Skip to main content

Privacy

Privacy policy

This company would hold other organisations' records for fifteen years, so the policy is built around the difference between information we decide about and information we would merely hold. Nothing has been deposited yet.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)Australian Privacy Principles 1 to 13

1Two capacities, and which one applies to you

ARCVAULT AI PTY LTD (ACN 696 486 987, ABN 11 696 486 987) would handle personal information in two quite different capacities, and almost every question about your rights depends on which one applies to you. A supplier whose business is holding other organisations' records for fifteen years and does not draw that line clearly has written a policy about a different company.

The two capacities, and who decides what happens to the information
CapacityWhose informationWho decidesWhere a request goes
ControllerOur own handling. People who write to us, prospective customer contacts, suppliers, anyone reading this websiteUsDirectly to us
ProcessorPersonal information inside a record deposited for retention by a customer organisation, about that organisation's own employees, clients, patients or membersThe depositing organisation, not usTo that organisation. We route it if you write to us by mistake

Why we could not act on a deposited person's request directly

Where we hold a record as processor, we hold it on a customer's documented instructions and for that customer's retention obligation. We have no purpose of our own for it. If somebody named inside a deposited payroll export asked us to delete their record and we did it, we would have destroyed material the customer is required by law to keep, acted against the instruction we were given, and made the customer's compliance position worse without their knowledge. A supplier prepared to do that is a supplier nobody should deposit with.

What we would do instead is route the request to the depositing organisation within 5 business days, tell you that we have done it and who it went to, and act on that organisation's instruction when it arrives. We will not ignore you and we will not pretend to a power we do not have.

The operative half, today

Nothing has been released and no organisation has deposited anything. There is no record belonging to anybody else in our possession, and therefore no processor activity at all at the date at the top of this page. The controller half of this policy is live now. The processor half describes how it is being designed to work, and it is published early so that it can be argued with before it matters.

2The law this policy answers to

The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.

Australian Privacy Principle 1, and why this document exists

APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.

The small business threshold, and why it does not get us out of this

Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. ARCVAULT AI PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.

We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.

If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.

Other Australian law that applies

  • Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
  • Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
  • Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
  • Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
  • Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.

3What we hold as controller

Australian Privacy Principle 3 governs collection. It permits an organisation to collect personal information that is reasonably necessary for one or more of its functions or activities, requires that it be collected by lawful and fair means, and requires that it be collected from the individual concerned unless that is unreasonable or impracticable. Sensitive information needs consent as well as necessity, subject to specific exceptions.

This section is what we hold in our own right, where we decide the purpose. It is short, and it is short because the company does not yet do very much.

Personal information held as controller
CategoryExample fieldsSourceWhy we have itIf you withhold it
CorrespondenceYour email address, your name if you sign your message, the display name your mail client sends, the content of the thread, message headers and timestampsYou, when you write to usAnswering you, and keeping a record of what was saidWe cannot reply. There is no other route in
Enquiry contextYour organisation, your role, what you are trying to retain and for how longYou, voluntarilyGiving a useful answer rather than a generic oneThe answer is more generic. Nothing else changes
Supplier and accounting recordsContact name, business email, invoice and payment details of people we buy fromThe supplierPaying for things, and the statutory obligation to keep financial recordsNot applicable. This is not information about visitors
Website request dataIP address, user agent string, requested path, response code, timestampYour browser, automaticallyServing the page at all, and absorbing malicious trafficCannot be withheld while still loading a page. It is held transiently by the host

What is deliberately not on that table

  • No analytics of any kind. No page view counter, no session recording, no heat mapping, no visitor identification service, no advertising pixel. This website measures nothing about you and we would have to change this policy before it could.
  • No cookie set by us. The cookie position in full is in its own section below and on the cookie notice.
  • No marketing list, no newsletter, no lead capture, and no form anywhere on this site.
  • No account system, because there is nothing to sign in to.
  • No sensitive information within the meaning of the Privacy Act. We do not ask for health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, or biometric or genetic material, and there is no field anywhere in our systems intended to hold any of it.

