Legal

PRISIMM Privacy Policy

Version 1.0.0 Effective date: 13 August 2026

This Privacy Policy describes how Barendon Holdings Pty Ltd (ABN 11 645 948 134) (PRISIMM, we, us, our) handles personal information in connection with the PRISIMM service (the Service). It forms part of the PRISIMM Terms of Service. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Who we are

PRISIMM audits websites and scores how well they support AI agents: whether a site is discoverable, machine-readable, correctly governed and usable by AI systems. The Service produces a numeric score, a report and a prioritised remediation list. PRISIMM is operated from Melbourne, Australia.

2. Scope of this policy

This policy covers the Service: the customer portal, audits, reports, connectors and associated APIs.

This is a single policy and it covers both surfaces. It applies to the PRISIMM marketing website as well as to the Service, so there is one document to read and one to keep current. Where a section applies to only one surface, it says so: the analytics position in section 14 is the clearest example.

3. What we collect and hold

Much of what the Service holds is information about websites and organisations rather than identifiable individuals: whether a robots.txt file exists, whether a sitemap is valid, whether a TLS certificate is current, whether machine-readable files are present. Information of that kind is generally not personal information. Personal information enters at the edges, and this section lists both.

PRISIMM primarily collects and analyses technical infrastructure data about corporate websites and domains. Where that data does not relate to a reasonably identifiable individual it is not personal information under section 6(1) of the Privacy Act 1988 (Cth), and it falls outside the scope of this policy. Where we do hold personal information, such as your account and billing details, or an individual's details incidentally published on a page we read, we handle it as set out below.

The exception we take seriously: sole traders and personal domains. A domain such as a consultant's own trading name can be inextricably linked to an identifiable individual, so observations about it may be personal information even though the same observations about a large company would not be. We do not attempt to classify domains one by one. Instead we apply the control in section 10: any readable text field incidentally captured from an audited site is de-identified after 90 days, leaving only the cryptographic hash. That control applies to every audited domain, so a sole trader gets it without having to ask and without us having to guess which domains are personal.

### 3.1 Account and billing information

### 3.2 Website observation data

### 3.3 Search-engine results data

We obtain search-results and business-listing data from a third-party provider, DataForSEO, by querying it with your domain name and brand-related search terms. This is the one class where we hold a raw third-party response, because our scoring depends on it. A raw search-results payload can incidentally contain personal information, so we delete it 30 days after the audit is scored, as section 10 sets out. The score, the hashes and the provenance record survive that deletion, so a past audit stays reproducible.

### 3.4 Support and communications

Messages you send us, support requests and our replies. We use a third-party customer messaging platform to handle support, and we sync a limited set of account attributes to it so we can help you without asking you to repeat yourself: your plan, your subscription status, your domain, your latest score and risk label, whether you are a founding member, your deployment status, the date of your last audit, and your marketing-consent setting.

### 3.5 Service and security records

Logs needed to operate and secure the Service, such as authentication events and API activity.

### 3.6 Technical and usage information collected automatically

When you use the Service we collect the following automatically:

### 3.7 Content you create in the Service

The identity content and clarifications you author and approve in the portal, which the Service publishes on your behalf as described in the Terms.

4. What we do not collect

5. How we collect

6. Why we collect, use and disclose it

We use the information above to:

Our audit scores are produced by a deterministic, versioned check registry. Remediation guidance text may be generated with AI assistance; the score itself contains no AI judgement.

Direct marketing. We send transactional messages because you need them: audit reports, verification, subscription confirmations, trial-conversion reminders, payment notices and service alerts. Those are part of the Service and you cannot opt out of them while you hold an account.

We send marketing messages only where you have consented, and we record that consent against your account. Every marketing message carries a one-click unsubscribe, and unsubscribing never affects the transactional messages above. We do not sell or rent your details to anyone for their own marketing.

7. Who we disclose it to

We disclose personal information only as needed to run the Service:

Our sub-processors, in full. We name them rather than describe them by category, so you can see exactly who handles what.

