Privacy Policy

Last updated: 7 July 2026

1. Introduction

INNONET PTY LTD ACN 625 992 529 as trustee for the Sharma Family Trust, ABN 31 598 198 475, trading as "CYBERWHITE" ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our compliance delivery platform and related services.

2. Information We Collect

2.1 Information You Provide

  • Account registration information (name, email, company details)
  • Profile information and organizational data
  • Assessment responses and security questionnaire data
  • Microsoft 365 tenant data (when you connect your M365 environment)
  • Payment and billing information
  • Communications with our support team

2.2 Information We Collect Automatically

  • Usage data and platform analytics
  • Device information (IP address, browser type, operating system)
  • Log files and system performance data
  • Cookies and similar tracking technologies

2.3 Microsoft 365 Integration Data

  • Security scores and compliance status
  • Security policies and configurations
  • User and license information
  • Security alerts and recommendations

3. How We Use Your Information

We use the collected information to:

  • Provide and maintain our compliance delivery services
  • Process security assessments and generate compliance reports
  • Assess your compliance using our CARS algorithm
  • Provide cross-framework compliance mapping and recommendations
  • Process payments and manage subscriptions
  • Send service-related communications and updates
  • Improve our platform and develop new features
  • Ensure platform security and prevent fraud
  • Comply with legal obligations

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information. We may share information in the following circumstances:

4.1 Service Providers

We may share information with trusted third-party service providers who assist us in operating our platform, including cloud hosting, AI processing, payment processing, email delivery, and analytics services. We disclose only the information each provider needs to perform its function, and we require them to protect it. Section 9 sets out the countries where your data is handled.

4.2 Legal Requirements

We may disclose information if required by law, court order, or government regulation, or to protect our rights, property, or safety.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.

4.4 MSP Client Data

For MSP accounts, client data is only accessible to the authorized MSP account holders and their designated users.

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption in transit and at rest using industry-standard protocols
  • Role-based access controls and secure authentication
  • Regular security audits and vulnerability assessments
  • Secure cloud infrastructure with redundancy and backup systems
  • Employee training on data protection and security practices
  • Incident response procedures for security breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

We also minimise the personal information used with AI features. User identifiers, such as names and email addresses, are redacted from scan evidence, and only aggregated compliance findings are used to generate AI insights.

6. Data Retention

We retain your information for as long as necessary to provide our services and comply with legal obligations:

  • Account data: Retained while your account is active and for 3 years after closure
  • Assessment data: Retained for 7 years for compliance and audit purposes
  • Payment records: Retained for 7 years as required by financial regulations
  • System logs: Retained for 12 months for security and troubleshooting

7. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information (subject to legal requirements)
  • Portability: Request transfer of your data in a structured format
  • Restriction: Request limitation of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests

To exercise any of these rights, or if you have a privacy concern or complaint, contact us using the details in section 13. We will respond within a reasonable time. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain your login session and preferences
  • Analyze platform usage and performance
  • Provide personalized content and recommendations
  • Ensure platform security and prevent fraud

You can control cookie settings through your browser preferences, though this may affect platform functionality.

9. Where Your Data Is Handled

We keep your core data in Australia wherever possible. Some supporting services are provided from overseas. In summary:

  • In Australia: your account and compliance data (including assessment and scan results) is stored in our primary database hosted in Sydney, Australia. AI processing of your compliance data is performed using Microsoft Azure OpenAI in Australia; that data is not used to train AI models and stays in Australia.
  • In the United States: payment and billing processing, transactional email delivery, product analytics, error monitoring, and our customer relationship management (CRM).
  • Your Microsoft 365 environment: we read configuration and security-policy data from your own tenant, in its existing region. We store only the resulting compliance data. We do not read or store your emails, files, or documents.

Before disclosing personal information to an overseas provider, we take steps that are reasonable in the circumstances to ensure the provider handles it consistently with the Australian Privacy Principles, and we remain accountable for that information.

10. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18.

11. Third-Party Links

Our platform may contain links to third-party websites. We are not responsible for the privacy practices of these external sites and encourage you to review their privacy policies.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or through our platform. The "Last updated" date indicates when the policy was last revised.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

Privacy Officer
INNONET PTY LTD
ACN 625 992 529 ATF ABN 31598198475
Trading as "CYBERWHITE"
Email: support@cyberwhite.ai