About this policy
This Privacy Policy explains how Nexus Cyber Pty Ltd (ABN to be confirmed) (the operator, we, our, us) collects, holds, uses, and discloses personal information when you use the DMARC Hub service (the Service). It is published under the Australian Privacy Principles (APPs) set out in Schedule 1 of the Privacy Act 1988 (Cth).
If you are a customer of an organisation that uses the Service to monitor that organisation's email domains, your personal information is collected and handled by us as a service provider to that organisation. Where this Policy refers to obligations to you, those obligations are owed by us in our capacity as service provider; obligations of the organisation itself (your employer or service provider) are governed by their own privacy policy.
We are committed to handling personal information openly and transparently. If you have any questions or concerns, please contact us using the details at the end of this policy.
What information we collect
We collect only the personal information needed to operate the Service. The categories are:
- Account identifiers: your email address, your name (if provided), and the organisation you belong to.
- Authentication credentials: a hashed (argon2id) form of your password. We never store your password in cleartext and we cannot recover it; lost passwords require a reset.
- Service usage data: timestamps of sign-ins and significant actions you take within the Service (e.g. adding a domain, configuring a mailbox, viewing reports). These are recorded in a structured audit log retained for security investigation and forensic purposes.
- Technical metadata: the IP address you connect from, your user-agent string, and information necessary for session management (HTTP cookies that hold an Auth.js JWT identifying your session). Cookies are first-party, HTTP-only, and marked Secure in production.
- DMARC aggregate report content: when you configure a mailbox source, we ingest DMARC aggregate reports delivered to that mailbox. These reports contain sending IP addresses, DKIM/SPF authentication results, message counts, and (in some reporters' formats) envelope-from and header-from email addresses. Most of this is metadata about machines and messages, not about identifiable individuals; some envelope-from values may identify a specific sender.
We do not collect or process sensitive information (as defined in section 6 of the Privacy Act 1988) such as health information, racial or ethnic origin, religious beliefs, or biometric data. If you provide such information unsolicited, we will delete it on becoming aware of it, unless retention is required by law.
How we collect personal information
We collect information directly from you when you sign in, when an administrator creates an account for you and you redeem the invitation link, when you submit a password-reset request, when you use the Service, and when you contact us for support.
We also collect technical metadata automatically (cookies, IP address, user-agent) and aggregate-report content automatically from mailboxes you have configured the Service to poll.
We do not buy lists of personal information from third parties.
Why we collect and use personal information
We collect and use personal information for the primary purposes of:
- Authenticating you and authorising your actions within the Service (APP 6.1(a)).
- Providing the Service to the organisation you belong to — ingesting and analysing DMARC reports, surfacing the results in dashboards, sending operational notifications (password reset, account invitation).
- Maintaining the security of the Service — failed-login throttling, audit logging, fraud and abuse detection (APP 11.1).
- Responding to your support requests and complaints.
- Complying with legal obligations (record-keeping, lawful requests from regulators or law-enforcement under proper authority).
We will not use your personal information for any secondary purpose unrelated to those listed above unless we have your consent or another exception in APP 6 applies.
Marketing and email
Operational and security emails — password reset, account invitation, breach notification, billing-related notices — are sent on the basis that they are necessary for the Service you have asked us to provide; you cannot unsubscribe from these without closing your account.
We do not send unsolicited commercial electronic messages within the meaning of the Spam Act 2003 (Cth) from the DMARC Hub Service. If we begin a marketing program in future, it will be opt-in, will include a working unsubscribe facility, and will identify the sender.
Disclosure of personal information
We disclose personal information to:
- Your organisation, where personal information about you is collected in the context of that organisation's use of the Service. Your organisation's administrators can see your account record (email, name, role, last-login timestamp) and the actions you take within the Service.
- Service providers we engage to operate the Service, including the cloud-infrastructure provider hosting the Service (currently Amazon Web Services), the email-delivery provider used for transactional emails (currently Amazon SES), and (where applicable) Microsoft 365, with which we authenticate to poll your configured mailbox under credentials you provide to us. These providers handle personal information only on our instructions and under contractual confidentiality obligations.
- Regulators, courts, or law-enforcement agencies where required by law, by a lawfully issued subpoena, warrant, or production order, or where we reasonably believe disclosure is necessary to prevent serious harm.
We do not sell, rent, or trade personal information to third parties.
Cross-border disclosure
The Service is operated from Australia and your data is hosted in an Australian-region data centre (ap-southeast-2, Sydney). Our principal cloud providers (Amazon Web Services for hosting, Amazon SES for email delivery) are organisations headquartered in the United States operating in the Australian region under the AWS Global Customer Agreement.
Microsoft 365 mailbox polling involves API calls to Microsoft Graph endpoints. Microsoft Corporation, the operator of those endpoints, is headquartered in the United States. Microsoft offers data-residency guarantees for many regions; the operative residency depends on your organisation's Microsoft 365 tenant configuration, which is outside our control.
Where personal information is disclosed to a recipient outside Australia, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information, consistent with APP 8.1. By using the Service you acknowledge this cross-border disclosure.
Security and retention
We protect personal information in transit using TLS 1.2 or higher between your browser and the Service, and between the Service and its upstream providers. Passwords are stored only as argon2id hashes. Microsoft Graph mailbox credentials (client secrets and certificate passwords) are encrypted at rest using AES-256-GCM with a key held outside the database.
Operational access to the production environment is restricted to authorised engineering personnel and protected by strong authentication.
We retain personal information only for as long as it is needed for the purposes described above, or as required by law:
- Account records: retained while your account is active. On account closure, we delete identifying information within 30 days, retaining only an anonymised audit-log reference where ongoing security investigations or legal obligations require it.
- Authentication audit logs (sign-ins, failed attempts, lockouts): retained for 365 days, then pruned.
- DMARC aggregate report content: retained for as long as your organisation requires the historical analysis; pruned on your organisation's request or on account closure.
- Backups: retained for up to 35 days for disaster recovery; personal information remains protected by the security controls described above.
Data breach notification
We operate under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). If we become aware of a data breach involving personal information about you that is likely to result in serious harm to you, and we have not been able to remediate the breach to prevent that harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
Notification will describe the breach, the kinds of information involved, and the steps you can take to reduce harm.
Access, correction, and complaints
Under APP 12 you have the right to request access to the personal information we hold about you. Under APP 13 you have the right to request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading information. Most account information is directly visible and editable within the Service; for anything not exposed there, contact us using the details below.
If you believe we have breached an Australian Privacy Principle, you may make a complaint to us in writing using the contact details below. We will investigate your complaint and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au/privacy/privacy-complaints.
Cookies and similar technologies
We use only strictly-necessary cookies. A single HTTP-only, first-party cookie holds the JSON Web Token (JWT) that identifies your authenticated session and your selected impersonation context (where applicable). The cookie has a maximum lifetime of 24 hours and is automatically marked Secure when the Service is accessed over HTTPS.
We do not use third-party analytics cookies, advertising cookies, or social-media tracking pixels in the Service. We do not use the Google Analytics suite or any equivalent.
Changes to this policy
We may update this Privacy Policy from time to time. The effective date and version identifier at the top of this page indicate the current version. When we make material changes, we will request your renewed consent at your next sign-in. Continuing to use the Service after that renewed consent constitutes acceptance of the updated policy.
Prior versions of this policy are available on request.
Contact
Nexus Cyber Pty Ltd
Privacy enquiries: privacy@nexuscyber.com.au
General enquiries: ops@nexuscyber.com.au
Postal address: to be confirmed at publication.