Collection from someone other than you

Occasionally a person writes on behalf of a colleague, or copies a colleague into a thread. That is collection from a third party and APP 3.6 permits it where collecting from the individual is unreasonable or impracticable. In that situation we take reasonable steps to notify the person whose information it is, which in practice means replying to all rather than replying privately so that everybody can see what we now hold.

4What we would hold as processor

This section covers material deposited by a customer organisation for long term retention. It is written as a commitment to those organisations as much as to the people whose information sits inside a deposit, because a processor's obligations are contractual first and the contract should not contradict the public page.

What a deposit would consist of

The parts of a deposit, and what we would and would not do with each
PartWhat it isWhat we do with itWhat we deliberately do not do
The payloadThe exported records themselves. Documents, structured exports, images, correspondence archives. It may contain personal information about the customer's own peopleVerify the digest, identify the format, store it, recompute the digest on schedule, migrate the format when instructedOpen it to look at the content, index the text, extract entities, profile it, or use it to improve anything
Technical metadataByte size, format identification, character encoding, digest value and algorithm, deposit timestampHold it beside the payload as the fixity and format recordDerive anything about individuals from it
The indexThe finding aid the customer writes. Origin system, arrangement, field meanings, code lists, the retention rule and its expiry dateHold it, keep it readable, return it with the payload on exitEdit its substance. Corrections come from the customer
Operator contactName, role and business email of the people at the customer authorised to give instructionsVerify that an instruction came from an authorised personMarket to them, or reuse the contact for anything else
Instruction logWho instructed what, when, and what we did about itKeep it for the life of the relationship, because a chain of custody with a gap in it is not a chain of custodyDelete it on request, since it is the evidence that the record was handled correctly

Not looking inside is a design decision, not a courtesy

A retention service that indexes content for search has to read every deposit, has to hold the index somewhere, and has to secure a second body of derived material that is often more sensitive than the original because it is easier to query. We have chosen not to build that, which is the reason the non-goal appears on the approach page as well as here. The practical consequence is that we usually cannot tell you whether a particular person appears in a particular deposit. The customer can, and that is the correct division.

What we would commit to as processor

  • Instructions only. We would process deposited material only on the customer's documented instructions, including for any transfer, unless an Australian law requires otherwise, in which case we tell the customer before processing unless the law forbids that.
  • No secondary use. Not for product development, not for benchmarks, not for an aggregate report about what organisations retain, and not for training any model. An archive that mines its holdings has stopped being an archive.
  • Confidentiality. Everyone with access would be under a confidentiality obligation that survives the end of their engagement, and access would be limited to those who need it to operate the service.
  • Assistance. We would assist the customer to answer access, correction and deletion requests, and to meet its own obligations after a breach.
  • Sub-processors. Named in the recipients table below, with at least 30 days notice before one is added or replaced, and a right for the customer to object.
  • Return or destruction. At the end of a contract, and at the customer's election, we return or destroy the deposit within 30 days and destroy remaining copies, unless a law requires retention. Return means the payload and the index together, in the formats they are held in, because a return that omits the index is not a return.
  • Audit. We would make available the information needed to demonstrate compliance and allow a reasonable audit by the customer or its auditor, on reasonable notice and no more than once a year unless a breach has occurred.
  • Notification to the customer. If we became aware of unauthorised access to, unauthorised disclosure of, or loss of deposited material, we would notify the affected customer without undue delay and in any event within 24 hours, with what we know at the time, and keep updating as we learn more. The customer, being the entity accountable under Part IIIC of the Privacy Act, decides whether the incident is an eligible data breach and makes any notification to the Commissioner and to affected individuals. We assist and we do not obstruct.
The exit clause matters more than the service

Because a fifteen year commitment from a company registered in 2026 is only credible if our disappearance is survivable, the intended design is that the customer holds a complete copy in the same open formats throughout, and that leaving is a file transfer rather than a negotiation. If that is ever weakened for commercial reasons, it will be visible here first.

