Register of holdings
Privacy policy
Personal information is described here the way this company describes everything else in its care. Each holding is a numbered series, and each series carries the same five facts: what is in it, who has custody of it, on what terms it may be seen, when its clock started, and the date it is destroyed.
Effective 14 August 2026Register edition 1.0Privacy Act 1988 (Cth)Australian Privacy Principles 1 to 13
1How to read an entry in this register
ARCVAULT AI PTY LTD, ACN 696 486 987 and ABN 11 696 486 987, keeps six series of personal information. Each is entered below under the same headings, in the same order, so that a reader chasing one fact can find it in the same position every time rather than reading the whole document to be sure.
| Element | What it answers |
|---|---|
| Contents | The fields and material actually in the series, named rather than gestured at |
| Provenance | Where the material came into the company's hands, and at whose initiative |
| Custodian | Which of the two capacities applies: the series is the company's own, or it belongs to a depositor and merely sits here |
| Conditions of access | Who inside the company may open the series, and what would take it outside |
| Disposal | The event that starts the clock, the period, and what happens when the period runs out |
Custodian is the element that decides your rights
A series marked own holding exists because this company decided it should. It set the purpose, it can widen or narrow that purpose, and every right in the Privacy Act runs against it directly. Five of the six series are of that kind, and between them they amount to a mailbox, a ledger and a web server log.
A series marked held for a depositor is different in every respect that matters. The material was placed here by a client organisation under a written instruction, for that organisation's own retention obligation, and this company has no purpose of its own for a single field in it. Physical care sits here. Legal control does not.
The practical consequence is worth stating plainly, because it is the one people are surprised by. If somebody named inside a deposited personnel file writes here asking for that file to be altered or destroyed, this company cannot act on it. Doing so would destroy material that a client is obliged by law to retain, on the word of somebody the instruction does not come from. What happens instead is set out at requisition and amendment: the request is passed to the organisation identified in the accession entry, and the person who sent it is told that day which organisation now has it.
Five of the six series are the company's own holdings, and between them they govern every dealing anyone can have with this company through this website. Series 5 is the one that belongs to somebody else, and it is the entry to read if the question is what happens to material placed in this company's custody.
2The statute this register is kept under
The governing instrument is the Privacy Act 1988 (Cth), and within it the thirteen Australian Privacy Principles at Schedule 1. Where a numbered principle is cited below as APP 6 or APP 11, the reference is to that Schedule.
Why the document takes this form
APP 1 obliges an entity to manage personal information openly and transparently, to put in place the practices and systems that make the remaining principles achievable, and to publish a current policy. APP 1.4 then lists what that policy must cover: the kinds of information held, how and why it is gathered, how it may be used and passed on, how a person seeks access and correction, how a complaint is dealt with, and whether anything travels to recipients abroad and to which countries. A register with a fixed set of elements answers all of that once per series, in a fixed place, instead of leaving a reader to infer it from continuous prose.
The turnover threshold, and why it is not relied on
Section 6D of the Act lifts most enterprises turning over $3 million or less out of the Australian Privacy Principles altogether. This company sits under that figure, so a narrow reading would say the principles do not yet bind it as a matter of law.
The register is kept as though they do. Several of the carve-outs in section 6D would draw a business of this shape back inside the Act as it grows, among them any business that passes personal information about one individual to another party for a benefit or advantage. Beyond that, the threshold is a fact about revenue rather than a fact about the information, and a holding does not become less sensitive because the entity holding it is small. Requests and complaints are handled on the footing that every principle applies.
Other Australian instruments engaged
- Spam Act 2003 (Cth), governing commercial electronic messages, consent, sender identification and functional unsubscribe.
- Do Not Call Register Act 2006 (Cth), governing unsolicited telemarketing. This company does not telephone anyone for marketing purposes.
- Australian Consumer Law at Schedule 2 of the Competition and Consumer Act 2010 (Cth), whose guarantees survive anything written on this website.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at loss of custody.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which created a statutory cause of action for serious invasion of privacy, provided for a Children's Online Privacy Code, and required certain automated decision-making to be disclosed in a policy of this kind.
- Section 286 of the Corporations Act 2001 (Cth), which fixes the period on the financial series and cannot be shortened by agreement between this company and anybody else.
3Series 1 — Correspondence and enquiry files
APP 3 allows an organisation to gather only what its own functions genuinely require, by means that are both lawful and fair, and as a rule from nobody but the person the information describes. This series is the whole of what that produces here. There is no form anywhere on this website, no newsletter, no account to open and no field that asks for anything: the material in Series 1 is what a correspondent chose to type.