ProviderPurposeWhat is shared with them
StripePayment processingEmail, name, payment details
RenderApplication hosting and our primary databaseAll service data
CloudflareEdge security, content delivery and Schema Worker servingIP address, domain
DataForSEOSearch-results and business-listing evidenceDomain name, brand-related search queries
CrispCustomer support and CRMEmail, name, plan, subscription status, domain, latest score and risk label, founding-member flag, deployment status, last audit date, marketing consent
MailerSendTransactional email deliveryEmail, name, and the audit and subscription data used in the message
APITemplatePDF report generationThe audit data being rendered
Google Analytics 4Analytics on the marketing website only, never in the portalStandard analytics data with anonymised IP

We update this table when a provider changes. A provider used for AI processing of generated guidance text will be added here before that capability is switched on.

8. Overseas disclosure

Some of our providers store or process information outside Australia.

Where we disclose personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, as APP 8 requires.

9. Security

We take security seriously and apply it by default: encrypted connections (TLS) for collection and transfer, least-privilege access controls, multi-factor authentication on accounts, and a design that stores fingerprints of what we observed rather than page content. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Retention

We keep personal information only as long as we need it, and no row below is open. The 30-day free-audit result access window is a display window and not a retention period, so it deliberately does not appear in this table: the result stays viewable for 30 days while the underlying record is retained under the rows below.

ClassRetention period
Account and billing records7 years after the account closes, being the period section 286 of the Corporations Act 2001 (Cth) requires financial records to be kept
Free-audit requester details (name, email)De-identified 12 months after capture, or earlier on request. See the note below on why this reads "de-identified" and not "deleted"
Website observation data: normalised observations, cryptographic hashes and provenance recordsRetained indefinitely. This class is technical information about corporate websites and is generally not personal information, so the destruction obligation in APP 11.2 does not attach to it. It is retained so that a past score stays reproducible
Readable text fields incidentally captured from an audited site (for example a contact email or a social profile link)De-identified 90 days after capture, leaving only the cryptographic hash. This is the control for the sole-trader case in section 3
Raw search-results responses from our evidence provider30 days from the date the audit is scored, then deleted. A raw search-results payload can incidentally contain personal information, and it has served its purpose once the score is generated and validated and the window to query that audit has passed
Third-party benchmark resultsNative provider results contain no personal information and follow the subscription record
IP addresses collected for rate limiting and audit location30 days, then deleted
Support and communicationsWhile your account is open and for 24 months after it closes, then deleted
Service and security logs12 months, then deleted
Identity content and clarifications you authorWhile your account is open and for 12 months after it closes, then deleted
PDF reports we generated for youWhile your account is open and for 12 months after it closes, then deleted. The underlying audit record is retained, so a report can be regenerated within that period
Audit history and scores after your account closesDe-identified at 12 months. The record itself is retained, severed from you, for the reasons in section 11

Why the free-audit row reads "de-identified" rather than "deleted", stated plainly because it is a correction to our own earlier position. Our systems hold a free-audit requester in the same customer table as a subscriber, and that record is referenced by the audit they requested. There is no mechanism to remove the row without breaking the audit record, and no such mechanism is planned, because audit records are immutable by design. APP 11.2 permits an entity to destroy or de-identify, so we describe what we actually do. An earlier draft of this policy promised deletion, which we could not have performed.

11. Access, correction and deletion

You may request access to, or correction of, the personal information we hold about you, and we will respond consistently with APPs 12 and 13.

Portability. Your audit reports are available to download as PDFs, and the identity content you author is viewable and exportable from the portal at any time.

Deletion and audit immutability. Audit records are immutable by design: once an audit is scored it is never re-scored or altered, so that a score stays reproducible later. APP 11.2 lets us either destroy personal information or de-identify it, and we de-identify, because destroying the record would destroy the reproducibility the product depends on.

When you ask us to delete your data, we action the request within 30 days and we do three things:

1. We sever the link between your account and the audit records. 2. We scrub the readable personal information from the audit payload, such as names and any email addresses read from the site, replacing each with a REDACTED_APP_11 marker. 3. We retain the cryptographic hash, the score and the non-identifying technical metadata, which after step 2 can no longer be linked to you.