5Notification at the point of collection

Australian Privacy Principle 5 requires us to tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. What we have to tell you includes who we are, the fact and circumstances of collection, the purpose, the consequences of not providing the information, how to get access and correction, how to complain, and whether the information goes overseas and where.

Where notice actually happens, in each capacity

  • As controller, here. This document is linked from the footer of every page of this website, including the page you would have been reading before you wrote to us. There is no collection point on this site other than the mail link, and the mail link goes to an address that is published in plain text beside it rather than hidden behind a script.
  • As controller, in the reply. Where a thread turns into something that will be kept for longer than an answer, for example an ongoing discussion with a prospective customer, we say so in the thread rather than relying on you having read this page.
  • As processor, through the customer. We would have no relationship with the people described inside a deposit and no way to contact them. Notice to them is the depositing organisation's obligation under its own APP 5 duty, and the contract would require it to have given that notice, or to be relying on a lawful basis for not doing so, before it deposits anything.

Consequences of not providing information

Set out against each row of the collection table above rather than described in general terms, because "we may not be able to provide our services" is a sentence that tells nobody anything. In practice the only consequence that arises is that without an email address we cannot reply to you.

What this page is not allowed to do

A privacy notice that reserves a right to change what it collects without telling you defeats the point of APP 5. Where we begin collecting a category of personal information that is not in the table above, this policy changes first and the notice provisions in the changes section apply.

6Dealing with us anonymously

Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.

Reading this website is anonymous in every sense we can control. There is no account, no cookie of ours, no analytics and no fingerprinting script, so nothing here attempts to work out who you are or to recognise you if you come back.

Writing to us can be pseudonymous. A message from an address that does not carry your name is answered on its merits. We will not insist on a real name, a company domain or a telephone number as a condition of a reply, and we will not treat a pseudonymous enquiry as less serious than one from a corporate address.

The option genuinely falls away in two places. The first is a request to access or correct personal information, because to answer it we have to be reasonably satisfied you are the person the information is about. The second is a contract. An organisation depositing records has to be identified, because the whole service rests on knowing whose records they are and who is authorised to instruct us about them.

7Information we did not ask for

Australian Privacy Principle 4 deals with personal information we receive without having asked for it.

For a company in this line of work the obvious route is a sample. Somebody wanting to know whether a format can be preserved attaches a real export rather than a synthetic one, and a real export from a payroll system, a case management tool or a clinical record contains a great many people who were never asked. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

Practically, an unsolicited attachment containing other people's personal information is deleted from the mailbox, disappears from the ordinary backup rotation as those copies age out, and the technical question it was sent to illustrate is written down without it. We then reply saying what we deleted, because a sender usually does not realise what was in the file.

The contact page asks you to describe a file before sending it, for exactly this reason. It is not a formality.

8Use and disclosure

Australian Privacy Principle 6 governs what may be done with personal information once it is held. The rule is that information collected for one purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, or where you have consented, or where a specific exception in the Act applies.

As controller

  • Replying to you, and continuing a thread you started.
  • Keeping a record of what was said, so that a later question about an earlier answer can be resolved by looking rather than remembering.
  • Improving what this website says. Where several people ask the same question, the fix is usually a paragraph on a page rather than nine identical replies. We use the substance of a question that way. We do not quote you, name you or reproduce your organisation.
  • Meeting statutory obligations, principally the requirement to keep financial records.
  • Establishing, exercising or defending a legal claim, if one ever arises.

As processor

Operating the retention service on the customer's documented instructions, and nothing else. There is no secondary purpose, because a processor that develops one has become a controller of that material and would have to say so on this page.

What we do not do, in either capacity

  • We do not sell personal information. Not to a data broker, not to an advertiser, not as an audience, not bundled into anything.
  • We do not use anything you send us for advertising. There is no advertising on this website and none in anything the company has built.
  • We do not train a model on your correspondence or on any deposited material. The company name contains the letters AI and that makes this worth stating rather than assuming. Nothing that arrives here becomes training data.
  • We do not enrich what you send us against a third party dataset to work out more about you or your organisation than you told us.

