Legal

Privacy policy

40° South AI Pty Ltd (ABN pending)

Effective date: March 2026

1. About this policy

This privacy policy explains how 40° South AI Pty Ltd ("40 South," "we," "us," "our") collects, uses, stores, and discloses personal information. It applies to the 40south.au website, the 40 South Guard platform, and any related services.

We're an Australian company registered in New South Wales. We take privacy seriously, not just because it's our legal obligation, but because our entire product exists to help businesses meet theirs.

2. What personal information we collect

Website visitors: We collect information you provide through our contact and enquiry forms, including your name, email address, company name, and industry. We also collect standard web analytics data (pages visited, time on site, referral source) through privacy-respecting analytics tools.

Guard platform users: When you use the Guard platform, we collect your name, email address, and role as provided by your organisation's administrator. We also collect usage data related to your interactions with the Guard dashboard.

Guard proxy data: Guard processes AI interactions on behalf of our customers. This data may contain personal information that our customers' employees send to AI models. We process this data as a service provider acting on our customer's instructions. We do not use this data for our own purposes. We do not train AI models on this data. We do not sell this data.

Guard's PII detection identifies sensitive data types (Tax File Numbers, Medicare numbers, ABNs, bank account numbers, and others) within AI interactions. When PII is detected, the finding is recorded in the audit trail (the type and location, not the PII itself). Evidence records are scrubbed of raw PII before storage.

3. How we collect personal information

We collect personal information directly from you (forms, account creation, email), from your organisation's administrator (account provisioning), automatically (cookies, server logs, analytics), and through the Guard proxy (AI interactions processed on your organisation's behalf).

4. Why we collect personal information

We collect and use personal information to provide and operate Guard, respond to enquiries, manage accounts, generate compliance reports and audit evidence, send service-related communications, improve our products, and comply with our legal obligations.

We do not use personal information collected through the Guard proxy for marketing, profiling, or any purpose other than providing the Guard service.

5. How we store and protect personal information

All data is processed and stored in Australia, specifically in Google Cloud's Sydney region (australia-southeast1), with failover to Melbourne (australia-southeast2). Data never leaves Australian borders.

We protect personal information using encryption at rest (customer-managed encryption keys), encryption in transit (TLS 1.2+), VPC Service Controls, role-based access controls (Firebase Authentication), Cloud IAP for administrative access, and regular security assessments.

Our infrastructure runs on Google Cloud Platform, which is IRAP PROTECTED assessed and SOC 2 Type II certified.

6. How long we keep personal information

Website enquiry data: 24 months, then deleted unless there is an ongoing business relationship.

Guard platform account data: Duration of the customer's subscription, plus 90 days after termination for data export.

Guard audit trail data: 7 years in a tamper-evident, immutable audit trail. This meets regulatory requirements under APRA CPS 234 and ADM transparency obligations.

Analytics data: Aggregated, non-identifiable analytics may be retained indefinitely.

7. Disclosure of personal information

We do not sell personal information. We do not disclose personal information to overseas recipients. All data remains in Australia.

We may disclose personal information to our infrastructure provider (Google Cloud Platform, under a data processing agreement in Australian data centres), your organisation's administrators (as part of the service), and law enforcement or regulators (if required by Australian law).

8. Cross-border disclosure (APP 8)

40 South does not transfer personal information outside Australia. Our infrastructure is in Australian data centres, our team is in Australia, and we do not use overseas sub-processors for data containing personal information.

Guard's core function includes monitoring whether our customers' AI interactions involve cross-border data flows. When a customer sends data to an overseas AI provider through Guard, Guard flags the APP 8 implications and records them in the attestation.

9. Cookies and tracking

Our website uses cookies for essential functionality (session management, theme preference). We use privacy-respecting analytics to understand how visitors use our site. We do not use third-party advertising trackers.

You can disable cookies in your browser settings. The website will still function, but some features may not work as expected.

10. Your rights

Under the Australian Privacy Principles, you have the right to access the personal information we hold about you, request correction of inaccurate information, request deletion (subject to legal retention obligations), and lodge a complaint if you believe we have breached the APPs.

To exercise any of these rights, contact us at privacy@40south.au. We will respond within 30 days.

11. Notifiable data breaches

In the event of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988.

12. Changes to this policy

We may update this policy from time to time. When we do, we will update the effective date at the top. For material changes, we will notify Guard platform customers by email.

13. Contact us

Privacy enquiries: privacy@40south.au

General enquiries: hello@40south.au

40° South AI Pty Ltd, New South Wales, Australia

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

40° South acknowledges the Traditional Custodians of the lands on which we work and live. We pay our respects to Elders past, present, and emerging, and recognise their continuing connection to land, waters, and culture.