Legal

Privacy Policy

Last updated: 30 September 2026

RG Labs, ABN 26 465 879 682, Melbourne, Victoria. In this policy, "RG Labs", "we", "us" and "our" refer to that business.

This policy explains what personal information we collect, how we use it, who we disclose it to, where it is stored and how long we keep it. It covers our websites (rglabs.com.au, portal.rglabs.com.au), the client portal, and our consulting engagements.

This policy is provided for transparency. It is not legal advice.

1. Our position under the Privacy Act

The Privacy Act 1988 (Cth) currently exempts most small businesses with annual turnover under $3 million from the Australian Privacy Principles (APPs). RG Labs is below that threshold, so the exemption presently applies to us.

We have chosen to handle personal information as though we were bound by the APPs regardless. We sell security engineering and we hold configuration data about our clients' environments, so an exemption is not a standard we are comfortable operating to. Where this policy describes an obligation, we treat it as binding on ourselves.

This is a commitment we make publicly, and we expect to be held to it.

2. What we collect

2.1 Enquiries

When you contact us through the website or by email, we collect your name, email address, organisation and whatever you include in your message.

2.2 Free external assessment

When you run a free check you provide a domain name, a work email address and, optionally, an organisation name. You also confirm that you are authorised to request an assessment of that domain. We record that confirmation together with the time of submission, the originating IP address and the browser user agent, so that we can demonstrate the assessment was authorised.

Free checks are limited to three per domain and per email address in a rolling quarter.

The check itself collects information about the domain you submit from publicly available sources: DNS records, published mail authentication records, TLS and web server configuration, certificate transparency logs and internet-exposed service information. This is information already visible to anyone on the internet. It is not personal information in most cases, but it may incidentally include personal information where an organisation has published it, for example in a registration record.

2.3 Client accounts and the portal

If you become a client we collect the name, email address and role of the people we deal with, your organisation's details, and account credentials for the portal.

2.4 Assessment data

When you engage us for a credentialed assessment, our scanning tools read configuration from the cloud environments in scope. The results we retain can include:

Some of this is personal information about your staff. We collect it because it is the evidence behind each finding, and because a finding without its evidence is not useful to you.

2.5 What we do not collect

We do not store your cloud credentials. The scanners run on an RG Labs operator workstation in Australia, not on the hosted platform. Credentials exist only on that workstation, for the duration of an assessment, and are revoked at the end of it. The platform has no ability to authenticate to, connect to or act against your environment.

We do not collect sensitive information as defined in the Privacy Act (health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and similar) and we ask that you do not send it to us.

2.6 Payments

Payments are processed by Stripe. Card details are entered directly with Stripe and are never received or stored by us. We retain the transaction record, the billing name and address, and the tax invoice.

2.7 Website analytics

rglabs.com.au uses Google Analytics 4 to understand aggregate traffic: pages visited, approximate city-level location and device or browser type. Google sets first-party analytics cookies such as _ga and processes this data on our behalf. We do not use advertising cookies, we do not build marketing profiles and we do not sell data.

You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout, or by blocking cookies in your browser.

3. How we use it

We do not use assessment data for any purpose other than delivering your assessment and the services you have engaged us for. We do not use it to train machine learning models, our own or anyone else's. We do not aggregate it into published benchmarks or research unless you have separately agreed in writing.

4. Artificial intelligence in report generation

Our reports include plain-English explanations of each finding. Those explanations are generated using a large language model.

Identifiers are removed before anything is sent. Every value that identifies a person, an account or a specific resource is replaced with a consistent placeholder before the finding reaches the model. User principal names, email addresses, display names, tenant and subscription identifiers, account numbers, resource names, hostnames and IP addresses are all substituted. The mapping between the real values and the placeholders is held in our database in Australia and is never transmitted.

The real values are substituted back in when your report is rendered, so the report you receive contains full detail. The model never receives it.

Credentials, secrets and authentication material are never sent, because they never enter the platform in the first place.

Content collected from your environment is passed to the model as clearly delimited untrusted input, with explicit instructions that it is never to be treated as an instruction. This protects against a prompt injection attempt planted in a client environment, for example a resource deliberately named to manipulate the output of a report.

You can switch AI-generated narrative off in your portal settings. If you do, you receive the findings and evidence without the written explanation. The findings themselves are produced entirely by the scanning engines and are unaffected.

5. Who we disclose it to

We do not sell personal information. We disclose it only to the service providers below, and only to the extent needed to deliver the service, or where required by law.