Disclosure to law enforcement, courts and regulators

We may disclose personal information where the Act permits it. That covers disclosure required or authorised by or under an Australian law or a court or tribunal order, a permitted general situation under section 16A including a serious threat to life, health or safety, and disclosure to an enforcement body where reasonably necessary for an enforcement related activity.

Where we make such a disclosure to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you a request was made, we will. Where a request relates to material we hold as processor, we tell the customer before responding unless the law forbids it, because the customer is the party accountable for that material and may have standing to object that we do not.

We do not have a policy of volunteering material we have not been compelled to produce.

9Recipients, sub-processors and where they are

The complete list. Where a recipient would touch material held as processor it is marked as a sub-processor, which triggers the notice obligation described earlier.

Recipients of personal information, and where they are
RecipientRolePurposeLocation
Cloudflare, Inc.Controller sideServing and protecting this website. Request data passes through the edge and is held transientlyGlobal edge network, including Australia. Company incorporated in the United States
Google LLCNeither. Your browser contacts them directlyDelivering the two web fonts this site uses. Your IP address and browser characteristics reach them because your browser makes the request, not because we forward anythingUnited States and global edge
Our email providerController sideReceiving, sending and storing correspondenceAustralia and the United States
Our accountantController sideStatutory accounts, business activity statements and taxAustralia
Storage and compute for the retention serviceWould be a sub-processorHolding deposits. Not yet contracted, because there is no service and nothing depositedTo be named here before any deposit is accepted, with the region stated

Not on that list

No analytics vendor, no advertising network, no data broker, no customer data platform, no visitor identification service, no marketing automation, no chat widget, no session recorder, no error tracking service that receives your browser state, and no artificial intelligence provider of any kind. A retention company adding a vendor that can see deposited material would be exactly the change that should be announced rather than absorbed, so it would go through the sub-processor notice process even where a strict reading might not require it.

Business transfer

On a sale of the company, personal information held as controller may transfer to the buyer. Material held as processor would transfer subject to the customer contract, which we will not sidestep by structuring a deal differently. Where we are lawfully able to, we give notice before such a transfer completes.

Insolvency

This one is usually left out and it is the case that actually worries a depositor. If the company failed, deposited material would be dealt with under the customer contract and under insolvency law, and neither of those is something a website can promise its way around. The honest mitigation is structural rather than contractual, which is why the design keeps a complete copy in the customer's own hands, in open formats, with the index, throughout.

10Direct marketing and the Spam Act

Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime: consent, accurate sender identification, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.

Our position

We do not run a marketing list. We have never sent a marketing email under this company name. If that changes, it will be opt in, the consent will be recorded with a timestamp and the wording you agreed to, and the first message will say where the address came from.

Writing to our support address does not subscribe you to anything. That is the most common way small companies quietly build a list, and we do not do it.

There is no advertising anywhere in this

This website carries no advertising, no sponsored content and no affiliate link, and nothing the company has built carries any either. There is no advertising network involved in this site, so there is no personalised advertising to switch off and no advertising identifier of any kind in play. The section exists to say that plainly rather than to leave a gap somebody has to interpret.

What a future announcement list would look like

If the company ever publishes a specification and people ask to be told when it changes, that would be a list, and the Spam Act would apply to it in full. It would be opt in from a page that does nothing else, the consent record would carry a timestamp and the exact wording agreed to, every message would identify the sender and carry a working unsubscribe link, and an unsubscribe would be actioned immediately rather than within the five working days the Act allows.

Writing to our support address would not put you on it. That is the most common way a small company quietly builds a list and we do not do it.

11Sending personal information overseas

Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.

We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".

How we meet APP 8

Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.

We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.

Where the data actually goes

The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.

12Government related identifiers

Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.

