Privacy Policy
Last updated: 1 June 2026
This Privacy Policy explains how Zoib Cyber handles your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Please read it alongside our Terms & Conditions.
1. About this policy
Zoib Cyber (“Zoib Cyber”, “we”, “us” or “our”) operates a multi-tenant software-as-a-service compliance platform that helps Australian businesses deliver privacy, cyber-security and AML/CTF training and build AML/CTF programs. We are committed to protecting your personal information and to handling it openly and transparently.
This policy explains how we collect, hold, use and disclose personal information in accordance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the 13 Australian Privacy Principles (APPs). It applies to our website, applications and related services (together, the “Platform”).
2. Whose information this policy covers
Zoib Cyber provides the Platform to organisations (our “Customers”) so their owners, administrators and staff can complete training and manage compliance. How we act depends on the information involved:
- Information you give us directly — for example when an organisation registers, an owner manages billing, or you contact support. We handle this information as the entity responsible for it under the APPs.
- Information handled on a Customer’s behalf — where a Customer organisation invites, uploads or manages its users (for example, learner records), we handle that personal information on the Customer’s instructions to provide the Platform. In those cases the Customer is responsible for telling its people how their information is used, for having a lawful basis to provide it, and for responding to their privacy requests. This policy describes our practices; the Customer’s own privacy policy governs its handling of your information.
If you are an employee or member of an organisation that uses Zoib Cyber and you have a question about your information, please contact your organisation in the first instance, or contact us and we will direct your request appropriately.
3. The kinds of personal information we collect and hold
The personal information we collect depends on how you use the Platform. It may include:
- Identity and account information — your first and last name, work email address, role within your organisation, and a securely hashed password.
- Authentication and security information — multi-factor authentication (TOTP) secrets and recovery codes (stored in protected or hashed form), single sign-on identifiers from Google or Microsoft where you use SSO, and session, sign-in and trusted-device records.
- Organisation and role data — the organisation you belong to, your group memberships, seat allocations and entitlements.
- Training and compliance evidence — modules assigned to you, your progress and completion records, quiz and scenario results, acknowledgements, certificates, and any external training records or files you upload.
- AML/CTF program information — where your organisation builds an AML/CTF program, this can include the names and positions of nominated personnel (such as the AML/CTF Compliance Officer) and business risk information you enter.
- Communications — feedback, support requests and related correspondence, and records of compliance emails we send you.
- Technical and usage information — IP address, browser user-agent, device and session data, audit-log entries recording security-relevant actions, and basic analytics about how the Platform is used.
- Billing information — your organisation’s subscription tier, seats and billing contact. Card payments, where applicable, are handled by our payment provider; we do not store full card numbers.
Sensitive information
We do not generally collect “sensitive information” as defined in the Privacy Act (such as health, racial or ethnic origin, religious beliefs, sexual orientation or criminal record). If we ever need to collect sensitive information, we will only do so with your consent or as otherwise permitted by law.
4. How we collect personal information
We collect personal information:
- Directly from you — when you register, accept an invitation, complete your profile, undertake training, upload records, or contact us.
- From your organisation — when a Customer invites you, bulk-uploads users, or assigns training to you.
- From third parties — such as Google or Microsoft when you sign in using single sign-on, limited to the identifiers and profile details needed to authenticate you.
- Automatically — through cookies and server logs as you use the Platform.
Where we collect your information from someone other than you, or where it is reasonable to do so, we take reasonable steps to make sure you are aware of the matters required by APP 5 (including who we are, why we collect the information, and how to contact us), generally through this policy.
5. Cookies and similar technologies
We use cookies that are strictly necessary to operate the Platform — for example to keep you signed in, maintain your session, protect against cross-site request forgery, and remember a trusted device for multi-factor authentication. We do not use third-party advertising cookies.
You can configure your browser to refuse cookies, but parts of the Platform may not function correctly without them.
6. Why we collect, hold, use and disclose your information
We collect, hold and use personal information for the following purposes (APP 6):
- To create and manage accounts and provide the Platform to you and your organisation.
- To deliver, track and record training, and to generate audit-ready completion evidence and certificates.
- To build, store and produce AML/CTF program documents your organisation generates.
- To authenticate users and keep the Platform secure, including MFA, access control and audit logging.
- To send service and compliance communications, such as assignment notices, reminders, certificates and account notices.
