CyberGrape logo - Cyber Security and SMB1001 certification platform for small business
    CyberGrape - GRC platform for SMB1001 security certification
    Insights

    Privacy Policy

    CyberGrape GRC Platform & cybergrape.io

    Version 2.2

    Effective Date: 1 July 2026

    Last Reviewed: 25 June 2026

    CyberGrape Pty Ltd, ABN 83 696 722 988 (Australia)

    CyberGrape Ltd, NZBN 9429048818155 (New Zealand)

    Trading as CyberGrape

    Registered address: Level 1, 470 St Pauls Terrace, Fortitude Valley, QLD 4006, Australia

    This document has been prepared by CyberGrape for internal use and client engagements. It does not constitute legal advice. CyberGrape recommends that all parties seek independent legal counsel before publishing or relying on this policy.

    Part I: Overview and General Provisions

    1. Who We Are

    CyberGrape Pty Ltd (ABN 83 696 722 988) and CyberGrape Ltd (NZBN 9429048818155), trading together as "CyberGrape", "we", "us" or "our", provide cyber security consulting, managed security services, and the CyberGrape GRC Platform, a multi-tenant software-as-a-service governance, risk and compliance product available at app.cybergrape.io (the "Platform"). This Privacy Policy also covers our marketing website at cybergrape.io (the "Website").

    This Privacy Policy explains how we collect, use, disclose, store, and otherwise manage personal information, and describes the rights available to individuals under the laws that apply to them. We maintain a single global policy structured in parts so that visitors and users can identify the section most relevant to them, while giving effect to the strictest applicable standard where obligations overlap.

    2. Scope

    This Policy applies to:

    • Visitors to the Website;
    • Registered users of the Platform, including client (CSSM) users, MSP console users, and platform administrators;
    • Individuals whose information is uploaded to the Platform by a client organisation in the course of using our GRC tooling (for example, personnel listed in a contractor register, visitor register, or risk assessment);
    • Prospective clients, partners and job applicants who contact us; and
    • Any other individual whose personal information we otherwise collect in the course of operating our business.

    Where a client organisation (a "Tenant") uploads personal information about its own personnel, customers, or contacts into the Platform, CyberGrape generally acts as a processor / service provider on the Tenant's behalf for that data, and the Tenant remains responsible as the controller / business for its own compliance obligations to those individuals. This Policy describes CyberGrape's own handling practices as operator of the Platform, including the security and confidentiality commitments we make to Tenants.

    3. Definitions

    • "Personal information" / "personal data" means information about an identified or reasonably identifiable individual, however that information is recorded.
    • "Sensitive personal information" means categories of personal information subject to heightened protection under applicable law, including health information, government identifiers, precise geolocation, and (under the CCPA/CPRA) personal information of a consumer the business has actual knowledge is under 16 years of age.
    • "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, and deletion.
    • "Service Provider" / "Subprocessor" means a third party that processes personal information on our behalf under contract.
    • "Tenant" means a client organisation with its own workspace on the Platform.

    4. Information We Collect

    4.1 Identity and Account Data

    • Name, job title, work email address, phone number;
    • Username and hashed password, multi-factor authentication settings;
    • Role, permissions, and Tenant/organisation affiliation.

    4.2 Platform and Compliance Data

    Where you use the Platform, we process the GRC data your organisation submits or connects, which may include security findings, control assessment responses, evidence files, risk register entries, policy documents, vendor assessment responses, contractor and personnel registers, and visitor register entries. This data may include personal information about your own personnel, contractors, vendors, or site visitors, which you are responsible for having a lawful basis to provide to us.

    4.3 Technical, Device and Usage Data

    • IP address, browser type and version, device and operating system identifiers;
    • Pages viewed, features used, session duration, referring/exit pages, and clickstream data;
    • Cookie and similar tracking identifiers (see Section 8 below).

    4.4 Communications

    • Support tickets, emails, call notes, and in-platform messages;
    • Marketing and newsletter subscription preferences.

    4.5 Payment and Billing Data

    Billing contact details, invoicing details, and subscription history. Card and payment details are processed directly by our payment processor (Stripe) and our accounting platform (Xero); we do not store full card numbers on our own systems.

