
Where a customer instructs us to produce or correct material relating to a person, we action the instruction within 10 business days of receiving it, or sooner if that customer's contract requires it, so that the customer can meet its own 30 day obligation with room to spare.
Verifying who you are
We have to be reasonably satisfied that you are the person the information is about, or an authorised representative. For correspondence, that means a reply from the address the thread was conducted on. We will not ask you to send identity documents, we will not ask for a scan of a licence or passport, and we will not use a third party verification service. Asking for identity documents in order to protect privacy collects more sensitive material than the request was ever about.
Timing, cost and form
We respond within 30 days. Access is free. We do not charge for making a request and we do not charge for correction. Where you ask for the information in a particular form we will provide it that way if it is reasonable and practicable to do so. If producing it in an unusual form imposes a genuine cost we will tell you the charge before doing the work, and it will not be excessive.
When access can be refused
The grounds in the Act are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable in them, where giving access would reveal our evaluative information in connection with a commercially sensitive decision, and where giving access would be unlawful.
If we refuse, in whole or in part, we give written reasons, identify the ground relied on, and tell you how to complain. Where part of the information can be given, or the need can be met another way, we offer that instead of a flat refusal. The most likely real instance is a thread involving several people, where the answer is usually to give you your own messages and a description of the rest.
Correction
If information is inaccurate, out of date, incomplete, irrelevant or misleading, we correct it. If we have disclosed it to somebody else and you ask us to tell them about the correction, we take reasonable steps to do so unless that is impracticable or unlawful.
If we decline to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is regularly overlooked and it is worth knowing about, particularly where the disagreement is about a matter of opinion rather than a matter of fact.
17Deletion and disposal
Deletion is not one of the thirteen Australian Privacy Principles in the way that access and correction are. It arrives through APP 11.2, which requires destruction or de-identification once information is no longer needed. In practice we treat a deletion request as a request we will honour rather than one we will argue about, and this section says what actually happens.
As controller
- Email [email protected] with "Delete my data" in the subject line.
- We confirm receipt within 5 business days and tell you what we hold, so that you can say whether you meant all of it.
- We delete it within 30 days, and confirm in writing when it is done.
- Ordinary backup copies age out on their normal rotation as described in the retention section. They are not used for anything in the meantime.
What survives a deletion, and why
- A minimal record of the request itself. The address, the date and what was done. Without it we cannot demonstrate that we complied, and we would have no way of recognising that the same address later reappears through a route you did not intend.
- Financial records. If you are a supplier and we have paid you, the invoice stays for the statutory period. Section 286 of the Corporations Act 2001 (Cth) is not something either of us can waive by agreement.
- Material relevant to a live dispute or a legal hold. Deleting evidence because it was requested is not compliance, and we will say plainly that this is the reason rather than going quiet.
As processor, disposal rather than deletion
Deposited material is destroyed on the instruction of the depositing organisation, on the expiry date recorded in the index, or at the end of the contract at that organisation's election. Destruction is confirmed back to the customer in a written disposal record that says what was destroyed, when, by what method, and who instructed it. That record is itself retained, because the evidence that a record was properly disposed of has to outlive the record.
We would not accept a destruction instruction from anyone other than an authorised operator at the depositing organisation. An archive that can be talked into destroying something by a convincing email is not an archive.
There is no deposited material of any kind, so every deletion request that could reach us right now is a controller request about correspondence, and it is answered by deleting a mail thread.
18Children and young people
This is a business to business proposition. The website is not directed at children, nothing on it is designed to appeal to children, and there is no account, no sign up, no game, no social feature, no chat and no user generated content anywhere on it.
The Australian position on capacity
The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless there is something to suggest otherwise. We apply that presumption to correspondence.
The Privacy and Other Legislation Amendment Act 2024 provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force, and we will update this policy at that point rather than guessing at its terms in advance.
Where a child's information could actually reach us
Not through this website. The realistic route is inside a deposit, where a customer organisation retains records about children. A school, a paediatric practice, a youth service or a local authority holds records of exactly that kind, and the retention periods that apply to them are among the longest in Australian law. A child's medical record in New South Wales is kept until that person turns 25, which can be a quarter of a century after the system that produced it was decommissioned.
In that situation the child, or their parent or guardian, has rights against the organisation that holds the record rather than against us. We would hold it as processor, we would not look inside it, and a request would be routed as described in the access section. We would apply the same handling to it as to anything else, which is to say we would not treat a record about a child as ordinary material merely because we cannot see what is in it.
If you believe a child's information has reached us as controller
Write to [email protected]. We will delete it without requiring proof of a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm when it is done.
19Automated decisions
The Privacy and Other Legislation Amendment Act 2024 inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026. It is disclosed here in advance of the commencement date rather than on it.
