Privacy Policy
Last updated: 1 August 2026 (draft v0.1)
1. Who is responsible
[Legal entity / trading name, ABN xx xxx xxx xxx], New South Wales, Australia, is the data controller for personal information processed through a50check.com. Contact for anything in this policy, including access and deletion requests: privacy@a50check.com.
2. What we collect
- Questionnaire answers— your responses about your organisation's AI and content practices. These describe your business, not individuals; please do not include personal information about individuals in free-text fields.
- Email address — collected by Stripe at checkout, used to deliver your pack and correspond about your order.
- Order records — order status, the requirements matched to your answers, timestamps, and review/approval records.
- Generated documents — the pack produced for your order.
- Payment data — handled entirely by Stripe; we never see or store card numbers.
- Basic technical data — [if analytics enabled: privacy-friendly, aggregate site analytics; no advertising trackers].
The free report runs in your browser; answers are only stored by us if you proceed to checkout.
3. Why we process it (lawful bases)
- To provide the report and deliver your pack — performance of a contract.
- To review, correct, and improve the service, keep records, and secure the platform — legitimate interests.
- To meet tax and accounting obligations — legal obligation.
We do not sell personal information, and we do not use your answers or documents to market to third parties.
4. Who processes it for us (sub-processors)
- Supabase — database and document storage (region: [Sydney, Australia / region you selected])
- Stripe — payments
- Resend — email delivery
- Anthropic — AI generation of documents (order answers and matched requirements are sent to generate your pack)
- Vercel — website hosting
5. International transfers
We are located in Australia, and data is stored in the region above; some sub-processors process data in other countries, including the United States. Where GDPR applies to you, transfers rely on appropriate safeguards such as standard contractual clauses in our sub-processors' terms. [FLAG FOR LAWYER — confirm transfer wording once the Supabase region and entity structure are settled.]
6. How long we keep it
Order records and generated documents are retained for up to 24 months after delivery, for support, correction, and record-keeping purposes, then reviewed for deletion. You can ask us to delete your order earlier at any time (see below).
7. Your rights
If you are in the EU/EEA or UK, you have GDPR rights over your personal data, including access, rectification, erasure, restriction, portability, and objection. Australian users have rights under the Privacy Act 1988 (Cth). To exercise any of these — including full deletion of your order, answers, and documents — email privacy@a50check.com from the address used at checkout. We aim to respond within [30] days. You may also lodge a complaint with your local supervisory authority.
8. Security
Access to stored orders is restricted to authorised reviewers over authenticated, encrypted connections; database access from the public internet is disabled.
9. Changes
We will post any changes to this policy on this page with an updated date.
