Draft for review. This document is pending legal review; bracketed placeholders will be completed before it takes effect.

Privacy Policy

Red Pulse Tech ("Red Pulse", "we", "us", "our") ABN [ABN] · [Registered address, Sydney NSW] Effective date: [DATE] · Version 1.0 (draft)

Red Pulse provides an Essential Eight compliance scanning and security-posture platform for Australian businesses, comprising an on-client scanning agent and a cloud dashboard. We take privacy seriously and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Scope

This policy covers personal information we collect through our website, the Red Pulse cloud dashboard, and the Red Pulse agent. It explains what we collect, why, who we share it with, where it is stored, and your rights. It does not cover third-party websites we may link to.

2. What we collect

Account and contact information — name, business email, company name, and messages you send us when you create an account, request access (magic-link sign-in), or contact support.

Security-posture evidence (collected by the agent). The Red Pulse agent runs inside your own environment and collects, on a read-only basis, configuration and security-state evidence used to assess Essential Eight maturity. This typically includes: device and operating-system configuration; patch and update status; multi-factor authentication and identity configuration (e.g. from Microsoft Entra ID and Active Directory); application and macro settings; backup and logging configuration; third-party application authorisations (OAuth grants) discovered in Microsoft and Google Workspace; and administrator account details. This evidence can include limited personal information such as user account names, email addresses, sign-in/MFA status and administrator identities.

The agent is designed to collect configuration and security metadata, not the contents of your files, emails, or documents. You control where the agent is deployed and what it is configured to read.

Usage and technical data — sign-in sessions, dashboard activity, IP address and approximate location of requests (used for security and abuse prevention), and product telemetry.

Assistant interactions — questions you ask the in-product assistant, and the posture snapshot used to generate an AI executive summary (see §4 and §6).

3. How we collect it

We collect information directly from you (account/contact), automatically from your use of the dashboard (usage/technical), and via the agent you deploy in your environment (posture evidence), which transmits it to our cloud over an authenticated, encrypted connection using your licence key.

4. Why we use it

We do not sell your personal information, and we do not use your security-posture data to train AI models.

5. Disclosure

We disclose personal information only as needed to run the service: - Service providers (sub-processors) listed in §6. - Professional advisers, assessors or insurers — only where you direct us to (e.g. when you export an evidence pack to share). - Legal/authority — where required by law. - Business transfer — in connection with a sale or restructure, subject to this policy.

6. Sub-processors and where data is stored

We host the platform on Microsoft Azure in Australian regions (Australia East / Australia Southeast), with geo-redundant backups. We rely on the following sub-processors:

Provider Purpose Location
Microsoft Azure Hosting, storage, backups Australia
Anthropic AI assistant + AI executive summary (processes a posture snapshot when you use those features) United States
[Email provider, e.g. Resend] Transactional email (sign-in links, notices) [location]
[CDN/DNS, e.g. Cloudflare] DNS, content delivery, security Global

We keep this list current and require sub-processors to protect information consistent with the APPs.

7. Security

We protect information with encryption in transit, tenant isolation (your data is segregated from other customers'), secret management for credentials, access controls, session expiry, and read-only collection in your environment. No method is perfectly secure, but we work to protect your information and to meet our obligations under the Notifiable Data Breaches (NDB) scheme — if an eligible data breach occurs, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required.

8. Overseas disclosure (APP 8)

Some features disclose limited data overseas. In particular, when you use the AI assistant or AI executive summary, a compact posture snapshot and your message are sent to Anthropic in the United States for processing and returned as a summary. By using those features you consent to this overseas disclosure. Core posture data at rest remains in Australia. [Confirm with counsel whether additional consent mechanics or a feature toggle are required.]

9. Retention

We retain account and posture data for the life of your subscription and for [retention period] afterwards, unless a longer period is required by law, then securely delete or de-identify it. You can request deletion (see §10).

10. Your rights

Under the APPs you may request access to, or correction of, the personal information we hold about you. Contact us at [privacy@redpulse.net]. We will respond within a reasonable period and may need to verify your identity.

11. Cookies

We use a small number of strictly-necessary and preference cookies, and no advertising or cross-site tracking cookies. See our Cookies Policy for details.

12. Changes

We may update this policy; material changes will be notified via the dashboard or email, and the effective date above will change.

13. Contact and complaints

Privacy enquiries and complaints: [privacy@redpulse.net] · [postal address]. If you are not satisfied with our response, you may contact the OAIC (oaic.gov.au).