We do not collect any government related identifier. There is no account, no age check and no identity verification step anywhere in what we do, and no field in any system we operate is intended to hold one.

If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.

The processor position, which is different

A record deposited for retention may well contain government related identifiers belonging to the depositing organisation's own people. A superannuation record contains tax file numbers. A clinical record contains Medicare numbers. That is not us adopting an identifier within the meaning of APP 9, because we do not use it to identify anybody and we do not look inside the deposit at all. It does mean that a deposit has to be treated as sensitive by default, which is the assumption the retention design starts from rather than one it reaches later.

13Keeping information accurate

Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.

Almost everything we hold as controller is something you wrote to us, which is accurate in the narrow sense that it faithfully records what was said and is the category most likely to go stale. Roles change, addresses change, and a thread from two years ago describes an organisation that may no longer be arranged that way. We do not periodically re-verify any of it, because doing so would mean contacting people who had finished dealing with us in order to ask them to confirm details they never asked us to keep.

The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.

As processor the principle bites differently and it is worth being exact about it. We do not correct the content of a deposited record, ever. An archive whose supplier edits the holdings is not an archive, and a record that has been silently improved is no longer evidence of anything. Where a depositing organisation instructs a correction, the corrected version is deposited as a new version, the instruction is recorded, and the superseded version is retained unless the instruction is to destroy it. That is the difference between correcting a record and falsifying one.

14Security, and what we do not hold

Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.

What "reasonable steps" means for a company this size

  • Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address is carried over TLS wherever the sending server offers it.
  • Encryption at rest for stored data, provided by the underlying platform.
  • Multi-factor authentication on every account that can reach the mailbox, the domain registration, the hosting account or the code repositories. Those four are the entire attack surface today, and there is no console behind any of them that holds anybody's records.
  • Access on a need to know basis. The number of people who can reach the mailbox is small and is reviewed whenever anyone joins or leaves.
  • Nothing live to breach. There is no hosted service, no account system, no customer database and no administrative interface behind this site. What has to be defended is a set of static files, one mailbox and a code repository.
  • Collecting less. The most reliable security control available to a company of this size is not holding the data, which is why the collection tables earlier on this page are as short as they are.

What we do not have, stated plainly

ARCVAULT AI PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.

We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.

What a retention service would have to add, and has not been built yet

Everything above describes a company that holds correspondence. A company holding other organisations' records for fifteen years needs a materially stronger position, and the honest statement is that it does not have one yet because there is nothing to protect. The design being written towards includes deposits encrypted with keys the customer can hold, an append only custody log so that a deletion cannot be made to look like it never happened, separation between the credential that can read a deposit and the credential that can destroy one, and destruction that requires a second authorised person. None of that is running. None of it should be believed until it is, and it will be described here in the present tense only when it is true.

Why an archive fails differently

The security failure that worries most companies is a breach that becomes public in a week. The one that should worry an archive is a slow corruption or a quiet deletion that nobody notices for eight years, by which time every copy that could have contradicted it has been rotated out. That is the reason fixity checking runs on a schedule and the custody log is designed to be append only. Confidentiality is the loud risk. Integrity is the one that actually loses the record.

15Retention, and a conflict of interest worth naming

Australian Privacy Principle 11.2 requires that personal information be destroyed or de-identified once it is no longer needed for any purpose for which it may be used or disclosed under the Act, unless it is contained in a Commonwealth record or a law requires it to be kept. For a company whose entire subject matter is long retention, this principle deserves more than a sentence, because our interests and yours point in opposite directions here and it is better to say so.

