Privacy Policy

PRIVACY POLICY

VanishingPoint Security
BankVault Pty Ltd ACN 117 130 257

Version 2.0
Effective 1 August 2026


We are built so that we hold as little information about you as possible. This policy explains what we hold, what we cannot hold, and what you can do about it.


IN SHORT

We identify you by an email address or username. We do not ask for your name or postal address.

We do not hold your payment card details. Payments are processed by Stripe.

The contents of your workspace are encrypted under keys that only you hold. We cannot decrypt or read them.

We are a temporary environment, not a data store. We do not back up your content, and we delete it.

We do not sell, rent or trade personal information, and we do not profile you for advertising.

The rest of this policy sets out the detail.


CONTENTS

1. Who We Are
2. What We Collect
3. What We Cannot Access
4. Why We Collect and How We Use It
5. Who We Disclose It To
6. Where Your Information Is Held
7. How Long We Keep It
8. How We Protect It
9. If Something Goes Wrong
10. Your Rights
11. Cookies
12. Children
13. Complaints
14. Changes to This Policy


1. WHO WE ARE

BankVault Pty Ltd ACN 117 130 257, trading as VanishingPoint Security, is an Australian company based in Perth, Western Australia.

For any privacy question, request or complaint, contact us at accounts@vanishingpointsecurity.com.

This policy applies to our websites and to all VanishingPoint Security and BankVault products and services.


2. WHAT WE COLLECT

Account information. The email address or username you register with, your account identifier, your subscription and plan status, and your service configuration settings.

Payment information. Payments are processed by Stripe, Inc. Stripe collects and holds your payment details directly. We receive confirmation of payment status and limited transaction metadata. We do not receive or store full card numbers. Stripe’s privacy policy applies to the information it holds and is available at stripe.com/privacy.

Technical and log data. When you visit our website or use the Service, our systems record the date and time, the IP address the request came from, the browser and operating system in use, the page that referred you, the address requested, and whether the request succeeded. We also record provisioning, session, authentication and error logs necessary to operate and secure the Service.

Referral and affiliate data. We operate an affiliate programme. If you arrive at our site through an affiliate or referral link, we and our affiliate tracking provider record the referral source and, if you subsequently sign up, the fact of that signup, so that commission can be calculated and paid. Affiliates receive aggregate or transactional reporting only. They do not receive your email address or account details from us.

Support communications. Anything you send us when you contact us for support, and our replies.

Encrypted workspace content. Where your plan includes a persistent workspace and you enable it, we store the encrypted contents of that workspace. See section 3.

Cookies. See section 11.

Some of this information may be capable of identifying you and some may not. Where it can be associated with you, we treat it as personal information.

We do not collect your name, postal address, date of birth, government identifiers, financial account details, biometric information, or any sensitive information as defined by the Privacy Act 1988 (Cth). We do not collect personal information from third party sources, data brokers, credit reporting bodies or consumer profiling services.


3. WHAT WE CANNOT ACCESS

Content in your workspace is encrypted before it is stored. The keys required to decrypt it are held solely by you and are derived from credentials that only you possess.

We do not hold, escrow, cache or retain any copy of those credentials or of the keys derived from them. We cannot access, decrypt, read, index, search, recover or reconstruct the contents of your workspace, and we have no administrative mechanism that would allow us to.

The specific cryptographic methods we use are part of our proprietary technology and are improved and replaced over time as the Service is upgraded. The properties described in this section apply regardless of the methods in use at any given time.

Two consequences follow.

If you lose your credentials, your workspace and everything in it is permanently and irrecoverably lost. We cannot restore it under any circumstances.

If we are lawfully compelled to produce information about your account, we can produce only what we actually hold. In respect of workspace content, that is encrypted data we are unable to decrypt.


4. WHY WE COLLECT AND HOW WE USE IT

We use the information we hold to:

create, authenticate and administer your account;

provision, deliver, maintain and support the Service;

process payments and issue invoices;

calculate and pay affiliate commissions;

detect, investigate and prevent security incidents, abuse and unlawful use;

communicate with you about the Service, including service, security and billing notices;

understand usage in aggregate so we can improve the Service;

comply with our legal obligations and to establish, exercise or defend legal claims.

We use information only where it is relevant to the purpose. We do not use your information for advertising, for automated decision making that produces legal or similarly significant effects, or for profiling.

If you are located in the European Economic Area or the United Kingdom, our lawful bases are: performance of our contract with you, for account, provisioning, billing and support; our legitimate interests in operating and securing the Service, preventing abuse, and administering our affiliate programme; compliance with legal obligations; and your consent, where we ask for it, which you may withdraw at any time.


5. WHO WE DISCLOSE IT TO

We disclose personal information only in the following circumstances.

Service providers. To providers who perform functions on our behalf, including payment processing, cloud and data centre infrastructure, affiliate tracking, email delivery, and support and monitoring tooling. They may use the information only to perform those functions for us, and are bound to protect it.

Legal. Where required by law, by a court order, subpoena or warrant, or by a regulator acting within its powers. Where we are lawfully able to do so, we will tell you that a disclosure has occurred.

Safety. Where we reasonably believe disclosure is necessary to prevent a serious and imminent threat to the life, health or safety of any person.