ProviderRoleWhat they receiveLocation
CloudflareHosting, database, access control, bot protection, DNSAll platform dataDatabase in Oceania; edge processing global
AnthropicReport narrative generation for the Security Controls Assessment. Not used for a Snapshot, and not used at all if you switch AI narrative off in your portal settingsTokenised findings only, no identifiersUnited States
Cloudflare Workers AIReport narrative generation, fallback engine — same scope and the same switchTokenised findings only, no identifiersCloudflare network
ResendTransactional email deliveryRecipient name and email addressUnited States
StripePayment processingBilling and payment detailsUnited States and Australia
Shodan InternetDBInternet-exposed service lookupPublic IP addresses of the domain assessedUnited States
SSLMate certspotterSubdomain discovery via Certificate TransparencyDomain name queriedUnited States
crt.shCertificate Transparency fallbackDomain name queriedCzech Republic
GoogleWebsite analytics (rglabs.com.au only)Aggregate traffic dataUnited States

Certificate Transparency sources return information that is public by design. CT logs are a public record of issued certificates, and no client data is disclosed to them beyond the domain being queried.

6. Overseas disclosure

Several of the providers above are located outside Australia, as set out in the table. Where we disclose personal information to an overseas recipient we take reasonable steps to ensure they handle it consistently with the APPs, and we remain accountable for that handling.

The assessment database itself does not leave Australia. See the next section.

7. Where your data is stored

Assessment data, findings, reports and client records are held in a Cloudflare D1 database in the Oceania region. Read replication is disabled, so there is exactly one copy of that database and it does not leave the region.

We want to be precise about what that does and does not mean. Cloudflare D1 offers a jurisdiction setting that contractually binds a database to a legal region, but that feature currently supports the European Union and US FedRAMP only. There is no Australian jurisdiction option available. Our database is therefore located in Oceania by regional placement rather than by a contractual jurisdiction lock.

We state this openly rather than describing the platform as offering guaranteed Australian data residency, which would overstate what the underlying service provides.

Separately, and as set out in section 5, specific data elements are disclosed to named third parties, some of which are offshore. Regional database placement and third-party disclosure are two different things, and both are true.

If you have a binding data residency obligation, raise it during scoping and we will address it directly.

Backups are encrypted and held in the same region.

8. How long we keep it

DataRetention
Snapshots and assessment reports12 months from delivery, then deleted
Clients on an annual re-assessmentLife of the arrangement plus 12 months
Extended retentionOnly where you opt in, for the period you specify
Enquiries that do not become engagements24 months
Tax and transaction records5 years, as required by Australian tax law
Backups30 days

Deletion on request. You can ask us to delete your data at any time, through your portal or by email, without giving a reason. We delete it from live systems within 5 business days and purge it from all backup and recovery history within 30 days. We retain a minimal audit record of the deletion itself (which account, when, at whose request) containing no assessment content.

Tax records are the one exception we cannot delete on request, because we are legally required to hold them.

9. Security

No system is perfectly secure, and we will not claim otherwise.

10. Data breaches

If we become aware of a security incident affecting personal information we hold, we will assess it promptly.

Where an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme, whether or not the scheme formally applies to us at the time.

Where the breach affects a client's data, we will notify that client directly and promptly, with what we know, what we do not yet know, and what we are doing about it. We will not wait for certainty before telling you something has happened.

11. Direct marketing

We send two kinds of email, and we keep them separate.

Transactional messages relate to something you asked for: your assessment result, your report, a renewal notice, a failed payment. We send these because you are using the service.

Marketing messages go only to people who have expressly opted in. Every one identifies us as the sender, includes our contact details, and carries a working unsubscribe link that we action promptly. Unsubscribing from marketing never stops your transactional messages.

The only marketing email we send is a monthly check-in: where your domain stands, the one thing worth fixing first, and news about our services such as the Snapshot. You ask for it by ticking the separate, unticked box on the free check, or in your portal under Account → Data and privacy. Each person chooses for themselves; a colleague's choice doesn't sign you up.

When you ask for it, we record your email address, when you asked, where (the free check or your portal), the exact words you agreed to, and the IP address and browser you used, so we can show what you consented to. If we change what the check-in covers, we ask again rather than treating your earlier yes as agreement.

You can opt out at any time with the one-click unsubscribe link in every check-in (no login needed), in your portal, or by emailing us. We act on it straight away. We keep a record that you opted out, so a later import can't sign you up again.

12. Access, correction and complaints

You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it. Email us using the details below and we will respond within 30 days.

If you are not satisfied with our response, contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.

13. Business continuity

RG Labs is a small business. If we cease trading, clients will be given 30 days to retrieve their reports and data from the portal, after which all client data will be deleted.

14. Changes to this policy

We will update this policy when our practices change, and the date at the top will reflect the most recent revision. Where a change materially affects how we handle data we already hold, we will notify affected clients directly rather than relying on you noticing.

15. Contact

Privacy questions: privacy@rglabs.com.au
Security issues: security@rglabs.com.au (see our vulnerability disclosure policy)

RG Labs
ABN 26 465 879 682
Melbourne, Victoria, Australia