Privacy Policy

Last updated: 3 September 2026

1. About this Policy

This Privacy Policy describes how Aicura Pty Ltd. ABN 85 696 789 876 ("Aicura", "we", "us", "our") collects, uses, holds, and discloses personal information.

We're an APP entity under the Privacy Act 1988 (Cth) and we comply with the Australian Privacy Principles (APPs). This Policy is intended to meet our APP 1 transparency obligations.

2. Who we are

Aicura is an Australian company providing a software platform that helps Australian organisations manage their AI governance obligations. We're based in Melbourne, Victoria.

The platform is hosted in AWS data centres in Australia (Sydney, ap-southeast-2; backups in Melbourne, ap-southeast-4).

3. What personal information we collect

We collect a limited set of personal information directly from the people who sign up for, use, or contact us about the Aicura service.

3.1 When you sign up

  • your full name
  • your work email address
  • your organisation's name, type, industry, and jurisdiction (and APRA classification, where relevant)

3.2 When you use the Aicura platform

  • email addresses, names, and roles of additional users you add to your account
  • the AI Register entries you create (these may include free-text descriptions identifying who is responsible for an AI system inside your organisation)
  • the documents you upload (privacy policies, governance policies and similar), which may incidentally contain personal information about other people, particularly your customers, employees or contractors
  • risk assessment, policy, and support ticket content you create or submit
  • log data about your use of the platform, including page accesses, requests made, and timestamps
  • where you enable discovery, the signals reported by the source systems you choose to connect (such as your identity provider, device management, cloud inventories, IT service management, code hosting, finance systems and workspace tools). These signals can include personal information about your own staff, for example the user associated with a sign-on to an AI service, or the person a managed device is assigned to. Signals from a connected code hosting source are limited to repository details and the AI SDKs and services identified in dependency and configuration files, and do not include file contents or commit or contributor information
  • where you run Aicura's enforcement or monitoring components in your own environment, the results those components report back, such as which rule fired and when. The AI prompts and responses themselves remain in your environment and are not sent to Aicura

3.3 When you contact us through our website

  • your name, email address, organisation, enquiry type, and message via our website contact form
  • your email address if you subscribe to our briefings
  • your email address if, after taking our AI governance maturity assessment, you ask for a copy of your result or ask us to get in touch. We use the address to send those emails and do not store it with your answers
  • whatever else you choose to include in correspondence

The AI governance maturity assessment itself stores your 38 answers, your scores, the industry and organisation size band you select, the role you enter if you choose to, and the country your connection came from. None of this identifies you, and it is kept so that later respondents can see averages for their industry and size band. A results link shows scores only.

3.4 What we don't collect

We don't ask for and don't collect:

  • payment card details (these are collected directly by Stripe, see section 6)
  • phone numbers
  • physical or postal addresses
  • date of birth
  • government-issued identifiers
  • sensitive information as defined in the Privacy Act (health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, biometric data, etc.)

If you happen to include any of these in a document you upload or in correspondence with us, we will hold them as part of that document or that correspondence, but we don't ask for them and don't have a specific use for them.

4. How we collect information

We collect most information directly from you, through the signup form, the platform interface, support tickets, the website contact form, the AI governance maturity assessment and email correspondence.

Where your organisation enables discovery, we also collect information from the source systems your organisation connects to Aicura for that purpose. Your organisation chooses which sources to connect and can disconnect them at any time. Information collected this way is collected on your organisation's instruction and held for your organisation's own governance record. If you are an employee whose details appear in those signals, your organisation is the entity that decided to connect the source, so a request about that information is best directed to them in the first instance, though you can also contact us using the details below.

We do not buy personal information from third parties or use enrichment services.

