Privacy Policy

Last updated: 27 April 2026

This Privacy Policy explains how FORTE/CYBERx Pty Ltd ("we", "us", "our") handles personal information in connection with the FORTE/CYBERx product (the "Service"), in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs 1โ€“13), including the Notifiable Data Breaches (NDB) scheme in Part IIIC of that Act.

1. Who we are

FORTE/CYBERx is an Australian cybersecurity and AI advisory firm headquartered in New South Wales. FORTE/CYBERx is our SaaS product providing AI-assisted decision support for information-security and technology leaders.

2. What we collect

  • Account data: name, email, organisation, role, optional phone.
  • Authentication data: hashed password, sign-in timestamps, TOTP MFA factor metadata (a reference to the enrolled factor โ€” never the shared secret), trusted-device tokens, and authentication assurance level (AAL) state.
  • Mission inputs: the challenge text, supporting context, advisor selections, and risk-appetite settings you submit.
  • Mission outputs: AI-generated advisor responses, board commentary, strategic options, and tactical execution plans.
  • Optional Big 5 leadership profile: only collected if you opt-in via Account โ†’ Leadership Profile. Used solely to lightly weight tactical-plan tone and emphasis. Can be deleted at any time without affecting any other Service functionality.
  • Referral data: referral codes you generate, referral codes you redeem, and the resulting linkage between your account and the referrer's account.
  • AI feedback events: ๐Ÿ‘ / ๐Ÿ‘Ž reactions and free-text comments you submit on advisor responses, tactical plans or Architect chat replies.
  • Usage analytics: page views, feature interactions, performance telemetry โ€” collected via Amplitude across the site.
  • Error-tracking events: exception messages, stack traces, and request URLs captured automatically when the application encounters an uncaught error, used to diagnose and fix bugs.
  • Billing data: Stripe customer ID and transaction metadata. Card details are processed by Stripe and never stored on our servers.
  • Support correspondence: email content, attachments and ticket metadata submitted via /support.
  • Cookies & device data: see our Cookie Policy.

3. How we use it

  • Operate the Service, deliver missions, and maintain account security.
  • Personalise advisor recommendations and dashboard analytics.
  • Process payments and manage credit balances.
  • Communicate operational notices, security alerts, and product updates.
  • Improve the Service through aggregated, de-identified analytics.
  • Improve advisor prompts and AI orchestration logic via aggregated, de-identified review of mission outputs (never raw inputs) by FORTE/CYBERx personnel.
  • Comply with legal, regulatory, and contractual obligations.

4. AI processing

Mission inputs are processed by large-language-model providers (currently Google Gemini 3.x Flash family, with selected functions also calling OpenAI) via secure server-side calls, routed through our managed AI gateway. We contractually instruct these providers not to use customer data to train their foundation models, and we do not transmit directly identifying account information with mission payloads where avoidable.

Aggregated, de-identified outputs (never raw inputs) may be reviewed by FORTE/CYBERx personnel for the purpose of improving advisor prompts, orchestration logic and output quality.

You are responsible for ensuring you have lawful basis to submit any third-party personal information contained in your mission inputs.

5. Data residency

Application data (accounts, missions, audit logs) is stored in our Supabase project hosted in the Sydney ap-southeast-2 AWS region. AI inference may transit provider regions outside Australia (see ยง11).

6. Third parties (sub-processors)

We share the minimum data required with vetted sub-processors:

  • Supabase โ€” database, auth, storage, edge functions. Hosted in AWS ap-southeast-2 (Sydney).
  • Managed cloud hosting โ€” application hosting and edge runtime. Global edge.
  • Managed AI gateway โ€” server-side proxy for LLM inference calls. Global.
  • Google AI (Gemini) โ€” primary LLM inference. United States.
  • OpenAI โ€” selected LLM inference for specific functions. United States.
  • Stripe โ€” credit-pack purchases and payment verification. Australia / United States.
  • Mailjet & Resend โ€” transactional email delivery (sign-in OTP codes, account notifications, mission completion alerts). EU / US.
  • HubSpot โ€” support tickets and CRM. United States.
  • Amplitude โ€” product analytics (events, sessions, autocapture). United States.
  • LinkedIn Insight Tag โ€” marketing conversion attribution on the public marketing surface (not loaded inside /app/*). United States.
  • Google Analytics 4 โ€” aggregate marketing analytics on the public surface. United States.

A current canonical sub-processor list is maintained at our Trust Center. We will publish material sub-processor changes on the Trust Center at least thirty (30) days before they take effect, so customers with regulated obligations can object before the change is in production.

7. Retention

  • Account data: retained for the life of the account + 7 years for Australian tax / audit obligations.
  • Soft-deleted accounts: 30 days during which the account can be restored on request; after 30 days, account data is permanently purged subject to the legal-hold and tax-retention exceptions in this section.
  • Mission inputs & outputs: retained for the life of the account unless you delete them in-product or request deletion.
  • Usage analytics: 12 months in Amplitude.
  • Referral linkage: life of account + 12 months.
  • Audit logs and NDB-eligible incident records: 7 years for regulatory obligations.
  • Backups: Supabase point-in-time-recovery snapshots retained for up to 7 days.

8. Your rights

Under the APPs, you may:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate information.
  • Delete your account at any time from Account โ†’ Delete account(initiates the 30-day soft-delete window described in ยง7).
  • Request a machine-readable export of your mission inputs and outputs by emailing info@fortecyberx.au (self-serve export will be added to the in-product Account screen in a future release).
  • Withdraw consent for marketing communications at any time.
  • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

9. Security

We protect data with TLS 1.3 in transit, AES-256 at rest, row-level security on every database table, optional TOTP MFA on accounts, scoped access controls for admins, and a mission audit log. See our Security Page for the full posture.

9.1 Notifiable Data Breaches scheme

We comply with the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth). Where we form a reasonable belief that a data breach has occurred and that it is likely to result in serious harm to one or more affected individuals (and we cannot prevent that harm through remedial action), we will:

  • Notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable;
  • Notify affected individuals as soon as practicable, including a description of the breach, the kinds of information involved, and the recommended steps in response;
  • Maintain an internal incident record retained for at least seven (7) years.

To report a suspected breach affecting your account, contact info@fortecyberx.au immediately.

10. Children

FORTE/CYBERx is not intended for use by individuals under 16 years of age. We do not knowingly collect personal information from children.

11. International transfers

Some sub-processors operate outside Australia. Where personal information is transferred offshore, we take reasonable steps to ensure the recipient handles it in a manner consistent with the APPs, including via written contractual obligations and standard data-protection clauses where applicable.

12. Cookies

We use strictly necessary, functional, analytics, and marketing cookies โ€” see our full Cookie Policy for categories and opt-out instructions.

13. GDPR / UK GDPR / FADP addendum

For visitors in the European Union, the United Kingdom, and Switzerland, our lawful bases under the EU GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection (FADP) are:contract (delivering the Service), legitimate interests (security, fraud prevention, product improvement), and consent (marketing communications and non-essential cookies).

EU / UK / Swiss data subjects also have the rights to portability,restriction, erasure, and objection, exercisable via the contact below. We act as data controller for account data and asdata processor for mission content. A standalone Data Processing Addendum (DPA) incorporating the European Commission's Standard Contractual Clauses (2021/914) is available on request to enterprise customers via info@fortecyberx.au.

14. Contact

Privacy enquiries: info@fortecyberx.au
Security disclosures: info@fortecyberx.au
General support: /support

FORTE/CYBERx Pty Ltd ยท Registered office: New South Wales, Australia ยท Contact: info@fortecyberx.au