Withholding any of it costs nothing except precision. A message with no employer and no description of the problem still gets answered; the answer is simply pitched more generally. The one thing that cannot be withheld is a reachable address, since there is no second channel by which a reply could be sent.
Where a message concerns somebody who did not send it
Threads sometimes carry a colleague in copy, or are written on another person's behalf. That is collection from a third party, which APP 3.6 allows where collecting from the individual directly would be unreasonable or impracticable. The step taken in response is deliberately visible rather than administrative: replies go to everyone on the thread rather than privately, so that a person whose details have arrived here can see that they have arrived and object.
Sensitive information
Sensitive information as the Act defines it — health, racial or ethnic origin, political or religious conviction, sexual orientation, criminal record, biometric and genetic material — is not sought in this series, and no field anywhere in the company's own systems is designed to hold any of it. Where such material appears inside a client deposit it is governed by Series 5, not by this entry.
4Series 2 — Requisition and complaint files
This series exists because a right that leaves no trace cannot be shown to have been honoured. If an access request was answered, a correction made or an entry destroyed, the proof is the file, and the file has to outlast the thing it records. That is why a request to be forgotten cannot itself be forgotten, a point returned to at a request to destroy.
Identity checking here is kept to the minimum that the request requires. Where a correspondent writes from the address that generated the material in question, that address is ordinarily sufficient, and nothing further is asked for. Documentary identification is requested only when the material sought would cause real harm if handed to the wrong person, and anything supplied for that purpose is destroyed once the check is complete rather than filed.
Security reports are filed here too. Where somebody writes in describing a weakness in this website or in the company's mail handling, the report, the reproduction steps and the remedial record form a file on the same terms and the same seven-year sentence.
5Series 3 — Trade, supplier and payment files
Nothing in this series describes a visitor to this website. It describes people at organisations this company has traded with, and it exists because financial records have to be kept, written up and available for a period that section 286 of the Corporations Act 2001 (Cth) fixes rather than leaves to judgement.
The period is the reason a supplier contact cannot have an invoice erased on request. A request that reaches this series is answered by explaining which document is caught by the statutory period, and by destroying anything in the file that sits outside it — a covering exchange, a duplicate, a note that served its purpose years ago.
6Series 4 — Web service transaction logs
A request log is the unavoidable by-product of answering an HTTP request. It cannot be declined while still receiving a page, which is why the entry says so rather than presenting it as a choice. What can be declined is everything usually built on top of it, and this website builds none of it: no measurement script, no session recorder, no heat map, no visitor identification service, no advertising pixel and no error reporting service that would receive the state of your browser. The cookie notice records the position on stored state, which follows from the same design.
These pages are static files. There is no application server behind them, no database that could be queried about a reader, and no administrative console in which anybody's browsing could be looked up.
7Series 5 — Deposited holdings, held for a depositor
The design assumption behind this series is that the safest position for a custodian is not to be able to read what it holds. Contents are opaque here by intent: nothing about a deposit is opened to build a search index, produce statistics, improve a product or feed a model. A retrieval is an event with a name attached to it, not a routine operation.
Three commitments follow from the custodian element and apply from the first deposit accepted.
- Instruction only. Deposited material is used solely to do what the deposit instruction says, which is to hold it, verify that it is unaltered, migrate its format when a format is failing, and produce it on request.
- No secondary purpose. A depositor's material is never repurposed, and a change on that point would be a change to the deposit contract rather than a quiet revision of this page.
- Notice before a sub-custodian changes. Any new party capable of touching deposited material is notified to depositors ahead of the change, with the region named, and with time to object.
8Series 6 — Accession and disposal control records
This series contains very little personal information — the name and role of whoever authorised an instruction, and nothing about the people described inside a deposit — but it is entered here because it is the series that makes the others checkable. A control record that could be edited without trace would let a destruction be presented as though it had never happened, or a retrieval be presented as though it had.
Its sentence deliberately outlives its subject. Evidence that a record was disposed of correctly is worth nothing if it is destroyed at the same moment as the record, which is why the clock on Series 6 starts where the clock on Series 5 stops.
9Notice given when a file is opened
APP 5 requires an entity to take reasonable steps, at or before collection, to make an individual aware of who is collecting, why, what the consequence of not supplying it would be, who else might see it, where to find this policy, and whether anything is likely to go overseas.
For Series 1 the notice is this page, reachable from the footer of every page on this website, including the page carrying the address that a correspondent writes to. Where a first exchange leads somewhere that a general notice would not cover — material arriving that nobody asked for, a request that has to be routed to a depositor — the specific position is set out in the reply itself rather than left to a reader to find here.