5. Why we collect it

We collect personal information to:

  • create and manage your account and your organisation's tenant
  • provide the Aicura service to you and your authorised users
  • bill you and process payments
  • respond to your support requests
  • send you transactional emails, covering welcome emails after signup, identity-provider emails (password set, password reset, verification) and billing emails (receipts, invoices, payment notifications)
  • send you our briefings, if you've subscribed to them
  • show you your maturity assessment result and the averages beside it, email you a copy if you ask for one, and get in touch if you ask us to
  • investigate and resolve issues with the platform
  • comply with our own legal obligations
  • as otherwise reasonably necessary to operate our business

6. How we use and share your information

6.1 Inside Aicura

Authorised Aicura personnel may access your data to provide support, investigate issues, curate regulatory content, and operate the service. Operator access is restricted, brokered through controlled and audited mechanisms (federated single sign-on with multi-factor authentication), and there is no standing administrative access and no direct interactive path to the production database. Changes operators make to your data are recorded in our audit log alongside changes you make yourself.

6.2 With service providers (sub-processors)

We use a small number of third-party service providers to deliver the platform. We don't sell your information to any of them, and we don't allow them to use your information for their own purposes.

  • Amazon Web Services — cloud infrastructure (compute, storage, databases). Australia (Sydney + Melbourne).
  • Amazon Web Services — Bedrock — AI model inference. Australia (Sydney + Melbourne).
  • Auth0 (Okta) — user identity, login, password management. Australia.
  • Stripe — subscription billing and payment processing. United States.
  • Resend — transactional email delivery (all outbound email from Aicura, including welcome emails, briefings, identity-provider emails, and billing emails). AWS Tokyo (ap-northeast-1), Japan.
  • Cloudflare — DNS, content delivery, web application firewall, request proxy, and bot verification (Turnstile) on the maturity assessment form. Global edge network.
  • Cloudflare D1 — storage of website contact form submissions, briefing subscriptions and anonymous maturity assessment results. Global edge network.
  • Grafana Cloud — application logging and observability. Australia.

We may update this list. Material changes will be reflected here. A more detailed sub-processor description is available on our sub-processors page.

6.3 When the law requires it

We may disclose your information when we're required to by law, in response to a valid legal process, or to protect our rights or the safety of others.

6.4 In a business sale

If Aicura is sold or restructured, your information may be transferred to the new owner. We'll let you know if that happens.

7. Overseas disclosure

Some of our service providers are based outside Australia (Stripe in the United States, Resend in Japan, Cloudflare globally). When your information passes through them as part of providing the service, it may be processed in those locations.

The bulk of your data stays in Australia, including the documents you upload, the AI Register, risk assessments, generated policies, support tickets, audit logs and AI processing.

We choose service providers that meet recognised security and data protection standards. We can't guarantee they comply with Australian privacy law to the same extent that an Australian provider would, but we take reasonable steps to ensure they handle your information appropriately.

8. AI processing

The Aicura platform uses large language models from Anthropic, accessed through Amazon Bedrock in Australia, to perform document analysis and content generation.

When you upload a document or run a workflow that generates AI output, your content is sent to Bedrock for processing. Under our agreement with AWS:

  • your inputs and outputs are not used to train or improve the foundation models
  • the model providers (including Anthropic) cannot access your prompts or completions
  • your content is processed and stored at rest in the AWS region where the platform is deployed

We log AI calls (prompt content and model output) for up to 90 days for operational debugging and quality assurance. After 90 days, those logs are automatically deleted.

9. Storage and security

We host the Aicura platform in AWS, with all primary infrastructure in the Sydney region (ap-southeast-2) and backups in the Melbourne region (ap-southeast-4), inside a separate AWS account used only for backups.

Security controls include:

  • encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) on all external and internal connections
  • encryption at rest using customer-managed AWS KMS keys, scoped per environment and per data class, with a dedicated key for the immutable evidence store
  • multi-tenant data isolation enforced in two independent layers: at the database (PostgreSQL row-level security, which the tenant-facing role cannot bypass) and at the storage layer (per-request scoped credentials pinned to a single tenant's storage area)
  • an immutable evidence store and immutable authentication-audit storage, using AWS Object Lock so that, once written, those records cannot be altered or deleted for their retention period by anyone, including Aicura
  • private network architecture; no public database endpoints, and no direct or "break-glass" interactive access to the production database
  • restricted operator access via AWS Identity Center and federated single sign-on with multi-factor authentication; no standing administrative access
  • AWS-managed threat detection (GuardDuty), vulnerability scanning (Inspector), security configuration monitoring (Security Hub, Config), and centralised, validated activity logging (CloudTrail) written to a dedicated audit account the application accounts cannot modify
  • point-in-time recovery and daily snapshots for the database, replicated cross-region to Melbourne and held in a backup vault locked to a minimum retention period; object storage uses versioning, Object Lock, and cross-region replication to Melbourne

No system is 100% secure, and we don't promise that your information will never be subject to unauthorised access.

