LAST UPDATED 27 AUGUST 2026
Privacy Policy
What personal information ISO Assist handles, why, and how you can access or correct it. Structured against the Australian Privacy Principles.
1. Who we are
ISO Assist Pty Ltd operates isoassist.com and the ISO Assist platform. Privacy contact: privacy@isoassist.com. This policy is written against the Australian Privacy Principles in the Privacy Act 1988 (Cth).
2. What we collect
- Account information: name, email address, hashed password, second-factor enrolment, session metadata (IP address, browser) and the time you accepted our terms.
- Workspace content you enter: documents, registers, assessments, evidence files, incident and training records. This may include personal information about your workers, contractors and contacts, which you control and we hold on your behalf.
- Connected systems: if you connect Google Workspace or Microsoft 365, file metadata and, where you enable directory sync, workforce names and email addresses.
- Billing information: your organisation's name and billing contact. Card details are handled by our payment provider and never stored by us.
- Website enquiries: the details you submit through our contact form.
- Operational records: an append-only audit log of sensitive actions, and the logs needed to run and secure the service.
We do not use tracking or advertising cookies. Session cookies are required to sign in. The website stores your theme preference in your browser only.
3. Why we handle it
To provide the platform, authenticate you, keep records you are legally required to keep, secure the service, support you, respond to enquiries and bill you. We do not sell personal information, and we do not use your workspace content to train AI models.
4. Where it is held
Your data is stored and processed in Australia. AI features are served from Australia. Where a sub-processor operates outside Australia it is listed in the Data Processing Addendum with the country and purpose.
5. Security
- Encryption in transit and at rest; files served only through short-lived signed URLs.
- Separation of every organisation's data enforced at the database level and tested per release.
- Mandatory second factor for administrative roles; rate limiting on authentication.
- Credentials for connected systems stored in a managed secret store, never in the database.
- An append-only audit log of sensitive actions.
6. Retention and destruction
We keep workspace content while your account is active. You can export everything at any time in an integrity-verifiable archive and request destruction from within the product. A second active owner must approve the request; destruction then runs after a seven-day grace period and removes database records, stored files and stored credentials for connected systems. The append-only audit log is retained as the tamper-evident record of what happened, including of the deletion, for 12 months from the date of each entry, after which entries are destroyed automatically. We may pause a pending deletion only where a documented legal or regulatory preservation obligation applies; the reason and its release are recorded and shown to the workspace.
7. Access and correction
Your own account details are editable in the product. For workspace content held on behalf of your employer, ask your organisation's workspace administrator; if you are that administrator, the export and deletion tools are in Settings. Otherwise contact privacy@isoassist.com and we will respond within 30 days.
8. Data breaches
We maintain an incident response process. Where an eligible data breach is likely to result in serious harm we notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme, and we notify affected customers without undue delay.
9. Complaints
Contact privacy@isoassist.com first. If you are not satisfied you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.