Data handling
What we collect, what we don't, why we don't train models on customer content, data residency in Australia, retention and deletion.
What we collect
- Your account information, meaning name, work email, organisation name and type, collected when you sign up.
- Documents you upload, meaning privacy policies, governance policies and any other materials you explicitly add to the platform.
- Your AI Register data, the structured metadata you enter about AI systems.
- Workflow data, meaning risk assessments, policy generations, scan results, recommendations and the artefacts the product produces for you.
- Discovery signals from the sources you connect, where you enable discovery. Aicura reads from the identity, device, cloud, ITSM, code hosting, finance and workspace systems you choose to connect, and correlates what they report into suggestions for your register. Those signals can name your own staff, for example a sign-on to an AI service or an application installed on a managed device, so they can contain personal information about your people. Where you connect a code hosting source, Aicura lists your repositories and reads dependency and configuration files to identify the AI SDKs and services in use. It records the matched names and the files they were found in. The file contents themselves are never captured, so no copy of your source code is retained, and the connector collects no commit or contributor information. Its repository access is read-only and you can install it on selected repositories only. You control which sources are connected and you can disconnect any of them.
- Enforcement and monitoring results, where you run them. The gateway, scanners and drift monitoring run in your environment and report through a Hub you run, which connects outbound to Aicura. Aicura holds the results and the governance record, not the underlying AI traffic.
- Support tickets and correspondence, anything you send us through support.
- Basic usage logs, enough to debug issues and understand which features are being used, no more.
What we don't collect
- Your customers' personal information, except incidentally in documents you upload.
- Behavioural tracking of any kind. Aicura never tracks site visitors or users, and discovery is not an exception. Discovery reads the inventory and access records of sources you deliberately connect, to find AI your organisation is running. It does not follow individuals or build profiles of them.
- Your AI traffic. Prompts and responses passing through your own gateway stay in your environment.
- Data from sources you haven't asked us to process.
- Anything used for advertising or cross-customer profiling.
- Payment card details, which go directly to Stripe.
We don't train models on customer content
This is unambiguous. The LLMs Aicura uses to generate assessments, draft statements and policy content are accessed via AWS Bedrock under enterprise terms that exclude your inputs and outputs from training of foundation models. Your privacy policy, your AI Register and your generated policies are never used to train a model that other tenants benefit from. This is both a technical commitment and a contractual one.
Data residency
Customer document content, the AI Register, generated outputs, support tickets, audit logs and AI inference all stay in Australia. Primary infrastructure is in AWS ap-southeast-2 (Sydney) and backups are in AWS ap-southeast-4 (Melbourne).
There are two narrow exceptions where transactional metadata leaves Australia, neither of which involves your document content.
- Stripe processes billing data in the United States.
- Resend sends transactional and briefing emails from AWS Tokyo (ap-northeast-1), Resend's closest region to Australia at the time of writing. Email content is the recipient address and the email itself.
Both are listed on the sub-processors page with full detail.
Retention and deletion
- Tenant data, meaning register, documents, assessments and generated policies. Duration of your subscription.
- Tenant data after subscription cancellation. 60 days, then deleted on request or at the end of that window.
- LLM call logs (prompts and model output). Up to 90 days, then automatically deleted.
- Change log (record of writes to your data). 7 years.
- Authentication audit logs. 7 years, held under AWS Object Lock and immutable for the retention period.
- Billing records. 7 years from end of relationship.
- Website contact form submissions. 2 years.
- Briefings subscription. Until you unsubscribe, plus 30 days.
You can ask us to delete your data sooner. Email [email protected] and we'll action deletion within 30 days. Specifics are also in the privacy policy.
Cookies and tracking
The Aicura platform doesn't set its own tracking or analytics cookies. It uses local storage in your browser to hold authentication tokens and interface preferences (theme, tour completion). Cloudflare may set technical cookies for security challenges and bot mitigation. The marketing site (aicura.com.au) doesn't run analytics, tracking pixels or behavioural advertising tools.
Your rights under Australian privacy law
As an Australian APP entity, Aicura complies with the Australian Privacy Principles. You have the right to access the personal information we hold about you, correct it if it's wrong and complain to the OAIC if you believe we've mishandled it. We take those rights seriously. We're in the business of helping our customers meet theirs, so meeting our own is table stakes.
Get started with Aicura.
Sign up and start the work. From your first session, you can catalogue your AI systems, run your privacy policy through Aicura's guidance and put your first risk assessments in place.