Privacy Policy-How Omnicomply handles personal information
Last updated: 19 August 2026
1. About this policy
Omnicomply Pty Ltd (Omnicomply, we, us or our) provides an AI-enabled governance, risk and compliance platform. This Privacy Policy explains how we handle personal information when you visit our website, contact us, register for a pilot or demonstration, work with us as a customer, partner or supplier, create an account, use the Omnicomply platform, or otherwise interact with us.
We use one global privacy baseline. Where a local law gives you additional rights or imposes stricter requirements, that local law applies. This policy is intended to support compliance with applicable privacy requirements in Australia, the EU/EEA, Singapore and Malaysia.
If your organisation uses Omnicomply to process personal information for its own purposes, your organisation remains responsible for its own privacy notices and legal basis for that processing.
2. Who is responsible for your information
Omnicomply Pty Ltd (ABN 84 687 271 843), Victoria, Australia, is responsible for personal information where we decide why and how it is used – for example, information about website visitors, prospects, pilot applicants, account administrators, business contacts, partners and suppliers.
For customer content placed in the Omnicomply platform, the customer will usually decide why the information is processed and Omnicomply will process it on the customer’s instructions and under the customer agreement.
For privacy questions or requests, contact info@omnicomply.ai.
3. Personal information we collect
| Interaction | Information we may collect |
| Website use | IP address, browser and device details, approximate location, pages viewed, referring page, timestamps, session, security and cookie or similar identifiers. |
| Enquiry, pilot or demo | Name, role, business email, mobile number, business name, industry, operating countries, head office location, enquiry details and lead-source information. |
| Customer and account administration | Account identifiers, organisation, role, permissions, authentication information, commercial and contact records, support communications and account administration details. |
| Platform use | Activity and audit logs, workflow and approval information, diagnostic and security events, service usage and technical information. |
| Customer content | Policies, evidence, assessment responses, control and risk information, documents and other information provided or generated through the service. Customer content may contain personal information about other people. |
| Partners, suppliers and advisers | Business contact details, correspondence, due diligence, contracting and relationship-management information. |
Our general website forms are not designed to collect sensitive information. Please do not send sensitive personal information through a general enquiry form unless it is genuinely necessary and we have asked for it.
4. Where information comes from
Most information comes directly from you. We may also receive personal information from:
- your employer, account administrator or another authorised person in your organisation;
- a referral, channel or business partner;
- service providers that support our website, communications, security or customer relationship processes;
- publicly available professional or business sources where it is appropriate and lawful to use them; and
- the operation of our website and platform, including logs, cookies and similar technologies.
If we receive personal information about you from another source, we will provide the information required by applicable law at the appropriate time unless an exception applies.
5. How and why we use personal information
We use personal information only for identified business, service, security and legal purposes, including to:
- respond to enquiries, arrange demonstrations and administer pilot registrations;
- create accounts, authenticate users and administer roles and permissions;
- provide, support, maintain and secure the Omnicomply platform;
- process assessments, evidence, workflows and reports requested by customers;
- detect misuse, fraud, threats, incidents and technical problems;
- improve our website, platform, service quality and customer experience;
- manage customer, partner, supplier and adviser relationships;
- send relevant business communications where local law permits and honour opt-out requests;
- meet legal, regulatory, contractual, audit and recordkeeping obligations; and
- protect Omnicomply, our customers and the security and integrity of our services.
Where the EU GDPR applies, our legal basis will depend on the activity. We generally rely on performance of a contract, steps requested before entering a contract, our legitimate interests in operating and securing the business, consent where required, or compliance with a legal obligation.
Where we rely on consent, you can withdraw consent for future processing. Where we rely on legitimate interests, we consider whether our interests are necessary and proportionate and whether they are overridden by your rights.
6. Information you need to provide
Fields marked as required are needed so we can process the relevant request. If you do not provide required information, we may not be able to assess a pilot registration, create an account, provide a requested service or respond to the request.
Other fields are optional unless we tell you otherwise.
7. AI and automated processing
AI is part of the Omnicomply platform, but it is designed to support accountable human decision-making rather than replace it. Depending on the feature and customer configuration, AI may help organise information, map obligations, analyse evidence, identify possible gaps, draft summaries or recommendations, and support reporting or workflow tasks.
Customers and authorised users are expected to review outputs and make decisions within their own governance processes. We do not currently use information collected through our website enquiry or pilot forms to make decisions about people based solely on automated processing that produce legal or similarly significant effects.
If we introduce significant automated decision-making involving personal information, we will assess it before deployment and provide the transparency, rights and safeguards required by applicable law.
8. Who we share information with
We do not sell personal information. We disclose it only where there is a legitimate service, business, security or legal reason. Recipients may include:
- cloud hosting, infrastructure, identity, security and monitoring providers;
- customer relationship management, communications, collaboration and support providers;
- website, analytics and other technology providers where those technologies are enabled;
- professional advisers, auditors, insurers and consultants;
- contractors or specialist partners that help us provide the service;
- channel or referral partners where that is relevant to your relationship with us;
- regulators, courts, law enforcement or government bodies where disclosure is required or authorised by law; and
- a genuine buyer, investor, lender or adviser involved in a corporate transaction, subject to appropriate safeguards.
