Legal
PRISIMM Privacy Policy
Version 1.0.0 Effective date: 13 August 2026
This Privacy Policy describes how Barendon Holdings Pty Ltd (ABN 11 645 948 134) (PRISIMM, we, us, our) handles personal information in connection with the PRISIMM service (the Service). It forms part of the PRISIMM Terms of Service. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who we are
PRISIMM audits websites and scores how well they support AI agents: whether a site is discoverable, machine-readable, correctly governed and usable by AI systems. The Service produces a numeric score, a report and a prioritised remediation list. PRISIMM is operated from Melbourne, Australia.
2. Scope of this policy
This policy covers the Service: the customer portal, audits, reports, connectors and associated APIs.
This is a single policy and it covers both surfaces. It applies to the PRISIMM marketing website as well as to the Service, so there is one document to read and one to keep current. Where a section applies to only one surface, it says so: the analytics position in section 14 is the clearest example.
3. What we collect and hold
Much of what the Service holds is information about websites and organisations rather than identifiable individuals: whether a robots.txt file exists, whether a sitemap is valid, whether a TLS certificate is current, whether machine-readable files are present. Information of that kind is generally not personal information. Personal information enters at the edges, and this section lists both.
PRISIMM primarily collects and analyses technical infrastructure data about corporate websites and domains. Where that data does not relate to a reasonably identifiable individual it is not personal information under section 6(1) of the Privacy Act 1988 (Cth), and it falls outside the scope of this policy. Where we do hold personal information, such as your account and billing details, or an individual's details incidentally published on a page we read, we handle it as set out below.
The exception we take seriously: sole traders and personal domains. A domain such as a consultant's own trading name can be inextricably linked to an identifiable individual, so observations about it may be personal information even though the same observations about a large company would not be. We do not attempt to classify domains one by one. Instead we apply the control in section 10: any readable text field incidentally captured from an audited site is de-identified after 90 days, leaving only the cryptographic hash. That control applies to every audited domain, so a sole trader gets it without having to ask and without us having to guess which domains are personal.
### 3.1 Account and billing information
- Name, email address and account details you provide at registration.
- Subscription, plan and billing records. Payments are processed by Stripe; we do not store your full card details.
- Records of the Terms version you accepted and when.
### 3.2 Website observation data
- Normalised observations about audited websites (for example, the presence and validity of robots.txt, sitemaps, TLS certificates and machine-readable files).
- Cryptographic hashes of responses: fingerprints proving what we saw, not the content itself.
- Provenance records: what was collected, when, and how.
- We deliberately do not store raw copies of the web pages we fetch. That storage decision is permanent by design.
- Where a crawled site publishes personal information, for example a contact page, a staff profile link or an email address in its markup, our observations may incidentally reference it. We do not seek it out and we do not build profiles from it. Any such readable text is de-identified 90 days after capture under section 10, leaving only the cryptographic hash.
### 3.3 Search-engine results data
We obtain search-results and business-listing data from a third-party provider, DataForSEO, by querying it with your domain name and brand-related search terms. This is the one class where we hold a raw third-party response, because our scoring depends on it. A raw search-results payload can incidentally contain personal information, so we delete it 30 days after the audit is scored, as section 10 sets out. The score, the hashes and the provenance record survive that deletion, so a past audit stays reproducible.
### 3.4 Support and communications
Messages you send us, support requests and our replies. We use a third-party customer messaging platform to handle support, and we sync a limited set of account attributes to it so we can help you without asking you to repeat yourself: your plan, your subscription status, your domain, your latest score and risk label, whether you are a founding member, your deployment status, the date of your last audit, and your marketing-consent setting.
### 3.5 Service and security records
Logs needed to operate and secure the Service, such as authentication events and API activity.
### 3.6 Technical and usage information collected automatically
When you use the Service we collect the following automatically:
- Your IP address, used to apply rate limits and, through our content-delivery provider, to determine the location an audit is run from.
- Approximate geographic location, being city, region and country, derived from that IP address by our content-delivery provider. We use it to set the audit location, because results can differ by region.
- Browser and device information, and usage information about how you move through the customer portal.
### 3.7 Content you create in the Service
The identity content and clarifications you author and approve in the portal, which the Service publishes on your behalf as described in the Terms.
4. What we do not collect
- Raw page bodies from audited websites (see 3.2).
- Full payment card numbers (Stripe holds these).
- We do not ask for sensitive information as defined by the Privacy Act, and the Service is not designed to collect it. We audit the technical construction of a website rather than its subject matter, so sensitive information is not something we look for. If a site we read happens to publish some, our observations record the technical facts about the page and not its content, and the 90-day de-identification in section 10 applies to any readable text we did capture.
5. How we collect
- Directly from you, when you create an account, subscribe or contact us.
- By automated scanning of websites: a domain you nominate as a customer, or a domain submitted for a free audit. A free-audit requester is not required to own the domain they submit, and section 12 sets out how we treat a site that is not our customer.