How long each category is kept, and the reason for the period
CategoryPeriodReason
General correspondence, no ongoing matter24 months from the last message in the threadLong enough that a follow up two years later has context. Short enough that an inbox does not become an archive of everybody who ever wrote in
Correspondence about a prospective engagement7 years from the end of the discussionPrecontractual dealings can matter to a later dispute, and the general limitation period in New South Wales for a contract claim is 6 years
Privacy requests and complaints, and what we did about them7 years from closureEvidence that we handled the request properly. Deleting the record of a deletion is how an organisation loses the ability to show it complied
Security reports and incident records7 yearsPattern recognition across years, and the record required if a notification is ever assessed
Financial and supplier records7 yearsSection 286 of the Corporations Act 2001 (Cth), and tax record keeping requirements
Website request data at the edgeDays, set by the host, not by usTransient operational logging. We do not copy it into anything of our own
Deposited material held as processorThe period the customer instructs, and no longerThe customer's retention obligation is the only reason the material exists here
Instruction and custody log for a deposit7 years after the deposit itself is destroyedProof of what was held and how it was disposed of, which outlives the thing it describes

The conflict of interest, stated openly

A company paid to store things has an obvious incentive to store them for longer than necessary. Three things are meant to hold against that. Retention is instructed by the customer and recorded, not inferred by us. Every deposit carries a stated expiry date in its index from the day it arrives. And a disposal that is due runs on the schedule rather than waiting for somebody to ask, with a report to the customer either way.

Backups and the awkward gap

Deleting something from a live system does not immediately delete it from the copies taken before the deletion. That is true here as everywhere, and a policy claiming otherwise is describing an imaginary system. Where we delete personal information, it is removed from the live system immediately and disappears from the ordinary backup rotation as those copies age out. Until then it is not used for anything, and a restore that would reinstate deleted information is followed by re-applying the deletion.

16Access and correction, in both capacities

Australian Privacy Principle 12 gives you the right to ask for access to the personal information held about you. Australian Privacy Principle 13 gives you the right to ask that it be corrected. Which door to knock on depends on the capacity, so it is set out twice.

Where an access or correction request goes
CapacityInformationWhat to do
ControllerYour correspondence with us, enquiry context, supplier recordsEmail ops@arcvaultai.co.im with "Privacy request" in the subject line. We respond within 30 days, access is free, and a refusal comes with written reasons, the ground relied on, and how to complain
ProcessorPersonal information inside a record deposited by an organisationAsk that organisation. It decides, it holds the index that connects a record to a person, and it is accountable for the material. If you write to us instead we route it within 5 business days and tell you where it went

Where a customer instructs us to produce or correct material relating to a person, we action the instruction within 10 business days of receiving it, or sooner if that customer's contract requires it, so that the customer can meet its own 30 day obligation with room to spare.

Verifying who you are

We have to be reasonably satisfied that you are the person the information is about, or an authorised representative. For correspondence, that means a reply from the address the thread was conducted on. We will not ask you to send identity documents, we will not ask for a scan of a licence or passport, and we will not use a third party verification service. Asking for identity documents in order to protect privacy collects more sensitive material than the request was ever about.

Timing, cost and form

We respond within 30 days. Access is free. We do not charge for making a request and we do not charge for correction. Where you ask for the information in a particular form we will provide it that way if it is reasonable and practicable to do so. If producing it in an unusual form imposes a genuine cost we will tell you the charge before doing the work, and it will not be excessive.

When access can be refused

The grounds in the Act are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable in them, where giving access would reveal our evaluative information in connection with a commercially sensitive decision, and where giving access would be unlawful.

If we refuse, in whole or in part, we give written reasons, identify the ground relied on, and tell you how to complain. Where part of the information can be given, or the need can be met another way, we offer that instead of a flat refusal. The most likely real instance is a thread involving several people, where the answer is usually to give you your own messages and a description of the rest.

Correction

If information is inaccurate, out of date, incomplete, irrelevant or misleading, we correct it. If we have disclosed it to somebody else and you ask us to tell them about the correction, we take reasonable steps to do so unless that is impracticable or unlawful.

If we decline to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is regularly overlooked and it is worth knowing about, particularly where the disagreement is about a matter of opinion rather than a matter of fact.