For Series 5 the notice obligation belongs to the depositing organisation, because it is that organisation that holds the relationship with the people described in the deposit. This company is not in a position to notify individuals it has no way of contacting and whose existence it does not inspect the deposit to discover. The deposit contract makes the notice obligation the depositor's expressly, so that it cannot fall between the two of us.
10Dealing with the registrar unnamed
APP 2 lets a person deal with an organisation while giving no name at all, or under a name adopted for the purpose. The principle yields in two situations only: where anonymity would make the dealing impracticable, and where a law or court order obliges the organisation to know who it is dealing with.
Nothing about this website asks a reader to be anyone. The pages are static and can be read without identifying yourself in any way. Correspondence can be sent from an address that carries a working name rather than a legal one, and it will be answered on the same terms; the only requirement is that a reply can reach whoever asked.
The exception is narrow and it is about protecting the person asking. Where somebody requisitions material from Series 1 or Series 2 that would cause harm if it went to the wrong hands, enough has to be established to be confident the material is going back to the person it concerns. That is the point at which a pseudonym stops being workable, and it is the only such point in this register.
11Material that arrives unbidden
APP 4 deals with personal information an entity receives without having solicited it. The entity must decide whether it could lawfully have collected the material under APP 3. If it could not, and the material is neither a Commonwealth record nor caught by a legal obligation to retain it, the entity must destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
Two things actually arrive here. Recruitment approaches with a curriculum vitae attached, and files sent by a correspondent before anybody has asked what is in them. Both are handled the same way. The material is assessed against APP 3, and where it fails that test it is destroyed and the sender told that it was destroyed and why. It is not filed against a future opportunity, and it is not kept because it might be useful.
Anyone with a file to send should say so first rather than attaching it. A message describing the material draws an answer about where it should go and on what terms, and that costs one exchange. A file containing another organisation's personal information, sent to a company that has no instruction covering it, is a disclosure that neither party wanted and that has to be undone by destruction.
12What each series may be used for
APP 6 confines an entity to the primary purpose for which information was collected, permitting a secondary purpose only with consent, where a reasonable person would expect it and it is related to the primary purpose, or under one of the exceptions the Act sets out.
| Series | Primary purpose | Secondary purpose relied on |
|---|---|---|
| 1 — Correspondence | Answering the person who wrote, and keeping a record of what was said on both sides | None. A thread is not used to build a marketing list, and it is not read for anything other than answering it |
| 2 — Requisitions and complaints | Carrying out the request and demonstrating afterwards that it was carried out | Recognising a pattern across security reports, which is related to the primary purpose and would be expected |
| 3 — Trade and payment | Paying and being paid, and meeting the statutory record-keeping obligation | None beyond statutory accounting and tax work |
| 4 — Transaction logs | Serving the page and absorbing hostile traffic | None. Not analysed, not aggregated into audience figures, not retained beyond the provider's rotation |
| 5 — Deposited holdings | Whatever the deposit instruction specifies, which is custody, verification, migration and production | None available. A secondary purpose would require a fresh instruction from the depositor |
| 6 — Control records | Proving what was held, what was done to it and what became of it | None |
Two exceptions in the Act are worth naming rather than leaving as boilerplate. Where a use or disclosure is required or authorised by an Australian law or a court order, it will be made, and where it is lawful to say so the affected person will be told it happened. Where there is a serious threat to somebody's life, health or safety, judgement will be exercised in favour of the person at risk. Neither exception has been relied on, and if either ever is, the fact of it belongs in the transparency reporting described at amendment of this register.
13Sub-custodians, and where each one sits
The list below is complete for the series that exist today. A party capable of touching Series 5 is marked as a sub-custodian, which is what triggers the advance notice promised in that entry.
| Party | Which series | What they do with it | Where they sit |
|---|---|---|---|
| Cloudflare, Inc. | 4 | Serve these pages and absorb hostile traffic. Request data passes through the edge and expires there | Edge network including Australian points of presence; company incorporated in the United States |
| Google LLC | None | Serves the web fonts these pages are set in. Your browser fetches them directly, so your connection reaches Google without anything being forwarded from here | United States and global edge |
| The company's mail provider | 1, 2 | Carry, deliver and store correspondence | Australia and the United States |
| The company's accountant | 3 | Statutory accounts, business activity statements and tax | Australia |
| Storage and compute for the deposit service | 5, 6 | Hold deposits and their control records under contract, on documented instruction and for no purpose of their own | Named in this table, with the region stated, before a single deposit is accepted |
Parties that appear on no row
No analytics vendor, advertising network, data broker, customer data platform, marketing automation system, chat widget, session recorder, visitor identification service or artificial intelligence provider receives anything from any series in this register. For a company whose subject matter is other organisations' records, adding a party able to see deposited material would be a structural change to what the service is, and it would be announced as one.
