Privacy Policy

Auresta AI Pty Ltd — Last updated: March 2026

Auresta AI Pty Ltd ("Auresta", "we", "us") is committed to protecting the privacy of our clients and website visitors. This policy is compliant with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Data Classification

We handle client data at four classification levels:

  • RESTRICTEDVulnerability scan results, attack paths, security findings — highest sensitivity
  • CONFIDENTIALClient system inventories, network diagrams, business context
  • INTERNALEngagement deliverables, reports, communication records
  • PUBLICGeneral correspondence, invoicing details, publicly available information

2. Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3 or higher. Vulnerability data, scan results, and client security artefacts are stored on sovereign Australian infrastructure and are never processed on offshore cloud platforms without explicit written consent.

3. Offshore Data Transfer

We operate sovereign compute infrastructure located in Melbourne, Australia (RTX Pro 6000 Blackwell). All AI inference for security-related tasks runs on-premises. Vulnerability scan data, attack surface maps, and security reports are never transferred offshore without your explicit written consent. This is a core commitment, not a footnote.

Where third-party services are used (e.g., communication platforms, project management tools), we ensure they meet Australian data residency standards or we obtain prior consent per APP 8.

4. Data Retention

Raw scan data and temporary vulnerability artefacts30 days
Final engagement reports and deliverables12 months
Audit trails, engagement records, and compliance evidence7 years
Contact form and pre-sales correspondence24 months

5. Information We Collect

We collect only what is necessary to deliver our services:

  • Contact details (name, email, phone, company) provided via our contact form or direct communication
  • Technical information about your systems within the agreed scope of an engagement
  • Basic usage analytics on our website (anonymised, no personal identifiers)

We do not sell, rent, or share your personal information with third parties for marketing purposes.

6. Your Rights

Under the Australian Privacy Act 1988, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or outdated information
  • Request deletion of your data (subject to legal retention obligations)
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

To exercise any of these rights, contact us at team@auresta.com.au. We will respond within 30 days.

7. Data Breach Notification

In the event of an eligible data breach under the Notifiable Data Breaches (NDB) scheme, we will notify affected individuals and the OAIC as required by law, typically within 30 days of becoming aware of the breach.

8. Contact

For privacy enquiries or complaints, contact our Privacy Officer at team@auresta.com.au or in writing to Auresta AI Pty Ltd, Melbourne, Victoria, Australia.

This policy may be updated periodically. Material changes will be communicated to active clients. The current version is always available at auresta.com.au/privacy.