17Deletion and disposal

Deletion is not one of the thirteen Australian Privacy Principles in the way that access and correction are. It arrives through APP 11.2, which requires destruction or de-identification once information is no longer needed. In practice we treat a deletion request as a request we will honour rather than one we will argue about, and this section says what actually happens.

As controller

  1. Email ops@arcvaultai.co.im with "Delete my data" in the subject line.
  2. We confirm receipt within 5 business days and tell you what we hold, so that you can say whether you meant all of it.
  3. We delete it within 30 days, and confirm in writing when it is done.
  4. Ordinary backup copies age out on their normal rotation as described in the retention section. They are not used for anything in the meantime.

What survives a deletion, and why

  • A minimal record of the request itself. The address, the date and what was done. Without it we cannot demonstrate that we complied, and we would have no way of recognising that the same address later reappears through a route you did not intend.
  • Financial records. If you are a supplier and we have paid you, the invoice stays for the statutory period. Section 286 of the Corporations Act 2001 (Cth) is not something either of us can waive by agreement.
  • Material relevant to a live dispute or a legal hold. Deleting evidence because it was requested is not compliance, and we will say plainly that this is the reason rather than going quiet.

As processor, disposal rather than deletion

Deposited material is destroyed on the instruction of the depositing organisation, on the expiry date recorded in the index, or at the end of the contract at that organisation's election. Destruction is confirmed back to the customer in a written disposal record that says what was destroyed, when, by what method, and who instructed it. That record is itself retained, because the evidence that a record was properly disposed of has to outlive the record.

We would not accept a destruction instruction from anyone other than an authorised operator at the depositing organisation. An archive that can be talked into destroying something by a convincing email is not an archive.

Today, in one sentence

There is no deposited material of any kind, so every deletion request that could reach us right now is a controller request about correspondence, and it is answered by deleting a mail thread.

18Children and young people

This is a business to business proposition. The website is not directed at children, nothing on it is designed to appeal to children, and there is no account, no sign up, no game, no social feature, no chat and no user generated content anywhere on it.

The Australian position on capacity

The Privacy Act does not fix an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have capacity unless there is something to suggest otherwise. We apply that presumption to correspondence.

The Privacy and Other Legislation Amendment Act 2024 provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code as it applies to us once it is registered and in force, and we will update this policy at that point rather than guessing at its terms in advance.

Where a child's information could actually reach us

Not through this website. The realistic route is inside a deposit, where a customer organisation retains records about children. A school, a paediatric practice, a youth service or a local authority holds records of exactly that kind, and the retention periods that apply to them are among the longest in Australian law. A child's medical record in New South Wales is kept until that person turns 25, which can be a quarter of a century after the system that produced it was decommissioned.

In that situation the child, or their parent or guardian, has rights against the organisation that holds the record rather than against us. We would hold it as processor, we would not look inside it, and a request would be routed as described in the access section. We would apply the same handling to it as to anything else, which is to say we would not treat a record about a child as ordinary material merely because we cannot see what is in it.

If you believe a child's information has reached us as controller

Write to ops@arcvaultai.co.im. We will delete it without requiring proof of a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm when it is done.

19Automated decisions

The Privacy and Other Legislation Amendment Act 2024 inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of such decisions made. That requirement commences on 10 December 2026. It is disclosed here in advance of the commencement date rather than on it.

Our position

We make no automated decision that significantly affects anybody's rights or interests. Nothing here decides whether a person gets credit, a job, a service, a benefit, housing, insurance or a legal entitlement, and nothing here scores or ranks individuals.

Automated processing that does happen, and why none of it meets the threshold

  • Format identification. A deposited file is inspected by a program that works out what format it is from its structure. It reaches a conclusion about a file, not about a person.
  • Fixity checking. A digest is recomputed on a schedule and compared to the recorded value. A mismatch raises an event for a person to investigate. Nothing is decided automatically.
  • Disposal scheduling. An expiry date recorded at deposit causes a disposal to become due. It does not cause a destruction. Destruction is confirmed against the customer instruction before it happens, because an automated deletion of a record somebody is legally obliged to keep is the worst failure this company could have.
  • Edge protection on this website. The host may automatically challenge or block a request that matches an abuse pattern. That affects a request, and the remedy is to write to us from another connection and say so.