If the company changes hands
On a sale of the business, own holdings may pass to a buyer with the rest of the company's assets. Series 5 and Series 6 pass subject to the deposit contract, which is not something to be manoeuvred around by structuring a transaction differently, and notice is given ahead of completion wherever the law permits it.
14Custody outside Australia
APP 8 governs disclosure to a recipient outside Australia, and section 16C is the provision that gives it teeth. If an overseas recipient does something that would have breached the Australian Privacy Principles had this company done it, the act is deemed to be this company's act and the liability lands here.
That deeming provision, rather than the list of exceptions, is what shapes the practice. Before anything crosses a border, reasonable steps are taken to bind the recipient to the Australian Privacy Principles, which in practice means the published data processing terms of each provider named in the sub-custodian table: process only on documented instruction, secure the material, assist with individual rights, and report a breach without delay.
The exception at APP 8.2(a) for recipients in countries with substantially similar protections is not relied on. Deciding whether a foreign regime is substantially similar is a legal judgement that would sit here and whose consequences would sit with the person whose information moved, and the accountability route is the more honest of the two.
The countries where personal information may be held or reached are the ones in the sub-custodian table. That table is the operative statement rather than an illustration, and a provider changing region is a change to it.
15Solicitation, and the Spam Act
APP 7 restricts the use of personal information for direct marketing, and the Spam Act 2003 (Cth) governs commercial electronic messages independently of it, requiring consent, honest sender identification and an unsubscribe facility that works.
There is no marketing list attached to this register. Nobody is added to one by writing in, no announcement is sent to correspondents, and there is no subscription anywhere on this website to be entered into inadvertently. A reply to a message goes to whoever sent it, and nothing else follows from having written.
If that ever changes, it changes by an explicit act on the part of the person joining, with a record of when and how consent was given, and with a working unsubscribe on every message. It will not change by a list being assembled from Series 1 and described as an existing relationship.
16Identifiers issued by government agencies
APP 9 sets two limits on identifiers that government agencies issue. An organisation may not press one into service as its own filing reference, and may use or pass on one it happens to hold only in the narrow circumstances the principle itemises.
No identifier of that kind is adopted for anything here. Files in Series 1 and Series 2 are located by the address that generated them, and control records in Series 6 are located by an accession number this company issues. A tax file number, Medicare number, driver licence number or passport number is not requested, not stored and has no field to sit in.
Identifiers of that kind can appear inside a deposit — a payroll export contains them by nature. Where they do, they are held under Series 5 as opaque content, on the depositor's instruction, and this company neither extracts them nor uses them to organise anything. Anyone who sends a government identifier here in ordinary correspondence, which happens occasionally by accident, is told, and it is removed from the file.
17Accuracy of the description
APP 10 imposes a quality duty pointing in two directions. Anything gathered must be right, up to date and whole. Anything then used or passed on must satisfy the same three tests and one more besides, since it also has to be pertinent to whatever is being done with it.
Most of the register is self-correcting, because nearly all of it is a verbatim record of what somebody wrote. A correspondence file does not become inaccurate when circumstances change; it remains an accurate record of an exchange on a date. What can go wrong is a contact detail carried forward into a later assumption, and the answer to that is not to carry any forward: a reply goes to the address a message arrived from.
Series 5 raises a different problem, and it is the one the business exists for. A deposited record is accurate as at deposit and cannot be silently corrected afterwards without destroying its value as evidence. Where a depositor tells this company that deposited material contains an error, the correction is recorded as an event in Series 6 alongside the original rather than written over it, so that both the record and its history remain legible. An archive that quietly improves its holdings is no longer holding what it was given.
18Security of custody
APP 11.1 calls for reasonable steps against two families of harm: misuse, interference and loss on one side; access, alteration or disclosure by somebody without authority on the other.
What is defended today
The surface is small enough to describe exactly, which is the only kind of description worth publishing. These pages are static files behind an edge network. Behind them sit one mailbox, one domain registration, one hosting account and the repositories the site is built from. Every one of those is reached through an account carrying multi-factor authentication, transport is encrypted on every connection, stored data is encrypted at rest by the underlying platform, and the number of people able to open the mailbox is small enough to name and is reviewed whenever somebody joins or leaves.