In short: if you request deletion, we delete your account, your billing history subject to the legal retention requirements in section 10, and any directly identifiable personal information. To preserve the integrity of our historical benchmarking we do not delete the cryptographic hashes of technical audits, but we fully de-identify those records so they can no longer be linked to you.

Your account is closed and your billing history is kept only for as long as Australian tax and corporate record-keeping law requires, per section 10. The change propagates to encrypted backups on the normal backup rotation cycle.

We do not say "we delete everything", because we do not. That sentence is the whole point of this section.

12. Websites we audit that are not our customers

We scan on the requester's authority, and that position is stated plainly in our Terms of Service at clauses 4.3 to 4.5: a customer nominates their own domain, and a free audit scans only the domain the requester submits (interim ruling R4, counsel to validate under Question D). A free audit may be requested for a domain the requester does not own. In performing it we fetch public pages over ordinary HTTPS at low rates, we do not attempt to access anything non-public, and we do not store raw page bodies.

We honour robots.txt. We treat a site's robots.txt as its stated wishes and we follow it, rather than treating "publicly reachable" as "fair game".

If you operate a website we have audited and you want us to stop, tell us using the contact method in section 19. We add your domain to our do-not-scan list and we stop. We will also tell you what we hold about the site and de-identify it on request. We do not require you to explain why.

Why we hold this position. Reading a page a website already publishes to the open internet, over ordinary HTTPS and without bypassing any password, paywall or other access control, operates under the implied licence that publishing to the open web grants. It is not unauthorised access. We honour robots.txt strictly because a site's stated wishes are the clearest signal of the limits of that licence. And once a site operator tells us to stop, the licence is revoked, so we stop: that is what the do-not-scan list is for.

We show, we do not publish. A result goes to the person who requested it. We do not publish scores about a business, or list them, or rank them, because an inaccurate adverse score published about a business could mislead the people who read it and could damage that business unfairly.

13. Agent-policy verification

One check verifies whether a site's published AI-agent policy is honoured in practice. It fetches a small number of public pages while identifying itself honestly as PRISIMM, and it operates inside a boundary we have written down and will not widen informally:

1. it runs against unauthenticated, public addresses only; 2. it makes at most 15 requests to any one domain in any 24-hour period; 3. it stops immediately for that run on an HTTP 429 or an HTTP 403 response; and 4. its user agent identifies PRISIMM and carries an address at which a site operator can ask us to stop.

It never presents another company's crawler identity, it does not attempt to bypass any access control, and it retains no page bodies. The check is disabled today and stays disabled until every one of those four conditions is enforced in the running system.

14. Cookies and similar technologies

The customer portal uses session cookies for authentication only. They keep you signed in and keep your session secure. There are no marketing or advertising cookies in the portal.

The marketing website uses Google Analytics 4, behind a cookie consent banner, so analytics cookies are set there only if you accept them. Declining does not affect your use of the Service.

15. Children

The Service is not intended for individuals under 18, we do not knowingly collect personal information from them, and the Terms require you to be at least 18 to hold an account.

16. Data breaches

We assess suspected data breaches under the Notifiable Data Breaches scheme and will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where the law requires.

17. Complaints

If you have a privacy concern or complaint, contact us using the details in section 19. We will acknowledge and investigate it, and respond within a reasonable time. If you are not satisfied with our response, you can complain to the OAIC at www.oaic.gov.au.

18. Changes to this policy

This policy is versioned like our Terms. The current version and its effective date appear at the top. If we make a material change, we will give reasonable notice through the Service.

19. Contact

Barendon Holdings Pty Ltd, owner of PRISIMM. ABN 11 645 948 134. Correspondence address: P.O. Box 874, Templestowe VIC 3106, Australia. Contact: through the contact form at https://prisimm.com/contact. We do not publish an email address. Privacy requests, complaints, and do-not-scan requests under section 12 all come through that form and are actioned by our privacy contact.

© 2026 Barendon Holdings Pty Ltd · ABN 11 645 948 134 PricingTermsPrivacyOur crawlerContact