Trust · Compliance posture

The paperwork behind the platform.

Data handling, subprocessors, privacy program, DPA, retention, residency, and cross border transfers, described in one place, in the terms your procurement, privacy, and legal teams already use.

Data handling

What we hold, why we hold it, and where it lives.

What we process

Source documents you upload, framework artifacts produced from them, generated instructional content, review history, evidence artifacts, and account metadata for the users you authorize.

Lawful basis

Processing is performed on the instruction of the customer as data controller under the master services agreement. We act as data processor. Purpose is bounded to service delivery.

Residency

Australian customers: production data in AWS ap-southeast-2 (Sydney). No routine replication across borders. Alternate residency is available on request for regulated deployments.

Retention

Content is retained for the term of the customer agreement plus a defined tail. On termination, data is exported on request and then deleted in line with the schedule in the DPA.

Deletion

Deletion initiated by the customer is honored on documented workflows. Full tenant deletion propagates to backups on the backup cycle schedule, with a written completion notice on request.

No model training

We do not use customer content to train third party foundation models. Where generative components are used, prompts and outputs remain within the customer's tenancy boundary.

Subprocessors

Who processes data on our behalf.

Named subprocessors are listed below. The full register (including legal entity, jurisdiction, and processing purpose) is provided to prospective customers on request. Material changes are notified to customers in line with the DPA.

Subprocessor
Purpose
Region / notes
Amazon Web Services
Cloud infrastructure. Compute, storage, database, key management.
ap-southeast-2 (Sydney) for AU tenants
Application observability provider
Performance monitoring and error tracking, with PII scrubbed at source
AU or EU regions per customer requirement
Transactional email provider
Account and workflow notifications only, not marketing
Standard contractual clauses in force where applicable
Customer support ticketing
Inbound support requests raised by customer administrators
Hosted in Australia where the vendor offers it
Privacy program

How the privacy program is run in practice.

Our privacy program is operated under the Australian Privacy Act 1988 and the Australian Privacy Principles. A named privacy contact receives requests from customers and, where relevant, from data subjects on customers' behalf. Requests to access, correct, or delete personal information are triaged against a documented workflow with defined response windows.

For customers whose end users reside in the European Union or the United Kingdom, we execute a data processing agreement incorporating the Standard Contractual Clauses where a transfer occurs. Where possible, EU/UK customer data is processed in a region that avoids the transfer altogether.

Data processing agreement

What the DPA covers.

Our DPA is available on request and can be executed alongside the master services agreement. It covers the controller/processor relationship, subprocessor authorization, security obligations, breach notification, mechanisms for cross border transfers, audit rights, and deletion or return of data on termination.

For regulated Australian customers, additional operating obligations (including those relevant to APRA CPS 234) can be reflected in schedules to the master services agreement. Customer legal and procurement teams should raise specific requirements during contracting.

Retention and deletion

How long we hold data.

Customer content is retained for the term of the customer agreement. On termination, the customer may request a full structured export for a defined window, after which data is deleted from primary systems on a documented schedule. Deletion propagates through backups on the backup cycle interval. A written completion notice is available on request.

Aggregate operational metrics that do not contain customer content or personal information may be retained for purposes of platform integrity beyond the customer term.

Australian Privacy Act alignment

How the platform maps to the APPs.

The Knowledge Foundry platform, and our operational practices around it, are designed to support customer obligations under the Australian Privacy Principles. Collection is limited to what the service requires. Notice is provided through the customer facing privacy policy and, for direct interactions, at the point of collection. Access, correction, and complaint handling are documented and time bound.

Where customer end users reside overseas, the customer remains the controller and determines the legal basis for processing. We support the customer's obligations with the documented residency, DPA, and subprocessor register described above.