← Back to RegIntel

Privacy Policy

Oryx Consulting Pty Ltd · ABN 76 651 693 793 · Privacy Act 1988 (Cth), Australian Privacy Principles

1. Who we are

RegIntel is operated by Oryx Consulting Pty Ltd (ABN 76 651 693 793) ("Oryx", "we", "us"), an Australian company. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Questions, access or correction requests, and complaints: richardm@oryxconsulting.com.au.

2. What we collect

Contact information: your name and email address when you request access to RegIntel, submit a form, or use our quiz and lead-capture pages.

Client documents: compliance documents your organisation uploads for assessment (policies, programs, registers, reports). These may incidentally contain personal information about your staff or customers.

Usage information: access logs and search queries, used to operate, secure and improve the platform.

3. Why we collect it (APP 3)

We collect personal information only for the purposes of providing the RegIntel service: authenticating access, performing compliance assessments you request, responding to enquiries, and improving the platform. We do not sell personal information, and we do not use client documents for marketing.

4. Where your data lives (APP 8 & 11)

Storage: all uploaded documents, assessment results and account information are stored in Australia (Supabase, hosted on AWS Sydney, ap-southeast-2). Our application runs on Vercel infrastructure in Sydney (syd1).

AI processing: assessments and search use Claude, operated by Anthropic (USA). Relevant document passages are transmitted for processing under a zero-data-retention configuration: content is processed transiently, is not stored by Anthropic, and is contractually excluded from AI model training. No personal information is stored outside Australia.

Subprocessors: Supabase (database, Sydney), Vercel (hosting, Sydney), Anthropic (AI processing, USA, zero retention), Resend (transactional email). All infrastructure providers hold ISO 27001 and/or SOC 2 Type II certifications.

5. How we secure it (APP 11)

Access to client data is authenticated and gated; database access is server-side only with row-level security enabled; nothing database-related is exposed to the browser. Documents are encrypted in transit (TLS) and at rest. Access to production systems is limited to authorised Oryx personnel.

When personal information is no longer required, we delete or de-identify it. Clients may request deletion of their uploaded documents and associated data at any time.

6. Cookies

RegIntel uses a single first-party authentication cookie to keep you signed in (7-day expiry). We do not use advertising or cross-site tracking cookies.

7. Access, correction and complaints (APP 12 & 13)

You may request access to, or correction of, personal information we hold about you by emailing richardm@oryxconsulting.com.au. We will respond within 30 days.

If you believe we have breached the APPs, contact us first and we will investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).

8. Data breaches

We comply with the Notifiable Data Breaches scheme. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC as required by law.

9. Changes to this policy

We may update this policy from time to time. The current version will always be available at this page, with the effective date below.

Effective date: 23 July 2026.

This policy describes our privacy practices and is provided for transparency. It is not legal advice to any client. For our data-flow and security documentation for vendor assessments, contact richardm@oryxconsulting.com.au. REGINTEL™ is a trade mark of Oryx Consulting Pty Ltd (Australian trade mark application pending, class 42).