Enforcement. To law enforcement where we reasonably suspect unlawful activity, or to establish, exercise or defend a legal claim.

Business transfer. To an acquirer in connection with a sale, merger or transfer of our business or assets, subject to that acquirer being bound by terms no less protective than this policy.

In every case we disclose only what is necessary in the circumstances.

We do not sell, rent, trade or share your personal information for the commercial benefit of any third party.


6. WHERE YOUR INFORMATION IS HELD

Our infrastructure is currently located in Australia, principally in Perth, and from time to time in Sydney.

Because the Service provisions computing environments close to where they are needed, we may establish infrastructure in other countries in response to demand, sometimes at short notice, and may decommission it when it is no longer required. We will update this policy to reflect the regions in use. If you need to know where your workspace is provisioned at a given time, contact us.

Stripe processes payment information in the United States and other countries in which it operates. Our affiliate tracking provider may process referral data outside Australia.

Wherever workspace content resides, it is encrypted under keys held solely by you, and we are unable to read it.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. For customers in the European Economic Area or the United Kingdom, transfers to Australia and elsewhere are made where necessary for the performance of our contract with you, or under other appropriate safeguards.


7. HOW LONG WE KEEP IT

We keep personal information only as long as we need it.

Account information is retained while your account is active and for a reasonable period afterwards, so that we can meet legal, tax and accounting obligations and deal with any dispute.

Workspace content is temporary by design. Session workspaces are destroyed when the session ends. Persistent workspaces are retained only while your subscription is active. We are under no obligation to retain workspace content, and we may delete it at any time following cancellation, expiry, non-payment or termination. We do not back it up for you.

Logs are retained on short operational cycles and are then deleted or de-identified.

Referral and affiliate records are retained for as long as necessary to calculate and substantiate commission payments and to meet our accounting obligations.

Support communications are retained while relevant and then deleted.

We may retain information for longer where we are required to by law, or where it is necessary to establish, exercise or defend a legal claim, and only for as long as that applies.


8. HOW WE PROTECT IT

We implement commercially reasonable technical and organisational measures designed to protect personal information against loss and against unauthorised access, use, alteration or disclosure. These include encryption of data in transit, encryption of workspace content under customer held keys, network isolation, access controls on a least privilege basis, logging of administrative access, staff and contractor training, and defined consequences for misuse. These measures are reviewed and updated as the Service evolves.

Security is not static and no set of measures is complete. Most compromises arise from how credentials are managed rather than from the underlying systems. We strongly recommend that you never share your account, never disclose your credentials to any other person, and never record them where they can be found.


9. IF SOMETHING GOES WRONG

If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly.

Where the incident is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Where the General Data Protection Regulation or UK General Data Protection Regulation applies, we will notify the relevant supervisory authority within 72 hours of becoming aware, and affected individuals where required.


10. YOUR RIGHTS

Access. You may ask for a copy of the personal information we hold about you. We will respond without undue delay, and free of charge in ordinary cases.

Correction. You may ask us to correct information that is inaccurate, out of date or incomplete.

Deletion. You may ask us to delete your account and the personal information associated with it. We will do so unless we are required to retain it by law. Note that deleting your account does not recover, and cannot recover, workspace content that has already been lost.

Identity verification. Because we hold so little about you, our ability to verify who you are is limited. We can ordinarily deal with a request made from the email address registered to the account. A request made through any other channel may require additional steps, or we may be unable to act on it.

If you are located in the European Economic Area or the United Kingdom, you also have the right to object to processing based on our legitimate interests, to request restriction of processing, to data portability, and to withdraw consent where processing is based on consent.

To exercise any right, contact accounts@vanishingpointsecurity.com.


11. COOKIES

We use cookies and similar technologies on our website and in the Service.

Essential cookies are necessary for the site and Service to function, including for authentication and session management. These cannot be disabled without affecting the Service.

Affiliate and referral cookies record where a visitor came from, so that commission can be attributed to the correct affiliate if a signup follows. These are not used to build a profile of you or to serve advertising.

We do not currently use analytics or advertising cookies. If we introduce them, we will update this policy, and where consent is required we will obtain it before setting them.

You can control cookies through your browser settings. Blocking essential cookies will prevent parts of the Service from working.


12. CHILDREN

The Service is intended for use by adults in a business or professional capacity. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe we have, contact us and we will delete it.


13. COMPLAINTS

If you have a concern about how we have handled your personal information, contact us first at accounts@vanishingpointsecurity.com. We will acknowledge your complaint, investigate it, and respond within 30 days.

You may also complain at any time, and without contacting us first, to:

the Office of the Australian Information Commissioner, at oaic.gov.au;

your local data protection supervisory authority, if you are in the European Economic Area or the United Kingdom;

any other regulator with jurisdiction over your personal information.

Nothing in this policy or in our Terms and Conditions of Supply limits your right to complain to a regulator.


14. CHANGES TO THIS POLICY

We may update this policy. We will publish the updated version with a new version number and effective date.

Where a change is material, we will notify you by email or in-product notification before it takes effect.

Previous versions are available on request.


BankVault Pty Ltd ACN 117 130 257, trading as VanishingPoint Security
Perth, Western Australia
accounts@vanishingpointsecurity.com