Privacy Policy
Effective 1 June 2026
Singulr Pty Ltd is committed to handling personal information responsibly and in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles.
1. Overview
Singulr Pty Ltd ("Singulr", "we", "us", or "our") is committed to protecting the privacy of individuals who use our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information in connection with the Singulr cybersecurity assessment management platform (the "Service").
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you have any questions, please contact us at the details provided below.
2. Information We Collect
Account information
When you register for an account, we collect your name, email address, and a hashed password. If you sign in via Google SSO, we receive your name, email address, and a Google account identifier.
Multi-factor authentication data
If you enable TOTP-based MFA, we store an encrypted TOTP secret tied to your account. This secret is used solely to verify your identity at sign-in.
Platform usage data
We collect information about how you use the Service, including pages visited, features used, and session activity. This is used to improve the platform and to detect and prevent unauthorised access.
Engagement and assessment data
As part of the Service, you may input client names, project details, security findings, assessment responses, and remediation records. This data is treated as confidential and is not shared beyond your workspace or the clients and team members you expressly grant access to.
Uploaded documents
If you use the AI Import feature, you may upload PDF or other documents for extraction and processing. Document content is transmitted to our AI provider (OpenAI) for processing and is subject to OpenAI's data handling policies. Documents are not retained by OpenAI for training purposes under our enterprise agreement.
Log and audit data
We maintain server-side logs of authentication events, administrative actions, and security-relevant activity for the purposes of security monitoring, incident response, and compliance. Logs are retained for 12 months.
3. How We Use Your Information
- To create and manage your account and authenticate your identity.
- To provide, operate, and improve the Service.
- To send transactional communications such as account invitations, password reset links, and security alerts.
- To detect, investigate, and respond to security incidents, fraud, or misuse.
- To comply with legal obligations, including responding to lawful requests from government authorities.
- To generate aggregated, de-identified usage analytics that help us understand how the platform is used.
4. Third-Party Processors
We share personal information with the following categories of third-party service providers only to the extent necessary to operate the Service:
Replit Inc. - Cloud infrastructure and hosting
Hosts the application runtime and database. Data is processed in accordance with Replit's Data Processing Addendum.
Google LLC - Single sign-on (OAuth 2.0)
Used for optional Google SSO authentication. Only the email address and Google account identifier are exchanged.
OpenAI, LLC - AI document processing (AI Import feature)
Document text is transmitted to OpenAI solely to extract structured control and requirement data. OpenAI does not use submitted data to train its models under our agreement.
We do not sell personal information to third parties.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service.
- Account data is retained while your account is active and for 30 days following account deletion, after which it is permanently removed.
- Engagement data (projects, findings, assessments) is retained until you delete it or close your account.
- Audit and security logs are retained for 12 months.
- Backup copies of data are retained for up to 30 days on a rolling basis.
6. Your Rights
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you (APP 12).
- Request correction of personal information that is inaccurate, out of date, or incomplete (APP 13).
- Request deletion of your personal information, subject to our legal and operational obligations.
- Complain about a breach of the APPs - we will respond to your complaint within 30 days.
To exercise any of these rights, please contact us at privacy@singulr.com.au. We will respond within a reasonable time and no later than 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
7. Security of Your Information
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Technical measures include TOTP-based multi-factor authentication, HMAC-signed session tokens, bcrypt-hashed passwords, TLS in transit, encrypted backups, rate limiting on authentication endpoints, and comprehensive audit logging.
Despite our efforts, no method of electronic transmission or storage is completely secure. If you believe your account has been compromised, please contact us immediately at security@singulr.com.au.
8. Contact Us
For privacy-related enquiries, requests, or complaints, please contact our Privacy Officer:
Singulr Pty Ltd - Privacy Officer
privacy@singulr.com.au