    5. How We Collect Information

    • Directly from you: account registration, forms, support requests, signup and onboarding flows;
    • Automatically: cookies, server logs, and analytics tools when you use the Website or Platform (see Section 8);
    • From your organisation: if your employer or an MSP administrator creates your Platform account or uploads your details;
    • From third parties you connect: single sign-on providers (e.g. Microsoft Entra ID, SAML/SCIM identity providers), and optional third-party security and IT integrations a Tenant chooses to connect to the Platform (for example, Microsoft 365, Black Kite, CrowdStrike, uSecure, KeepIt, PowerDMARC, and similar tools).

    6. How We Use Information

    PurposeExamples
    Provide and operate the PlatformAccount provisioning, authentication, compliance workflows, evidence and reporting features
    Customer supportResponding to tickets, diagnosing issues, onboarding assistance
    Security and integrityFraud and abuse prevention, audit logging, access control, incident response
    Billing and contract administrationInvoicing, subscription management, payment processing via Stripe and Xero
    Product improvementUnderstanding feature usage in aggregate or de-identified form
    Legal and regulatory complianceMeeting record-keeping, tax, and law-enforcement obligations
    Marketing (with consent or as permitted by law)Newsletters, product updates, event invitations, always with an opt-out

    We do not use personal information for automated decision-making that produces legal or similarly significant effects about an individual without human review.

    8. Cookies, Analytics and Tracking Technologies

    Cookies are small text files placed on your device when you visit the Website or Platform. We and our service providers use cookies and similar technologies (such as pixels, local storage, and SDKs) for the purposes described below.

    8.1 Categories of Cookies We Use

    CategoryPurposeCan be disabled?
    Strictly necessaryAuthentication, session management, security (e.g. CSRF protection), load balancingNo, required for the Website/Platform to function
    Functional / preferenceRemembering display settings, language, and in-platform preferencesYes, via browser or cookie settings
    AnalyticsUnderstanding aggregate usage patterns to improve the Website and Platform, using Google AnalyticsYes, via our cookie banner or browser settings
    Marketing / advertisingWe plan to add a LinkedIn Insight Tag to cybergrape.io to measure the effectiveness of our marketing campaigns. It is not yet live. Once added, it will only run on the Website, never on the authenticated Platform, and only after you consent via our cookie bannerYes, via our cookie banner, once introduced

    8.2 Consent and Cookie Preferences

    On first visit, the Website presents a cookie banner, managed through our consent management platform, CookieYes, allowing you to accept or decline non-essential cookies. We default to the most privacy-preserving option. Google Analytics is only loaded after you provide affirmative consent through the CookieYes banner, and defaults to a denied consent state until you do so. We intend to add a LinkedIn Insight Tag in future for marketing measurement, and the same consent-first approach will apply once it goes live. You can change your preferences at any time via the cookie settings link in the Website footer, or by adjusting your browser settings to block or delete cookies (noting this may affect Website or Platform functionality).

    8.3 Do Not Track and Global Privacy Control

    Where technically supported, we honour the Global Privacy Control (GPC) browser signal as a valid request to opt out of the sale or sharing of personal information for California visitors (see Section 12.3 and Section 14). We do not currently respond differently to the general "Do Not Track" browser header, as no common industry standard for its interpretation exists.

    8.4 Third-Party Analytics

    Google processes Website analytics data under its own privacy terms and acts as our service provider for this purpose, bound by contract not to use Website data for its own independent purposes. LinkedIn will act in the same capacity once the Insight Tag referred to above goes live. We do not permit analytics or marketing tags on authenticated areas of the Platform where Tenant compliance data is displayed.

    9. Who We Share Information With

    We do not sell personal information for money. We disclose personal information only in the following circumstances:

    • Service providers / subprocessors who process data on our behalf under contract, which may include: Microsoft (Microsoft 365, Entra ID, Graph API for email/Teams/SharePoint), Amazon Web Services (application hosting), Cloudflare (network security and content delivery), OpenAI and/or Anthropic (AI-assisted features, subject to our AI use safeguards), Stripe (payment processing), Xero (invoicing and accounting), and, where a Tenant enables them, third-party security integrations such as Black Kite, CrowdStrike, uSecure, KeepIt, PowerDMARC, Bitwarden, Meraki, NinjaOne, Cisco Umbrella, CheckRed, Google Workspace, Bitdefender, and Jira;
    • Within a Tenant's own organisation: in the multi-tenant Platform, data you submit is visible to authorised users within your own Tenant, and, where applicable, to an MSP administrator managing your Tenant on your organisation's instruction;
    • Professional advisers such as our lawyers, accountants and auditors, under confidentiality obligations;
    • Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections;
    • Legal and safety reasons: where required by law, to respond to lawful requests from public authorities, or to protect the rights, property or safety of CyberGrape, our users, or others.

