What this covers
How ThreatCanary handles personal information.
Plain-language details for website visitors, customers, partners and researchers. Effective 27 July 2026.
01What we collect
- Website forms collect the identity, business contact, organisation and enquiry details you choose to provide. If required fields are not supplied, we may not be able to route or answer the request.
- We also process limited technical submission data, timestamps and anti-abuse signals to protect the forms and investigate delivery failures.
- When you use ThreatCanary services, applicable contracts govern account details, authorised scope, configuration, findings, evidence, audit records and operational telemetry.
02Why we use it
- To answer demo, contact, partnership, support, assurance, research and media enquiries and to maintain an appropriate record of those conversations.
- To provide and secure our services, administer accounts, maintain auditability, prevent abuse and meet legal or contractual obligations.
- We do not sell or rent personal information. We do not use sensitive security material submitted through a marketing form because those forms are not intended to receive it.
03Service providers and disclosure
- Authorised ThreatCanary personnel receive enquiries according to their business purpose. Access is limited to people who need it to respond or operate the service.
- AWS supports form hosting, queuing, processing and email delivery. Our business email and other operational providers may also process information on our behalf.
- We may disclose information to professional advisers, regulators or law-enforcement bodies where reasonably necessary or required by law, or in connection with a corporate transaction subject to appropriate safeguards.
04Location and overseas handling
- The core marketing form service runs in the AWS Sydney region. Enquiries are delivered to ThreatCanary's business email environment for follow-up.
- Global delivery and security services may process limited request metadata outside Australia. Email, support or business service providers may process enquiry information in other countries, depending on their infrastructure and our configuration.
- When information is handled overseas, we use reasonable contractual, access and security measures appropriate to the service and the information involved.
05Retention and deletion
- Marketing form messages are normally processed promptly. Temporary queue copies expire within four days; failed-delivery queue copies expire within 14 days.
- Operational form logs are retained for about one month and are designed to record processing outcomes and anti-abuse reason codes rather than submitted form content.
- Enquiry correspondence in business email is kept only while reasonably needed for follow-up, business records, disputes or legal obligations, then deleted or securely archived under the applicable retention process.
06Security and data minimisation
- We use encryption in transit, encrypted service queues, least-privilege access, validation, rate controls, anti-spam checks and monitored delivery workflows for marketing forms.
- Please do not submit passwords, credentials, secrets, health information, classified material or sensitive security evidence through a website enquiry form.
- No internet transmission or storage method is risk-free. We review safeguards as our services and risks change and do not present this policy as a security certification.
07Access, correction and complaints
- ThreatCanary Pty Ltd is responsible for this policy. Email hello@threatcanary.io to request access, correction or deletion where applicable, or to ask a privacy question. We may need to verify your identity.
- Mark privacy complaints clearly. We will acknowledge the issue, investigate it and explain the outcome or any lawful reason we cannot fulfil a request.
- If you remain dissatisfied, you may contact the Office of the Australian Information Commissioner (OAIC) or another privacy regulator or dispute body available to you under applicable law. Contractual privacy contacts apply where customer agreements specify them.