The most effective control in the list is the shape of the register itself. Series 1 to 4 are short because very little is collected, and material that was never gathered cannot be exposed by any failure of any of the controls above.
What custody of Series 5 requires in addition
Holding another organisation's records for fifteen years asks more of a custodian than answering correspondence does. The controls below are the terms a deposit is held under, and each one is written into the deposit agreement so that a depositor can verify it rather than take it on trust.
- Deposits encrypted under keys the depositor is able to hold, so that custody does not imply readability.
- An append-only custody log, so that no destruction and no retrieval can be made to look as though it never occurred.
- Separation between the credential that can produce a deposit and the credential that can destroy one, because those two powers should never sit in a single set of hands.
- Destruction requiring a second authorised person, on the same reasoning.
- Fixity verification on a fixed cycle across the whole holding, with a mismatch raised as an incident rather than silently corrected.
The failure this design is aimed at
Most organisations plan against a breach that becomes public inside a week. The failure that matters to an archive is slower and quieter: material that degrades, or is destroyed early, or is altered, and where nobody discovers it for a decade because nobody looked. Fixity verification and the append-only log exist to make that class of failure noisy, which is the only way it gets caught in time to matter.
19The disposal schedule
APP 11.2 obliges an entity to destroy personal information, or strip it of its identifying character, once every purpose that would have permitted its use or disclosure has fallen away. Two things are excepted: a Commonwealth record, and material some law compels the entity to keep. For a company built around long retention this principle deserves the longest section in the register, because retention is the product and an unbounded retention period is the failure mode the whole design is arranged against.
Every series above carries a sentence. A sentence has three parts: the event that starts the clock, the period the clock runs for, and what happens when it stops. All three are fixed when the series is created, not decided later when somebody notices the material is still there.
| Series | Event that starts the clock | Period | At expiry | Why that period |
|---|---|---|---|---|
| 1 — Correspondence, no live matter | The last message in the thread | 24 months | Thread destroyed | Long enough that somebody returning to a question a year later still has context; short enough that a mailbox does not silently become an archive of everyone who ever wrote |
| 1 — Correspondence about a prospective engagement | The close of the discussion, whether or not it led anywhere | 7 years | Thread destroyed | Precontractual dealings bear on a later contractual dispute, and the limitation period for a contract claim in New South Wales is six years, with a margin |
| 2 — Requisitions, complaints, security reports | The date the written outcome issues | 7 years | File destroyed | The only evidence that a right was honoured is the file recording it, and it has to survive any later question about whether it was |
| 3 — Trade, supplier and payment | The close of the financial year the transaction falls in | 7 years | File destroyed | Section 286 of the Corporations Act 2001 (Cth), and Australian Taxation Office record-keeping requirements |
| 4 — Transaction logs | The request itself | Days, on the edge provider's rotation | Overwritten in place | Operational only. It is never copied anywhere that would give it a longer life |
| 5 — Deposited holdings | The event named in the deposit instruction, which is frequently one that has not happened yet | Exactly what the depositor instructs | Destroyed and certified to the depositor | The depositor's own retention obligation is the only reason the material is here at all |
| 6 — Accession and disposal control records | Destruction of the deposit the record describes | 7 years after that | Record destroyed | Proof of proper disposal is worthless if it dies with the thing it proves something about |
A schedule that runs by itself
The date in the schedule is the whole of the control, so it has to act without anyone remembering it. A due disposal runs on its date rather than waiting to be raised, and for Series 5 the depositor is told either way — that material was destroyed on schedule, or that it was held past its date and on what authority. Retention that continues because nobody reviewed it is the thing this arrangement is designed to make impossible.
Copies that outlive the original
Destroying something in a live system does not reach the backup taken the night before. Backups of own holdings run on a rotation measured in weeks, are held encrypted, and are restored only to recover from a failure — never consulted to look something up, and never used to reconstruct material that has been destroyed on schedule. A destruction becomes complete when the last rotation carrying the material has aged out, which is a period of weeks after the destruction itself rather than an instant.
20Sentencing, freezes and certificates of destruction
Sentencing is the act of deciding, at the moment material comes into custody, how long it lives and what happens at the end. It is done at accession rather than at disposal, and that ordering is the point: a decision taken while the material is being described, by people who know what it is, is a better decision than one taken years later by whoever finds it.
What a sentence records
- The trigger event, named precisely enough that an outsider could tell when it happened. "Seven years after the last occasion of service" is a trigger. "Seven years" on its own is not, because it does not say from when.
