Privacy Policy
Last updated: [DATE] · Version: draft 0.1
1. Our approach
nexreg.ai ([LEGAL ENTITY NAME], ABN [ABN]) collects as little personal information as we can, and only what we need to run our services. Some small businesses are exempt from the Privacy Act 1988 (Cth). Whether or not that exemption applies to us, we aim to handle personal information in line with the Australian Privacy Principles.
2. What we collect
- Free quiz: nothing. The quiz runs entirely in your browser. Your answers are not sent to us or stored by us.
- Waitlist: your email address, an optional description of your role or firm size, and a record of your consent.
- Readiness Check purchase: your name, email, business name and billing details. Card payments are handled by Stripe; we do not receive your full card number.
- Readiness Check questionnaire: information about your firm, its services and its AML/CTF processes, and any documents you choose to share. This may include names and roles of your staff (for example, your AML/CTF compliance officer).
- Correspondence: anything you include when you email us.
Please don't send us your clients' personal information or identity documents. We don't need them. If you send them by mistake, we will delete them and let you know.
You can browse the site and use the quiz without identifying yourself (APP 2). We need contact details to deliver a paid service.
3. Website data, cookies and analytics
We do not currently use advertising or tracking cookies. Our hosting provider (Cloudflare) processes technical data such as IP addresses to deliver and protect the site. [Update if analytics are added; prefer cookieless analytics.]
4. How we use it
- To deliver the Readiness Check and communicate with you about it.
- To send waitlist updates you've agreed to receive.
- To process payments, keep business and tax records, and meet legal obligations.
- To improve our questionnaire and report templates, using de-identified information only.
We do not sell personal information. We do not use your questionnaire answers or documents to train third-party AI models. [Confirm with the AI provider's data-use terms.]
5. AI processing and human review
We use AI software to draft gap reports from the information you provide. A person reviews every report before it is sent. Information you share may be processed by our AI provider for this purpose under its business terms. [Name the AI provider, its data-retention settings and processing location.]
6. Who we share it with
We share personal information only with service providers who help us run nexreg.ai, and only as needed:
- Stripe (payments)
- Cloudflare (website hosting and security)
- [Email / waitlist provider]
- [AI provider]
- [Document storage / database provider (prefer Australian region)]
We may also disclose information where the law requires it.
7. Overseas disclosure (APP 8)
Some of these providers may store or process information outside Australia, including in [COUNTRIES, e.g. the United States]. Where practical, we choose Australian data regions and take reasonable steps to ensure overseas recipients handle information consistently with the APPs.
8. Security and retention (APP 11)
We use encryption in transit and at rest where our providers support it, restrict access to people who need it, and use multi-factor authentication on our accounts. We keep questionnaire material and reports for [RETENTION PERIOD, e.g. 12 months after delivery] unless you ask us to delete them sooner or we must keep them longer by law (for example, tax records). Waitlist details are kept until you unsubscribe or the waitlist closes. We securely delete or de-identify information we no longer need.
9. Marketing and unsubscribing (APP 7)
We send marketing emails only with your consent. Every email identifies us and includes an unsubscribe link, and we act on unsubscribe requests promptly.
10. Access and correction (APPs 12 and 13)
You can ask to see or correct the personal information we hold about you, or ask us to delete it, by emailing hello@nexreg.ai. We'll respond within 30 days.
11. Data breaches
If a data breach is likely to cause serious harm, we will notify affected people and, where required, the Office of the Australian Information Commissioner (OAIC). [Lawyer to confirm Notifiable Data Breaches scheme applicability.]
12. Complaints
If you have a privacy concern, contact us first at hello@nexreg.ai. We aim to respond within 30 days. If you're not satisfied, you can contact the OAIC at oaic.gov.au.
13. Changes
We'll update this policy when our practices change and show the date of the latest version at the top.