Home / Privacy Policy
Privacy Policy
Last updated 15 September 2026. Privacy Act 1988 (Cth) and the Australian Privacy Principles. TEQNIX Pty Ltd, ABN 46 647 038 524.
1. What this covers
TEQNIX Pty Ltd is committed to protecting the privacy of people who interact with our website, our services and our client portal. This policy explains what we collect, why, who we disclose it to, and what you can ask us to do about it.
In plain terms: we collect what we need to deliver testing and to reply to you. We do not sell it, we do not share it for marketing, and we do not use it to build profiles.
2. What we collect
From enquiries. Name, work email, organisation, what you are considering, and whatever you write in the message field.
From clients. Contact details for the people you nominate for portal access, and billing details sufficient to invoice you.
From engagements. Asset and configuration data, scan output, findings, evidence such as screenshots and request logs, and command-level logs of agent activity. This is engagement data. It can contain personal information where your systems do, which is why section 6 treats it separately.
From the People module, where selected. Aggregate response data for phishing simulations. Individual responses are processed to produce aggregates and are never reported to your management, named, or used for disciplinary purposes.
From the website. Pages visited, browser type, IP address and referrer, through server logs and Google's advertising tag. We do not use analytics products that share data with advertising networks beyond that tag.
We do not collect sensitive information as defined by the Privacy Act unless it is strictly necessary and you have consented.
3. How we collect it
- When you submit the contact form or email us
- When we set up portal accounts for the people you nominate
- During delivery of an engagement, from the systems in the agreed scope
- Through cookies and server logs when you visit teqnix.io
There is no self-serve signup, so we do not collect account details from anyone who is not already speaking to us.
4. Why we use it
- To reply to your enquiry
- To scope, schedule and deliver testing
- To verify domain ownership and authorisation before testing begins
- To provide portal access and issue reports
- To invoice you and keep required financial records
- To meet legal obligations
- To protect the security of our own systems
We do not use your personal information for direct marketing without consent, and we do not use it to train machine learning models.
5. Artificial intelligence
Our testing is delivered by human consultants and agentic AI working together, which means some of your data is processed by a third-party model provider. We would rather state this plainly here than leave you to find it in a contract.
- Who. Anthropic, via Anthropic's commercial API, using Claude models.
- What. Scan output, asset and configuration data, and finding detail for in-scope assets.
- Where. Anthropic processes API requests on infrastructure in the United States. See section 8.
- Training. Under Anthropic's commercial API terms, data submitted through the API is not used to train Anthropic's models.
- Retention at the provider. We use the standard commercial API, so provider-side retention is governed by Anthropic's published terms rather than a bespoke agreement.
- Human oversight. A consultant reviews agent activity each reporting cycle, and no finding reaches you without a person reproducing or confirming it.
If your obligations require testing data to remain in Australia, tell us during scoping.
6. Engagement data
Data generated during testing is treated as confidential to the engagement. It:
- is used solely to deliver the engagement you contracted for;
- is accessible to the consultants assigned to your engagement, and to the people you nominate through the portal;
- is not used to benchmark you against other clients;
- is not used to train models; and
- is retained for twelve months after the engagement ends, then securely deleted, unless you ask in writing for longer or a law requires it.
7. Who we disclose to
We do not sell, rent or trade personal information. We disclose it only:
- To Anthropic, as described in section 5.
- To infrastructure providers that host our systems, under contract.
- To subcontracted consultants, where used, bound by equivalent confidentiality obligations.
- To a payment processor, where you pay electronically. We do not receive or store card numbers.
- Where required by law, a court order or a regulator with lawful authority. We will tell you where we are legally permitted to.
- In a business transfer, if TEQNIX is merged or acquired, with notice to affected individuals and equivalent obligations on the acquirer.
8. Cross-border disclosure
Some of the recipients above are overseas, which engages Australian Privacy Principle 8.
- United States. Anthropic, for the AI processing described in section 5.
- Australia. Our platform infrastructure and engagement data storage.
Where information is disclosed overseas we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including through the contractual terms we accept from those providers. By engaging us you consent to the disclosures described in this section.
9. Security
We take reasonable technical and organisational measures to protect personal information, including encryption in transit using TLS 1.2 or higher, encryption at rest, access limited to personnel who need it, multi-factor authentication on internal systems, and command-level logging of agent activity.
No method of transmission or storage is completely secure, and we do not claim otherwise.
10. Retention
- Enquiries: kept while we are in contact and for a reasonable period afterwards
- Engagement data: twelve months after the engagement ends
- Account records: while the account is active, and up to three years after closure
- Financial records: seven years, as Australian tax law requires
11. Your rights
Under the Privacy Act 1988 (Cth) you may ask us to:
- give you access to the personal information we hold about you;
- correct it where it is inaccurate or incomplete;
- delete it, subject to legal retention requirements; and
- consider a complaint about how we have handled it.
Contact privacy@teqnix.io. We respond within 30 days.
12. Cookies
We use cookies that are necessary for the website and portal to function, including session management and security. The Google advertising tag on this site sets cookies used for conversion measurement. You can block cookies in your browser, though portal functionality will be affected.
13. Children
Our services are for business use by adults. We do not knowingly collect personal information from anyone under 18, and will delete it promptly if we learn we have.
14. Changes
We may update this policy to reflect changes in our practices or the law. The current version is always at teqnix.io/privacy with its revision date. We notify existing clients of material changes by email.
15. Contact and complaints
Privacy Officer, TEQNIX Pty Ltd, 31 Market Street, Sydney NSW 2000, Australia.
privacy@teqnix.io
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, by telephone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.