- The period, and the authority it rests on — a statute, a limitation period, a depositor's instruction, or a business need that is stated rather than assumed.
- The action at expiry: destruction, or transfer back to the depositor, and by what method.
- The person or role empowered to alter the sentence, which for Series 5 is only ever the authorised person named by the depositor.
Disposal freeze
A sentence can be suspended, and there are circumstances in which suspending it is obligatory. Where material is relevant to a live dispute, an investigation, a regulator's enquiry or a court order, a freeze is placed on the series and the schedule stops running until the freeze is lifted. Destroying material because its date arrived, while knowing it is wanted in a proceeding, is not compliance with a schedule; it is spoliation dressed as routine.
A freeze is written into Series 6 with its reason, its date and who imposed it, and lifting one is recorded the same way. A freeze that nobody wrote down would be indistinguishable from material that was simply never disposed of.
Certificate of destruction
Destruction under Series 5 produces a document, issued to the depositor, stating what was destroyed, the date, the method, the instruction it was carried out under and the person who authorised it. That certificate is filed in Series 6 and outlives the material by seven years. For own holdings the equivalent is lighter but exists: a destruction under Series 1 or Series 2 leaves a dated line saying what was destroyed and why, without reproducing the content that was the point of destroying.
Instructions to destroy are accepted only from the person the deposit instruction names. An archive that can be argued into destroying something by a persuasive message has no meaningful custody, and the second-person authorisation described under security of custody exists precisely because destruction is the one operation that cannot be undone by restoring from anywhere.
21A request to destroy, against a schedule that says keep
This company promises that a record made in 2026 will still open in 2040, and the Privacy Act gives individuals a route to having personal information destroyed when it is no longer needed. Those two things pull in opposite directions, and a policy that did not say where they meet would be avoiding the only hard question on the page.
They meet at the custodian element, and the reconciliation is not a rhetorical one. The fifteen-year promise attaches to Series 5, which is not this company's information to erase; it is a client's record held to that client's legal obligation, and APP 11.2 itself carves out information that a law requires to be retained. The series that do belong to this company, where a right of erasure runs directly, carry the shortest sentences in the register.
A request to delete your data therefore lands differently depending on which series is holding it, and the table below is the whole of the answer rather than a summary of one.
| Series | Outcome of a request | What survives it |
|---|---|---|
| 1 — Correspondence | Honoured. The thread is destroyed within thirty days and the outcome confirmed in writing | Nothing of the content. Backup rotations age out over the following weeks |
| 2 — Requisitions and complaints | The substance is destroyed; the fact of the request is not | A dated line recording that a request was made and what was done, which is the evidence of compliance |
| 3 — Trade and payment | Partly honoured. Anything outside the statutory period goes | The invoice and payment record, until section 286 releases it |
| 4 — Transaction logs | Nothing to action. It has already expired on the provider's rotation | Nothing |
| 5 — Deposited holdings | Passed to the depositor, who is the only party able to decide it | The deposit, unless and until that organisation instructs otherwise |
| 6 — Control records | Not available. The series is the audit trail for everything else | The control record, on its own seven-year sentence |
Material under a live dispute
Where a freeze is in force, a request to destroy is answered with the reason rather than with silence or delay. The person is told that the material is held under a disposal freeze, told in general terms why, and told that the schedule resumes when the freeze lifts. Going quiet on a request in order to run out a clock is worse than refusing it, because it leaves the person with nothing to escalate.
The residue, stated plainly
The honest limit of this section is that a person named inside a client's deposited holding cannot have that holding destroyed by writing to the company that stores it. The request travels to the depositor, quickly and with an explanation, and the depositor decides. No arrangement of words on this page changes who holds that power, and it would be misleading to suggest otherwise in order to make the section read more generously.
22Requisition and amendment of an entry
APP 12 gives an individual a right of access to the personal information an entity holds about them. APP 13 gives a right to have that information corrected where it is inaccurate, out of date, incomplete, irrelevant or misleading, and requires that where corrected information has already been disclosed elsewhere, the recipient be told on request.
Requisition for access
Write to ops@arcvaultai.co.im, saying what you are looking for. The request is entered in Series 2 on the day it arrives and answered inside thirty days, which is well within the reasonable period APP 12 requires. What comes back is the material itself where it can sensibly be produced — usually a mail thread — together with an entry-by-entry account of which series hold anything about you and under what sentence each is held.
No charge is made for a requisition or for producing the material. APP 12.8 permits a charge that is not excessive; there is nothing here whose production would justify one.