    10. International / Overseas Data Transfers

    CyberGrape operates globally, with a primary presence in Australia and New Zealand and clients in Australia, New Zealand, South Africa, Singapore, Malaysia, Japan, the United Kingdom, and the United States. Personal information may be processed in countries other than the one in which it was collected, including the United States (where our infrastructure and AI service providers are based) and Ireland (as an EU/UK fallback region for Microsoft datacentres).

    Where we transfer personal information overseas, we take reasonable contractual, technical and organisational measures designed to ensure the recipient handles it consistently with the Australian Privacy Principles, the New Zealand Information Privacy Principles, and, for Californians, the CCPA/CPRA, regardless of where processing occurs.

    11. Data Retention

    Data typeRetention approach
    Account dataDuration of the customer agreement, plus a period necessary to meet statutory limitation periods (typically up to 7 years)
    Platform GRC / compliance dataPer the Tenant's own data retention configuration and contractual terms
    Application and security logsRolling retention window, typically 90 days
    BackupsRolling retention window, typically 30 days, then securely purged
    Marketing subscriber dataUntil you unsubscribe or request deletion

    12. Security

    We maintain administrative, technical and physical safeguards designed to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

    • Encryption in transit (TLS 1.2+) and at rest (AES-256), including per-tenant data encryption keys;
    • Role-based access controls and multi-factor authentication;
    • Audit logging and continuous monitoring;
    • Regular security testing, including penetration testing;
    • Alignment with ISO 27001:2022 and SMB1001:2026 control frameworks across our own operations.

    No method of transmission or storage is completely secure. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the relevant regulator in accordance with the notification obligations described in Part II and Part III below.

    Part II: Australia and New Zealand

    This Part applies to individuals in Australia and New Zealand and sets out our compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the Privacy Act 2020 (NZ) and the Information Privacy Principles (IPPs).

    13. Your Rights: Australia

    • Access your personal information (APP 12);
    • Request correction of inaccurate, out-of-date or incomplete information (APP 13);
    • Opt out of direct marketing at any time (APP 7);
    • Make a complaint to us, and if unresolved, to the Office of the Australian Information Commissioner (oaic.gov.au).

    13.1 Notifiable Data Breaches (Australia)

    Under Part IIIC of the Privacy Act 1988, where a data breach is likely to result in serious harm to affected individuals, we will notify those individuals and the OAIC within the required timeframe (currently within 30 days of becoming aware, where practicable).

    14. Your Rights: New Zealand

    • Access and request correction of your personal information (IPPs 6–7);
    • Make a complaint to us, and if unresolved, to the Office of the Privacy Commissioner (privacy.org.nz).

    14.1 Notifiable Privacy Breaches (New Zealand)

    Under Part 6 of the Privacy Act 2020, where a breach is likely to cause serious harm, we will notify affected individuals and the Privacy Commissioner as soon as reasonably practicable after becoming aware.

    Part III: United States and California

    This Part applies to individuals located in the United States, and in particular to California residents ("consumers") under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), and to the California Online Privacy Protection Act (CalOPPA). Where our processing of a California resident's personal information falls within the scope of the CCPA/CPRA, we provide the disclosures and rights below as a matter of both legal compliance and consistent global policy, regardless of whether our organisation independently meets every CCPA/CPRA applicability threshold.

    15. Categories of Personal Information We Collect and Disclose (California)

    In the preceding 12 months, we have collected the following categories of personal information, as defined by the CCPA/CPRA, from Website visitors, Platform users, and individuals whose data a Tenant has uploaded:

    CCPA CategoryExamplesDisclosed to service providers?
    IdentifiersName, email, IP address, account IDYes
    Customer recordsBilling name and address, phone numberYes
    Commercial informationSubscription and billing historyYes
    Internet / network activityBrowsing and usage data, cookie identifiersYes
    Geolocation (approximate)IP-derived location for security and analyticsYes
    Professional / employment informationJob title, employer, role within TenantYes
    Sensitive personal informationAccount credentials; and, only where a Tenant chooses to upload it, limited personnel data such as police vetting recordsOnly to the relevant service provider required to deliver that specific feature

    We do not sell personal information for monetary consideration. We do not "share" personal information (as that term is defined under the CPRA, in relation to cross-context behavioural advertising) on the authenticated Platform. Our public marketing Website may use advertising cookies as described in Section 8, which can constitute "sharing" under the CPRA's broad definition; you can opt out at any time as described in Section 14 below.