Our position
We make no automated decision that significantly affects anybody's rights or interests. Nothing here decides whether a person gets credit, a job, a service, a benefit, housing, insurance or a legal entitlement, and nothing here scores or ranks individuals.
Automated processing that does happen, and why none of it meets the threshold
- Format identification. A deposited file is inspected by a program that works out what format it is from its structure. It reaches a conclusion about a file, not about a person.
- Fixity checking. A digest is recomputed on a schedule and compared to the recorded value. A mismatch raises an event for a person to investigate. Nothing is decided automatically.
- Disposal scheduling. An expiry date recorded at deposit causes a disposal to become due. It does not cause a destruction. Destruction is confirmed against the customer instruction before it happens, because an automated deletion of a record somebody is legally obliged to keep is the worst failure this company could have.
- Edge protection on this website. The host may automatically challenge or block a request that matches an abuse pattern. That affects a request, and the remedy is to write to us from another connection and say so.
About the letters in the company name
The registered name is ARCVAULT AI PTY LTD. No model is trained on anything held here, no deposited material is sent to a third party inference service, and no decision about a person is delegated to a statistical system. Where machine assistance is ever used in the work, it will be described in this section, in specific terms, before it starts rather than after.
20Data breaches and the notification scheme
Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.
The process we follow
- Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
- Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
- Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
- Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.
What a notification will contain
Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.
If you think a breach has happened
Write to [email protected] with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.
21The statutory tort of serious invasion of privacy
A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.
This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.
22Cookies on this website
Short version. This website sets no cookies of its own, runs no analytics, and shows no consent banner because there is nothing to consent to. The full account is on the cookie notice and the substance is summarised here so that this policy is complete on its own.
- No first party cookie. Nothing on this site writes a cookie. The site is static files and one small script that does a navigation toggle and a scroll reveal.
- No local storage. Nothing is written to localStorage, sessionStorage or IndexedDB.
- Two web fonts from Google Fonts. Your browser fetches them directly from Google, which means your IP address and browser characteristics reach Google as part of that request. Google states that Google Fonts sets no cookies. This is the only third party contact the page makes and it is named in the recipients table.
- Edge request logging. The host records the ordinary details of an HTTP request in order to serve it and to absorb attacks. We do not read those logs routinely and we do not copy them into anything.
Australian law does not have a direct equivalent of the European consent rule for cookies. What applies is the Privacy Act, and it applies to a cookie only where the cookie involves personal information. Since there is no cookie, the question does not arise. If that ever changes, the change appears in this policy and in the cookie notice before any cookie is set, and anything beyond what is strictly necessary would be opt in.
23Complaints
Step one: tell us
Email [email protected] with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.
Step two: the Commissioner
If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.
The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.
What we will not do
We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.
24If you are outside Australia
This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.
European Economic Area and United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Send any such request to [email protected] and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.
California
Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising on this website and none in anything the company has built, so there is no sharing to opt out of in the first place. Global Privacy Control signals sent by your browser to this website are honoured.
Everywhere else
If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.
25Changes to this policy
We may change this policy. When we do, the effective date and the version number in the header of this page change with it.
Where a change materially reduces your rights or materially expands what we collect, we give notice before it takes effect. That means a dated note at the top of this page for at least 30 days beforehand, and, for anyone with an active thread or a contract, an email. We will not make a material change effective retrospectively.
Two changes are already foreseeable and are flagged now rather than being sprung later. The first is naming the storage and compute provider for the retention service, which has to happen before any deposit is accepted. The second is the arrival of the Children's Online Privacy Code and the automated decision transparency requirement, both of which have their own sections above.
Previous versions are not published as separate pages, but they are kept. If you want to know what this document said on a particular date, ask and we will send you that version.
This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner about your own circumstances.
26How to contact us
All privacy matters reach one address, and it is the same address as everything else. There is no separate privacy officer inbox, because inventing one would imply a function that does not exist in a company this size.
| Matter | Subject line | Response |
|---|---|---|
| Access to your personal information (APP 12) | Privacy request | 30 days |
| Correction of your personal information (APP 13) | Privacy request | 30 days |
| Deletion of what we hold about you | Delete my data | 30 days |
| Complaint about our handling of personal information | Privacy complaint | Acknowledged in 5 business days, answered in 30 days |
| Suspected security incident or data breach | Security | Same or next business day |
| Anything else | Anything sensible | 5 business days |
Email: [email protected]
Entity: ARCVAULT AI PTY LTD, ACN 696 486 987, ABN 11 696 486 987, an Australian proprietary company registered in New South Wales. Registered for GST from 24 March 2026.
We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 696 486 987 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.
If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.