Privacy policy
Effective 12 August 2026. Applies to ironbarkaml.com.au and the Ironbark service.
Who we are
IRONBARKTECH (ABN 29659123086, ASIC business name 1-75912446328), of Joondalup WA AU, trading as Ironbark. We are the entity responsible for the personal information described here.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Contact: hello@ironbarktech.com.au.
What we collect
Information you give us. Your name, work email, business name and ABN when you contact us, request a readiness check, or create an account. Billing details when you buy, which are handled by our payment provider and described below.
Information about businesses you check. Ironbark screens Australian businesses against public registers. The ABNs and entity details you submit are processed to produce a result and retained as a record that the check happened.
Technical information. Server logs, IP address, browser type, pages requested and timestamps. We use privacy-preserving analytics that do not use cookies to track you across sites.
What we do not collect. We do not collect sensitive information as defined in the Privacy Act unless it appears in a public register we search. We do not buy personal information from data brokers.
Public register data
Our results are drawn from Australian public registers and published sanctions lists, including the Australian Business Register, ASIC, AUSTRAC, DFAT consolidated sanctions, AFSA and the Federal Court. That information is published by those bodies, not by us. We reproduce it, record when we retrieved it, and show the source.
If you believe a register entry about you is wrong, the correction has to be made at the source, because we reflect what the register says. Tell us as well and we will note the dispute against the record and refresh it once the source changes.
How we use it
To provide the service: run checks, return results, maintain your account, take payment, and keep the audit record a compliance tool has to keep. To support you when you contact us. To keep the service secure and detect abuse. To meet our own legal obligations.
We do not sell personal information. We do not use your data or your check history to train AI models, and we do not permit our AI sub-processors to train on it.
Where your data lives
Customer data is resident in Australia: AWS Sydney (ap-southeast-2) with disaster recovery in Melbourne (ap-southeast-4). Encrypted at rest with AES-256 and in transit with TLS 1.3.
Some sub-processors operate control planes outside Australia even where data is stored here. That is disclosed per vendor on our sub-processor register, which lists every vendor, what it receives, and which countries are involved. We give 30 days notice of changes to that register.
Who we share it with
Our sub-processors, for the purposes listed on the register, under contract and only as needed to run the service. Professional advisers where we need advice. Law enforcement or a regulator where we are legally required to disclose, and we will tell you unless we are prohibited from doing so.
We do not disclose your check history to the businesses you check.
How long we keep it
Account and contact information: while your account is open, then removed or de-identified after the closure window below.
Check records and the audit log: seven years, in an immutable store. This is deliberate and it is not something we can shorten on request. Ironbark exists to evidence that a check was performed at a point in time, and an audit record you can delete is not evidence. Where a record must be kept, we remove or de-identify the personal information in it that is no longer needed rather than destroying the record.
Server logs: retained for a limited operational period and then discarded.
Your rights
Access. You can ask for a copy of the personal information we hold about you. We will respond within 30 days.
Correction. You can ask us to correct information that is wrong. For public register data, see the section above.
Deletion. You can ask us to delete your account. We will close it, end billing, revoke access, and after a short reversal window remove or de-identify your personal information, except where a record is subject to the seven-year retention above. We will tell you specifically what is retained and why rather than claiming everything was erased.
Complaints. Email us first and we will work through it. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
If something goes wrong
We operate under the Notifiable Data Breaches scheme. If a breach is likely to cause you serious harm, we will notify you and the OAIC. Our target is to notify affected customers within 24 hours of confirming an eligible breach, ahead of the statutory assessment period.
To report a vulnerability, see our disclosure page.
Changes to this policy
We will post changes here with a new effective date. For changes that materially affect how we handle your information, we will tell account holders directly.
Related: Terms of service · Security · Sub-processors