Access can be refused in the circumstances APP 12.3 sets out, of which two are realistic at this scale: material whose release would unreasonably affect another person's privacy, most often a third party quoted in the same thread, and material subject to legal professional privilege in a live dispute. A refusal is given in writing with its reason, with as much of the material released as can be separated from the part that cannot, and with the complaint route set out in the same reply.
Amendment
An amendment request should say which entry is wrong and what the corrected version is. Where the point is agreed, the entry is amended within thirty days and confirmation sent. Where it is not, APP 13.4 gives a right that is easy to overlook: a statement can be attached to the record saying that the information is disputed and why, and that statement travels with the entry from then on, so that anyone reading it later sees the disagreement rather than only one side of it.
For anything held under Series 5, an amendment request is routed to the depositor. This company will not alter the substance of a record it holds for somebody else, since a holding that can be edited on external request is not evidence of anything.
23Series touching children and young people
Nothing on this website is directed at children, and the retention service is for organisations rather than for individuals. No series is designed to receive a child's information, and no age is asked for anywhere.
Two situations still have to be dealt with, because saying children are out of scope does not make them so.
A child writes in. If it becomes apparent that a correspondent is under 15, the exchange is answered plainly and the file is closed and destroyed as soon as the question has been dealt with, rather than running the ordinary 24-month sentence. Where a message from a child concerns a matter that requires an adult on the other side, the reply says so.
A deposit contains children's records. This is not an edge case; it is a large part of what long retention is for. A New South Wales health service keeps a child patient's record until that child turns 25, and school, care and juvenile case records carry comparably long periods for the same reason: the person the record concerns may need it long after the organisation that made it has changed systems twice. Those records sit in Series 5 as opaque content, on the depositor's instruction and sentence. They are not opened, not indexed and not used for anything, and the notice and consent obligations towards the children concerned remain with the depositing organisation, which is the party with the relationship.
The Children's Online Privacy Code provided for by the Privacy and Other Legislation Amendment Act 2024 (Cth) is being developed by the Commissioner. If any part of it comes to bear on this company, this entry is where the change will appear, with its date, rather than being folded silently into a later edition.
24Decisions reached without a person
The 2024 amendments to the Privacy Act require a policy to disclose where automated processes are used in decisions that could reasonably be expected to significantly affect an individual's rights or interests.
No decision of that kind is automated here. Nobody is scored, ranked, profiled or assessed by any process in this register, and there is no system anywhere in the company capable of accepting or rejecting a person.
Automation exists, but it acts on material rather than on people. Fixity verification runs on a cycle and compares a digest against the one recorded at deposit. Disposal dates fall due on their own, without waiting for anyone to notice. Migration jobs convert a format that is failing into one that is not. The distinction that matters is what happens at the end of each: a mismatch or a due destruction raises an event for a person to act on, and the irreversible operations — destroying, releasing, migrating over a prior version — are authorised by a human being every time.
If automated decision-making about individuals is ever introduced, this entry will name the decision, the inputs it uses and the route to having it reviewed by a person, before it is switched on rather than after.
25Loss of custody, and the notification scheme
The notification scheme lives in Part IIIC of the Privacy Act, and it turns on a threshold rather than on the bare fact that something went wrong. An eligible data breach has two limbs, and both have to be satisfied. Personal information must have been reached or given out by somebody with no authority to do either, or else lost. And the probable consequence, judged the way a reasonable person would judge it, must be serious harm to somebody the information describes. Once both limbs are made out, the Commissioner and the people at risk must be told as soon as practicable.
What happens, in order
- Containment first. Stop the exposure, revoke what needs revoking, and preserve the evidence of what happened before touching anything else. A remediation that destroys the log of the incident makes the assessment impossible.
- Assessment. Where it is unclear whether the threshold is met, section 26WH requires a reasonable and expeditious assessment, completed within thirty days of becoming aware of the grounds for suspicion. That assessment is a floor, not a target.
- Notification. Where the threshold is met, a statement goes to the Commissioner and to the individuals at risk, describing the breach, the kinds of information involved and the steps they should take. Where individuals cannot be contacted directly, a notice is published and the Commissioner told.
- The file. The incident, its assessment and its outcome are recorded in Series 2 on a seven-year sentence, including incidents assessed as not notifiable, with the reasoning that led there.
Where a breach touches a deposit
An incident affecting Series 5 has a different shape, because the people at risk are the depositor's people and the depositor is the entity with the obligation towards them. The depositor is told immediately — before any assessment is finished, and without waiting to establish the full extent — because it cannot discharge its own obligation on information it does not have. The deposit contract makes that notice a term rather than a courtesy, and this company supports the depositor's assessment and notification rather than substituting its own judgement for theirs.
