Privacy

Privacy Policy

What Auregis 2 Comply collects, why we hold it, where it is processed and what you can ask us to do about it. We describe only what our platform actually does today.

About this policy

Auregis 2 Comply (ABN 79 218 812 511) develops and operates Auregis 2 Comply (A2C), a regulatory compliance, governance and assurance platform for regulated industries. This policy explains how we handle personal information in our own business, marketing and platform operations.

Where we hold compliance records on behalf of a customer organisation, that organisation decides why the information is processed and we process it to provide the platform under our agreement with them. That organisation is the first point of contact for requests about those records.

Information we collect

Business contact information you give us: name, work email address, organisation, and optionally role, country, industry, approximate organisation size, enquiry type, your primary compliance challenge and any message you write.

Account and access information for authorised platform users: identity, role, permissions and authentication and security events.

Customer-entered compliance records, which may identify inspectors, contractors, responsible persons, scheme contacts or other individuals.

Evidence and documents you upload — certificates, inspection reports and related records — where these contain personal information.

Technical and usage information needed to operate, secure and diagnose the service, and anonymous website analytics as described below.

Demo and pilot enquiries

We use enquiry details only to respond to you and to arrange and follow up a demonstration or pilot discussion. Our lawful basis is our legitimate interest in responding to a business enquiry you initiated.

Submitting an enquiry records a request for our team to review. It does not create an account, a membership or any access to the platform. Access is granted only by invitation of a customer organisation after a separate, explicit approval step.

Account and platform information

Platform accounts are created by invitation of a customer organisation. There is no public self-service signup.

Each organisation's data is separated from every other organisation by access rules enforced in the database, not by application code alone. Access within an organisation is controlled by role and permission.

Evidence and document processing

Uploaded evidence is held in private storage that is not publicly addressable, and is retrievable only through the platform by users with the necessary permission in the owning organisation.

Evidence is retained as part of the compliance record so that the basis of a compliance decision can be shown later.

AI-assisted processing

AI is used for two defined functions: assisted extraction of fields from an uploaded document, and a read-only compliance assistant that answers questions over the signed-in user's own organisation records. AI features are off by default and can be enabled or disabled for an organisation.

When AI-assisted extraction is used, the submitted document is transmitted to our AI processing provider for analysis. Extraction proposes values only: it cannot approve evidence or determine compliance, and a person must verify and approve the evidence before any compliance status changes.

Requirement applicability, rules evaluation, due dates, scheduling, workflow states and compliance roll-ups are deterministic and are not produced by an AI model. Each AI interaction is recorded against the organisation, user, document and time.

We are still verifying our AI provider's retention period, processing location and treatment of submitted content for model training. Until those arrangements are confirmed contractually we make no claim about them in this policy.

Website analytics

Website analytics are deliberately minimal and first-party: no cookies on the public website, no advertising or tracking pixels, no session recording, no cross-site tracking, no profiling and no third-party analytics service.

We record the page path, a random identifier that exists only for the current browser tab and disappears when the tab closes, a coarse device class (desktop, tablet or mobile) and the host name of the site that referred you — never the full referring address.

Nothing you type into a form is ever sent to analytics. Names, email addresses and free-text answers are excluded by design, and short descriptive labels are the only additional values recorded.

The only cookie in the product is an interface preference that remembers whether the navigation sidebar is open, and it exists only after you sign in to the application, alongside the strictly necessary sign-in token held in your browser's local storage.

Service providers

We use service providers to host the application and database, store evidence files, deliver the application at the network edge, dispatch email and provide AI processing. They process data on our instructions and under contract.

We do not sell, rent or trade personal information, and we do not disclose customer platform data for advertising. A register of material service providers and their processing locations is available under customer and procurement due diligence.

Data location and international processing

Customer platform data, including evidence files, is stored at rest in a managed database and private object storage located in Australia (Sydney). There is no customer-selectable hosting region today.

Some processing occurs outside Australia: the application is delivered from a globally distributed edge platform, AI-assisted extraction transmits the submitted document to our AI processing provider, and transactional email is dispatched from notify.auregis2comply.com through a delivery provider.

Encryption in transit and at rest is provided by our hosting, database and storage providers. We do not represent that data remains within Australia at all times.

Retention

We keep information only for as long as it is needed for the service, security, our contractual commitments, regulatory evidence and applicable legal obligations. Enquiry records are retained for up to 24 months from your last contact with us unless a commercial relationship follows.

Each customer organisation has a retention setting, which defaults to seven years. It records the organisation's retention position; it is not an automatic purge.

Deletion

Deletion is performed as a governed, audited action rather than silently. Certain audit, evidence-review, inspection and regulatory-release records are append-only by design so that compliance lineage remains provable: they are corrected by supersession, with the earlier record preserved and visible.

Deletion from the active service does not immediately remove data from protected backup copies, which age out on our providers' cycles.

Your rights

You can ask for a copy of the personal information we hold about you, ask us to correct or delete it, or object to our use of it, subject to applicable law. Where the information is controlled by a customer organisation we will refer the request to, or assist, that organisation.

If you are not satisfied with our response you may escalate to the Office of the Australian Information Commissioner or, where applicable, the UK Information Commissioner's Office.

Changes to this policy

We may update this policy when laws, products, data flows, AI features, hosting or service providers materially change. The version and review date below indicate the current published state.

Contact

For any privacy question, or to exercise the rights above: Contact us through the enquiry form. We will respond within one month.

How we protect this information is described on our Trust & Security page.

Version
1.3
Last reviewed
22 August 2026
Next review
At least annually, and on any material legal, product, data-flow, AI, hosting or security change