About the letters in the company name

The registered name is ARCVAULT AI PTY LTD. No model is trained on anything held here, no deposited material is sent to a third party inference service, and no decision about a person is delegated to a statistical system. Where machine assistance is ever used in the work, it will be described in this section, in specific terms, before it starts rather than after.

20Data breaches and the notification scheme

Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.

The process we follow

  1. Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
  2. Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
  3. Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
  4. Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.

What a notification will contain

Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.

If you think a breach has happened

Write to ops@arcvaultai.co.im with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.

21The statutory tort of serious invasion of privacy

A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.

This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.

22Cookies on this website

Short version. This website sets no cookies of its own, runs no analytics, and shows no consent banner because there is nothing to consent to. The full account is on the cookie notice and the substance is summarised here so that this policy is complete on its own.

  • No first party cookie. Nothing on this site writes a cookie. The site is static files and one small script that does a navigation toggle and a scroll reveal.
  • No local storage. Nothing is written to localStorage, sessionStorage or IndexedDB.
  • Two web fonts from Google Fonts. Your browser fetches them directly from Google, which means your IP address and browser characteristics reach Google as part of that request. Google states that Google Fonts sets no cookies. This is the only third party contact the page makes and it is named in the recipients table.
  • Edge request logging. The host records the ordinary details of an HTTP request in order to serve it and to absorb attacks. We do not read those logs routinely and we do not copy them into anything.

Australian law does not have a direct equivalent of the European consent rule for cookies. What applies is the Privacy Act, and it applies to a cookie only where the cookie involves personal information. Since there is no cookie, the question does not arise. If that ever changes, the change appears in this policy and in the cookie notice before any cookie is set, and anything beyond what is strictly necessary would be opt in.

23Complaints

Step one: tell us

Email ops@arcvaultai.co.im with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.

Step two: the Commissioner

If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.

The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.

What we will not do

We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.

24If you are outside Australia

This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.

European Economic Area and United Kingdom

Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Send any such request to ops@arcvaultai.co.im and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.

California

Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising on this website and none in anything the company has built, so there is no sharing to opt out of in the first place. Global Privacy Control signals sent by your browser to this website are honoured.

Everywhere else

If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.

25Changes to this policy

We may change this policy. When we do, the effective date and the version number in the header of this page change with it.

Where a change materially reduces your rights or materially expands what we collect, we give notice before it takes effect. That means a dated note at the top of this page for at least 30 days beforehand, and, for anyone with an active thread or a contract, an email. We will not make a material change effective retrospectively.

Two changes are already foreseeable and are flagged now rather than being sprung later. The first is naming the storage and compute provider for the retention service, which has to happen before any deposit is accepted. The second is the arrival of the Children's Online Privacy Code and the automated decision transparency requirement, both of which have their own sections above.

Previous versions are not published as separate pages, but they are kept. If you want to know what this document said on a particular date, ask and we will send you that version.

This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner about your own circumstances.

26How to contact us

All privacy matters reach one address, and it is the same address as everything else. There is no separate privacy officer inbox, because inventing one would imply a function that does not exist in a company this size.

Contact points for privacy matters
MatterSubject lineResponse
Access to your personal information (APP 12)Privacy request30 days
Correction of your personal information (APP 13)Privacy request30 days
Deletion of what we hold about youDelete my data30 days
Complaint about our handling of personal informationPrivacy complaintAcknowledged in 5 business days, answered in 30 days
Suspected security incident or data breachSecuritySame or next business day
Anything elseAnything sensible5 business days

Email: ops@arcvaultai.co.im

Entity: ARCVAULT AI PTY LTD, ACN 696 486 987, ABN 11 696 486 987, an Australian proprietary company registered in New South Wales. Registered for GST from 24 March 2026.

We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 696 486 987 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.

If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.