- To administer billing, subscriptions and seats.
- To respond to support requests and feedback.
- To improve and maintain the Platform, including using aggregated or de-identified data for analytics.
- To comply with our legal obligations and to establish, exercise or defend legal claims.
Direct marketing
We may occasionally send you information about Zoib Cyber products and updates. We will only do so where permitted under APP 7, and every marketing message will include a simple way to opt out. Service and compliance messages (such as training reminders and certificates) are part of the Platform and are not marketing.
7. Who we disclose your information to
We may disclose personal information to:
- Your organisation — owners and administrators within your organisation can see your training records, completion evidence and related data for the organisation you belong to. Our multi-tenant design keeps each organisation’s data isolated from other organisations.
- Service providers — trusted suppliers who help us run the Platform, such as cloud hosting and storage (Microsoft Azure), email delivery (Mailgun), and error-monitoring providers. They may only use the information to provide services to us.
- Professional advisers — such as auditors, lawyers and accountants, where reasonably required.
- Regulators, courts and law enforcement — where required or authorised by law.
- A successor entity — in connection with a sale, merger or reorganisation of our business, subject to appropriate confidentiality protections.
We do not sell your personal information.
8. Overseas disclosure
We host the Platform and store data in Australia where practicable. However, some of our service providers, or their sub-processors, may store or access personal information outside Australia — most commonly in the United States — including for email delivery, error monitoring and support tooling. Several of our providers are part of global groups headquartered overseas.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual protections (APP 8).
9. How we keep your information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11). These steps include:
- Encryption of data in transit (TLS) and at rest.
- Multi-factor authentication, enforced for owner and administrator roles.
- Role-based access controls and strict tenant isolation between organisations.
- Append-only, immutable completion and audit-log records.
- Hashed passwords and protected authentication secrets.
- Ongoing security monitoring, access restrictions and dependency management.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security.
10. Keeping your information accurate
We take reasonable steps to ensure the personal information we hold is accurate, up to date and complete (APP 10). You can review and update much of your information through your profile. Please let us, or your organisation’s administrator, know if any of your details change.
11. How long we keep your information
We keep personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it by law (APP 11.2).
Because the Platform exists to produce audit-ready compliance evidence, completion records, certificates and audit logs are designed to be immutable and are retained for as long as your organisation needs them to meet its record-keeping and regulatory obligations. For example, AML/CTF record-keeping obligations can require records to be kept for up to seven years. When information is no longer needed and we are not required to keep it, we take reasonable steps to destroy it or de-identify it.
12. Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 12 and APP 13). To make a request, contact us at hello@zoibcyber.com.au.
We will respond within a reasonable period (generally within 30 days). We may need to verify your identity first. Access is usually free, though we may charge a reasonable fee for some requests. If we refuse access or correction, we will tell you why and how you can complain.
Where the information relates to your use of the Platform as a member of a Customer organisation, we may need to refer your request to that organisation, which controls that data.
13. Data breaches
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of an eligible data breach that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required, and work with affected Customers to respond.
14. How to make a privacy complaint
If you believe we have breached the APPs or mishandled your personal information, please contact us at hello@zoibcyber.com.au with details of your concern. We will acknowledge your complaint, investigate it, and respond to you (generally within 30 days).
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
15. Third-party links and services
The Platform may link to, or integrate with, third-party services (such as Google and Microsoft sign-in). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before using them.
16. Children and young people
The Platform is a workplace training tool for organisations and their staff. It is not directed to the general public or marketed to children, and we do not knowingly collect personal information from members of the public under 18.
We recognise that some staff who need training may be under 18. Where an organisation adds a user who is under 18, that organisation is responsible for ensuring it has the authority or parental/guardian consent needed to provide that person’s information to us and for that person’s use of the Platform. We handle the personal information of young people in accordance with this policy and take particular care to protect it.
17. Changes to this policy
We may update this policy from time to time to reflect changes to our practices or legal obligations. The current version, with its effective date, will always be available on this page. Where changes are material, we will take reasonable steps to notify you.
18. Contact us
For any privacy question, request or complaint, contact our Privacy Officer:
- Zoib Cyber
- Email: hello@zoibcyber.com.au
You can read this policy alongside our Terms & Conditions.
Note: This Privacy Policy is provided for transparency about how the Zoib Cyber Platform handles personal information. It is general in nature and is not legal advice.