Service providers that process personal information for us are expected to use it only for the agreed purpose and to apply appropriate privacy, confidentiality and security safeguards.
9. International data sharing and data residency
Our corporate website and the personal information collected directly through it are hosted and stored in an Australian data centre. This means information you provide through our corporate website, including enquiry, pilot and demonstration forms, may be stored in Australia even if you reside in another country.
For personal information processed through the Omnicomply platform, our data-residency approach is to keep that information in the country in which you reside, or in another hosting location agreed with the customer. If we need to share, store, access or otherwise process that information outside the applicable country or agreed hosting location, we will keep you informed before the planned transfer begins, or before a material change to an existing arrangement, unless the law prevents us from giving advance notice.
The information we provide will include, as applicable:
- the personal information or categories of information being shared, including whether sensitive information is involved;
- the destination country or countries and, where practicable, the recipient or service provider;
- why the transfer is necessary and how the information will be used;
- the legal basis, consent, authority or other permitted ground relied on for the transfer where relevant;
- the contractual, technical and organisational safeguards used to protect the information;
- the retention period, or the criteria used to determine it, and what will happen to the information when that period ends;
- whether onward transfers to another recipient or country are expected; and
- the rights, choices and complaint avenues available to you.
Any cross-border transfer will be limited to what is reasonably necessary for the stated purpose. We will apply the safeguards required by the law governing the transfer and require the recipient to delete, return or de-identify the information when the authorised retention period ends, subject to legal requirements.
If you use Omnicomply through an organisation, that organisation may contract with us for a specific approved hosting location for customer content. Where an agreed hosting location applies, that location governs the relevant customer content. This does not change the separate position for our corporate website, which is hosted in Australia. For our corporate website, Australia is the designated data-hosting location. Where a website service provider or optional third-party technology needs to process personal information outside Australia, the cross-border transparency commitments above apply.
10. Security and data breaches
We use technical and organisational measures appropriate to the nature of the information and the risks involved. These may include access controls, authentication, encryption, logging and monitoring, secure development practices, vulnerability management, backups and incident response.
If a personal data breach occurs, we assess it promptly, contain and remediate it, and notify affected individuals and regulators where applicable law requires notification.
11. How long we keep information
We keep personal information only for as long as we reasonably need it for the purpose for which it was collected, to provide or secure the service, maintain appropriate business and audit records, meet legal or contractual requirements, or establish and defend legal claims.
When information is no longer needed, we take reasonable steps to delete, destroy or de-identify it, subject to legal, backup, security and recordkeeping requirements. Customer content is retained and deleted in accordance with the customer agreement and configured service settings.
12. Marketing, cookies and similar technologies
We may send relevant business communications about Omnicomply, pilots, events and services where local law permits. Marketing communications will provide a practical way to opt out.
Our website uses cookies and similar technologies. Necessary technologies support operation and security. Optional preference, analytics or marketing technologies are subject to the choices described in our Cookie Policy and Configuration.
13. Your privacy rights
Depending on the law that applies, you may have the right to:
- ask whether we hold or process personal information about you and request access to it;
- ask us to correct inaccurate, incomplete or out-of-date information;
- ask us to delete information or restrict its use where the applicable law gives you that right;
- object to certain processing, including direct marketing;
- withdraw consent for future processing where consent is relied on;
- request portability of eligible information where that right applies;
- request information or safeguards relating to certain significant automated decisions; and
- make a complaint to us or an applicable privacy regulator.
To make a request, email info@omnicomply.ai with “Privacy Request” in the subject line. We may need enough information to verify your identity or authority. We will respond within the period required by applicable law.
If the information is held in a customer’s Omnicomply environment and we process it only on that customer’s instructions, please contact the customer first. We will support the customer where required.
14. Local privacy information
Australia
Where the Privacy Act 1988 (Cth) and Australian Privacy Principles apply, you may request access to and correction of personal information we hold about you and complain about our handling of personal information. We will also provide the transparency required for certain significant automated decisions where those requirements apply.
EU/EEA
Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, objection, data portability, withdrawal of consent and complaint to a supervisory authority. International transfers are subject to the safeguards required by Chapter V of the GDPR where applicable.
Singapore
Where Singapore’s Personal Data Protection Act applies, you may request access to and correction of applicable personal data and may withdraw consent where consent is relied on, subject to legal exceptions and reasonable consequences. Omnicomply maintains a business privacy contact for data-protection enquiries.
Malaysia
Where Malaysia’s Personal Data Protection Act 2010, as amended, applies, you may have rights to be informed about processing, request access and correction, withdraw consent, prevent certain processing likely to cause damage or distress, and object to direct marketing, subject to the Act. The approved policy should also be made available in Bahasa Malaysia where required.
15. Complaints
If you think we have handled your information incorrectly, contact info@omnicomply.ai with “Privacy Complaint” in the subject line. We will investigate and respond within a reasonable period.
You may also have the right to complain to the privacy or data-protection regulator that applies to you.
16. Children
Omnicomply is designed for organisations and business users, not children. We do not knowingly seek personal information from children through our general website, pilot or sales forms.
17. Contact us and policy updates
Omnicomply Pty Ltd
ABN 84 687 271 843
Victoria, Australia
Email: info@omnicomply.ai
We update this policy when our service, data flows, providers or legal obligations materially change. The current version will be published on our website with its last-updated date.