- From service providers: our payment processor (Stripe) and our search-results provider (DataForSEO).
6. Why we collect, use and disclose it
We use the information above to:
- provide the Service: run audits, produce scores, reports and remediation guidance;
- operate accounts, subscriptions, trials and billing;
- send transactional messages, including trial-conversion notices before a trial renews;
- provide support;
- secure the Service, prevent misuse and meet our legal obligations;
- improve the Service.
Our audit scores are produced by a deterministic, versioned check registry. Remediation guidance text may be generated with AI assistance; the score itself contains no AI judgement.
Direct marketing. We send transactional messages because you need them: audit reports, verification, subscription confirmations, trial-conversion reminders, payment notices and service alerts. Those are part of the Service and you cannot opt out of them while you hold an account.
We send marketing messages only where you have consented, and we record that consent against your account. Every marketing message carries a one-click unsubscribe, and unsubscribing never affects the transactional messages above. We do not sell or rent your details to anyone for their own marketing.
7. Who we disclose it to
We disclose personal information only as needed to run the Service:
Our sub-processors, in full. We name them rather than describe them by category, so you can see exactly who handles what.
| Provider | Purpose | What is shared with them |
|---|---|---|
| Stripe | Payment processing | Email, name, payment details |
| Render | Application hosting and our primary database | All service data |
| Cloudflare | Edge security, content delivery and Schema Worker serving | IP address, domain |
| DataForSEO | Search-results and business-listing evidence | Domain name, brand-related search queries |
| Crisp | Customer support and CRM | Email, name, plan, subscription status, domain, latest score and risk label, founding-member flag, deployment status, last audit date, marketing consent |
| MailerSend | Transactional email delivery | Email, name, and the audit and subscription data used in the message |
| APITemplate | PDF report generation | The audit data being rendered |
| Google Analytics 4 | Analytics on the marketing website only, never in the portal | Standard analytics data with anonymised IP |
We update this table when a provider changes. A provider used for AI processing of generated guidance text will be added here before that capability is switched on.
- Professional advisers and authorities where the law requires or permits it.
- We do not sell personal information.
8. Overseas disclosure
Some of our providers store or process information outside Australia.
- The United States. Our application hosting and primary database, which holds account, subscription and audit records, and our payment processor.
- The European Union. Our search-results and business-listing evidence provider.
- Globally distributed. Our content-delivery and edge-security provider operates a global network, so edge processing may occur in the region nearest the request.
Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, as APP 8 requires.
9. Security
We take security seriously and apply it by default: encrypted connections (TLS) for collection and transfer, least-privilege access controls, multi-factor authentication on accounts, and a design that stores fingerprints of what we observed rather than page content. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Retention
We keep personal information only as long as we need it, and no row below is open. The 30-day free-audit result access window is a display window and not a retention period, so it deliberately does not appear in this table: the result stays viewable for 30 days while the underlying record is retained under the rows below.
| Class | Retention period |
|---|---|
| Account and billing records | 7 years after the account closes, being the period section 286 of the Corporations Act 2001 (Cth) requires financial records to be kept |
| Free-audit requester details (name, email) | De-identified 12 months after capture, or earlier on request. See the note below on why this reads "de-identified" and not "deleted" |
| Website observation data: normalised observations, cryptographic hashes and provenance records | Retained indefinitely. This class is technical information about corporate websites and is generally not personal information, so the destruction obligation in APP 11.2 does not attach to it. It is retained so that a past score stays reproducible |
| Readable text fields incidentally captured from an audited site (for example a contact email or a social profile link) | De-identified 90 days after capture, leaving only the cryptographic hash. This is the control for the sole-trader case in section 3 |
| Raw search-results responses from our evidence provider | 30 days from the date the audit is scored, then deleted. A raw search-results payload can incidentally contain personal information, and it has served its purpose once the score is generated and validated and the window to query that audit has passed |
| Third-party benchmark results | Native provider results contain no personal information and follow the subscription record |
| IP addresses collected for rate limiting and audit location | 30 days, then deleted |
| Support and communications | While your account is open and for 24 months after it closes, then deleted |
| Service and security logs | 12 months, then deleted |
| Identity content and clarifications you author | While your account is open and for 12 months after it closes, then deleted |
| PDF reports we generated for you | While your account is open and for 12 months after it closes, then deleted. The underlying audit record is retained, so a report can be regenerated within that period |
| Audit history and scores after your account closes | De-identified at 12 months. The record itself is retained, severed from you, for the reasons in section 11 |
Why the free-audit row reads "de-identified" rather than "deleted", stated plainly because it is a correction to our own earlier position. Our systems hold a free-audit requester in the same customer table as a subscriber, and that record is referenced by the audit they requested. There is no mechanism to remove the row without breaking the audit record, and no such mechanism is planned, because audit records are immutable by design. APP 11.2 permits an entity to destroy or de-identify, so we describe what we actually do. An earlier draft of this policy promised deletion, which we could not have performed.
