VTARATECH

PRIVACY POLICY

Last updated: August 2026

VCLARIFI is committed to protecting privacy and handling personal information responsibly, transparently and securely.

This Privacy Policy explains how VCLARIFI collects, holds, uses, discloses and protects personal information when you access our websites, products, applications and services.

We manage personal information in accordance with applicable privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply.

1. Information we collect

Depending on how you use VCLARIFI, we may collect:

  • your name, email address, organisation and contact information

  • account, subscription and authentication information;

  • information you provide when creating or managing a Decision Case;

  • documents, evidence, assumptions, comments and other information submitted to the platform;

  • information concerning decisions, authorities, approvals and governance events;

  • communications with VCLARIFI, including support requests and feedback;

  • transaction and billing information;

  • technical information such as device, browser, IP address, log and security information; and

  • usage information relating to your interaction with the platform.

Information submitted to a Decision Case may contain personal information about you or other individuals. You are responsible for ensuring you have the necessary authority or lawful basis to provide that information to VCLARIFI.

We do not require sensitive information unless it is reasonably necessary for the relevant purpose. Users should avoid submitting unnecessary sensitive information.

2. How we collect information

We may collect information:

  • directly from you;

  • through your use of VCLARIFI;

  • from an organisation that provides you access to VCLARIFI;

  • through authorised integrations and connected systems;

  • from service providers acting on our behalf; or

  • automatically through security, operational and analytics technologies.

Where practicable and lawful, you may interact with us anonymously or using a pseudonym. Certain VCLARIFI functions require identification because identity, attribution or authority forms part of the governance record.

3. How we use information

We may use information to:

  • provide, operate and secure VCLARIFI;

  • establish and administer accounts;

  • create, process and maintain Decision Cases and governance records;

  • authenticate users and establish attribution or authority;

  • provide requested analysis, reports and platform functionality;

  • maintain auditability and integrity of governance events;

  • detect fraud, misuse and security threats;

  • provide customer support;

  • administer subscriptions and payments;

  • monitor and improve platform reliability and performance;

  • comply with legal, regulatory and contractual obligations; and

  • communicate with you about VCLARIFI where permitted by law.

We will not use personal information for an unrelated purpose unless permitted or required by law or appropriate consent has been obtained.

4. VCLARIFI, AI and automated processing

VCLARIFI may use computational and artificial intelligence systems to assist with functions such as identifying assumptions, analysing evidence, identifying contradictions or dependencies, generating questions, assessing decision conditions and presenting information for consideration.

VCLARIFI is designed to support structured decision governance. It does not mean that every output constitutes an autonomous decision about an individual.

Where VCLARIFI uses personal information in connection with automated or AI-assisted processing, we will manage that information in accordance with applicable privacy requirements.

Where required by applicable law, we will provide information about substantially automated decisions that use personal information and could reasonably be expected to significantly affect an individual's rights or interests.

5. Customer data and AI model training

Customer information and Decision Case content remain subject to the rights set out in our Terms of Use and applicable customer agreements.

VCLARIFI does not use private customer Decision Case content to train publicly available or general-purpose AI models unless the customer has expressly agreed to that use.

Where third-party AI or infrastructure providers are used to deliver a VCLARIFI function, information is provided only as reasonably necessary to deliver that function and subject to appropriate contractual, privacy and security controls.

6. Disclosure of information

We may disclose information to:

  • technology, infrastructure and cloud service providers;

  • payment and subscription providers;

  • security and authentication providers;

  • professional advisers;

  • contractors supporting the operation of VCLARIFI;

  • an organisation administering your VCLARIFI account; and

  • regulators, courts, law enforcement agencies or other parties where disclosure is required or authorised by law.

We do not sell personal information.

7. Overseas processing and disclosure

Some service providers used by VCLARIFI may process or store information outside Australia.

Where personal information is disclosed to an overseas recipient, VCLARIFI will take steps required by applicable law in relation to that disclosure.

Information about countries in which relevant overseas recipients are located will be maintained in this Privacy Policy where required and reasonably practicable.

Current overseas processing locations: (TBC AWS)

8. Data security

VCLARIFI applies administrative, technical and organisational safeguards designed to protect information against misuse, interference, loss, unauthorised access, modification and disclosure.

Security measures may include, as appropriate:

  • encryption in transit and at rest;

  • identity and access controls;

  • authentication controls;

  • tenant and data segregation;

  • logging and monitoring;

  • vulnerability and patch management;

  • secure development practices;

  • backup and recovery controls;

  • incident response procedures; and

  • access restrictions based on operational need.

No digital system can be guaranteed to be completely secure. VCLARIFI continually assesses security risk and develops its controls as the platform and threat environment evolve.

Further information is available in our Security & Assurance statement.

9. Data retention

We retain personal information only for as long as reasonably required for the purposes for which it was collected, to provide the services, maintain legitimate governance and audit records, or satisfy legal, regulatory and contractual obligations.

Where information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to applicable retention requirements and legitimate system backup processes.

Certain governance records may need to be retained to preserve the integrity, attribution and auditability of a Decision Case.

10. Access and correction

You may request access to personal information VCLARIFI holds about you or request that inaccurate, incomplete or out-of-date information be corrected.

Requests may be subject to exceptions permitted by law.

Contact us at privacy@vtaratech.com

11. Data breaches

VCLARIFI maintains processes for assessing and responding to suspected or confirmed data breaches.

Where a breach is subject to the Notifiable Data Breaches scheme, VCLARIFI will assess the incident and make notifications to affected individuals and the Office of the Australian Information Commissioner where required by law.

12. Cookies and analytics

VCLARIFI may use cookies and similar technologies for authentication, security, preferences, platform operation and analytics.

Where required, you may control optional cookies through available consent or browser settings.

13. Complaints

If you have a privacy concern or believe VCLARIFI has not handled your personal information appropriately, contact:

Privacy Officer
VCLARIFI
Email: privacy@vtaratech.com

We will investigate and respond to privacy complaints within a reasonable period.

If you are not satisfied with our response, you may have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) or another applicable regulator.

14. Changes to this policy

We may update this Privacy Policy to reflect changes to our services, technology, legal obligations or information-handling practices.

The current version will be published on the VCLARIFI website with its effective or last-updated date.

15. Contact

For privacy enquiries:

VCLARIFI
Operated by: VTARA TECH PTY LIMITED

ABN: 28 619 398 462
Email: privacy@vtaratech.com
Address: Skyline Drive, Tweed Heads West, NSW Australia 2485