10. Retention

  • Your account and tenant data (register, documents, assessments, generated policies): for the duration of your subscription.
  • AI processing logs (prompts and model output): up to 90 days.
  • Audit logs (records of changes to your data): 7 years from the date of the change.
  • Billing records (Stripe IDs, contracts, invoices): 7 years from the end of our relationship.
  • Authentication logs (login events, password resets, identity-provider activity): 7 years (held in dedicated AWS S3 audit storage with Object Lock).
  • Website contact form submissions: 2 years.
  • Briefings subscription data: until you unsubscribe, plus 30 days.
  • Maturity assessment results (answers, scores, industry, size band, optional role, country; no name or email): indefinitely, because the averages shown to later respondents are calculated from them. An email address given to receive a copy of a result is used for that email and not retained.
  • Support correspondence: for the duration of your subscription, plus 12 months.

After your subscription ends, we keep your tenant data for 60 days to allow for export or reactivation, then delete it (other than the categories above that we retain for our own legal, tax, or audit purposes).

You can ask us to delete your tenant data sooner, as set out in section 12.

11. Cookies and tracking

The Aicura platform itself does not set tracking or analytics cookies. The web app uses browser local storage to hold authentication tokens and your interface preferences (light/dark theme, tour completion), but does not write its own cookies. Fonts and other static assets are served from Aicura's own domain; no third-party font services or asset CDNs are loaded.

The platform is served behind Cloudflare. Cloudflare may set technical cookies for bot protection, security challenges, and Cloudflare Access authentication. These cookies are necessary for the security and operation of the platform.

Our marketing website (aicura.com.au) uses local storage to remember your theme preference and, if you take the maturity assessment, your answers in progress and a link to your result, so you can leave and come back. It does not run third-party analytics, tracking pixels, or behavioural advertising tools. The assessment form uses Cloudflare Turnstile to tell people from bots, which may set a technical cookie for that purpose.

The identity provider (Auth0) sets cookies on its own domain during login. These are necessary for authentication and are governed by the identity provider's own privacy policy.

12. Your rights

12.1 Access

You can ask for a copy of the personal information we hold about you. Send your request to [email protected]. We aim to respond within 30 days. For tenant administrators, this includes the ability to request an export of your organisation's data on the platform.

12.2 Correction

If anything we hold is wrong or out of date, ask us to correct it. You can edit most information about yourself directly inside the platform. For anything you can't edit yourself, email [email protected].

12.3 Deletion

You can ask us to delete your personal information. Email [email protected]. We aim to action deletion requests within 30 days. We may retain limited information where the law requires us to (for example, billing records for tax purposes, as set out in section 10).

12.4 Complaints

If you think we've handled your information in a way that breaches the Privacy Act, contact us first at [email protected]. We'll investigate and respond within 30 days. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):

  • web: oaic.gov.au
  • phone: 1300 363 992
  • post: GPO Box 5288, Sydney NSW 2001

12.5 Notifiable Data Breaches

If a data breach occurs that meets the threshold for notification under the Privacy Act, we'll notify affected individuals and the OAIC in line with the Notifiable Data Breaches scheme.

13. Children

The Aicura platform is intended for use by organisations through their authorised employees and contractors. It is not intended for individuals under 18. We don't knowingly collect personal information from children under 18. If you believe we've collected information from a child, contact us and we'll delete it.

14. Changes to this Policy

We may update this Policy. The "Last updated" date at the top reflects the most recent change. If we make a change that materially affects how we handle personal information, we'll let existing customers know by email or through the platform.

15. Contact

Privacy contact: [email protected]

Aicura Pty Ltd.
ABN: 85 696 789 876
Melbourne, Victoria, Australia

Get started with Aicura.

Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.