11. Access, correction and deletion
You may request access to, or correction of, the personal information we hold about you, and we will respond consistently with APPs 12 and 13.
Portability. Your audit reports are available to download as PDFs, and the identity content you author is viewable and exportable from the portal at any time.
Deletion and audit immutability. Audit records are immutable by design: once an audit is scored it is never re-scored or altered, so that a score stays reproducible later. APP 11.2 lets us either destroy personal information or de-identify it, and we de-identify, because destroying the record would destroy the reproducibility the product depends on.
When you ask us to delete your data, we action the request within 30 days and we do three things:
1. We sever the link between your account and the audit records. 2. We scrub the readable personal information from the audit payload, such as names and any email addresses read from the site, replacing each with a REDACTED_APP_11 marker. 3. We retain the cryptographic hash, the score and the non-identifying technical metadata, which after step 2 can no longer be linked to you.
In short: if you request deletion, we delete your account, your billing history subject to the legal retention requirements in section 10, and any directly identifiable personal information. To preserve the integrity of our historical benchmarking we do not delete the cryptographic hashes of technical audits, but we fully de-identify those records so they can no longer be linked to you.
Your account is closed and your billing history is kept only for as long as Australian tax and corporate record-keeping law requires, per section 10. The change propagates to encrypted backups on the normal backup rotation cycle.
We do not say "we delete everything", because we do not. That sentence is the whole point of this section.
12. Websites we audit that are not our customers
We scan on the requester's authority, and that position is stated plainly in our Terms of Service at clauses 4.3 to 4.5: a customer nominates their own domain, and a free audit scans only the domain the requester submits (interim ruling R4, counsel to validate under Question D). A free audit may be requested for a domain the requester does not own. In performing it we fetch public pages over ordinary HTTPS at low rates, we do not attempt to access anything non-public, and we do not store raw page bodies.
We honour robots.txt. We treat a site's robots.txt as its stated wishes and we follow it, rather than treating "publicly reachable" as "fair game".
If you operate a website we have audited and you want us to stop, tell us using the contact method in section 19. We add your domain to our do-not-scan list and we stop. We will also tell you what we hold about the site and de-identify it on request. We do not require you to explain why.
Why we hold this position. Reading a page a website already publishes to the open internet, over ordinary HTTPS and without bypassing any password, paywall or other access control, operates under the implied licence that publishing to the open web grants. It is not unauthorised access. We honour robots.txt strictly because a site's stated wishes are the clearest signal of the limits of that licence. And once a site operator tells us to stop, the licence is revoked, so we stop: that is what the do-not-scan list is for.
We show, we do not publish. A result goes to the person who requested it. We do not publish scores about a business, or list them, or rank them, because an inaccurate adverse score published about a business could mislead the people who read it and could damage that business unfairly.
13. Agent-policy verification
One check verifies whether a site's published AI-agent policy is honoured in practice. It fetches a small number of public pages while identifying itself honestly as PRISIMM, and it operates inside a boundary we have written down and will not widen informally:
1. it runs against unauthenticated, public addresses only; 2. it makes at most 15 requests to any one domain in any 24-hour period; 3. it stops immediately for that run on an HTTP 429 or an HTTP 403 response; and 4. its user agent identifies PRISIMM and carries an address at which a site operator can ask us to stop.
It never presents another company's crawler identity, it does not attempt to bypass any access control, and it retains no page bodies. The check is disabled today and stays disabled until every one of those four conditions is enforced in the running system.
14. Cookies and similar technologies
The customer portal uses session cookies for authentication only. They keep you signed in and keep your session secure. There are no marketing or advertising cookies in the portal.
The marketing website uses Google Analytics 4, behind a cookie consent banner, so analytics cookies are set there only if you accept them. Declining does not affect your use of the Service.
15. Children
The Service is not intended for individuals under 18, we do not knowingly collect personal information from them, and the Terms require you to be at least 18 to hold an account.
16. Data breaches
We assess suspected data breaches under the Notifiable Data Breaches scheme and will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where the law requires.
17. Complaints
If you have a privacy concern or complaint, contact us using the details in section 19. We will acknowledge and investigate it, and respond within a reasonable time. If you are not satisfied with our response, you can complain to the OAIC at www.oaic.gov.au.
18. Changes to this policy
This policy is versioned like our Terms. The current version and its effective date appear at the top. If we make a material change, we will give reasonable notice through the Service.
19. Contact
Barendon Holdings Pty Ltd, owner of PRISIMM. ABN 11 645 948 134. Correspondence address: P.O. Box 874, Templestowe VIC 3106, Australia. Contact: through the contact form at https://prisimm.com/contact. We do not publish an email address. Privacy requests, complaints, and do-not-scan requests under section 12 all come through that form and are actioned by our privacy contact.