    16. Your Rights: California / CCPA-CPRA

    • Right to know / access: request the specific pieces and categories of personal information we have collected about you, the sources, the purposes of collection, and the categories of third parties to whom it has been disclosed;
    • Right to delete: request deletion of personal information we have collected from you, subject to legal exceptions (e.g. information needed to complete a transaction, detect security incidents, or comply with a legal obligation);
    • Right to correct: request correction of inaccurate personal information;
    • Right to opt out of sale/sharing: direct us not to sell or share your personal information (see Section 14);
    • Right to limit use of sensitive personal information: direct us to limit use of sensitive personal information to what is necessary to provide the Website or Platform;
    • Right to non-discrimination: we will not deny goods or services, charge different prices, or provide a different level of service because you exercised a CCPA/CPRA right;
    • Right to data portability: receive a copy of your personal information in a portable format, where technically feasible;
    • Right to designate an authorised agent to make a request on your behalf.

    To exercise these rights, contact us using the details in Section 20. We will verify your identity using information already associated with your account before completing a request, and will respond within the statutory timeframe (currently 45 days, extendable once by a further 45 days with notice).

    17. Children's Privacy: United States

    17.1 COPPA (Under 13)

    The Website and Platform are business tools directed at organisations and their personnel and are not directed at, marketed to, or knowingly used by children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly. If you believe a child under 13 has provided us with personal information, contact us using the details in Section 20.

    17.2 CCPA/CPRA: Consumers Aged Under 16

    We do not knowingly sell or share the personal information of consumers we know to be under 16 years of age. Where we have actual knowledge that a consumer is under 16, that consumer's personal information is treated as sensitive personal information under the CPRA, and:

    • For consumers under 13, we require verifiable authorisation from a parent or guardian before any sale or sharing of personal information would occur;
    • For consumers aged 13 to 15, we require the consumer's own affirmative opt-in before any sale or sharing of personal information would occur;
    • As stated above, we do not currently sell personal information, and we do not knowingly direct advertising cookies at users under 16.

    17.3 General Approach to Minors

    Consistent with Part II, the Website and Platform are not directed at individuals under 16 in any jurisdiction. If we become aware that personal information has been collected from a minor without the necessary consent, we will delete it as soon as reasonably practicable.

    18. Do Not Sell or Share My Personal Information

    California residents may opt out of any sale or sharing of their personal information at any time by:

    • Using the "Do Not Sell or Share My Personal Information" link in the Website footer;
    • Enabling a Global Privacy Control (GPC) signal in a supporting browser or extension, which we will treat as a valid opt-out request for that browser; or
    • Contacting us using the details in Section 20.

    Once you opt out, we will wait at least 12 months before asking you to re-authorise the sale or sharing of your personal information, and it will remain equally easy to opt out again as it was to opt in.

    19. Shine the Light (California Civil Code 1798.83–1798.84)

    California residents with an established business relationship with us may request, once per calendar year, a list of the categories of personal information we have disclosed to third parties for their own direct marketing purposes in the preceding calendar year, and the names of those third parties. As stated above, we do not disclose personal information to third parties for their own direct marketing purposes.

    Part IV: General

    20. Changes to This Policy

    We may update this Policy from time to time to reflect changes in our practices or legal obligations. Material changes will be notified via email to registered Platform users and/or a prominent notice on the Website or within the Platform prior to taking effect. The "Last Reviewed" date at the top of this document indicates when it was last updated.

    21. Contact Us / Privacy Officer

    For privacy enquiries, complaints, or to exercise any of the rights described in this Policy, contact:

    Email: [email protected]

    Postal address: Level 1, 470 St Pauls Terrace, Fortitude Valley, QLD 4006, Australia

    We aim to acknowledge privacy enquiries within 5 business days and to resolve them within the timeframes required by applicable law.

    This document has been prepared by CyberGrape for internal use and client engagements. It does not constitute legal advice. CyberGrape recommends that all parties seek independent legal counsel before publishing or relying on this policy.

    © CyberGrape 2026