A suspected incident can be reported to ops@arcvaultai.co.im with Security in the subject line. Reports made in good faith are welcome, will not be treated as hostile, and will not be met with a demand for confidentiality before anyone is willing to read them.
26Serious invasion of privacy
The Privacy and Other Legislation Amendment Act 2024 (Cth) created a statutory cause of action for serious invasion of privacy, which came into operation on 10 June 2025. It covers intrusion upon seclusion and misuse of information, where a person had a reasonable expectation of privacy, where the invasion was intentional or reckless, and where it was serious. It provides defences and a public interest balancing exercise, and it allows damages including for emotional distress.
It is mentioned here because it sits outside everything else on this page. It is a right of action in a court, brought by the person affected, and it does not depend on the Commissioner, on this policy, or on whether the small business threshold takes this company inside or outside the Australian Privacy Principles. It is not something an entity can contract out of, and nothing in the terms of use attempts to.
The practical effect on the register is that the sentence structure and the closed condition of access on Series 5 are not only compliance mechanics. Material held with no purpose of one's own, opened only on instruction and destroyed on its date, is material that is difficult to misuse by accident.
27State stored in your browser
Stored browser state is dealt with in full in the cookie notice, which is written as a nil return with the working shown. In summary: reading these pages leaves no identifier on your machine that this company placed there or can read, and there is nothing to consent to, dismiss or configure.
The one outbound connection worth knowing about is the typeface request your browser makes to Google's font service while rendering these pages. That request is made by your browser directly, so your network address and browser characteristics reach Google in the ordinary way an HTTP request does, without anything being sent on from here. The cookie notice explains what that means and how to stop it if you would rather.
28Complaint, and the Commissioner
A complaint about the handling of personal information should go to ops@arcvaultai.co.im. It opens a file in Series 2 on the day it lands, and the written outcome issues within thirty days. That outcome says what was found, what was done about it and what will change, and where the finding is that nothing went wrong it says that too, with the reasoning, rather than closing the file quietly.
An unsatisfactory answer, or no answer, can be taken to the Office of the Australian Information Commissioner, which is the independent regulator for the Privacy Act.
The Commissioner's office generally asks that an organisation be given the opportunity to answer a complaint before a file is opened, and allowed a reasonable interval to do so. That is why the route above exists and why the thirty-day commitment is made. It is a sequencing preference on the regulator's part, not a permission this company grants, and nobody needs agreement from here before approaching the Commissioner.
29Readers outside Australia
This register is kept under Australian law by an Australian company, and the Australian Privacy Principles are what it is measured against. Readers elsewhere are welcome and correspondence from anywhere is answered on the same terms.
Where a European or United Kingdom data protection regime applies to a particular exchange, the practical rights it confers are already available here in substance: access, correction, destruction, an explanation of purposes and recipients, and an independent complaint route. What differs is the vocabulary and the supervisory authority, not the answer somebody gets by writing in.
The retention question that visitors from those regimes ask most often is the one about storage limitation, and this register answers it in the same place for everybody: a named trigger event, a stated period, and a stated action at expiry, for every series, in the disposal schedule.
30Amendment of this register
Register editions are numbered and dated, and the current edition is shown at the head of this page. An amendment that changes what is held, who can reach it, where it goes or how long it survives is a substantive amendment, and it appears with its own date rather than being merged into an unmarked revision.
Where a substantive amendment affects Series 5, depositors are told directly and in advance, because the sub-custodian notice and the sentence attached to a deposit are terms of the deposit contract and not merely statements on a website.
A superseded edition is kept. Anyone who wants to know what this page said on a given date can ask for the edition that was current then, which for a company arguing that records should outlive the systems that produced them is the least it can do with its own.
31The registrar
Everything in this register is administered from one address, read by the people who keep it.
| Matter | Subject line | Outcome |
|---|---|---|
| Access to what is held about you (APP 12) | Privacy request | Within thirty days |
| Amendment of something inaccurate (APP 13) | Privacy request | Within thirty days |
| Destruction of what is held about you | Delete my data | Within thirty days |
| Complaint about the handling of personal information | Privacy complaint | Written outcome within thirty days |
| Suspected security incident | Security | The day it is read, or the following working day |
| A question about this register | Anything intelligible | Within a week |
Anyone preferring not to raise a matter here at all can go directly to the Office of the Australian Information Commissioner, whose details are at complaint, and the Commissioner.